US2023156022A1PendingUtilityA1

System and methods for detecting and mitigating golden saml attacks against federated services

Assignee: QOMPLX INCPriority: Oct 28, 2015Filed: Jan 9, 2023Published: May 18, 2023
Est. expiryOct 28, 2035(~9.2 yrs left)· nominal 20-yr term from priority
H04L 63/126H04L 63/0815H04L 9/3239H04L 63/1466H04L 63/0876H04L 63/1425H04L 63/1416H04L 63/1433
73
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and methods for detecting and mitigating golden SAML attacks against federated services is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to create a security cookie for each valid authentication session; wherein subsequent access requests accompanied by authentication objects are validated by checking for a valid security cookie.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for detecting and mitigating golden SAML attacks against federated services, comprising:
 an authentication object inspector comprising at least a processor, a memory, and a plurality of programming instructions stored in the memory and operating on the processor, wherein the programmable instructions, when operating on the processor, cause the processor to:
 receive network traffic comprising a plurality of network packets, the plurality of network packets comprising at least a first authentication object known to be generated by an identity provider associated with a federated service; 
 store a record of the first authentication object, with attached metadata comprising at least a timestamp of when the authentication object was received, in a time-series database; 
 generate a security cookie for the first authentication object using a hashing engine; 
 provide the security cookie to the identity provider from which the first authentication object was generated; 
 receive a request for access to the federated service accompanied by a second authentication object; 
 compare a value of an ID string within the second authentication object against a value of a corresponding ID string within the stored record of the first authentication object; 
 check the second authentication object for a valid security cookie; and 
   a hashing engine comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing device, wherein the second plurality of programmable instructions, when operating on the processor, cause the computing device to:
 receive authentication objects from the authentication object inspector; 
 calculate a security cookie for each authentication object received by performing at least a plurality of calculations and transformations on each authentication object received; and 
 return the security cookie for each authentication object received to the authentication object inspector. 
   
     
     
         2 . The system of  claim 1 , wherein the authentication object inspector is operated by the identity provider. 
     
     
         3 . The system of  claim 1 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network. 
     
     
         4 . A method for detecting golden SAML attacks against federated services, comprising the steps of:
 (a) receiving a first authentication object at an authentication object inspector, the authentication object being generated by an identity provider;   (b) generating a security cookie for the first authentication object using a hashing engine;   (c) providing the security cookie to the identity provider from which the first authentication object was generated;   (d) receiving a request for access to a federated service accompanied by a second authentication object; and   (e) checking the second authentication object for a valid security cookie.   
     
     
         5 . The method of  claim 4 , wherein the identity provider includes the security cookie in additional authentication objects issued to the same user to which the first authentication object was issued. 
     
     
         6 . The method of  claim 4 , wherein a missing or invalid security cookie results in authentication failure.

Join the waitlist — get patent alerts

Track US2023156022A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.