Remote Desktop Access Risk Assessment via Client Environment Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting unauthorized access via Remote Desktop Protocol (RDP) are inadequate, as they rely on network traffic analysis which can be evaded by attackers, leading to undetected malicious activities.

Innovation Solution

A system that establishes a remote desktop access connection to acquire and analyze information about the client machine's system environment, comparing it to defined usage patterns to assess the risk level and apply control actions based on the analysis, without requiring additional connections or software on the client machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic analysis is used to detect unauthorized access, then detection capability is provided, but attackers can evade detection by disguising malicious activities

Engineering Contradiction:
Improvedetection capabilityVSAvoidevasion by attackers
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Instead of analyzing network traffic packets to detect attacks, the patent inverts the approach by having the target machine actively query and analyze the client machine's system environment information through the RDP connection. This reversal allows detection of the client's true identity and status, making evasion ineffective.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary assessment mechanism that operates through the existing RDP connection. The target machine acts as an intermediary to evaluate client machine information (OS version, screen resolution, hardware details) without requiring additional connections, thereby detecting disguised attacks while maintaining protocol compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If additional connections or software are deployed on the client machine for security monitoring, then detection accuracy is improved, but system complexity and client burden increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The target machine performs self-service security assessment by actively querying the client machine through existing RDP protocols. No additional software or agents are installed on the client; the client's own system information (OS, hardware, screen resolution) is utilized to assess its identity and detect spoofing, thereby maintaining simplicity while improving accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The RDP connection serves multiple functions: it enables both legitimate remote access and security assessment simultaneously. The same connection channel is used for both operational purposes and detection purposes, eliminating the need for separate monitoring infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If real-time analysis of client machine information is performed, then malicious behavior is identified promptly, but processing resources are consumed

Engineering Contradiction:
Improvereal-time detection speedVSAvoidprocessing resources
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The target machine performs preliminary assessment of client machine information immediately upon connection establishment. By evaluating system environment details (OS version, screen resolution, hardware configuration) at the outset, the patent enables real-time detection without continuous heavy processing, thereby balancing speed with resource consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10445490B2Remote desktop access to a target machine
Publication Date: 2019.10.15 CYBER ARK SOFTWARE LTD
  • US10445490B2 patent drawing
  • US10445490B2 patent drawing
  • US10445490B2 patent drawing

AI summary

A method for assessing a risk level of a remote desktop access connection includes establishing a remote desktop access connection session between a target machine and the client machine over a network. The remote desktop access connection is established in response to a request received from the client machine. The remote desktop access connection is used acquire, from the client machine, information pertaining to a system environment of the client machine during the connection session. The acquired information is analyzed by comparing the acquired information to information indicative of a defined use of the client machine. Based on the analysis, an assessment is generated of the risk level of the connection session and/or to identify suspicious use of the remote desktop access connection by the client machine.