Kerberos interdiction and decryption for real-time analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Kerberos-based network authentication systems are vulnerable to advanced attacks like SolarWinds, which leverage multiple authentication protocols to gain unauthorized access, and require additional security measures like FAST and external stateful validation to enhance detection and prevention.
Innovation Solution
Implement a system and method for Kerberos interdiction and decryption using an interdiction agent that imports authentication private keys, decrypts network requests, analyzes the information for validity, and generates real-time notifications, combined with host-based agents for direct decryption and stateful validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Kerberos encryption is used for authentication, then security is improved, but vulnerability to advanced attacks like SolarWinds increases due to inability to detect credential compromise
Solution Approach 1:
The patent introduces an intermediary component (decryption module/agent) that sits between the Kerberos authentication process and the monitoring system. This intermediary captures encrypted Kerberos tickets, decrypts them using obtained session keys, and forwards the decrypted credentials to the SIEM system for analysis, enabling detection of compromised credentials while maintaining Kerberos encryption security
Solution Approach 2:
The system establishes a feedback loop where decrypted Kerberos credentials are continuously monitored and analyzed by the SIEM system. When anomalies or compromises are detected, the system can trigger alerts and responses, creating a closed-loop security mechanism that provides real-time feedback on authentication security status
2Difficulty of detecting and measuring
If FAST and external stateful validation are implemented, then detection capability is improved, but system complexity increases
Solution Approach 1:
The patent merges multiple security functions into a unified architecture: Kerberos FAST authentication, external stateful validation, ticket decryption, and SIEM integration are combined into a single cohesive system. The interdiction agent integrates credential capture, decryption, and forwarding functions, reducing operational complexity despite enhanced detection capabilities
Solution Approach 2:
The authentication system is designed with multi-functionality, where the same infrastructure supports both standard Kerberos authentication and enhanced security monitoring. The decryption agent can handle multiple ticket types and the SIEM system can analyze various authentication protocols (Kerberos, SAML, OAuth2), providing universal security monitoring across different authentication mechanisms
3Productivity
If real-time Kerberos ticket decryption is implemented, then credential monitoring is improved, but computational resources increase
Solution Approach 1:
The system implements partial decryption monitoring by focusing only on specific Kerberos tickets that require decryption based on predefined criteria (e.g., tickets from monitored services or users). The decryption agent selectively processes tickets rather than decrypting all Kerberos traffic, reducing computational overhead while maintaining effective credential monitoring for critical assets
Solution Approach 2:
The decryption agent obtains session keys automatically from the Kerberos Key Distribution Center (KDC) without requiring manual key management. The agent self-configures by requesting and storing session keys as needed, eliminating the need for complex key distribution infrastructure and reducing the computational burden of key management on the monitoring system
Data Source
AI summary
A system and methods for Kerberos protocol collection, interdiction and decryption for real-time analysis to aid in both operational and security functions in SSO-enabled networks, using agent processes that intercept and decrypt Kerberos traffic to identify compromised credentials and accounts in real-time without exposing sensitive information.


