Privilege Assurance via Lateral Movement Detection in Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions lack comprehensive preventative measures to protect Active Directory from attacks, particularly in ensuring privilege assurance and enforcing the principle of 'least privilege' across enterprise computer networks.

Innovation Solution

A system and method utilizing local agents to monitor and log user sessions, combined with a directed computational graph module, to detect and prevent lateral movement attacks by mapping attack paths and ensuring privilege assurance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If indirect approach of securing access points and responding after attack is used, then implementation simplicity is maintained, but security reliability is insufficient

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and logging user sessions and host relationships before attacks occur. The directed computational graph module pre-computes attack paths and privilege escalation routes, enabling the system to detect and prevent lateral movement attacks before they compromise Active Directory, rather than merely responding after detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary directed computational graph module that sits between traditional security measures and Active Directory. This module analyzes session data, maps attack paths, and identifies privilege assurance violations, providing an additional layer of security analysis without directly modifying Access Point protocols or Active Directory itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of user sessions and host relationships is implemented, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvedetection precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into distinct functional components: local agents that collect session data, a centralized logging system that stores information, and a directed computational graph module that analyzes relationships. This segmentation allows each component to perform its specific function with high precision while managing overall system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces traditional mechanical security monitoring approaches with a computational graph-based system. Instead of using complex rule-based analysis or manual security auditing, the system uses directed computational graphs to automatically model and analyze attack paths, privilege relationships, and lateral movement patterns, achieving high detection precision through algorithmic analysis rather than manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If local agents are deployed to monitor and log sessions, then detection capability is enhanced, but ease of operation deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The local agents deployed across the network are designed to be multi-functional, serving both as session monitoring points and as data collection nodes for the centralized logging system. This universality reduces the need for separate specialized components, simplifying deployment and operation while maintaining high detection capability through comprehensive session monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250030746A1Privilege assurance of enterprise computer network environments using lateral movement detection and prevention
Publication Date: 2025.01.23 QOMPLX INC
  • US20250030746A1 patent drawing
  • US20250030746A1 patent drawing
  • US20250030746A1 patent drawing

AI summary

A system and method for the privilege assurance of enterprise computer network environments using lateral movement detection and prevention. The system uses local session monitors to monitor logon sessions within a network, generating and verifying event logs and authentication records to ensure the legitimacy of authenticated user sessions and to revoke credentials when an illicit session is detected, halting lateral movement in real-time.