Systems, methods, and computer program products for detecting anomalies in computing system based on related session data

By collecting and analyzing the session data of the source target server in the computing system, detecting and terminating abnormal communication sessions, the problem of difficult-to-prevent horizontal attacks in the computing system is solved, and the system security is improved.

CN120345211APending Publication Date: 2025-07-18VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380084422.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-09
Filing Date
2023-12-08
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The lack of micro-segment protection in computing systems makes it difficult to detect, track and prevent lateral attacks, especially when low-risk computing devices access high-risk computing devices to store sensitive information through lateral attacks.

Method used

By receiving connection requests from the source server, generating a communication session, collecting session data from the target and source servers, related to this data to detect exceptions, terminate an exception communication session, and store session data for further analysis.

Benefits of technology

Effectively detect and prevent lateral attacks, protect high-risk computing devices from unauthorized access, and improve the security of computing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120345211A_ABST
    Figure CN120345211A_ABST
Patent Text Reader

Abstract

Systems, methods, and computer program products are provided for detecting anomalies in a computing system using related session data from a source server and a target server. The method comprises the steps that a connection request for connection with a target server is received from a source server, the connection request comprises a login request for a service account on the target server, and the connection request is initiated by a user account on the source server; generating a communication session of the user account between the source server and the target server based on the connection request; collecting target server session data associated with the target server and source server session data associated with the source server; correlating the target server session data with the source server session data to provide related session data; and detecting an anomaly based on the relevant session data.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims priority to U.S. Provisional Patent Application No. 63 / 431,400, filed on December 9, 2022, the disclosure of which is hereby incorporated herein by reference in its entirety. Technical Field

[0003] This disclosure generally relates to detecting anomalies in a computing system, and in some non - limiting embodiments or aspects, to systems, methods, and computer program products for detecting anomalies in a computing system based on related session data. Background Art

[0004] In some cases, a computing system (e.g., a system of one or more computing devices connected via a communication network) may be configured to be protected by subsystems implemented in hardware and / or software at the computing system perimeter level (e.g., a firewall, etc.). However, the computing system may not implement micro - segmentation within the computing system. Micro - segmentation may include subsystems implemented with software instructions that protect (e.g., monitor, block, blacklist, etc.) connections and / or communications from one computing device to another within the computing system via the communication network.

[0005] However, implementing micro - segmentation in a computing system can be difficult and / or expensive. A computing system without micro - segmentation may be vulnerable to lateral attacks (e.g., potentially unauthorized, harmful, malicious, etc. connections and / or communications between computing devices via the communication network within the computing system). A lateral attack may be initiated in the computing system via a first computing device and may result in a user obtaining access to a second computing device in the computing system via the first computing device. For example, the first computing device may be considered a low - risk computing device (e.g., based on the computing device storing and / or accessing public information) and / or a computing device that the user is authorized to access. The second computing device may be considered a high - risk computing device (e.g., based on the computing device storing and / or accessing sensitive and / or private information) and / or a computing device that the user is not authorized to access. Thus, a user can access the second computing device via a lateral attack initiated on the first computing device, and such access may be difficult to detect, difficult to trace, and / or difficult to prevent. Summary of the Invention

[0006] Accordingly, systems, methods, and computer program products are provided for detecting anomalies in a computing system (e.g., overcoming some or all of the disadvantages identified above).

[0007] According to some non - limiting embodiments or aspects, there is provided a computer - implemented method for detecting anomalies in a computing system (e.g., a server system), which includes receiving a connection request for a connection to a target server from a source server. The connection request may include a login request for a service account on the target server. The connection request may be initiated by a user account on the source server. The method may further include generating a communication session of the service account between the source server and the target server based on the connection request. The method may further include collecting target server session data associated with the target server and including a service account identifier of the service account. The method may further include collecting source server session data associated with the source server and including a user account identifier of the user account based on the communication session. The method may further include correlating the target server session data with the source server session data to provide correlated session data. The method may further include detecting an anomaly based on the correlated session data.

[0008] In some non - limiting embodiments or aspects, the method may further include generating an alert based on detecting the anomaly. The method may further include terminating the communication session of the service account based on the alert.

[0009] In some non - limiting embodiments or aspects, the method may further include storing the target server session data and the source server session data in a data repository.

[0010] In some non - limiting embodiments or aspects, the method may further include retrieving the target server session data and the source server session data from the data repository.

[0011] In some non - limiting embodiments or aspects, correlating the target server session data with the source server session data to provide correlated session data may include: correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data. Correlating the target server session data with the source server session data to provide correlated session data may further include: correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data. Correlating the target server session data with the source server session data to provide correlated session data may further include: correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data. Correlating the target server session data with the source server session data to provide correlated session data may further include: correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data. Correlating the target server session data with the source server session data to provide correlated session data may further include: correlating the target timestamp of the target server session data with the source timestamp of the source server session data. The target timestamp may include a timestamp associated with the time of generating the communication session. The source timestamp may include a timestamp associated with the time when the source server received a response for generating the communication session from the target server.

[0012] In some non - limiting embodiments or aspects, detecting the anomaly based on the correlated session data may include: identifying, based on the correlated session data, the user account that initiated the communication session and the service account associated with the communication session. The correlated session data may include the user account identifier of the source server session data and the service account identifier of the target server session data. Detecting the anomaly based on the correlated session data may further include determining the existence of the anomaly. Determining the existence of the anomaly may include comparing the activities of the user account with one or more anomaly criteria. Detecting the anomaly based on the correlated session data may further include determining that the activities of the user account satisfy the one or more anomaly criteria.

[0013] According to some non - limiting embodiments or aspects, a system is provided that includes at least one processor and at least one non - transient computer - readable medium. The at least one non - transient computer - readable medium stores instructions that, when executed by the at least one processor, cause the at least one processor to receive, from a source server, a connection request for a connection to a target server. The connection request may include a login request for a service account on the target server. The connection request may be initiated by a user account on the source server. A communication session of the service account between the source server and the target server may be generated based on the connection request. Target server session data associated with the target server and including a service account identifier of the service account, and source server session data associated with the source server and including a user account identifier of the user account may be collected based on the communication session. The target server session data may be correlated with the source server session data to provide correlated session data. An anomaly may be detected based on the correlated session data.

[0014] In some non - limiting embodiments or aspects, an alert may be generated based on the detected anomaly. The communication session of the user account may be terminated based on the alert.

[0015] In some non - limiting embodiments or aspects, the communication session may be based on the Secure Shell protocol.

[0016] In some non - limiting embodiments or aspects, the target server session data and the source server session data may be stored in a data repository.

[0017] In some non - limiting embodiments or aspects, the login request may include a username of the service account and a password of the service account.

[0018] In some non - limiting embodiments or aspects, the login request may include a key associated with the Secure Shell protocol.

[0019] In some non - limiting embodiments or aspects, correlating the target server session data with the source server session data to provide correlated session data may include: correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data; correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data; correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data; correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data; and correlating the target timestamp of the target server session data with the source timestamp of the source server session data. The target timestamp may be associated with the time when the communication session is generated. The source timestamp may be associated with the time when the source server receives a response for generating the communication session from the target server.

[0020] In some non - limiting embodiments or aspects, detecting the anomaly based on the correlated session data may include: identifying, based on the correlated session data, the user account that initiated the communication session and the service account associated with the communication session, the correlated session data including the user account identifier of the source server session data and the service account identifier of the target server session data; and determining that the anomaly exists. Determining that the anomaly exists may include: comparing the activities of the user account with one or more anomaly criteria; and determining that the activities of the user account satisfy the one or more anomaly criteria.

[0021] According to some non - limiting embodiments or aspects, there is provided a computer program product comprising at least one non - transitory computer - readable medium, the at least one non - transitory computer - readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to receive, from a source server, a connection request for a connection to a target server. The connection request may include a login request for a service account on the target server. The connection request may be initiated by a user account on the source server. A communication session of the service account between the source server and the target server may be generated based on the connection request. Target server session data associated with the target server and including the service account identifier of the service account and source server session data associated with the source server and including the user account identifier of the user account may be collected based on the communication session. The target server session data may be correlated with the source server session data to provide correlated session data. An anomaly may be detected based on the correlated session data.

[0022] According to some non - limiting embodiments or aspects, a system is provided that includes at least one processor and at least one non - transient computer - readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to perform any of the methods described herein.

[0023] According to some non - limiting embodiments or aspects, a computer program product is provided that includes at least one non - transient computer - readable medium, the at least one non - transient computer - readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to perform any of the methods described herein.

[0024] Other non - limiting embodiments or aspects will be set forth in the numbered clauses below:

[0025] Clause 1: A computer - implemented method includes: receiving, by at least one processor, a connection request for a connection to a target server from a source server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; generating, by at least one processor, a communication session for the service account between the source server and the target server based on the connection request; collecting, by at least one processor, target server session data associated with the target server and including a service account identifier of the service account and source server session data associated with the source server and including a user account identifier of the user account based on the communication session; correlating, by at least one processor, the target server session data with the source server session data to provide correlated session data; and detecting, by at least one processor, an anomaly based on the correlated session data.

