Graph-Based Authentication Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for detecting network intrusions in enterprise computer networks are inadequate for identifying advanced adversaries using zero-day exploits and stealthy procedures, as they rely on signatures of known-bad events and rudimentary behavioral analytics, leading to high false positives and delayed detection.

Innovation Solution

A graph data model is constructed using authentication logs to detect anomalous authentication events through unsupervised node embedding and link prediction, identifying low-probability links indicative of malicious lateral movement by authenticating entities within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based intrusion detection is used, then detection of known malware is improved, but detection of zero-day exploits and novel malware deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transforms authentication log data from traditional tabular formats into graph-structured data, where nodes represent authenticating entities (users, machines, services) and edges represent authentication events. This structural parameter change enables the system to capture relational patterns and contextual information that signature-based methods miss, allowing detection of novel lateral movement techniques without relying on known malware signatures.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The invention adds a dimensional transformation by representing authentication data as graphs with multiple node types and edge attributes, creating a multi-dimensional view of authentication behavior. This dimensional enrichment allows the system to analyze patterns across different entity types and relationships simultaneously, improving detection of sophisticated attacks that operate across multiple dimensions of the network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If rudimentary behavioral analytics are used, then detection of abnormal network activity is improved, but false positive rate increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication graph into different node types (users, machines, services) and edge types (authentication events with various attributes). This segmentation allows the system to apply type-specific analysis and understand the contextual meaning of different authentication patterns, reducing false positives by distinguishing between legitimate and malicious behavior based on entity relationships rather than generic statistical anomalies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The graph structure acts as an intermediary that transforms raw authentication logs into meaningful relational patterns. The graph model mediates between the raw data and the detection algorithm, enabling the system to understand the contextual relationships between authenticating entities and reduce false positives by considering the broader authentication ecosystem rather than isolated events.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional behavioral analytics are used, then detection of network anomalies is improved, but investigation complexity increases

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidinvestigation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

By transforming authentication data into graph representations, the patent adds structural dimensions that make patterns more visually and analytically apparent. The graph structure organizes complex authentication relationships in a way that is easier to investigate and understand, allowing security analysts to trace authentication paths and identify lateral movement patterns more efficiently than with traditional tabular analytics.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The graph data model serves multiple functions simultaneously: it enables anomaly detection, provides investigative context, and captures relational patterns. This multi-functionality reduces investigation complexity by consolidating multiple analysis needs into a single unified representation that can be queried and visualized in various ways.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11856013B2Method and system for detecting lateral movement in enterprise computer networks
Publication Date: 2023.12.26 GEORGE WASHINGTON UNIVERSITY
  • US11856013B2 patent drawing
  • US11856013B2 patent drawing
  • US11856013B2 patent drawing

AI summary

A system includes a log receiving module, an authentication graph module, a sampling module, an embedding module, a training module, a link prediction module, and an anomaly detection module. The log receiving module is configured to receive a first plurality of network-level authentication logs. The authentication graph module is configured to generate an authentication graph. The sampling module is configured to generate a plurality of sequences. The embedding module is configured to tune a plurality of node embeddings according to the plurality of sequences. The training module is configured to train a link predictor according to the plurality of node embeddings and ground-truth edge information from the authentication graph. The link prediction module is configured to apply the link predictor to performs a link prediction. The anomaly detection module is configured to perform anomaly detection according to the link prediction.