The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 25, 2020

Filed:

Nov. 14, 2017
Applicant:

Lookingglass Cyber Solutions, Inc., Reston, VA (US);

Inventors:

Steven Weinstein, Baltimore, MD (US);

Jason Lewis, Baltimore, MD (US);

Douglas Parker, Owings Mills, MD (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 17/00 (2019.01); G06F 21/00 (2013.01); G06F 21/31 (2013.01); G06F 16/901 (2019.01); G06F 16/951 (2019.01);
U.S. Cl.
CPC ...
H04L 63/101 (2013.01); G06F 16/9014 (2019.01); G06F 17/00 (2013.01); G06F 21/00 (2013.01); H04L 63/083 (2013.01); H04L 63/1408 (2013.01); H04L 63/1425 (2013.01); G06F 16/951 (2019.01); G06F 21/31 (2013.01);
Abstract

In some embodiments, an apparatus includes a memory, storing processor-executable instructions, blacklist terms, and credential dump records, and a processor. The processor receives repository data from targeted remote repositories and stores the repository data as a potential credential dump in the memory when the repository data includes a credential dump attribute. The processor stores the potential credential dump as a probable credential dump when the potential credential dump does not include a blacklist term, in which case the processor also detects a format and delimiter of the probable credential dump. Based on the format and delimiter, pairs of usernames and associated passwords are identified and hashed. If a percentage of the hashes not associated with the credential dump records exceeds a predetermined threshold, the probable credential dump is deemed authentic.


Find Patent Forward Citations

Loading…