East-West Traffic Analysis for Lateral Movement Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cybersecurity measures struggle to detect cyber-attacks during lateral movement within enterprise networks, especially when malicious activities resemble normal traffic, and may fail to differentiate between legitimate and malicious activities, leading to false positives or negatives, and are ineffective against polymorphic or zero-day malware.
Innovation Solution
A cyber-attack analysis system that captures internal network traffic, analyzes communications, and uses correlation logic to group weak indicators into strong indicators by identifying patterns and sequences associated with known malicious activities, providing alerts to administrators even when only weak indicators are available.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional security devices are deployed at the periphery of the enterprise network to detect cyber-attacks, then early phases of Web-based attacks such as initial infiltration and malware downloads can be detected, but post-intrusion activities during lateral movement within the network cannot be detected
Solution Approach 1:
The patent transitions from periphery-based detection (north-south traffic) to internal network detection (east-west traffic). The security device is repositioned conceptually to monitor lateral movement within the network infrastructure, adding a new dimensional perspective to threat detection that captures post-intrusion activities previously invisible to conventional perimeter security
2Measurement precision
If security devices monitor internal network traffic to detect lateral movement, then post-intrusion activities can be detected, but legitimate network traffic may generate false positives
Solution Approach 1:
The patent applies partial action by focusing detection efforts on specific indicators of lateral movement rather than attempting to analyze all internal traffic comprehensively. By targeting particular suspicious patterns and behaviors associated with post-intrusion activities, the system achieves effective detection while minimizing false positives from legitimate traffic
Solution Approach 2:
The patent applies local quality by making different parts of the network traffic analysis serve different functions. Rather than uniformly analyzing all traffic, the system applies specialized detection rules to specific traffic patterns, protocols, and behaviors that are characteristic of lateral movement, while allowing legitimate traffic patterns to pass with minimal scrutiny
3Measurement precision
If conventional security measures are used, then known malware can be detected through signature matching, but polymorphic and zero-day malware cannot be detected
Solution Approach 1:
The patent transitions from static signature-based detection to dynamic behavior-based detection. Instead of relying on fixed malware signatures that become obsolete against polymorphic and zero-day threats, the system continuously monitors and analyzes the behavior and characteristics of network traffic in real-time, adapting to new threat patterns as they emerge
Solution Approach 2:
The patent changes the detection parameters from fixed signature matching to variable behavioral analysis. By monitoring changes in traffic patterns, communication protocols, and network behavior over time, the system can identify malicious activities regardless of whether the malware is known or has mutated, effectively detecting polymorphic and zero-day threats
Data Source
AI summary
A method and system to detect cyber-attacks by analyzing client-server or other east-west traffic within an enterprise network is disclosed. East-west traffic comprises communications between network devices within the enterprise network, in contradistinction to north-south traffic which involves communications intended to traverse the periphery of the enterprise network. The system includes a network interface to receive the network traffic; analysis logic to analyze communications within the received network traffic to identify a set of indicators; correlation logic to assemble one or more groups of weak indicators from the set of indicators, and conduct an analysis to determine whether each of the groups of weak indicators is correlated with known malicious patterns or sequences of indicators, thereby producing at least one strong indicator from which a determination can be made of whether a cyber-attack is being conducted.


