East-West Traffic Analysis for Lateral Movement Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity measures struggle to detect cyber-attacks during lateral movement within enterprise networks, especially when malicious activities resemble normal traffic, and may fail to differentiate between legitimate and malicious activities, leading to false positives or negatives, and are ineffective against polymorphic or zero-day malware.

Innovation Solution

A cyber-attack analysis system that captures internal network traffic, analyzes communications, and uses correlation logic to group weak indicators into strong indicators by identifying patterns and sequences associated with known malicious activities, providing alerts to administrators even when only weak indicators are available.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional security devices are deployed at the periphery of the enterprise network to detect cyber-attacks, then early phases of Web-based attacks such as initial infiltration and malware downloads can be detected, but post-intrusion activities during lateral movement within the network cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoidcoverage of attack phases
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from periphery-based detection (north-south traffic) to internal network detection (east-west traffic). The security device is repositioned conceptually to monitor lateral movement within the network infrastructure, adding a new dimensional perspective to threat detection that captures post-intrusion activities previously invisible to conventional perimeter security

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If security devices monitor internal network traffic to detect lateral movement, then post-intrusion activities can be detected, but legitimate network traffic may generate false positives

Engineering Contradiction:
Improvedetection of malicious activitiesVSAvoidaccuracy of detection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies partial action by focusing detection efforts on specific indicators of lateral movement rather than attempting to analyze all internal traffic comprehensively. By targeting particular suspicious patterns and behaviors associated with post-intrusion activities, the system achieves effective detection while minimizing false positives from legitimate traffic

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies local quality by making different parts of the network traffic analysis serve different functions. Rather than uniformly analyzing all traffic, the system applies specialized detection rules to specific traffic patterns, protocols, and behaviors that are characteristic of lateral movement, while allowing legitimate traffic patterns to pass with minimal scrutiny

Inventive Principle:
Principle #3Local quality

3Measurement precision

If conventional security measures are used, then known malware can be detected through signature matching, but polymorphic and zero-day malware cannot be detected

Engineering Contradiction:
Improvedetection of known malwareVSAvoiddetection of advanced threats
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static signature-based detection to dynamic behavior-based detection. Instead of relying on fixed malware signatures that become obsolete against polymorphic and zero-day threats, the system continuously monitors and analyzes the behavior and characteristics of network traffic in real-time, adapting to new threat patterns as they emerge

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the detection parameters from fixed signature matching to variable behavioral analysis. By monitoring changes in traffic patterns, communication protocols, and network behavior over time, the system can identify malicious activities regardless of whether the malware is known or has mutated, effectively detecting polymorphic and zero-day threats

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10855700B1Post-intrusion detection of cyber-attacks during lateral movement within networks
Publication Date: 2020.12.01 MAGENTA SECURITY HOLDINGS LLC
  • US10855700B1 patent drawing
  • US10855700B1 patent drawing
  • US10855700B1 patent drawing

AI summary

A method and system to detect cyber-attacks by analyzing client-server or other east-west traffic within an enterprise network is disclosed. East-west traffic comprises communications between network devices within the enterprise network, in contradistinction to north-south traffic which involves communications intended to traverse the periphery of the enterprise network. The system includes a network interface to receive the network traffic; analysis logic to analyze communications within the received network traffic to identify a set of indicators; correlation logic to assemble one or more groups of weak indicators from the set of indicators, and conduct an analysis to determine whether each of the groups of weak indicators is correlated with known malicious patterns or sequences of indicators, thereby producing at least one strong indicator from which a determination can be made of whether a cyber-attack is being conducted.