[0026] Clause 2: The computer - implemented method according to Clause 1 further includes: generating, by at least one processor, an alert based on detecting the anomaly; and terminating, by at least one processor, the communication session of the service account based on the alert.

[0027] Clause 3: The computer - implemented method according to Clause 1 or Clause 2, wherein the communication session is based on the Secure Shell protocol.

[0028] Clause 4: The computer - implemented method according to any one of Clauses 1 to 3 further includes: storing, by at least one processor, the target server session data and the source server session data in a data repository.

[0029] Clause 5: The computer-implemented method according to any one of Clauses 1 to 4, wherein the login request includes the username of the service account and the password of the service account.

[0030] Clause 6: The computer-implemented method according to any one of Clauses 1 to 5, wherein the login request includes a key associated with the Secure Shell protocol.

[0031] Clause 7: The computer-implemented method according to any one of Clauses 1 to 6, wherein the target server session data further includes: a source server identifier associated with the source server; a target server identifier associated with the target server; a source port number associated with the source server; a target port number associated with the target server; a target timestamp associated with the time when the communication session is generated; or any combination thereof.

[0032] Clause 8: The computer-implemented method according to any one of Clauses 1 to 7, wherein the source server session data further includes: a source server identifier associated with the source server; a target server identifier associated with the target server; a source port number associated with the source server; a target port number associated with the target server; a source timestamp associated with the time when the source server receives a response for generating the communication session from the target server; or any combination thereof.

[0033] Clause 9: The computer-implemented method according to any one of Clauses 1 to 8, further comprising: retrieving the target server session data and the source server session data from a data repository by using at least one processor.

[0034] Clause 10: The computer-implemented method according to any one of Clauses 1 to 9, wherein correlating the target server session data with the source server session data to provide correlated session data includes: correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data; correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data; correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data; correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data; and correlating the target timestamp of the target server session data with the source timestamp of the source server session data, the target timestamp being associated with the time when the communication session is generated, and the source timestamp being associated with the time when the source server receives a response for generating the communication session from the target server.

[0035] Clause 11: The computer-implemented method according to any one of Clauses 1 to 10, wherein detecting the anomaly based on the relevant session data includes: identifying, based on the relevant session data, the user account that initiated the communication session and the service account associated with the communication session, the relevant session data including the user account identifier of the source server session data and the service account identifier of the target server session data; and determining the existence of the anomaly, wherein determining the existence of the anomaly includes: comparing the activities of the user account with one or more anomaly criteria; and determining that the activities of the user account satisfy the one or more anomaly criteria.

[0036] Clause 12: A system, the system comprising: at least one processor; and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to: receive, from a source server, a connection request for a connection to a target server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; generate, based on the connection request, a communication session for the service account between the source server and the target server; collect, based on the communication session, target server session data associated with the target server and including the service account identifier of the service account and source server session data associated with the source server and including the user account identifier of the user account; correlate the target server session data with the source server session data to provide relevant session data; and detect an anomaly based on the relevant session data.

[0037] Clause 13: The system according to Clause 12, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to: generate an alert based on detecting the anomaly; and terminate the communication session of the user account based on the alert.

[0038] Clause 14: The system according to Clause 12 or Clause 13, wherein the communication session is based on the Secure Shell protocol.

[0039] Clause 15: The system according to any one of Clauses 12 to 14, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to: store the target server session data and the source server session data in a data repository.

[0040] Clause 16: The system according to any one of Clauses 12 to 15, wherein the login request includes the user name of the service account and the password of the service account.

[0041] Clause 17: The system according to any one of Clauses 12 to 16, wherein the login request includes a key associated with the Secure Shell protocol.

[0042] Clause 18: The system according to any one of Clauses 12 to 17, wherein correlating the target server session data with the source server session data to provide correlated session data includes: correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data; correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data; correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data; correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data; and correlating the target timestamp of the target server session data with the source timestamp of the source server session data, the target timestamp being associated with the time when the communication session is generated, and the source timestamp being associated with the time when the source server receives a response for generating the communication session from the target server.

[0043] Clause 19: The system according to any one of Clauses 12 to 18, wherein detecting the anomaly based on the correlated session data includes: identifying the user account that initiated the communication session and the service account associated with the communication session based on the correlated session data, the correlated session data including the user account identifier of the source server session data and the service account identifier of the target server session data; and determining the existence of the anomaly, wherein determining the existence of the anomaly includes: comparing the activities of the user account with one or more anomaly criteria; and determining that the activities of the user account satisfy the one or more anomaly criteria.

[0044] Clause 20: A computer program product, comprising at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: receive a connection request for a connection to a target server from a source server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; generate a communication session of the service account between the source server and the target server based on the connection request; collect target server session data associated with the target server and including a service account identifier of the service account and source server session data associated with the source server and including a user account identifier of the user account based on the communication session; correlate the target server session data with the source server session data to provide correlated session data; and detect an anomaly based on the correlated session data.

[0045] Clause 21: A system, comprising: at least one processor; and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to perform the method according to any one of the preceding claims.

[0046] Clause 22: A computer program product, comprising at least one non-transitory computer-readable medium containing program instructions that, when executed by at least one processor, cause the at least one processor to perform the method according to any one of Clauses 1 to 11.

[0047] These and other features and characteristics of the present disclosure, as well as the methods of operation and functions of the related structural elements and combinations of the various parts, and the manufacturing economy, will become more apparent when considering the following description and the appended claims in reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals designate corresponding parts in the various figures. However, it should be clearly understood that the drawings are for illustrative and descriptive purposes only and are not intended as a definition of the limits of the disclosed subject matter. Description of the Drawings

[0048] Additional advantages and details are explained in more detail below with reference to non-limiting exemplary embodiments shown in the schematic drawings, in which:

[0049] Figure 1 is a schematic diagram of a system for detecting anomalies in a computing system based on correlated session data according to some non-limiting embodiments or aspects;

[0050] Figure 2A flowchart of a method for detecting anomalies in a computing system based on relevant session data according to some non - limiting embodiments or aspects;

[0051] Figure 3 A diagram of an exemplary environment in which the methods, systems, and / or computer program products described herein may be implemented according to some non - limiting embodiments or aspects;

[0052] Figure 4 According to some non - limiting embodiments or aspects Figure 1 and / or Figure 3 A schematic diagram of example components of one or more devices; and

[0053] Figure 5 A schematic diagram of an exemplary implementation of a system and method for detecting anomalies in a computing system based on relevant session data according to some non - limiting embodiments or aspects. Detailed Description

[0054] For the following description, the terms "end", "upper", "lower", "right", "left", "vertical", "horizontal", "top", "bottom", "lateral", "longitudinal" and their derivatives shall relate to the orientation of the embodiments in the figures. However, it should be understood that the embodiments may adopt various alternative variations and step sequences, unless explicitly specified to the contrary. It should also be understood that the specific devices and processes shown in the figures and described in the following specification are merely exemplary embodiments or aspects of the disclosed subject matter. Accordingly, specific dimensions and other physical characteristics related to the embodiments or aspects disclosed herein should not be considered limiting.

[0055] As used herein, aspects, components, elements, structures, actions, steps, functions, instructions, etc. should not be construed as critical or essential unless explicitly so described. Also, as used herein, the article "a" is intended to include one or more items and may be interchangeable with "one or more" and "at least one". Further, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, combinations of related and unrelated items, etc.) and may be interchangeable with "one or more" or "at least one". In cases where only one item is desired, the term "one" or similar language is used. Moreover, as used herein, the term "having" and / or its like is intended to be an open - ended term. Additionally, unless otherwise explicitly stated, the phrase "based on" is intended to mean "at least partially based on". Additionally, a reference to an action "based on" a condition may mean that the action is "responsive to" the condition. For example, in some non - limiting embodiments or aspects, the phrases "based on" and "responsive to" may refer to a condition that automatically triggers an action (e.g., a specific operation of an electronic device such as a computing device, a processor, etc.).

[0056] As used herein, the term "acquiring party institution" may refer to an entity that is licensed and / or approved by a transaction service provider to initiate transactions (e.g., payment transactions) using a payment device associated with the transaction service provider. Transactions that an acquiring party institution may initiate can include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), and / or the like). In some non-limiting embodiments or aspects, the acquiring party institution may be a financial institution, such as a bank. As used herein, the term "acquiring party system" may refer to one or more computing devices operated by or on behalf of an acquiring party institution, such as a server computer executing one or more software applications.

