Identity Control Appliance for Network Lateral Movement Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions automatically block all authentications from a compromised device, disrupting normal business operations and failing to efficiently target specific accounts for malicious activities, leading to fidelity issues and unnecessary interruptions.
Innovation Solution
Implementing an identity control mechanism on a security appliance that receives telemetry data from endpoint devices, determines threat behaviors, and enforces targeted security actions on specific user identities to prevent lateral movement, such as blocking authentications and enforcing multi-factor authentication, without halting all lateral movements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all authentications from a compromised device are automatically blocked, then credential theft and lateral movement are prevented, but normal business operations are interrupted and lateral movements are stopped
Solution Approach 1:
The patent segments the authentication blocking action by identifying and isolating only the specific compromised identity from the set of all identities. Instead of blocking all authentications from a device, the system blocks only the authentication attempts using the compromised identity token, allowing other legitimate identities to continue accessing resources normally.
Solution Approach 2:
The patent applies local quality by targeting the specific compromised identity with security controls while maintaining normal access for other identities. The system distinguishes between the compromised identity and other legitimate identities, applying blocking only where necessary to prevent lateral movement without affecting overall business operations.
2Reliability
If all authentications are blocked to prevent lateral movement, then threat behavior is intercepted, but fidelity problem occurs and specific accounts cannot be targeted
Solution Approach 1:
The patent segments the authentication blocking action by identifying and isolating only the specific compromised identity from the set of all identities. Instead of blocking all authentications from a device, the system blocks only the authentication attempts using the compromised identity token, allowing other legitimate identities to continue accessing resources normally.
Solution Approach 2:
The patent replaces broad mechanical blocking mechanisms with more precise identity-aware filtering. Instead of using simple device-level blocking, the system uses identity token-based filtering that can distinguish between compromised and legitimate identities, enabling precise targeting of specific accounts for malicious activities.
Data Source
AI summary
Methods and systems for detecting malicious attacks in a network and preventing lateral movement in the network by identity control are disclosed. According to an implementation, a security appliance may receive telemetry data from an endpoint device collected during a period of time. The security appliance may determine a threat behavior based on the telemetry data. The threat behavior may be associated with a user identity or user account. The security appliance further determines one or more additional user identities based on the user identity connected to the threat behavior. The security appliance may enforce one or more security actions on the user identity and the one or more additional user identities to prevent attacks to a plurality of computing domains from the endpoint device using the one or more additional user identities. The security appliance may be implemented on any network participants including servers, cloud device, cloud-based services/platforms, etc.


