Identity Control Appliance for Network Lateral Movement Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions automatically block all authentications from a compromised device, disrupting normal business operations and failing to efficiently target specific accounts for malicious activities, leading to fidelity issues and unnecessary interruptions.

Innovation Solution

Implementing an identity control mechanism on a security appliance that receives telemetry data from endpoint devices, determines threat behaviors, and enforces targeted security actions on specific user identities to prevent lateral movement, such as blocking authentications and enforcing multi-factor authentication, without halting all lateral movements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all authentications from a compromised device are automatically blocked, then credential theft and lateral movement are prevented, but normal business operations are interrupted and lateral movements are stopped

Engineering Contradiction:
Improvesecurity controlVSAvoidbusiness operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the authentication blocking action by identifying and isolating only the specific compromised identity from the set of all identities. Instead of blocking all authentications from a device, the system blocks only the authentication attempts using the compromised identity token, allowing other legitimate identities to continue accessing resources normally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by targeting the specific compromised identity with security controls while maintaining normal access for other identities. The system distinguishes between the compromised identity and other legitimate identities, applying blocking only where necessary to prevent lateral movement without affecting overall business operations.

Inventive Principle:
Principle #3Local quality

2Reliability

If all authentications are blocked to prevent lateral movement, then threat behavior is intercepted, but fidelity problem occurs and specific accounts cannot be targeted

Engineering Contradiction:
Improvelateral movement preventionVSAvoididentity targeting accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the authentication blocking action by identifying and isolating only the specific compromised identity from the set of all identities. Instead of blocking all authentications from a device, the system blocks only the authentication attempts using the compromised identity token, allowing other legitimate identities to continue accessing resources normally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces broad mechanical blocking mechanisms with more precise identity-aware filtering. Instead of using simple device-level blocking, the system uses identity token-based filtering that can distinguish between compromised and legitimate identities, enabling precise targeting of specific accounts for malicious activities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240007491A1Methods and systems for identity control
Publication Date: 2024.01.04 CROWDSTRIKE
  • US20240007491A1 patent drawing
  • US20240007491A1 patent drawing
  • US20240007491A1 patent drawing

AI summary

Methods and systems for detecting malicious attacks in a network and preventing lateral movement in the network by identity control are disclosed. According to an implementation, a security appliance may receive telemetry data from an endpoint device collected during a period of time. The security appliance may determine a threat behavior based on the telemetry data. The threat behavior may be associated with a user identity or user account. The security appliance further determines one or more additional user identities based on the user identity connected to the threat behavior. The security appliance may enforce one or more security actions on the user identity and the one or more additional user identities to prevent attacks to a plurality of computing domains from the endpoint device using the one or more additional user identities. The security appliance may be implemented on any network participants including servers, cloud device, cloud-based services/platforms, etc.