Privilege Assurance via Lateral Movement Detection in Enterprise Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity solutions lack comprehensive preventative measures to protect Active Directory from attacks, particularly in ensuring privilege assurance and enforcing the principle of 'least privilege' across enterprise computer networks.
Innovation Solution
A system and method utilizing local agents to monitor and log user sessions, combined with a directed computational graph module, to detect and prevent lateral movement attacks by mapping attack paths and ensuring privilege assurance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If indirect approach of securing access points and responding after attack is used, then implementation simplicity is maintained, but security reliability is insufficient
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and logging user sessions and host relationships before attacks occur. The directed computational graph module pre-computes attack paths and privilege escalation routes, enabling the system to detect and prevent lateral movement attacks before they compromise Active Directory, rather than merely responding after detection.
Solution Approach 2:
The patent introduces an intermediary directed computational graph module that sits between traditional security measures and Active Directory. This module analyzes session data, maps attack paths, and identifies privilege assurance violations, providing an additional layer of security analysis without directly modifying Access Point protocols or Active Directory itself.
2Measurement precision
If comprehensive monitoring of user sessions and host relationships is implemented, then detection precision is improved, but device complexity increases
Solution Approach 1:
The monitoring system is segmented into distinct functional components: local agents that collect session data, a centralized logging system that stores information, and a directed computational graph module that analyzes relationships. This segmentation allows each component to perform its specific function with high precision while managing overall system complexity through modular architecture.
Solution Approach 2:
The patent replaces traditional mechanical security monitoring approaches with a computational graph-based system. Instead of using complex rule-based analysis or manual security auditing, the system uses directed computational graphs to automatically model and analyze attack paths, privilege relationships, and lateral movement patterns, achieving high detection precision through algorithmic analysis rather than manual processes.
3Reliability
If local agents are deployed to monitor and log sessions, then detection capability is enhanced, but ease of operation deteriorates
Solution Approach 1:
The local agents deployed across the network are designed to be multi-functional, serving both as session monitoring points and as data collection nodes for the centralized logging system. This universality reduces the need for separate specialized components, simplifying deployment and operation while maintaining high detection capability through comprehensive session monitoring.
Data Source
AI summary
A system and method for the privilege assurance of enterprise computer network environments using lateral movement detection and prevention. The system uses local session monitors to monitor logon sessions within a network, generating and verifying event logs and authentication records to ensure the legitimacy of authenticated user sessions and to revoke credentials when an illicit session is detected, halting lateral movement in real-time.


