Anomalous Lateral Movement Detection in Computer Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods are inefficient and time-consuming in detecting anomalous lateral movement within computer networks, allowing malicious actors to evade detection for extended periods by using compromised credentials and secure channels.
Innovation Solution
A system utilizing a machine learning model with sub-models for point-of-entry, timing, mode-of-access, and peer analysis to generate scores based on session history, timing, and peer activity, comparing these scores to thresholds to identify anomalous lateral movement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional detection methods are used to monitor network activity, then system administrators can review security logs, but the detection process becomes inefficient and time-consuming, allowing attackers to evade detection for months
Solution Approach 1:
The patent replaces manual review of security logs with an automated machine learning model that analyzes network session data. The system automatically evaluates multiple features (point of entry, timing, mode of access, peer activity) and generates anomaly scores without human intervention, eliminating the time loss associated with manual detection while maintaining or improving detection accuracy through sophisticated pattern recognition algorithms.
2Reliability
If comprehensive monitoring of all network sessions is implemented to detect lateral movement, then detection capability is improved, but the complexity of the detection system increases significantly
Solution Approach 1:
The patent segments the detection problem into four distinct feature categories: point of entry analysis, timing analysis, mode of access analysis, and peer activity analysis. Each category is evaluated independently by the machine learning model, which then combines these segmented evaluations into an overall anomaly score. This segmentation approach improves detection reliability by comprehensively examining multiple aspects of lateral movement while managing system complexity through modular feature evaluation.
3Productivity
If manual analysis of security logs is performed, then system complexity remains low, but the productivity of security monitoring decreases significantly
Solution Approach 1:
The patent implements a self-service detection system where the machine learning model autonomously collects network session data, evaluates multiple features, generates anomaly scores, and identifies lateral movement without requiring manual analysis. The system serves itself by automatically processing security monitoring tasks, dramatically improving productivity while the complexity is justified by the automated intelligence required to achieve this level of autonomous security monitoring.
Data Source
AI summary
Various embodiments of methods for detecting anomalous activity in a computer network are disclosed. A method includes a computer system receiving an indication of a current session establishing a secure channel to a computing device within a network. The computer system evaluates information relating to the current session, as well as information relating to one or more other sessions. Using this information, the computing system performs monitoring to detect the presence of anomalous lateral movement within the network, for example based on detecting multiple user credentials. Based on the evaluating performed, the computer system generates a score for the current session and reports whether the score is indicative of anomalous lateral movement.


