Centralized Aggregation for Stealthy Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional malware-based security architectures are unable to detect lateral movement of stealthy cyber-attacks within an enterprise network, as attackers use legitimate credentials and low-observability techniques to infiltrate and move undetected, avoiding detection by signature-based methods.

Innovation Solution

A centralized aggregation technique that utilizes a data center security appliance, a malware detection system appliance, and an attack analyzer to correlate and analyze indicators from multiple vantage points, detecting the download and use of credential cracking tools, and unusual credential usage patterns to identify and track lateral movement of stealthy attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If traditional signature-based malware detection methods are used, then detection simplicity is maintained, but detection capability against stealthy attacks deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The detection system is divided into multiple independent components: endpoint detection agents on individual devices, network traffic analysis systems, and centralized correlation platforms. Each segment handles specific detection tasks independently, improving overall detection capability while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple detection data sources including endpoint logs, network traffic data, and threat intelligence feeds are merged and correlated centrally. This combination enables the system to detect stealthy attacks that individual signature-based methods would miss, as the correlation of multiple indicators reveals patterns invisible to single-point detection.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If centralized aggregation of indicators from multiple vantage points is implemented, then detection accuracy improves, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

A centralized correlation platform acts as an intermediary between distributed detection agents and security analysts. This mediator collects, normalizes, and correlates indicators from multiple vantage points, improving detection accuracy while shielding analysts from the complexity of managing multiple data sources through automated correlation logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds a temporal dimension to detection by analyzing sequences of indicators over time rather than isolated events. By correlating indicators across multiple dimensions (spatial distribution across network, temporal progression of attack stages), the system achieves higher accuracy without proportionally increasing operational complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If multiple detection sensors and appliances are deployed throughout the network, then coverage improves, but operational complexity increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Detection appliances and endpoint agents are designed with universal functionality to operate across diverse network environments and device types. This multi-functionality enables broad network coverage with standardized components, reducing operational complexity by eliminating the need for specialized configurations for different network segments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10454950B1Centralized aggregation technique for detecting lateral movement of stealthy cyber-attacks
Publication Date: 2019.10.22 MAGENTA SECURITY HOLDINGS LLC
  • US10454950B1 patent drawing
  • US10454950B1 patent drawing
  • US10454950B1 patent drawing

AI summary

A centralized aggregation technique detects lateral movement of a stealthy (i.e., covert) cyber-attack in an enterprise network. A data center security (DCS) appliance may be located at a data center of the enterprise network, while a malware detection system (MDS) appliance may be located at a periphery of the network, an endpoint may be internally located within the enterprise network and an attack analyzer may be centrally located in the network. The appliances and endpoint may provide results of heuristics to an attack analyzer, wherein the heuristic results may be used to detect one or more tools downloaded to the endpoint, as well as resulting actions of the endpoint to determine whether the tools and actions manifest observable behaviors of the lateral movement of the SC-attack. The observable behaviors may include (i) unauthorized use of legitimate credentials obtained at the endpoint, as well as (ii) unusual access patterns via actions originated at the endpoint to acquire sensitive information stored on one or more servers on the network. The attack analyzer may then collect and analyze information related to the observable behaviors provided by the appliances and endpoint to create a holistic view of the lateral movement of the SC-attack.