Anomalous Lateral Movement Detection in Computer Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are inefficient and time-consuming in detecting anomalous lateral movement within computer networks, allowing malicious actors to evade detection for extended periods by using compromised credentials and secure channels.

Innovation Solution

A system utilizing a machine learning model with sub-models for point-of-entry, timing, mode-of-access, and peer analysis to generate scores based on session history, timing, and peer activity, comparing these scores to thresholds to identify anomalous lateral movement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional detection methods are used to monitor network activity, then system administrators can review security logs, but the detection process becomes inefficient and time-consuming, allowing attackers to evade detection for months

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual review of security logs with an automated machine learning model that analyzes network session data. The system automatically evaluates multiple features (point of entry, timing, mode of access, peer activity) and generates anomaly scores without human intervention, eliminating the time loss associated with manual detection while maintaining or improving detection accuracy through sophisticated pattern recognition algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive monitoring of all network sessions is implemented to detect lateral movement, then detection capability is improved, but the complexity of the detection system increases significantly

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the detection problem into four distinct feature categories: point of entry analysis, timing analysis, mode of access analysis, and peer activity analysis. Each category is evaluated independently by the machine learning model, which then combines these segmented evaluations into an overall anomaly score. This segmentation approach improves detection reliability by comprehensively examining multiple aspects of lateral movement while managing system complexity through modular feature evaluation.

Inventive Principle:
Principle #1Segmentation

3Productivity

If manual analysis of security logs is performed, then system complexity remains low, but the productivity of security monitoring decreases significantly

Engineering Contradiction:
Improvemonitoring efficiencyVSAvoiddetection system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a self-service detection system where the machine learning model autonomously collects network session data, evaluates multiple features, generates anomaly scores, and identifies lateral movement without requiring manual analysis. The system serves itself by automatically processing security monitoring tasks, dramatically improving productivity while the complexity is justified by the automated intelligence required to achieve this level of autonomous security monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11736503B2Detection of anomalous lateral movement in a computer network
Publication Date: 2023.08.22 SALESFORCE INC
  • US11736503B2 patent drawing
  • US11736503B2 patent drawing
  • US11736503B2 patent drawing

AI summary

Various embodiments of methods for detecting anomalous activity in a computer network are disclosed. A method includes a computer system receiving an indication of a current session establishing a secure channel to a computing device within a network. The computer system evaluates information relating to the current session, as well as information relating to one or more other sessions. Using this information, the computing system performs monitoring to detect the presence of anomalous lateral movement within the network, for example based on detecting multiple user credentials. Based on the evaluating performed, the computer system generates a score for the current session and reports whether the score is indicative of anomalous lateral movement.