RDP Lateral Movement Detection via Execution Graph Trails

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security solutions are unable to deterministically detect attack progression in real-time across enterprise infrastructure due to their unimodal nature, reliance on artifact signatures, and susceptibility to false positives, which makes it difficult to identify and respond to ongoing attacks, especially those using Remote Desktop Protocol (RDP) lateral movement techniques.

Innovation Solution

A computer-implemented method involving software agents that monitor system-level activities to construct execution graphs, identify logon sessions, and attribute behavior, allowing for real-time detection and tracking of attack progressions by forming global execution trails and determining risk scores, enabling precise interception and surgical response to attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security solutions use artifact signatures and simple rules to detect attacks, then they can identify isolated indicators of compromise, but they produce false positives and cannot deterministically detect attack progression

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple unimodal security sensors and detection methods into a unified multi-modal system that correlates events across different data sources. This merging allows the system to distinguish true attack indicators from false positives by requiring consensus across multiple detection modalities, thereby improving reliability while maintaining detection accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback loops where detection results from multiple sensors are continuously correlated and refined. The multi-modal correlation mechanism provides feedback that adjusts detection thresholds and prioritization based on the convergence of multiple indicators, reducing false positives while maintaining high detection accuracy for genuine threats.

Inventive Principle:
Principle #23Feedback

2Productivity

If security solutions monitor individual alerts and logs separately, then they can capture isolated security events, but they cannot connect the dots to identify ongoing attack sequences

Engineering Contradiction:
Improvedetection speedVSAvoidattack context
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces a new dimension of analysis by creating global execution trails that span multiple systems and time periods. Instead of analyzing isolated events in a single dimension, the system constructs multi-dimensional attack graphs that correlate events across different hosts, users, and time sequences, enabling the reconstruction of complete attack narratives while maintaining real-time detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system performs preliminary actions by pre-establishing execution trails and correlating event sequences before attacks complete their full progression. By proactively building and maintaining global execution graphs that link related events across systems, the system can quickly identify attack patterns as they develop rather than waiting for all indicators to manifest.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional systems focus on entry prevention or retroactive forensics, then they can protect endpoints or identify root causes, but they cannot detect the critical phase of attack progression in real-time

Engineering Contradiction:
Improvesecurity protectionVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary detection by continuously monitoring and correlating events that indicate attack progression before damage occurs. The multi-modal correlation engine proactively identifies suspicious patterns in real-time, enabling security teams to intervene during the progression phase rather than waiting for retroactive forensic analysis, thus reducing response time while maintaining reliable detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements real-time feedback mechanisms that continuously update the security posture based on correlated event patterns. By providing immediate feedback on detected attack progressions through the multi-modal system, organizations can respond dynamically to threats as they unfold, bridging the gap between preventive security measures and reactive incident response.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If security operations teams manually analyze alerts through onion peeling, then they can drill down to identify attack trails, but this process exceeds human capacity for large volumes of information

Engineering Contradiction:
Improveattack trail identificationVSAvoidanalysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an automated multi-modal correlation engine as an intermediary between raw security logs and analyst interpretation. This intermediary system performs the complex task of connecting dots across multiple data sources and time sequences, reducing the analytical burden on human operators while maintaining high precision in attack trail identification through automated pattern recognition and correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates simplified copies or representations of complex attack trails through standardized execution graph models. By transforming raw log data into structured global execution trails that capture the essential attack narrative, the system makes complex attack patterns more manageable and analyzable without losing critical detection precision.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10887337B1Detecting and trail-continuation for attacks through remote desktop protocol lateral movement
Publication Date: 2021.01.05 XM CYBER LTD
  • US10887337B1 patent drawing
  • US10887337B1 patent drawing
  • US10887337B1 patent drawing

AI summary

Infrastructure attacks involving lateral movement are identified by monitoring system level activities using software agents deployed on respective operating systems, and constructing, based on the system level activities, an execution graph comprising execution trails. A logon session between a remote connection client executing on a first operating system and a remote connection server executing on a second operating system is identified. Behavior exhibited from the logon session is attributed to a first global execution trail in the execution graph. A reconnection to the logon session between a remote connection client executing on a third operating system and the remote connection server is then identified, and, thereafter, behavior exhibited from the logon session is attributed to a second global execution trail in the execution graph.