Network Traffic Correlation Engine for Lateral Movement Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods struggle to identify in real time lateral movement between hosts in enterprise computing systems, which can be associated with network intruders or malicious inside threats, due to the difficulty in correlating host-to-host communication and validating network traffic.
Innovation Solution
A network traffic correlation engine that monitors inbound and outbound connections across host devices, correlates connections between different hosts, and generates alerts for unmatched connections, providing a mapping of communications that may indicate compromised hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If Host Based Intrusion Detection solutions (HIDS) are used to monitor network traffic, then the ability to detect attacks against individual hosts is improved, but the ability to identify lateral movement between hosts deteriorates
Solution Approach 1:
The patent combines HIDS from multiple hosts with a centralized correlation engine to create a system that maintains the detection accuracy of individual HIDS while adding the capability to detect lateral movement by correlating events across the network. The correlation engine aggregates logs from multiple HIDS instances and identifies patterns indicating lateral movement that would be invisible to any single HIDS.
Solution Approach 2:
The patent introduces a correlation engine as an intermediary component that receives data from multiple HIDS systems and processes it to identify lateral movement. This intermediary layer enables the detection of cross-host attacks without modifying the individual HIDS systems, preserving their single-host detection capabilities while adding network-wide visibility.
2Reliability
If anti-virus and anti-malware tools rely on known patterns, then detection of known threats is improved, but identification of custom malware and legitimate tools used for unauthorized connections deteriorates
Solution Approach 1:
The patent implements preliminary action by establishing a baseline of normal network behavior and communication patterns before attacks occur. The system learns what constitutes legitimate traffic between hosts and uses this knowledge to detect deviations, enabling identification of both custom malware and legitimate tools misused for unauthorized connections without relying solely on known threat patterns.
Solution Approach 2:
The patent incorporates feedback mechanisms where the correlation engine continuously monitors network traffic, compares it against established baselines, and adjusts its detection parameters based on observed patterns. This feedback loop enables the system to adapt to new threats and recognize when legitimate tools are being used for unauthorized purposes, going beyond static pattern matching.
Data Source
AI summary
A network traffic correlation engine monitors inbound and/or outbound connection information received from on each host computer system on a network. Each host device on the network store data logs corresponding to information corresponding to communications sent by the device and received by the device. The network traffic correlation engine correlates connections between different hosts throughout the network. If the network traffic correlation engine identified unmatched outbound and inbound connections, the network traffic correlation engine generates an alert to initiate further investigation and may also provide a mapping of the communications showing a possible start device for the connection and/or a type of access that the connections may now be providing.