[0057] As used herein, the term "account identifier" may include one or more primary account numbers (PANs), tokens, or other identifiers associated with a customer account. The term "token" may refer to an identifier that is used as an alternative or replacement for an original account identifier such as a PAN. An account identifier may be any combination of alphanumeric or characters and / or symbols. A token may be associated with a PAN or other original account identifier in one or more data structures (e.g., one or more databases, etc.) such that the token can be used to conduct a transaction without directly using the original account identifier. In some examples, an original account identifier such as a PAN may be associated with multiple tokens for different individuals or purposes.

[0058] As used herein, the term "communicate" may refer to the receipt, acceptance, sending, transmission, provision, etc. of data (e.g., information, signals, messages, instructions, commands, etc.). One unit (e.g., a device, system, component of a device or system, a combination thereof, etc.) communicating with another unit means that the one unit is capable of receiving information from and / or sending information to the other unit, either directly or indirectly. This may refer to a direct or indirect connection that is wired and / or wireless in nature (e.g., a direct communication connection, an indirect communication connection, and / or the like). Additionally, although the information being sent may be modified, processed, relayed, and / or routed between a first unit and a second unit, the two units may still communicate with each other. For example, a first unit may communicate with a second unit even if the first unit passively receives information and does not actively send information to the second unit. As another example, a first unit may communicate with a second unit if at least one intermediate unit processes the information received from the first unit and transmits the processed information to the second unit. In some non-limiting embodiments or aspects, a message may refer to a network packet (e.g., a data packet, etc.) that contains data. It should be understood that there may be many other arrangements.

[0059] As used herein, the term "computing device" may refer to one or more electronic devices configured to process data. In some examples, a computing device may include the necessary components for receiving, processing, and outputting data, such as a processor, a display, a memory, an input device, a network interface, and / or the like. A computing device may be a mobile device. As an example, a mobile device may include a cellular phone (e.g., a smartphone or a standard cellular phone), a portable computer, a wearable device (e.g., a watch, glasses, lenses, clothing, and / or the like), a personal digital assistant (PDA), and / or other similar devices. A computing device may also be a desktop computer or other forms of non-mobile computers.

[0060] As used herein, the terms "electronic wallet" and "electronic wallet application" refer to one or more electronic devices and / or software applications configured to initiate and / or conduct payment transactions. For example, an electronic wallet may include a mobile device that executes an electronic wallet application, and may also include server-side software and / or databases for maintaining transaction data and providing the transaction data to the mobile device. An "electronic wallet provider" may include an entity that provides and / or maintains an electronic wallet for customers, such as Google Android Apple Samsung and / or other similar electronic payment systems. In some non-limiting examples, an issuing bank may be an electronic wallet provider.

[0061] As used herein, the term "issuing entity" may refer to one or more entities, such as a bank, that provide customers with accounts for conducting transactions (e.g., payment transactions), such as initiating credit and / or debit payments. For example, an issuing entity may provide a customer with an account identifier that uniquely identifies one or more accounts associated with the customer, such as a PAN. The account identifier may be embodied on a portable financial device, such as a physical financial instrument (e.g., a payment card), and / or may be electronic and used for electronic payments. The term "issuing system" refers to one or more computer devices operated by or on behalf of an issuing entity, such as a server computer that executes one or more software applications. For example, an issuing system may include one or more authorization servers for authorizing transactions.

[0062] As used herein, the term "merchant" may refer to a person or entity that provides goods and / or services or access to goods and / or services to a customer based on a transaction, such as a payment transaction. The term "merchant" or "merchant system" may also refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer that executes one or more software applications.

[0063] As used herein, a "Point of Sale (POS) device" can refer to one or more devices that can be used by a merchant to conduct transactions (e.g., payment transactions) and / or process transactions. For example, a POS device can include one or more client devices. Additionally or alternatively, a POS device can include peripheral devices, card readers, scanning devices (e.g., code scanners), communication receivers, Near Field Communication (NFC) receivers, Radio Frequency Identification (RFID) receivers, and / or other non-contact transceivers or receivers, contact-based receivers, payment terminals, etc. As used herein, a "Point of Sale (POS) system" can refer to one or more client devices and / or peripheral devices used by a merchant to conduct transactions. For example, a POS system can include one or more POS devices and / or other similar devices that can be used to conduct payment transactions. In some non-limiting embodiments or aspects, a POS system (e.g., a merchant POS system) can include one or more server computers configured to process online payment transactions via a web page, a mobile application, and / or the like.

[0064] As used herein, the terms "client" and "client device" can refer to one or more client-side devices or systems (e.g., remotely located from a transaction service provider) used to initiate or facilitate a transaction (e.g., a payment transaction). As an example, a "client device" can refer to one or more POS devices used by a merchant, one or more acquirer host computers used by an acquirer, one or more mobile devices used by a user, etc. In some non-limiting embodiments or aspects, a client device can be an electronic device configured to communicate with one or more networks and initiate or facilitate a transaction. For example, a client device can include one or more computers, laptop computers, tablet computers, mobile devices, cellular phones, wearable devices (e.g., watches, glasses, lenses, clothing, etc.), PDAs, etc. Additionally, a "client" can also refer to an entity (e.g., a merchant, an acquirer, etc.) that owns, utilizes, and / or operates a client device to initiate a transaction (e.g., initiate a transaction with a transaction service provider).

[0065] As used herein, the term "payment device" can refer to a payment card (e.g., a credit card or a debit card), a gift card, a smart card, a smart medium, a payroll card, a healthcare card, a wristband, a machine-readable medium containing account information, a keychain device or fob, an RFID transponder, a retailer discount or membership card, a cellular phone, an electronic wallet mobile application, a Personal Digital Assistant (PDA), a pager, a security card, a computing device, an access card, a wireless terminal, a transponder, etc. In some non-limiting embodiments or aspects, a payment device can include volatile or non-volatile memory for storing information (e.g., an account identifier, an account holder's name, etc.).

[0066] As used herein, the term "payment gateway" may refer to an entity and / or a payment processing system operated by or on behalf of such entity, where the entity (such as a merchant service provider, payment service provider, payment facilitator, payment facilitator under contract with an acquirer, payment aggregator, etc.) provides payment services (such as transaction service provider payment services, payment processing services, etc.) to one or more merchants. The payment services may be associated with the use of a portable financial device managed by a transaction service provider. As used herein, the term "payment gateway system" may refer to one or more computer systems, computer devices, servers, server groups, etc. operated by or on behalf of a payment gateway.

[0067] As used herein, the term "server" may refer to or include one or more computing devices operated by multiple parties or facilitating communication and processing among multiple parties in a network environment such as the Internet, but it should be understood that communication may be facilitated through one or more public or private network environments and there may be various other arrangements. Additionally, multiple computing devices (such as servers, point-of-sale (POS) devices, mobile devices, etc.) that communicate directly or indirectly in a network environment may constitute a "system".

[0068] As used herein, the term "system" may refer to one or more computing devices or a combination of computing devices (such as processors, servers, client devices, software applications, their components, etc.). As used herein, references to "device", "server", "processor", etc. may refer to a previously recited device, server, or processor stated to perform a previous step or function, a different server or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server or first processor recited as performing a first step or first function may refer to the same or different server or the same or different processor recited as performing a second step or second function.

[0069] As used herein, the term "transaction service provider" may refer to an entity that receives a transaction authorization request from a merchant or other entity and, in some cases, provides payment assurance through an agreement between the transaction service provider and an issuer institution. For example, a transaction service provider may include, for example such payment networks, or any other entity that processes transactions. The term "transaction processing system" may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction processing server that executes one or more software applications. The transaction processing server may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.

[0070] Non-limiting embodiments or aspects of the disclosed subject matter relate to systems, methods, and computer program products for detecting anomalies, including but not limited to detecting anomalies in a computing system based on relevant session data from a source server and / or a target server. For example, non-limiting embodiments or aspects of the disclosed subject matter provide receiving, at a source server, a connection request for a connection to a target server. The connection request may include a login request for a service account on the target server. The connection request may be initiated by a user account on the source server. Non-limiting embodiments or aspects may generate a communication session for the service account between the source server and the target server based on the connection request. Non-limiting embodiments or aspects may collect target server session data associated with the target server and source server session data associated with the source server. The target server session data may include a service account identifier for the service account based on the communication session. The source server session data may include a user account identifier for the user account based on the communication session. Non-limiting embodiments or aspects may correlate the target server session data with the source server session data to provide relevant session data. Non-limiting embodiments or aspects may detect anomalies (e.g., in a computing system, with respect to a user account, etc.) based on the relevant session data. Such embodiments or aspects may provide techniques and systems for protecting a computing system (e.g., a system of one or more computing devices such as servers connected via a communication network) from lateral attacks (e.g., potentially unauthorized, harmful, malicious, etc. connections and / or communications between computing devices via a communication network within the computing system) and / or preventing lateral attacks in the case where the computing system does not implement micro-segmentation. Non-limiting embodiments or aspects may detect lateral attacks that may be initiated in a computing system via a computing device that may be considered a low-risk computing device (e.g., the computing device stores public information and / or is accessible by multiple users). Non-limiting embodiments or aspects may detect lateral attacks by a user attempting to access a computing device in a computing system that may be considered a high-risk computing device (e.g., the computing device stores sensitive and / or private information). Non-limiting embodiments or aspects may detect lateral attacks based on the username of a user attempting to access a computing device considered a high-risk computing device. Non-limiting embodiments or aspects provide collecting and / or extracting information associated with a user (e.g., the user's username, network information, source information, etc.) and information associated with the computing device the user is attempting to access (e.g., destination information, destination port, destination hostname, etc.). Non-limiting embodiments or aspects may utilize information associated with a user account and information associated with the computing device (e.g., target computing device) the user account is attempting to access in order to detect potentially malicious activities (e.g., anomalies, abnormal activities of the user, etc.) of the user account (e.g., the user using the user account).

