RDP Lateral Movement Detection via Execution Graph Trails
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security solutions are unable to deterministically detect attack progression in real-time across enterprise infrastructure due to their unimodal nature, reliance on artifact signatures, and susceptibility to false positives, which makes it difficult to identify and respond to ongoing attacks, especially those using Remote Desktop Protocol (RDP) lateral movement techniques.
Innovation Solution
A computer-implemented method involving software agents that monitor system-level activities to construct execution graphs, identify logon sessions, and attribute behavior, allowing for real-time detection and tracking of attack progressions by forming global execution trails and determining risk scores, enabling precise interception and surgical response to attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional security solutions use artifact signatures and simple rules to detect attacks, then they can identify isolated indicators of compromise, but they produce false positives and cannot deterministically detect attack progression
Solution Approach 1:
The patent combines multiple unimodal security sensors and detection methods into a unified multi-modal system that correlates events across different data sources. This merging allows the system to distinguish true attack indicators from false positives by requiring consensus across multiple detection modalities, thereby improving reliability while maintaining detection accuracy.
Solution Approach 2:
The system implements feedback loops where detection results from multiple sensors are continuously correlated and refined. The multi-modal correlation mechanism provides feedback that adjusts detection thresholds and prioritization based on the convergence of multiple indicators, reducing false positives while maintaining high detection accuracy for genuine threats.
2Productivity
If security solutions monitor individual alerts and logs separately, then they can capture isolated security events, but they cannot connect the dots to identify ongoing attack sequences
Solution Approach 1:
The patent introduces a new dimension of analysis by creating global execution trails that span multiple systems and time periods. Instead of analyzing isolated events in a single dimension, the system constructs multi-dimensional attack graphs that correlate events across different hosts, users, and time sequences, enabling the reconstruction of complete attack narratives while maintaining real-time detection capability.
Solution Approach 2:
The system performs preliminary actions by pre-establishing execution trails and correlating event sequences before attacks complete their full progression. By proactively building and maintaining global execution graphs that link related events across systems, the system can quickly identify attack patterns as they develop rather than waiting for all indicators to manifest.
3Reliability
If traditional systems focus on entry prevention or retroactive forensics, then they can protect endpoints or identify root causes, but they cannot detect the critical phase of attack progression in real-time
Solution Approach 1:
The system performs preliminary detection by continuously monitoring and correlating events that indicate attack progression before damage occurs. The multi-modal correlation engine proactively identifies suspicious patterns in real-time, enabling security teams to intervene during the progression phase rather than waiting for retroactive forensic analysis, thus reducing response time while maintaining reliable detection.
Solution Approach 2:
The system implements real-time feedback mechanisms that continuously update the security posture based on correlated event patterns. By providing immediate feedback on detected attack progressions through the multi-modal system, organizations can respond dynamically to threats as they unfold, bridging the gap between preventive security measures and reactive incident response.
4Measurement precision
If security operations teams manually analyze alerts through onion peeling, then they can drill down to identify attack trails, but this process exceeds human capacity for large volumes of information
Solution Approach 1:
The patent introduces an automated multi-modal correlation engine as an intermediary between raw security logs and analyst interpretation. This intermediary system performs the complex task of connecting dots across multiple data sources and time sequences, reducing the analytical burden on human operators while maintaining high precision in attack trail identification through automated pattern recognition and correlation.
Solution Approach 2:
The system creates simplified copies or representations of complex attack trails through standardized execution graph models. By transforming raw log data into structured global execution trails that capture the essential attack narrative, the system makes complex attack patterns more manageable and analyzable without losing critical detection precision.
Data Source
AI summary
Infrastructure attacks involving lateral movement are identified by monitoring system level activities using software agents deployed on respective operating systems, and constructing, based on the system level activities, an execution graph comprising execution trails. A logon session between a remote connection client executing on a first operating system and a remote connection server executing on a second operating system is identified. Behavior exhibited from the logon session is attributed to a first global execution trail in the execution graph. A reconnection to the logon session between a remote connection client executing on a third operating system and the remote connection server is then identified, and, thereafter, behavior exhibited from the logon session is attributed to a second global execution trail in the execution graph.


