Enterprise File Lateral Movement Detection via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting lateral movement of attackers within enterprise networks are costly and inefficient, requiring constant signature updates and making assumptions about attacker techniques, which can lead to delayed detection of security breaches.

Innovation Solution

A computer-implemented method that uses machine learning to detect patterns of file movement across devices within an enterprise network, calculating a likelihood score to determine potential malicious activity and initiating remedial actions without relying on behavioral or static signatures, by constructing a file movement graph and extracting features such as metadata and entropy metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If constant signature updates are used to detect lateral movement, then detection reliability is improved, but device complexity and operational cost increase

Engineering Contradiction:
Improvebreach detection reliabilityVSAvoidsignature update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical system of manual signature updates with an automated machine learning system that autonomously learns and adapts to detection patterns, eliminating the need for constant manual intervention while maintaining high detection reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The machine learning model performs self-updates and self-improvement by continuously learning from new data, making the system self-sufficient and eliminating dependency on external signature updates for maintaining detection effectiveness

Inventive Principle:
Principle #25Self-service

2Measurement precision

If signature-based detection methods are used, then detection precision is improved for known threats, but adaptability to new attack methods deteriorates

Engineering Contradiction:
Improvethreat detection precisionVSAvoidadaptability to new attack methods
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic detection system using machine learning that continuously adapts its detection criteria based on learned patterns, allowing it to maintain high precision for known threats while simultaneously adapting to new attack methods without requiring pre-defined signatures

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The machine learning model dynamically changes its detection parameters and thresholds based on learned patterns from training data, enabling it to adjust its sensitivity and detection criteria to match both known and emerging threat patterns

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If manual detection and response processes are used, then operational control is improved, but productivity and response speed deteriorate

Engineering Contradiction:
Improveoperational controlVSAvoidbreach detection productivity
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements automated feedback loops where detection results and remedial actions are continuously monitored and fed back into the machine learning model, enabling autonomous optimization of detection strategies while maintaining operational oversight

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual detection and response operations with automated machine learning-based detection and remediation systems, dramatically increasing productivity and response speed while maintaining operational control through configurable parameters and oversight mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11030311B1Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise
Publication Date: 2021.06.08 CA TECH INC
  • US11030311B1 patent drawing
  • US11030311B1 patent drawing
  • US11030311B1 patent drawing

AI summary

Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise. A method may include obtaining data associated with an existence a computer file in a first computing device and a second computing device of an enterprise, detecting a pattern of lateral movement of the computer from the first computing device to the second computing device over a predetermined period of time, based on the data, calculating a likelihood score that the computer file is malicious based on the detected pattern, determining that the likelihood score satisfies a predetermined breach threshold, and in response to determining that the likelihood score satisfies the predetermined breach threshold, initiating remedial action on the computer file to protect the enterprise against the computer file.