Patent · US Active

Lateral movement analysis using certificate private keys

US11916926B1 · kind B1 · utility

9Cited by
7References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 29, 2023
Grant dateFeb 27, 2024
Priority date
Expiry dateSep 29, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0823
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and method for detecting potential lateral movement in a cloud computing environment includes detecting a private encryption key and a certificate, each of which further include a hash value of a respective public key, wherein the certificate is stored on a first resource deployed in the cloud computing environment; generating in a security graph: a private key node, a certificate node, and a resource node connected to the certificate node, wherein the security graph is a representation of the cloud computing environment; generating a connection in the security graph between the private key node and the certificate node, in response to determining a match between the hash values of the public key of the private key and the public key of the certificate; and determining that the first resource node is potentially compromised, in response to receiving an indication that an element of the public key is compromised.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.