US2022294829A1PendingUtilityA1

Privilege assurance of enterprise computer network environments

Assignee: QOMPLX INCPriority: Oct 28, 2015Filed: Mar 29, 2022Published: Sep 15, 2022
Est. expiryOct 28, 2035(~9.2 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/1441H04L 63/1433H04L 63/1408H04L 63/20H04L 67/12G06F 16/951H04L 67/306H04L 67/02G06F 16/2477
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for the prevention, mitigation, and detection of cyberattack attacks on computer networks by identifying weaknesses in directory access object allowances and providing professionals with centralized graph-centric tools to maintain and observe key security and performance insights into their security posture. The system uses an interrogation agent to collect Active Directory configuration parameters and activity information about a forest and the devices operating within. Cyber-physical graphs and histograms using persisted time-series data provides critical information, patterns, and alerts about configurations, attack vectors, and vulnerabilities which enable information technology and cybersecurity professionals greater leverage and control over their infrastructure.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for privilege assurance protection of computer networks, comprising:
 a graph engine comprising a first plurality of programming instructions stored in a memory of, and operating on a processor of, a first computing device, wherein the first plurality of programming instructions, when operating on the processor of the first computing device, cause the first computing device to:
 receive a plurality of messages from a plurality of devices on a network, each message comprising network information relevant to privilege assurance, the network information comprising device identifiers and configuration parameters; 
 create and store a cyber-physical graph of the computer network using the received messages, wherein the vertices of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects; 
 perform a plurality of queries over time on the cyber-physical graph for a cyberattack parameter of interest; 
 receive results of the plurality of queries; and 
 send the results to a time-series rule comparator; and 
   the time-series rule comparator comprising a second plurality of programming instructions stored in a memory of, and operating on a processor of, a second computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the second computing device to:
 receive the results from the graph engine; 
 measure changes over time in the results; 
 if the measurement of changes over time exceeds a threshold, identify the directory access protocol objects and relationships which caused the measurement of changes to exceed the threshold and send the results to a user interface. 
   
     
     
         2 . A method for privilege assurance protection of computer networks, comprising the steps of:
 receiving, at a graph engine, a plurality of messages from a plurality of devices on a network, each message comprising network information relevant to privilege assurance, the network information comprising device identifiers and configuration parameters;   using the graph engine, creating and storing a cyber-physical graph of the network using the received messages, wherein the vertices of the cyber-physical graph represent directory access protocol objects and the edges of the cyber-physical graph represent the relationships between those objects;   performing a plurality of queries over time on the cyber-physical graph for a cyberattack parameter of interest;   receiving results of the plurality of queries;   using a time-series rule comparator, measuring changes over time in the results; and   if the measurement of changes over time exceeds a threshold, identifying the directory access protocol objects and relationships which caused the measurement of changes to exceed the threshold and sending the results to a user interface.

Join the waitlist — get patent alerts

Track US2022294829A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.