Patent · US Active

Detecting attacks using compromised credentials via internal network monitoring

US10129298B2 · kind B2 · utility

8Cited by
5References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 30, 2016
Grant dateNov 13, 2018
Priority date
Expiry dateJul 17, 2036

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2151
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The threat of malicious parties exposing users' credentials from one system and applying the exposed credentials to a different system to gain unauthorized access is addressed in the present disclosure by systems and methods to preemptively and reactively mitigate the risk of users reusing passwords between systems. A security device passively monitors traffic comprising authorization requests within a network to reactively identify an ongoing attack based on its use of exposed credentials in the authorization request and identifies accounts that are vulnerable to attacks using exposed credentials by actively attempting to log into those accounts with exposed passwords from other networks. The systems and methods reduce the number of false positives associated with attack identification and strengthens the network against potential attacks, thus improving the network's security and reducing the amount of resources needed to securely manage the network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.