Network Lateral Movement Graph Analysis for Security Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network lateral movements pose a significant security threat as they can be difficult to detect, especially when attackers gain administrative privileges, and existing solutions lack an automated and effective means to suggest and implement mitigation actions without impacting network usability.

Innovation Solution

A method utilizing a graph of network lateral movements to identify vulnerabilities, update probabilities and payload utilities, and determine mitigation actions, which can be automatically applied or suggested to prevent lateral movements, focusing on reducing security risks while minimizing resource investment and usability impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated mitigation actions are applied to prevent lateral movements, then security risk is reduced, but network usability may be impacted

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidnetwork usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary analysis to identify critical assets and potential lateral movement paths before deploying mitigation actions. By pre-calculating the impact of mitigation on both security and usability, the system can prioritize actions that provide maximum security benefit with minimum usability disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies mitigation actions selectively to specific critical assets rather than uniformly across the entire network. By identifying which assets are most vulnerable to lateral movements and applying targeted mitigations only to those areas, the system reduces overall security risk while minimizing impact on general network usability.

Inventive Principle:
Principle #3Local quality

2Difficulty of detecting and measuring

If comprehensive monitoring of network lateral movements is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The monitoring system is divided into modular components that independently analyze different aspects of network traffic. Each module focuses on specific indicators of lateral movement, allowing the system to achieve comprehensive detection capability while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary analysis layer that processes raw network data and translates it into meaningful security insights. This intermediary layer simplifies the complexity by abstracting the detailed monitoring logic while maintaining comprehensive detection capabilities through standardized processing pipelines.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If real-time updates to penetration probabilities and payload utilities are performed, then security assessment accuracy is improved, but computational resource consumption increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs updates to penetration probabilities and payload utilities at periodic intervals rather than continuously. By triggering updates based on specific events or time schedules rather than constant computation, the system maintains accurate security assessments while reducing overall computational resource consumption.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system focuses computational resources on updating probabilities and utilities for critical assets that have higher impact on security, rather than uniformly updating all assets. By applying partial updates only where most needed, the system achieves improved assessment accuracy for high-value targets while conserving computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11818168B2Monitoring for lateral movements-related security threats
Publication Date: 2023.11.14 CYMULATE LTD
  • US11818168B2 patent drawing
  • US11818168B2 patent drawing
  • US11818168B2 patent drawing

AI summary

Method, product and apparatus for monitoring for security threats from lateral movements. A method comprises obtaining a graph of network lateral movements, that comprises nodes, representing network assets, and directed edges, representing a network lateral movement from a source asset to a target asset. An event that affects the graph of network lateral movements is detected. The event affects at least one of: the payload utility of the node and the probability of penetration to the node. The graph of network lateral movements is updated based on the event. The updated graph is analyzed to determine one or more mitigation actions to be applied. The one or more mitigation actions are applied automatically, manually or the like.