Graph-Based Lateral Movement Detection in Computer Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in detecting lateral movement attacks across multiple devices due to scalability issues and limited network visibility, making it difficult to identify malicious activities that involve multiple network segments.

Innovation Solution

The technology employs a graph-based approach to detect lateral movement candidates by analyzing event data, assigning similarity scores to network devices based on user interactions, and using dynamic weights to refine the identification of potential threats, enabling a broader view of network activities and improving threat detection accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security appliances are installed to monitor network traffic, then network security detection capability is improved, but scalability and network visibility are worsened due to appliance swap requirements and limited view of other network segments

Engineering Contradiction:
Improvenetwork security detection capabilityVSAvoidscalability and network visibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the network monitoring function into multiple distributed data collection points (security appliances, endpoints, network devices) that each collect local event data independently. These segmented components feed into a centralized graph processing system that reconstructs the complete network picture, allowing both local detection capability and global network visibility without requiring appliance swaps or upgrades.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional single-dimension appliance-based monitoring to a multi-dimensional approach by creating a graph structure that connects events across multiple network segments, devices, and time periods. This dimensional expansion allows the system to detect lateral movement attacks that span across previously isolated network segments, providing comprehensive visibility without adding physical appliances.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If traditional security appliances are used, then localized security monitoring is achieved, but detection of lateral movement attacks across multiple network segments is worsened due to limited network visibility

Engineering Contradiction:
Improvelocalized security monitoringVSAvoiddetection of lateral movement attacks
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system merges data from multiple localized security monitoring points into a unified graph structure that preserves the local context while adding global connectivity. Each security appliance continues to monitor its local segment independently, but the graph processing system combines these local views to detect patterns spanning multiple segments, such as lateral movement attacks, without losing the simplicity of localized operation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The graph processing system acts as an intermediary that receives event data from multiple localized security appliances and endpoints. It processes this data to identify relationships and patterns that indicate lateral movement attacks, then generates alerts that combine information from multiple sources. This intermediary layer enables detection of cross-segment attacks while allowing each local appliance to continue its simple, localized monitoring function.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If security appliances are deployed, then network traffic monitoring is improved, but scalability is worsened due to time-consuming appliance swaps or upgrades when traffic increases

Engineering Contradiction:
Improvenetwork traffic monitoring capabilityVSAvoidappliance swap or upgrade time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system uses universal event data collection that works across multiple device types and network segments without requiring specialized appliances for each function. The graph processing system handles various event formats and sources uniformly, allowing the infrastructure to scale by adding new data sources rather than deploying additional specialized appliances, thereby eliminating the need for time-consuming appliance swaps or upgrades.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11658992B2Lateral movement candidate detection in a computer network
Publication Date: 2023.05.23 CISCO TECHNOLOGY INC
  • US11658992B2 patent drawing
  • US11658992B2 patent drawing
  • US11658992B2 patent drawing

AI summary

A lateral movement application identifies lateral movement (LM) candidates that potentially represent a security threat. Security platforms generate event data when performing security-related functions, such as authenticating a user account. The disclosed technology enables greatly increased accuracy identification of lateral movement (LM) candidates by, for example, refining a population of LM candidates based on an analysis of a time constrained graph in which nodes represent entities, and edges between nodes represent a time sequence of login or other association activities between the entities. The graph is created based on an analysis of the event data, including time sequences of the event data.