[0071] Figure 1Describes system 100 for detecting anomalies in a computing system based on associated session data according to some non - limiting embodiments or aspects. System 100 may include an anomaly detection system 102, a plurality of servers (e.g., first server 104 - 1 and second server 104 - 2, collectively referred to as "servers 104" and individually as "server 104"), and / or a data repository 106. The anomaly detection system 102, servers 104, and / or data repository 106 may be interconnected (e.g., establish connections for communication) via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection.

[0072] The anomaly detection system 102 may include a computing device, such as a server (e.g., a single server), a server group, and / or other similar devices. In some non - limiting embodiments or aspects, the anomaly detection system 102 may include a processor and / or a memory, as described herein. In some non - limiting embodiments or aspects, the anomaly detection system 102 may include one or more software instructions (e.g., one or more software applications) executed on a server (e.g., a single server), a server group, a computing device (e.g., a single computing device), a computing device group, and / or other similar devices. In some non - limiting embodiments or aspects, the anomaly detection system 102 may be configured to perform one or more steps of the methods described herein. In some non - limiting embodiments or aspects, the anomaly detection system 102 may be configured to communicate with servers 104 and / or data repository 106. In some non - limiting embodiments or aspects, the anomaly detection system 102 may communicate with servers 104 and / or data repository 106 such that the anomaly detection system 102 is separate from servers 104 and / or data repository 106. In some non - limiting embodiments or aspects, at least one server 104 (e.g., all servers 104) and / or data repository 106 may be implemented by the anomaly detection system 102 (e.g., may be a part thereof).

[0073] Each server 104 may include at least one server, computing device, and / or at least one processor (e.g., a multi-core processor), such as a central processing unit (CPU), an accelerated processing unit (APU), a graphics processing unit (GPU), a microprocessor, and / or the like. In some non-limiting embodiments or aspects, the server 104 may be configured to perform one or more steps of the methods described herein. In some non-limiting embodiments or aspects, the server 104 may communicate with the data repository 106. In some non-limiting embodiments or aspects, the server 104 may be configured to receive information and / or transmit (e.g., send) information to / from the anomaly detection system 102, the data repository 106, and / or one or more other servers 104. In some non-limiting embodiments or aspects, the server 104 may execute a software instance of the anomaly detection system 102 (e.g., an instance of a software application including software instructions). In some non-limiting embodiments or aspects, the server 104 may be implemented by the anomaly detection system 102 (e.g., may be a part thereof). Alternatively, the server 104 may communicate with the anomaly detection system 102 such that the server 104 is separate from the anomaly detection system 102.

[0074] In some non-limiting embodiments or aspects, at least one server 104 may include a bastion host. A bastion host may refer to a dedicated computer (e.g., a dedicated server) in a communication network that may be configured to withstand attacks. For example, the bastion host may execute (e.g., host) a process and / or an application (e.g., a proxy server, a load balancer, etc.). In some non-limiting embodiments or aspects, the bastion host may not store sensitive or private information and / or may act as a gateway for the communication network (e.g., a server through which all traffic must pass in order to be sent within the communication network). In some non-limiting embodiments or aspects, the bastion host may include a first target server, and one or more client devices may connect to the first target server by sending a connection request from a user account on the one or more client devices to the bastion host. In this way, the client device may include a first source server.

[0075] The data repository 106 may include a computing device (e.g., a database device and / or the like) configured to communicate with the anomaly detection system 102 and / or the server 104 via a communication network. For example, the data repository 106 may include a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the data repository 106 may be associated with one or more computing devices that provide an interface so that a user (e.g., an administrative user, a user using a service account, etc.) can interact with the data repository 106 via the one or more computing devices. The data repository 106 may communicate with the anomaly detection system 102 and / or the server 104 so that the data repository 106 is separate from the anomaly detection system 102 and / or the server 104. Alternatively, in some non-limiting embodiments or aspects, the data repository 106 may be implemented by the anomaly detection system 102 and / or at least one server 104 (e.g., may be a part thereof).

[0076] Figure 1 The number and arrangement of systems and devices shown in the are provided as examples. Figure 1 There may be additional systems and / or devices, fewer systems and / or devices, different systems and / or devices, and / or systems and / or devices arranged in a different manner than the systems and / or devices shown in the drawings. Furthermore, the present invention may be implemented within a single system or device. Figure 1 Two or more systems or devices shown, or Figure 1 The single system or device shown may be implemented as multiple distributed systems or devices. Additionally or alternatively, a group of systems (e.g., one or more systems) or a group of devices (e.g., one or more devices) of system 100 may perform one or more functions described as being performed by another group of systems or another group of devices of system 100.

[0077] Reference now Figure 2 , illustrates a process 200 for detecting anomalies in a computing system using correlated session data, according to some non-limiting embodiments or aspects. Figure 2 The steps shown are for example purposes only. It should be understood that additional, fewer, different and / or different order steps may be used in non-limiting embodiments or aspects.

[0078] like Figure 2As shown, at step 202, process 200 may include receiving a connection request. For example, the second server 104-2 may receive a connection request for a connection with the second server 104-2 (e.g., the target server) from the first server 104-1 (e.g., the source server). In some non-limiting embodiments or aspects, the connection request may include a login request (e.g., a request including login credentials) to a service account on the second server 104-2 (e.g., the target server). In some non-limiting embodiments or aspects, the login request may include the username of the service account and the password of the service account (e.g., login credentials). In some non-limiting embodiments or aspects, the login request may include a key associated with a security protocol (e.g., the Secure Shell (SSH) protocol).

[0079] In some non-limiting embodiments or aspects, the connection request may be initiated by a user account (e.g., a logged-in user account and / or a user using the user account) on the first server 104-1 (e.g., the source server). In some non-limiting embodiments or aspects, the service account may include an account (e.g., an account for obtaining access to a computing system) that may include one or more access levels (e.g., roles, such as a privileged user role, an administrative user role, a root role, etc.). The service account may refer to an account that can be accessed by an application (e.g., a service) running on the server.

[0080] In some non-limiting embodiments or aspects, the source server (e.g., for one connection request and / or communication session) may include the target server (e.g., for another connection request and / or communication session). For example, the first server may include a first source server, and the second server may include a first target server. The second server may include a second source server, and the third server may include a second target server. In this example, the third server may include the target server relative to the second server, and the second server may include the source server relative to the third server. Thus, the second server may include a first target server and a second source server (e.g., a communication session chain from the first server to the second server and then to the third server). In this way, the second server may include the target server relative to the first server, and the second server may include the source server relative to the third server. Thus, the anomaly detection system 102 may include multiple servers 104 and / or communicate with the multiple servers, where each server 104 may include a source server and / or a target server (e.g., for different communication sessions).

[0081] As Figure 2As shown, at step 204, process 200 may include generating a communication session. For example, the second server 104-2 (e.g., the target server) may generate a communication session for the service account based on a connection request. In some non-limiting embodiments or aspects, the communication session may include a communication session between the first server 104-1 (e.g., the source server) and the second server 104-2 (e.g., the target server). The communication session may refer to a two-way link (e.g., a connection, a channel, etc.) between a first computing device and a second computing device. The two-way link may facilitate the exchange of information (e.g., data, messages, requests, responses, etc.) between the first computing device and the second computing device. The communication session may be generated at a first point in time and may be terminated at a second point in time later than the first point in time. The first computing device and the second computing device communicating via the communication session may include data associated with the state of the communication session (e.g., data associated with login credentials, data associated with a timestamp, data associated with the source server and / or the target server, etc.). The communication session may not be accessible by other computing devices and may only be accessible by the first computing device and the second computing device that initially established the communication session.

[0082] In some non-limiting embodiments or aspects, the communication session may include a session based on the Hypertext Transfer Protocol (HTTP), a session based on telnet, and / or another type of communication session that may be implemented and / or based on an application layer protocol. In some non-limiting embodiments or aspects, the communication session may be based on a security protocol (e.g., the Secure Shell (SSH) protocol).

