FIELD: corporate network security.
SUBSTANCE: method for preventing compromise of directory service (MS AD) objects in a corporate network, in which: data is obtained from the corporate network's MS AD storage that characterizes network objects and their attributes; defining highly privileged objects (HVO) of MS AD and MS AD objects associated with the HVO, allowing access to them; forming a graph, where nodes are MS AD objects, and edges are access parameters between them; modelling attack paths against the HVO based on the resulting graph, determining a subgraph containing nodes that allow control over the HVO or its associated MS AD objects; monitoring MS AD objects to determine changes in access privilege parameters on subgraph nodes; transfer data on the objects identified on the subgraph to the control system when changing their access privileges; performing access privilege management on identified MS AD objects.
EFFECT: increased efficiency of protecting the corporate network from compromising objects and gaining access to highly privileged objects.
4 cl, 4 dwg, 2 tbl
| Title | Year | Author | Number | 
|---|---|---|---|
| METHOD AND SYSTEM FOR PREVENTING COMPROMISE OF NETWORK INFRASTRUCTURE OBJECTS IN FREEIPA DIRECTORY SERVICE | 2023 | 
 | RU2826430C1 | 
| STRATEGIES TO STUDY VULNERABILITIES AND TO SUPPRESS VULNERABILITIES CAUSED BY CAPTURING ACCOUNT DATA | 2007 | 
 | RU2462753C2 | 
| METHOD OF DETECTING USE OF FAKE AUTHENTICATION DATA | 2024 | 
 | RU2830818C1 | 
| SYSTEM AND METHOD OF INTERCEPTING FILE STREAMS | 2023 | 
 | RU2816551C1 | 
| CONTROL SYSTEM FOR SECURITY POLICY OF ELEMENTS OF CORPORATE COMMUNICATION NETWORK | 2023 | 
 | RU2813469C1 | 
| SYSTEM AND METHOD FOR PRIORITIZING INSTALLATION OF PATCHES ON COMPUTERS IN NETWORK | 2023 | 
 | RU2813483C1 | 
| SYSTEM FOR CONTROLLING ACCESS TO FILES BASED ON MANUAL AND AUTOMATIC MARKUP THEREOF | 2013 | 
 | RU2543556C2 | 
| EXPERT ANALYSIS OF SYSTEM AND GRAPHIC DISPLAY OF PRIVILEGES ESCALATION ROUTES IN COMPUTING ENVIRONMENT | 2006 | 
 | RU2421792C2 | 
| SYSTEM FOR AUTOMATIC UPDATING AND GENERATION OF TECHNIQUES FOR IMPLEMENTING COMPUTER ATTACKS FOR INFORMATION SECURITY SYSTEM | 2023 | 
 | RU2809929C1 | 
| SYSTEM FOR CONTROLLING ACCESS TO FILES BASED ON AUTOMATIC MARKUP THEREOF WITH ARRANGEMENT OF ACCOUNT DATA OF ACCESS SUBJECT TO CREATED FILE | 2015 | 
 | RU2583759C1 | 
Authors
Dates
2023-07-04—Published
2022-11-30—Filed