Enterprise File Lateral Movement Detection via Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting lateral movement of attackers within enterprise networks are costly and inefficient, requiring constant signature updates and making assumptions about attacker techniques, which can lead to delayed detection of security breaches.
Innovation Solution
A computer-implemented method that uses machine learning to detect patterns of file movement across devices within an enterprise network, calculating a likelihood score to determine potential malicious activity and initiating remedial actions without relying on behavioral or static signatures, by constructing a file movement graph and extracting features such as metadata and entropy metrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If constant signature updates are used to detect lateral movement, then detection reliability is improved, but device complexity and operational cost increase
Solution Approach 1:
The patent replaces the mechanical system of manual signature updates with an automated machine learning system that autonomously learns and adapts to detection patterns, eliminating the need for constant manual intervention while maintaining high detection reliability
Solution Approach 2:
The machine learning model performs self-updates and self-improvement by continuously learning from new data, making the system self-sufficient and eliminating dependency on external signature updates for maintaining detection effectiveness
2Measurement precision
If signature-based detection methods are used, then detection precision is improved for known threats, but adaptability to new attack methods deteriorates
Solution Approach 1:
The patent implements a dynamic detection system using machine learning that continuously adapts its detection criteria based on learned patterns, allowing it to maintain high precision for known threats while simultaneously adapting to new attack methods without requiring pre-defined signatures
Solution Approach 2:
The machine learning model dynamically changes its detection parameters and thresholds based on learned patterns from training data, enabling it to adjust its sensitivity and detection criteria to match both known and emerging threat patterns
3Ease of operation
If manual detection and response processes are used, then operational control is improved, but productivity and response speed deteriorate
Solution Approach 1:
The system implements automated feedback loops where detection results and remedial actions are continuously monitored and fed back into the machine learning model, enabling autonomous optimization of detection strategies while maintaining operational oversight
Solution Approach 2:
The patent replaces manual detection and response operations with automated machine learning-based detection and remediation systems, dramatically increasing productivity and response speed while maintaining operational control through configurable parameters and oversight mechanisms
Data Source
AI summary
Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise. A method may include obtaining data associated with an existence a computer file in a first computing device and a second computing device of an enterprise, detecting a pattern of lateral movement of the computer from the first computing device to the second computing device over a predetermined period of time, based on the data, calculating a likelihood score that the computer file is malicious based on the detected pattern, determining that the likelihood score satisfies a predetermined breach threshold, and in response to determining that the likelihood score satisfies the predetermined breach threshold, initiating remedial action on the computer file to protect the enterprise against the computer file.