[0083] As Figure 2As shown, at step 206, process 200 may include collecting source server session data and target server session data. For example, the second server 104-2 (e.g., the target server) and / or an instance of the anomaly detection system 102 (e.g., an agent) running on the second server 104-2 may collect target server session data associated with the target server (e.g., based on a communication session). Additionally or alternatively, the first server 104-1 (e.g., the source server) and / or an instance of the anomaly detection system 102 (e.g., an agent) running on the first server 104-1 may collect source server session data associated with the source server (e.g., based on a communication session). In some non-limiting embodiments or aspects, the target server session data may include a service account identifier (e.g., a username) of a service account. In some non-limiting embodiments or aspects, the source server session data may include a user account identifier (e.g., a username) of a user account. In some non-limiting embodiments or aspects, the anomaly detection system 102 (and / or each server 104) may store the target server session data and / or the source server session data in the data repository 106. In some non-limiting embodiments or aspects, the anomaly detection system 102 may receive (e.g., retrieve, access, etc.) the target server session data and / or the source server session data from a data repository (e.g., the data repository 106).

[0084] In some non-limiting embodiments or aspects, the target server session data may refer to data associated with a target server (e.g., the second server 104-2) that is tracked (e.g., stored and / or saved) by the target server participating in a communication session and / or used by the target server participating in a communication session to facilitate the communication session (e.g., data associated with the state of the communication session). For example, the target server session data may refer to data associated with the target server that identifies the target server as one or more endpoints of a communication session (e.g., a hostname, a port number, a process identifier, an Internet Protocol (IP) address, etc.), where the one or more endpoints may send and / or receive messages (e.g., requests and / or responses). The target server session data may refer to data associated with the target server generated based on a communication session. For example, the target server session data may refer to data associated with one or more timestamps generated by a communication session, data associated with one or more messages sent via the communication session, etc.

[0085] In some non - limiting embodiments or aspects, source server session data may refer to data associated with a source server (e.g., the first server 104 - 1), which is tracked by the source server participating in a communication session and / or used by the source server participating in the communication session to facilitate the communication session. For example, source server session data may refer to data associated with the source server that identifies the source server as one or more endpoints of a communication session (e.g., hostname, port number, process identifier, IP address, etc.), where the one or more endpoints may send and / or receive messages. Source server session data may refer to data associated with the source server generated based on the communication session. For example, source server session data may refer to data associated with one or more timestamps generated by the communication session, data associated with one or more messages sent via the communication session, etc.

[0086] In some non - limiting embodiments or aspects, when there are multiple communication sessions between different servers 104 (e.g., a communication session chain), a particular server 104 that acts as the target server for one communication session and the source server for another communication session may collect (e.g., via an instance of the anomaly detection system 102 thereon) both the source server session data of the one communication session and the target server session data of the other communication session. In this way, the particular server 104 may collect target session data based on the first communication session, where the particular server 104 includes the target server, and / or the particular server 104 may collect source server session data based on the second communication session, where the particular server 104 includes the source server.

[0087] In some non - limiting embodiments or aspects, the target server session data may include a source server identifier associated with the source server (e.g., IP address, hostname, etc.). In some non - limiting embodiments or aspects, the target server session data may include a target server identifier associated with the target server (e.g., IP address, hostname, etc.). In some non - limiting embodiments or aspects, the target server session data may include a source port number associated with the source server and / or a target port number associated with the target server. In some non - limiting embodiments or aspects, the target server session data may include a target timestamp associated with the time when the communication session is generated (e.g., a timestamp indicating the time when the target server generates the communication session).

[0088] In some non - limiting embodiments or aspects, the source server session data may include a source server identifier associated with the source server. In some non - limiting embodiments or aspects, the source server session data may include a target server identifier associated with the target server. In some non - limiting embodiments or aspects, the source server session data may include a source port number associated with the source server and / or a target port number associated with the target server. In some non - limiting embodiments or aspects, the source server session data may include a source timestamp associated with the time when the source server received a response from the target server to generate a communication session (e.g., a timestamp indicating the time when the source server received an acknowledgement that the target server has generated a communication session).

[0089] As Figure 2 shown, at step 208, process 200 may include correlating the target server session data with the source server session data. For example, the anomaly detection system 102 may correlate the target server session data with the source server session data to provide correlated session data. In some non - limiting embodiments or aspects, the anomaly detection system 102 may correlate the target server session data with the source server session data based on comparing the target server session data with the source server session data from the communication session.

[0090] In some non - limiting embodiments or aspects, the anomaly detection system 102 may correlate the target server session data with the source server session data to provide correlated session data by correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data. In some non - limiting embodiments or aspects, the anomaly detection system 102 may correlate the target server session data with the source server session data to provide correlated session data by correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data.

[0091] In some non - limiting embodiments or aspects, the anomaly detection system 102 may correlate the target server session data with the source server session data to provide correlated session data by correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data. In some non - limiting embodiments or aspects, the anomaly detection system 102 may correlate the target server session data with the source server session data to provide correlated session data by correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data.

[0092] In some non - limiting embodiments or aspects, the anomaly detection system 102 can correlate the target server session data with the source server session data by correlating the target timestamp of the target server session data with the source timestamp of the source server session data to provide correlated session data. In some non - limiting embodiments or aspects, the target timestamp can include a timestamp associated with the time of generating a communication session. In some non - limiting embodiments or aspects, the source timestamp can include a timestamp associated with the time when the source server receives a response (e.g., an acknowledgment response, a response acknowledging that a communication session has been generated, etc.) for generating a communication session from the target server.

[0093] As Figure 2 shown, at step 210, process 200 can include detecting an anomaly. For example, the anomaly detection system 102 can detect an anomaly (e.g., an anomaly regarding the activity of a user account and / or a service account on the target server) based on the correlated session data. In some non - limiting embodiments or aspects, the anomaly detection system 102 can detect an anomaly based on the correlated session data by identifying the user account that initiated the communication session and / or identifying the service account associated with the communication session based on the correlated session data. In some non - limiting embodiments or aspects, the correlated session data can include the user account identifier of the source server session data and the service account identifier of the target server session data.

[0094] In some non - limiting embodiments or aspects, the anomaly detection system 102 can detect an anomaly based on the correlated session data by determining the presence of an anomaly (e.g., present in the source server, the target server, and / or the anomaly detection system 102). In some non - limiting embodiments or aspects, the anomaly detection system 102 can determine the presence of an anomaly by comparing the activity of the user account with one or more anomaly criteria. In some non - limiting embodiments or aspects, the anomaly detection system 102 can determine the presence of an anomaly by determining that the activity of the user account meets one or more anomaly criteria. For example, the anomaly detection system 102 can determine the presence of an anomaly by determining that the user account associated with a connection request to a service account on the target server (e.g., the user account that initiated the connection request) is not permitted to access the target server using the service account. In this way, the anomaly detection system can utilize the user account identifier (e.g., username) of the user account to identify the user associated with an anomaly in initiating a connection request and / or a communication session.

[0095] In some non - limiting embodiments or aspects, the anomaly detection system 102 may detect anomalies based on (e.g., using) a machine - learning model. In some non - limiting embodiments or aspects, the anomaly detection system 102 may detect anomalies by sending relevant session data as input to a machine - learning model and using the machine - learning model to provide an output (e.g., a prediction) of the machine - learning model based on the relevant session data, where the output indicates the presence of an anomaly.

[0096] In some non - limiting embodiments or aspects, the anomaly detection system 102 may perform an action based on detecting an anomaly. For example, the anomaly detection system 102 may terminate a communication session based on detecting an anomaly (e.g., based on relevant session data associated with a communication session to be terminated).

[0097] In some non - limiting embodiments or aspects, anomaly criteria may refer to rules, policies, and / or definitions of anomalies that may be specific to the anomaly detection system 102 and / or the network of computing devices to which the anomaly detection system 102 belongs, and / or associated therewith. For example, the anomaly criteria may include a requirement to terminate the communication session if the duration of the communication session activity exceeds a predetermined duration. Additionally or alternatively, the anomaly criteria may include a requirement to deactivate a service account and / or a user account (e.g., revoke access rights of the service account and / or user account to one or more target servers, etc.) based on the activity of the service account and / or user account (e.g., performed by the service account and / or user account). In some non - limiting embodiments or aspects, the anomaly detection system 102 may implement one or more anomaly criteria to automatically detect anomalies. For example, the anomaly detection system 102 may be configured to detect anomalies via software instructions, machine - learning models, etc. Additionally or alternatively, the anomaly detection system 102 may be configured to detect anomalies based on one or more anomaly criteria for non - automatic (e.g., manual) detection of anomalies. For example, the anomaly detection system 102 may be configured to detect anomalies by providing an interface for a user to analyze relevant session data. The anomaly detection system 102 may allow the user to compare the relevant session data with the one or more anomaly criteria via the interface.

