FIELD: corporate network security.
SUBSTANCE: method for preventing compromise of directory service (MS AD) objects in a corporate network, in which: data is obtained from the corporate network's MS AD storage that characterizes network objects and their attributes; defining highly privileged objects (HVO) of MS AD and MS AD objects associated with the HVO, allowing access to them; forming a graph, where nodes are MS AD objects, and edges are access parameters between them; modelling attack paths against the HVO based on the resulting graph, determining a subgraph containing nodes that allow control over the HVO or its associated MS AD objects; monitoring MS AD objects to determine changes in access privilege parameters on subgraph nodes; transfer data on the objects identified on the subgraph to the control system when changing their access privileges; performing access privilege management on identified MS AD objects.
EFFECT: increased efficiency of protecting the corporate network from compromising objects and gaining access to highly privileged objects.
4 cl, 4 dwg, 2 tbl
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR PREVENTING COMPROMISE OF NETWORK INFRASTRUCTURE OBJECTS IN FREEIPA DIRECTORY SERVICE | 2023 |
|
RU2826430C1 |
STRATEGIES TO STUDY VULNERABILITIES AND TO SUPPRESS VULNERABILITIES CAUSED BY CAPTURING ACCOUNT DATA | 2007 |
|
RU2462753C2 |
SYSTEM AND METHOD OF INTERCEPTING FILE STREAMS | 2023 |
|
RU2816551C1 |
CONTROL SYSTEM FOR SECURITY POLICY OF ELEMENTS OF CORPORATE COMMUNICATION NETWORK | 2023 |
|
RU2813469C1 |
SYSTEM AND METHOD FOR PRIORITIZING INSTALLATION OF PATCHES ON COMPUTERS IN NETWORK | 2023 |
|
RU2813483C1 |
EXPERT ANALYSIS OF SYSTEM AND GRAPHIC DISPLAY OF PRIVILEGES ESCALATION ROUTES IN COMPUTING ENVIRONMENT | 2006 |
|
RU2421792C2 |
SYSTEM FOR CONTROLLING ACCESS TO FILES BASED ON MANUAL AND AUTOMATIC MARKUP THEREOF | 2013 |
|
RU2543556C2 |
SYSTEM FOR AUTOMATIC UPDATING AND GENERATION OF TECHNIQUES FOR IMPLEMENTING COMPUTER ATTACKS FOR INFORMATION SECURITY SYSTEM | 2023 |
|
RU2809929C1 |
SYSTEM FOR CONTROLLING ACCESS TO FILES BASED ON AUTOMATIC MARKUP THEREOF WITH ARRANGEMENT OF ACCOUNT DATA OF ACCESS SUBJECT TO CREATED FILE | 2015 |
|
RU2583759C1 |
SYSTEM AND METHOD FOR DEPLOYING PRECONFIGURED SOFTWARE | 2012 |
|
RU2541935C2 |
Authors
Dates
2023-07-04—Published
2022-11-30—Filed