Network Lateral Movement Graph Analysis for Security Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network lateral movements pose a significant security threat as they can be difficult to detect, especially when attackers gain administrative privileges, and existing solutions lack an automated and effective means to suggest and implement mitigation actions without impacting network usability.
Innovation Solution
A method utilizing a graph of network lateral movements to identify vulnerabilities, update probabilities and payload utilities, and determine mitigation actions, which can be automatically applied or suggested to prevent lateral movements, focusing on reducing security risks while minimizing resource investment and usability impact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If automated mitigation actions are applied to prevent lateral movements, then security risk is reduced, but network usability may be impacted
Solution Approach 1:
The system performs preliminary analysis to identify critical assets and potential lateral movement paths before deploying mitigation actions. By pre-calculating the impact of mitigation on both security and usability, the system can prioritize actions that provide maximum security benefit with minimum usability disruption.
Solution Approach 2:
The system applies mitigation actions selectively to specific critical assets rather than uniformly across the entire network. By identifying which assets are most vulnerable to lateral movements and applying targeted mitigations only to those areas, the system reduces overall security risk while minimizing impact on general network usability.
2Difficulty of detecting and measuring
If comprehensive monitoring of network lateral movements is implemented, then detection capability is improved, but system complexity increases
Solution Approach 1:
The monitoring system is divided into modular components that independently analyze different aspects of network traffic. Each module focuses on specific indicators of lateral movement, allowing the system to achieve comprehensive detection capability while maintaining manageable complexity through modular architecture.
Solution Approach 2:
The system introduces an intermediary analysis layer that processes raw network data and translates it into meaningful security insights. This intermediary layer simplifies the complexity by abstracting the detailed monitoring logic while maintaining comprehensive detection capabilities through standardized processing pipelines.
3Measurement precision
If real-time updates to penetration probabilities and payload utilities are performed, then security assessment accuracy is improved, but computational resource consumption increases
Solution Approach 1:
The system performs updates to penetration probabilities and payload utilities at periodic intervals rather than continuously. By triggering updates based on specific events or time schedules rather than constant computation, the system maintains accurate security assessments while reducing overall computational resource consumption.
Solution Approach 2:
The system focuses computational resources on updating probabilities and utilities for critical assets that have higher impact on security, rather than uniformly updating all assets. By applying partial updates only where most needed, the system achieves improved assessment accuracy for high-value targets while conserving computational resources.
Data Source
AI summary
Method, product and apparatus for monitoring for security threats from lateral movements. A method comprises obtaining a graph of network lateral movements, that comprises nodes, representing network assets, and directed edges, representing a network lateral movement from a source asset to a target asset. An event that affects the graph of network lateral movements is detected. The event affects at least one of: the payload utility of the node and the probability of penetration to the node. The graph of network lateral movements is updated based on the event. The updated graph is analyzed to determine one or more mitigation actions to be applied. The one or more mitigation actions are applied automatically, manually or the like.