[0098] In some non - limiting embodiments or aspects, the anomaly detection system 102 may generate an alert based on the anomaly detection system 102 detecting an anomaly. In some non - limiting embodiments or aspects, the anomaly detection system 102 may terminate the communication session of a service account based on the alert.

[0099] Now refer to Figure 3 , Figure 3 is a diagram of a non - limiting embodiment or aspect of an exemplary environment 300 in which the systems, products, and / or methods described herein may be implemented. AsFigure 3 As shown, the environment 300 includes a transaction service provider system 302, an issuer system 304, a customer device 306, a merchant system 308, an acquirer system 310, and a communication network 312. In some non-limiting embodiments or aspects, each of the anomaly detection system 102, the server 104, and / or the data repository 106 may be implemented by the transaction service provider system 302 (e.g., as a part thereof). In some non-limiting embodiments or aspects, at least one of the anomaly detection system 102, the server 104, and / or the data repository 106 may be implemented by another system, another device, another group of systems, or another group of devices that is separate from or includes the transaction service provider system 302 (e.g., as a part thereof), such as by the issuer system 304, the merchant system 308, the acquirer system 310, etc.

[0100] The transaction service provider system 302 may include one or more devices capable of receiving information from and / or transmitting information to the issuer system 304, the customer device 306, the merchant system 308, and / or the acquirer system 310 via the communication network 312. For example, the transaction service provider system 302 may include computing devices such as servers (e.g., transaction processing servers, etc.), server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, the transaction service provider system 302 may be associated with a transaction service provider as described herein. In some non-limiting embodiments or aspects, the transaction service provider system 302 may communicate with a data storage device, which may be local or remote to the transaction service provider system 302. In some non-limiting embodiments or aspects, the transaction service provider system 302 is capable of receiving information from a data storage device, storing information in a data storage device, transmitting information to a data storage device, or searching for information stored in a data storage device.

[0101] The issuer system 304 may include one or more devices capable of receiving information from and / or transmitting information to the transaction service provider system 302, the customer device 306, the merchant system 308, and / or the acquirer system 310 via the communication network 312. For example, the issuer system 304 may include computing devices such as servers, server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, the issuer system 304 may be associated with an issuer institution as described herein. For example, the issuer system 304 may be associated with an issuer institution that issues credit accounts, debit accounts, credit cards, debit cards, etc. to users associated with the customer device 306.

[0102] The customer device 306 may include one or more devices capable of receiving information from and / or transmitting information to the transaction service provider system 302, the issuer system 304, the merchant system 308, and / or the acquirer system 310 via the communication network 312. Additionally or alternatively, each customer device 306 may include a device capable of receiving information from and / or transmitting information to other customer devices 306 via the communication network 312, another network (e.g., an ad-hoc network, a local network, a private network, a virtual private network, etc.), and / or any other suitable communication technology. For example, the customer device 306 may include a client device, etc. In some non-limiting embodiments or aspects, the customer device 306 may or may not be capable of receiving information via a short-range wireless communication connection (e.g., an NFC communication connection, an RFID communication connection, communication connection, communication connection, etc.) (e.g., from the merchant system 308 or from another customer device 306), and / or transmitting information via a short-range wireless communication connection (e.g., to the merchant system 308).

[0103] The merchant system 308 may include one or more devices capable of receiving information from and / or transmitting information to the transaction service provider system 302, the issuer system 304, the customer device 306, and / or the acquirer system 310 via the communication network 312. The merchant system 308 may also include a device capable of receiving information from the customer device 306 via the communication network 312, a communication connection with the customer device 306 (e.g., an NFC communication connection, an RFID communication connection, communication connection, communication connection, etc.), etc., and / or transmitting information to the customer device 306 via the communication network 312, the communication connection, etc. In some non-limiting embodiments or aspects, the merchant system 308 may include computing devices, such as servers, server clusters, client devices, client device clusters, and / or other similar devices. In some non-limiting embodiments or aspects, the merchant system 308 may be associated with a merchant as described herein. In some non-limiting embodiments or aspects, the merchant system 308 may include one or more client devices. For example, the merchant system 308 may include a client device that allows a merchant to transmit information to the transaction service provider system 302. In some non-limiting embodiments or aspects, the merchant system 308 may include one or more devices that can be used by a merchant to conduct transactions with a user, such as computers, computer systems, and / or peripheral devices. For example, the merchant system 308 may include a POS device and / or a POS system.

[0104] The acquirer system 310 may include one or more devices capable of receiving information from and / or transmitting information to the transaction service provider system 302, the issuer system 304, the client device 306, and / or the merchant system 308 via the communication network 312. For example, the acquirer system 310 may include a computing device, a server, a server group, etc. In some non-limiting embodiments or aspects, the acquirer system 310 may be associated with an acquirer, as described herein.

[0105] The communication network 312 may include one or more wired and / or wireless networks. For example, the communication network 312 may include a cellular network (e.g., Long Term Evolution). networks, third generation (3G) networks, fourth generation (4G) networks, fifth generation (5G) networks, code division multiple access (CDMA) networks, etc.), public land mobile networks (PLMNs), local area networks (LANs), wide area networks (WANs), metropolitan area networks (MANs), telephone networks (e.g., public switched telephone networks (PSTNs)), private networks (e.g., private networks associated with transaction service providers), ad hoc networks, intranets, the Internet, fiber-optic-based networks, cloud computing networks, etc., and / or combinations of these or other types of networks.

[0106] Provided as an example Figure 3 The number and arrangement of systems, devices, and / or networks shown are not intended to be construed as limiting the number and arrangement of systems, devices, and / or networks shown. Additional systems, devices, and / or networks may exist; fewer systems, devices, and / or networks; different systems, devices, and / or networks; and / or networks in a manner similar to that shown. Figure 3 The systems, devices and / or networks shown in the figure may be arranged in different ways. In addition, the system or device may be implemented in a single system or device. Figure 3 Two or more systems or devices shown, or Figure 3 The single system or device shown may be implemented as multiple distributed systems or devices. Additionally or alternatively, a set of systems (e.g., one or more systems) and / or a set of devices (e.g., one or more devices) of environment 300 may perform one or more functions described as being performed by another set of systems or another set of devices of environment 300.

[0107] Reference now Figure 4 , a diagram showing example components of an apparatus 400 according to a non-limiting embodiment or aspect. As an example, the apparatus 400 may correspond to Figure 1 At least one of the anomaly detection system 102, the server 104, and / or the data repository 106, and / or Figure 3 At least one of the transaction service provider system 302, the issuer system 304, the client device 306, the merchant system 308 and / or the acquirer system 310 in the transaction. In some non-limiting embodiments or aspects,Figure 1 or Figure 3 Such a system or device in Figure 3 may include at least one device 400 and / or at least one component of device 400. As an example, there is provided Figure 4 the number and arrangement of the components shown. In some non-limiting embodiments or aspects, compared with Figure 4 those components shown in Figure 4 , device 400 may include additional components, fewer components, different components, or components arranged in a different manner. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 may perform one or more functions described as being performed by another set of components of device 400.

[0108] As Figure 4 shown, device 400 may include a bus 402, a processor 404, a memory 406, a storage component 408, an input component 410, an output component 412, and a communication interface 414. Bus 402 may include components that permit communication between the components of device 400. In some non-limiting embodiments or aspects, processor 404 may be implemented in hardware, firmware, or a combination of hardware and software. For example, processor 404 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and / or any processing component that can be programmed and / or configured to perform functions (e.g., a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.). Memory 406 may include random access memory (RAM), read only memory (ROM), and / or another type of dynamic or static storage device that stores information and / or instructions for use by processor 404 (e.g., flash memory, magnetic memory, optical memory, etc.). In some non-limiting embodiments or aspects, memory 406 may be the same as or similar to data repository 106.

[0109] Continuing to refer to Figure 4, the storage component 408 can store information and / or software related to the operation and use of the device 400. For example, the storage component 408 can include a hard disk (such as a magnetic disk, an optical disk, a magneto-optical disk, a solid-state disk, etc.) and / or another type of computer-readable medium. In some non-limiting embodiments or aspects, the storage component 408 can be the same as or similar to the data repository 106. The input component 410 can include components that allow the device 400 to receive information, for example, through user input (such as a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, etc.). Additionally or alternatively, the input component 410 can include sensors for sensing information (such as a Global Positioning System (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). The output component 412 can include components that provide output information from the device 400 (such as a display, a speaker, one or more light-emitting diodes (LEDs), etc.). The communication interface 414 can include transceiver-like components (such as a transceiver, a separate receiver and transmitter, etc.) that enable the device 400 to communicate with other devices, for example, via a wired connection, a wireless connection, or a combination of wired and wireless connections. The communication interface 414 can allow the device 400 to receive information from another device and / or provide information to another device. For example, the communication interface 414 can include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a Universal Serial Bus (USB) interface, interface, a cellular network interface, etc.

