Lateral movement analysis using certificate private keys

A system and method for detecting potential lateral movement in a cloud computing environment includes detecting a private encryption key and a certificate, each of which further include a hash value of a respective public key, wherein the certificate is stored on a first resource deployed in the cl...

Full description

Saved in:
Bibliographic Details
Main Authors Costica, Yinon, Lichtenstein, Avi Tal, Luttwak, Ami
Format Patent
LanguageEnglish
Published 17.09.2024
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A system and method for detecting potential lateral movement in a cloud computing environment includes detecting a private encryption key and a certificate, each of which further include a hash value of a respective public key, wherein the certificate is stored on a first resource deployed in the cloud computing environment; generating in a security graph: a private key node, a certificate node, and a resource node connected to the certificate node, wherein the security graph is a representation of the cloud computing environment; generating a connection in the security graph between the private key node and the certificate node, in response to determining a match between the hash values of the public key of the private key and the public key of the certificate; and determining that the first resource node is potentially compromised, in response to receiving an indication that an element of the public key is compromised.
Bibliography:Application Number: US202318394608