US 12,273,357 B2
System and method for detecting lateral movement using SSH private keys
Avi Tal Lichtenstein, Tel Aviv (IL); Ami Luttwak, Binyamina (IL); and Yinon Costica, Tel Aviv (IL)
Assigned to Wiz, Inc., New York, NY (US)
Filed by Wiz, Inc., New York, NY (US)
Filed on Sep. 18, 2024, as Appl. No. 18/888,947.
Application 18/888,947 is a continuation of application No. 18/887,706, filed on Sep. 17, 2024.
Application 18/887,706 is a continuation of application No. 18/798,397, filed on Aug. 8, 2024.
Application 18/798,397 is a continuation of application No. 18/588,981, filed on Feb. 27, 2024, granted, now 12,095,777, issued on Sep. 17, 2024.
Application 18/588,981 is a continuation of application No. 18/457,752, filed on Aug. 29, 2023, granted, now 11,949,690, issued on Apr. 2, 2024.
Application 18/457,752 is a continuation of application No. 17/657,495, filed on Mar. 31, 2022, granted, now 11,799,874, issued on Oct. 24, 2023.
Claims priority of provisional application 63/170,123, filed on Apr. 2, 2021.
Prior Publication US 2025/0016175 A1, Jan. 9, 2025
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/14 (2013.01) 25 Claims
OG exemplary drawing
 
1. A method for detecting lateral movement based on an exposed cryptographic network protocol (CNP) key in a cloud computing environment, comprising:
inspecting a first workload for a private CNP key, the private CNP key associated with a hash of a public CNP key;
detecting a user identifier associated with the private CNP key;
detecting in a security database a representation of the public CNP key;
detecting in the security database a representation of a second workload connected to the representation of a second private CNP key; and
generating a lateral movement path, the lateral movement path including an identifier of the second workload, in response to detecting that the representation of the second private CNP key is connected to the representation of the public CNP key; and
generating a visual graph based on the generated lateral movement path and the detected user identifier.