[0110] The device 400 can perform one or more of the processes described herein. The device 400 can perform these processes based on software instructions stored in a computer-readable medium such as the memory 406 and / or the storage component 408 by the processor 404. The computer-readable medium can include any non-transitory memory device. The memory device includes a memory space located inside a single physical storage device or a memory space spread across multiple physical storage devices. The software instructions can be read into the memory 406 and / or the storage component 408 from another computer-readable medium or from another device through the communication interface 414. When executed, the software instructions stored in the memory 406 and / or the storage component 408 can cause the processor 404 to perform one or more of the processes described herein. Additionally or alternatively, hardwired circuitry can be used instead of or in combination with software instructions to perform one or more of the processes described herein. Therefore, the embodiments described herein are not limited to any specific combination of hardware circuitry and software. As used herein, the term "configured to" can refer to an arrangement of software, a device, and / or hardware for performing and / or implementing one or more functions (such as actions, processes, steps of a process, etc.). For example, a "processor configured to..." can refer to a processor that executes software instructions (such as program code) that cause the processor to perform one or more functions.

[0111] Now refer toFigure 5 , according to some non - restrictive embodiments or aspects, a schematic diagram of an exemplary implementation 500 of a system and method for detecting anomalies in a computing system based on relevant session data is shown. In some non - restrictive embodiments or aspects, implementation 500 may include an anomaly detection system 502, a plurality of servers (e.g., a first server 104 - 1, a second server 104 - 2, …, an nth server 504 - N, collectively referred to as "servers 504" and individually as "server 504"), a data repository 506, a user device 508, and / or an administrator device 509. The anomaly detection system 502, servers 504, data repository 506, user device 508, and / or administrator device 509 may be interconnected (e.g., establish connections for communication) via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection. In some non - restrictive embodiments or aspects, the anomaly detection system 502 may be the same as or similar to the anomaly detection system 102. In some non - restrictive embodiments or aspects, the server 504 may be the same as or similar to the server 104. In some non - restrictive embodiments or aspects, the data repository 506 may be the same as or similar to the data repository 106.

[0112] The user device 508 may include a computing device associated with a user. For example, the user may have a user account. In some non - restrictive embodiments or aspects, the user account may enable the user to access the user device 508. Additionally or alternatively, the user account may also enable the user to access at least one server 504 (e.g., via the user device 508). In some non - restrictive embodiments or aspects, the user account may be associated with login credentials (e.g., the user's username, the user's password, a key associated with the user, biometric information associated with the user, other login credentials, any combination thereof, etc.), and the user may use the login credentials (e.g., input into the user device 508, etc.) to access the user device 508 and / or at least one server 504.

[0113] In some non - restrictive embodiments or aspects, the user device 508 may be connected to the first server 504 - 1 (e.g., a bastion host server, etc.) based on the user account. For example, based on the user account, the user device 508 may access the first server 504 - 1 via a production access 530.

[0114] Each server 504 may include at least one server, at least one computing device, and / or at least one processor, as described herein. For example, each server 504 may be the same as or similar to the server 104. In some non - restrictive embodiments or aspects, at least one server 504 (e.g., the first server 504 - 1) may include a bastion host, as described herein.

[0115] In some non - limiting embodiments or aspects, a server 504 may receive a connection request from another server 504 as described herein. For example, a second server 504 - 2 may receive a connection request for a connection to the second server 504 - 2 (e.g., the target server) from a first server 504 - 1 (e.g., the source server) as described herein. For illustrative purposes, the connection request may include a login request for a service account on the target server (e.g., the second server 504 - 2). In some non - limiting embodiments or aspects, the connection request may have been initiated on the source server (e.g., the first server 504 - 1) by a user account (e.g., a user of the user device 508 who may access the first server 504 - 1 via production access 530). In some non - limiting embodiments or aspects, the login request may include the username of the service account and the password of the service account as described herein. Additionally or alternatively, the login request may include a key associated with the Secure Shell protocol as described herein.

[0116] In some non - limiting embodiments or aspects, a communication session for the service account may be generated between the source server (e.g., the second server 504 - 2) and the target server (e.g., the first server 504 - 1) based on the connection request as described herein. Such communication may be considered a lateral access (e.g., a first lateral access 540 - 1). In some non - limiting embodiments or aspects, the communication session may be based on the Secure Shell protocol as described herein.

[0117] In some non - limiting embodiments or aspects, a lateral access chain may be created by repeatedly generating communication sessions between one server 504 and another server 504 as described herein. For example, after generating a first lateral access 540 - 1 between the first server 504 - 1 and the second server 504 - 2, a second lateral access 540 - 2 may be generated between the second server 504 - 2 and another server 504 (e.g., the second server 504 - 2 becomes the source of the next lateral access, and the other server will be the target server of this lateral access), and so on until a lateral access 540 - N - 1 to the Nth server 504 - N is generated.

[0118] Each server 504 may include an agent 520 of the anomaly detection system 502 as described herein. For example, the agent 520 may include an instance of the anomaly detection system 502 executed by each server 504 (e.g., an instance of a software application including software instructions). In some non - limiting embodiments or aspects, each agent 520 may collect target server session data and / or source server session data as described herein. For example, the target server session data may be associated with a target server and may include a service account identifier of a service account as described herein. The source server session data may be associated with a source server as described herein. In some non - limiting embodiments or aspects, the source server session data (e.g., of the first server 504 - 1) may include a user account identifier of a user account (e.g., a user account for accessing a bastion host server, which may be the first link in a lateral access chain as described herein).

[0119] In some non - limiting embodiments or aspects, the target server session data may further include a source server identifier associated with the source server, a target server identifier associated with the target server, a source port number associated with the source server, a target port number associated with the target server, a target timestamp associated with the time of generating a communication session, a user account identifier of a user account, a service account identifier of a service account, any combination thereof, and so on.

[0120] In some non - limiting embodiments or aspects, the source server session data may further include a source server identifier associated with the source server, a target server identifier associated with the target server, a source port number associated with the source server, a target port number associated with the target server, a source timestamp associated with the time when the source server receives a response to generating a communication session from the target server, a process owner username (e.g., a user account identifier of a user account, a service account identifier of a service account, and / or a similar identifier of an account initiating the communication session), any combination thereof, and so on.

[0121] The agent 520 of each server 504 may transmit the collected data (e.g., target server session data and / or source server session data) to the data repository 506 and / or store the collected data in the data repository. The data repository 506 may include a computing device (e.g., a database device, etc.) configured to communicate with the anomaly detection system 502 and / or the server 504 (e.g., the agent 520 of the server 504) as described herein. In some non - limiting embodiments or aspects, the data repository 506 may be the same as or similar to the data repository 106.

[0122] In some non - limiting embodiments or aspects, the anomaly detection system 502 may include a correlation engine 521, a Security Information and Event Management system (SIEM) 522, a data lake 523, an identity security analytics system 524, a remediation system 525, and / or an Identity and Access Management system (IAM) 526. The components of the anomaly detection system 502 are provided only as examples. There may be additional components, fewer components, different components, and / or components arranged in a different manner compared to those shown in the anomaly detection system 502. Additionally, two or more of the components shown in the anomaly detection system 502 may be implemented within a single component, or a single component shown in the anomaly detection system 502 may be implemented as multiple distributed components. Additionally or alternatively, a set of components (e.g., one or more components) of the anomaly detection system 502 may perform one or more functions described as being performed by another set of components of the anomaly detection system 502.

[0123] In some non - limiting embodiments or aspects, the correlation engine 521 may correlate target server session data with source server session data to provide correlated session data, as described herein. For example, the correlation engine 521 may retrieve target server session data and source server session data from a data repository 506, and the correlation engine 521 may correlate the target server session data with the source server session data to provide correlated session data, as described herein. Additionally or alternatively, the correlation engine 521 may transmit the correlated session data to the SIEM 522, which may format the correlated session data and / or store the correlated session data in the data lake 523.

[0124] In some non - limiting embodiments or aspects, the identity security analytics system 524 may detect anomalies based on the correlated session data, as described herein. For example, the identity security analytics system 524 may retrieve the correlated session data from the data lake 523, and the identity security analytics system 524 may detect anomalies based on the correlated session data, as described herein.

[0125] In some non - limiting embodiments or aspects, the identity security analytics system 524 identifies the user account that initiated a communication session and the service account associated with the communication session based on the correlated session data, as described herein. Additionally or alternatively, the identity security analytics system 524 may determine that an anomaly exists, as described herein. For example, determining that an anomaly exists may include comparing the activity of the user account with one or more anomaly criteria and / or determining that the activity of the user account meets the one or more anomaly criteria.

