Datacenter Lateral Movement Detection via Connection Graph Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing datacenter security measures are inadequate in detecting lateral movement threats, which can occur when an attacker gains access to one virtual machine and uses it to access others, often appearing as normal activity and requiring administrators to manually connect dots between events.
Innovation Solution
An analysis appliance generates a graph of connections between data compute nodes in the datacenter, analyzing data flow and context information to identify anomalous events and potential lateral movement threats by tracing paths of remote service connections, and applies remediation techniques such as generating alerts and configuring firewall rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If administrators manually analyze individual events to detect lateral movement threats, then detection accuracy may improve, but time consumption and operational complexity increase significantly
Solution Approach 1:
The patent replaces manual administrative analysis with an automated analysis appliance that generates connection graphs and detects lateral movement threats algorithmically. The system automatically correlates events across multiple DCNs by analyzing connection relationships, substituting human manual dot-connecting with automated graph-based analysis that processes data faster and without human time constraints.
Solution Approach 2:
The patent introduces a connection graph as an intermediary representation between raw security events and threat detection. The graph structure with DCNs as nodes and connections as edges serves as a mediator that organizes complex event data, enabling automated detection of lateral movement patterns without requiring administrators to manually trace connections between events.
2Ease of operation
If remote services are made accessible for administration, then ease of operation improves, but security vulnerabilities and attack surfaces increase
Solution Approach 1:
The patent implements continuous monitoring and detection of remote service connections through the analysis appliance. The system provides feedback by detecting anomalous connection patterns and lateral movement threats that exploit remote services, enabling security teams to respond to attacks on accessible administrative interfaces before significant damage occurs.
3Reliability
If comprehensive event collection is performed across all DCNs, then detection capability improves, but data processing complexity and resource requirements increase
Solution Approach 1:
The patent extracts only the essential connection information needed for lateral movement detection from comprehensive event data. The analysis appliance focuses on generating connection graphs that capture DCN relationships and remote service connections, extracting the critical subset of data required for threat detection while filtering out unnecessary detailed event information that would complicate processing.
Data Source
AI summary
Some embodiments provide a method for detecting a threat to a datacenter. The method generates a graph of connections between data compute nodes (DCNs) in the datacenter. Each connection has an associated time period during which the connection is active. The method receives an anomalous event occurring during a particular time period at a particular DCN operating in the datacenter. The method analyzes the generated graph to determine a set of paths between DCNs in the datacenter that include connections to the particular DCN during the particular time period. The method uses the set of paths to identify a threat to the datacenter.


