Graph-Based Lateral Movement Detection in Computer Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in detecting lateral movement attacks across multiple devices due to scalability issues and limited network visibility, making it difficult to identify malicious activities that involve multiple network segments.
Innovation Solution
The technology employs a graph-based approach to detect lateral movement candidates by analyzing event data, assigning similarity scores to network devices based on user interactions, and using dynamic weights to refine the identification of potential threats, enabling a broader view of network activities and improving threat detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security appliances are installed to monitor network traffic, then network security detection capability is improved, but scalability and network visibility are worsened due to appliance swap requirements and limited view of other network segments
Solution Approach 1:
The system segments the network monitoring function into multiple distributed data collection points (security appliances, endpoints, network devices) that each collect local event data independently. These segmented components feed into a centralized graph processing system that reconstructs the complete network picture, allowing both local detection capability and global network visibility without requiring appliance swaps or upgrades.
Solution Approach 2:
The patent transitions from traditional single-dimension appliance-based monitoring to a multi-dimensional approach by creating a graph structure that connects events across multiple network segments, devices, and time periods. This dimensional expansion allows the system to detect lateral movement attacks that span across previously isolated network segments, providing comprehensive visibility without adding physical appliances.
2Ease of operation
If traditional security appliances are used, then localized security monitoring is achieved, but detection of lateral movement attacks across multiple network segments is worsened due to limited network visibility
Solution Approach 1:
The system merges data from multiple localized security monitoring points into a unified graph structure that preserves the local context while adding global connectivity. Each security appliance continues to monitor its local segment independently, but the graph processing system combines these local views to detect patterns spanning multiple segments, such as lateral movement attacks, without losing the simplicity of localized operation.
Solution Approach 2:
The graph processing system acts as an intermediary that receives event data from multiple localized security appliances and endpoints. It processes this data to identify relationships and patterns that indicate lateral movement attacks, then generates alerts that combine information from multiple sources. This intermediary layer enables detection of cross-segment attacks while allowing each local appliance to continue its simple, localized monitoring function.
3Productivity
If security appliances are deployed, then network traffic monitoring is improved, but scalability is worsened due to time-consuming appliance swaps or upgrades when traffic increases
Solution Approach 1:
The system uses universal event data collection that works across multiple device types and network segments without requiring specialized appliances for each function. The graph processing system handles various event formats and sources uniformly, allowing the infrastructure to scale by adding new data sources rather than deploying additional specialized appliances, thereby eliminating the need for time-consuming appliance swaps or upgrades.
Data Source
AI summary
A lateral movement application identifies lateral movement (LM) candidates that potentially represent a security threat. Security platforms generate event data when performing security-related functions, such as authenticating a user account. The disclosed technology enables greatly increased accuracy identification of lateral movement (LM) candidates by, for example, refining a population of LM candidates based on an analysis of a time constrained graph in which nodes represent entities, and edges between nodes represent a time sequence of login or other association activities between the entities. The graph is created based on an analysis of the event data, including time sequences of the event data.