[0126] In some non - limiting embodiments or aspects, the identity security analytics system 524 may detect anomalies based on (e.g., using) a machine - learning model, as described herein.

[0127] In some non - limiting embodiments or aspects, the identity security analysis system 524 can generate an alert based on detecting an anomaly, as described herein. For example, the identity security analysis system 524 can transmit the alert to the remediation system 525.

[0128] In some non - limiting embodiments or aspects, the remediation system 525 can generate an alert based on detecting an anomaly, as described herein. Additionally or alternatively, the remediation system 525 can transmit the alert to the administrator device 509.

[0129] In some non - limiting embodiments or aspects, the remediation system 525 can take a remediation action based on the alert. For example, the remediation system 525 can instruct the IAM 526 to terminate the communication session of a user account, block the user account, deactivate the user account, remove the user account's access to one or more servers 504 and / or service accounts of such servers 504, terminate the user account, any combination thereof, etc.

[0130] The administrator device 509 can include a computing device associated with an administrator. For example, the administrator can use the administrator device 509 to receive and / or review the alert, conduct an investigation based on the alert, and / or determine whether to terminate the communication session and / or take other remediation actions.

[0131] In some non - limiting embodiments or aspects, as described herein, correlating source session data and target session data enables identification of the original user who initiated a communication session from a first server (e.g., a bastion host) to impersonate a service account on one or more target servers. Additionally, the disclosed subject matter enables detection of the full chain (e.g., full journey) of lateral access from one end to the other. For example, once a user accesses a target server via lateral access, the user can further laterally access other target servers from there, but by using the techniques described herein to detect lateral access, all individual lateral access segments can be identified, and if any of these individual lateral access segments are linked together, a lateral access chain from an initial server (e.g., a bastion host) through multiple steps (e.g., intermediate servers each connected with a separate lateral access segment) to a final target server can be identified. For example, each target server can be a candidate as the source server for the next lateral access, and by correlating the target session data of one lateral access with the source session data of another lateral access on the same server (e.g., the same host), these two lateral accesses can be detected as two links (e.g., two steps) in a chain (e.g., one long transitive access including multiple lateral accesses). By repeating this matching, the full journey of multiple lateral accesses can be detected. Further, anomalies can be detected as described herein, and once an anomaly is detected, a remediation action (e.g., terminating the communication session and / or the user account) can be initiated.

[0132] Figure 5 The number and arrangement of systems and devices shown in the are provided as examples. Figure 5 There may be additional systems and / or devices, fewer systems and / or devices, different systems and / or devices, and / or systems and / or devices arranged in a different manner than the systems and / or devices shown in the drawings. Furthermore, the present invention may be implemented within a single system or device. Figure 5 Two or more systems or devices shown, or Figure 5 The single system or device shown may be implemented as multiple distributed systems or devices. Additionally or alternatively, a group of systems (e.g., one or more systems) or a group of devices (e.g., one or more devices) of system 500 may perform one or more functions described as being performed by another group of systems or another group of devices of system 500.

[0133] Although the embodiments have been described in detail for the purpose of illustration, it should be understood that such details are used for that purpose only, and the present disclosure is not limited to the disclosed embodiments or aspects, but on the contrary, is intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it should be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment or aspect can be combined with one or more features of any other embodiment or aspect.

Claims

1. A computer-implemented method, comprising: Receiving, by at least one processor, a connection request for a connection to a target server from a source server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; Generating, by at least one processor, a communication session of the service account between the source server and the target server based on the connection request; Collecting, by at least one processor, target server session data associated with the target server and including a service account identifier of the service account and source server session data associated with the source server and including a user account identifier of the user account based on the communication session; Correlating, by at least one processor, the target server session data with the source server session data to provide correlated session data; And Detecting, by at least one processor, an anomaly based on the correlated session data.

2. The computer-implemented method according to claim 1, further comprising: Generating, by at least one processor, an alert based on detecting the anomaly; And Terminating, by at least one processor, the communication session of the user account based on the alert.

3. The computer-implemented method according to claim 1, wherein the communication session is based on the Secure Shell protocol.

4. The computer-implemented method according to claim 1, further comprising: Storing, by at least one processor, the target server session data and the source server session data in a data repository.

5. The computer-implemented method according to claim 1, wherein the login request includes a username of the service account and a password of the service account.

6. The computer-implemented method according to claim 1, wherein the login request includes a key associated with the Secure Shell protocol.

7. The computer-implemented method according to claim 1, wherein the target server session data further includes: A source server identifier associated with the source server; A target server identifier associated with the target server; A source port number associated with the source server; A target port number associated with the target server; A target timestamp associated with the time of generating the communication session; or Any combination thereof.

8. The computer-implemented method according to claim 1, wherein the source server session data further includes: A source server identifier associated with the source server; A target server identifier associated with the target server; A source port number associated with the source server; A target port number associated with the target server; A source timestamp associated with the time when the source server receives a response for generating the communication session from the target server; or Any combination thereof.

9. The computer-implemented method according to claim 1, further comprising: Retrieving, by at least one processor, the target server session data and the source server session data from the data repository.

10. The computer-implemented method according to claim 1, wherein correlating the target server session data with the source server session data to provide correlated session data includes: correlating a first copy of a target server identifier of the target server session data with a second copy of the target server identifier of the source session data; correlating a first copy of a source server identifier of the target server session data with a second copy of the source server identifier of the source session data; correlating a first copy of a target port number of the target server session data with a second copy of the target port number of the source server session data; correlating a first copy of a source port number of the target server session data with a second copy of the source port number of the source server session data; and correlating a target timestamp of the target server session data with a source timestamp of the source server session data, the target timestamp being associated with the time of generating the communication session, and the source timestamp being associated with the time when the source server received a response for generating the communication session from the target server.

11. The computer-implemented method according to claim 1, wherein detecting the anomaly based on the correlated session data includes: identifying, based on the correlated session data, the user account that initiated the communication session and the service account associated with the communication session, the correlated session data including the user account identifier of the source server session data and the service account identifier of the target server session data; and determining that there is the anomaly, wherein determining that there is the anomaly includes: comparing the activities of the user account with one or more anomaly criteria; and determining that the activities of the user account satisfy the one or more anomaly criteria.

12. A system, the system comprising: at least one processor; and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the at least one processor to: receive, from a source server, a connection request for a connection to a target server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; generate, based on the connection request, a communication session of the service account between the source server and the target server; collect, based on the communication session, target server session data associated with the target server and including a service account identifier of the service account and source server session data associated with the source server and including a user account identifier of the user account; correlate the target server session data with the source server session data to provide correlated session data; and detect an anomaly based on the correlated session data.

13. The system according to claim 12, wherein the instructions, when executed by the at least one processor, further cause the at least one processor: Generate an alert based on detecting the anomaly; and Terminate the communication session of the user account based on the alert.

14. The system according to claim 12, wherein the communication session is based on the Secure Shell protocol.

15. The system according to claim 12, wherein the instructions, when executed by the at least one processor, further cause the at least one processor to: Store the target server session data and the source server session data in a data repository.

16. The system according to claim 12, wherein the login request includes the username of the service account and the password of the service account.

17. The system according to claim 12, wherein the login request includes a key associated with the Secure Shell protocol.

18. The system according to claim 12, wherein correlating the target server session data with the source server session data to provide correlated session data includes: Correlating a first copy of the target server identifier of the target server session data with a second copy of the target server identifier of the source session data; Correlating a first copy of the source server identifier of the target server session data with a second copy of the source server identifier of the source session data; Correlating a first copy of the target port number of the target server session data with a second copy of the target port number of the source server session data; Correlating a first copy of the source port number of the target server session data with a second copy of the source port number of the source server session data; And Correlating the target timestamp of the target server session data with the source timestamp of the source server session data, the target timestamp being associated with the time when the communication session is generated, and the source timestamp being associated with the time when the source server receives a response for generating the communication session from the target server.

19. The system according to claim 12, wherein detecting the anomaly based on the correlated session data includes: Identifying the user account that initiated the communication session and the service account associated with the communication session based on the correlated session data, the correlated session data including the user account identifier of the source server session data and the service account identifier of the target server session data; And Determining that the anomaly exists, wherein determining that the anomaly exists includes: Comparing the activities of the user account with one or more anomaly criteria; And Determining that the activities of the user account satisfy the one or more anomaly criteria.

20. A computer program product, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium including program instructions that, when executed by at least one processor, cause the at least one processor to: Receive, from a source server, a connection request for a connection to a target server, the connection request including a login request for a service account on the target server, wherein the connection request is initiated by a user account on the source server; Generate a communication session of the service account between the source server and the target server based on the connection request; Collect target server session data associated with the target server and including the service account identifier of the service account and source server session data associated with the source server and including the user account identifier of the user account based on the communication session; Correlate the target server session data with the source server session data to provide correlated session data; And Detect an anomaly based on the correlated session data.