Remote Protocol Tunnel Detection for Malicious Lateral Movement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote system protocols like RDP are vulnerable to malicious tunneling, which can bypass firewalls and pose cybersecurity threats, necessitating a solution to detect and mitigate such malicious lateral movements.
Innovation Solution
A method and system for detecting malicious tunnels by identifying atomic tunnels based on packet data, classifying them using isomorphic graph structures, and performing mitigation actions on potentially malicious tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote system protocols are used to enable tunneling for convenient access, then ease of operation is improved, but cybersecurity reliability deteriorates due to vulnerability to malicious exploitation
Solution Approach 1:
The patent introduces an intermediary detection system that monitors and analyzes tunneling traffic between devices. This intermediary layer inspectes packet data, identifies malicious lateral movement patterns, and blocks threatening connections while allowing legitimate remote access to continue, thus resolving the contradiction between maintaining operational convenience and ensuring security reliability
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring tunneling traffic, comparing observed patterns against known malicious behaviors, and dynamically adjusting security responses. The detection system provides real-time feedback about potential threats, enabling the system to maintain both convenient access for legitimate users and reliable security against malicious exploitation
2Adaptability or versatility
If tunneling is allowed to bypass firewalls, then adaptability is improved, but harmful factors increase due to unauthorized actions
Solution Approach 1:
The patent segments the tunneling traffic analysis into atomic tunnels, where each atomic tunnel represents a discrete communication path between two devices. By analyzing each atomic tunnel independently and identifying malicious patterns at this granular level, the system can selectively block harmful tunnels while allowing legitimate ones to maintain their adaptability for bypassing firewalls when authorized
Solution Approach 2:
The system changes the 'color' or state of tunnel connections by marking them as legitimate or malicious based on pattern recognition. Legitimate tunnels continue to function with adaptability for bypassing firewalls, while malicious tunnels are identified and blocked, thus maintaining versatility for authorized access while eliminating unauthorized harmful actions
Data Source
AI summary
A system and method for malicious lateral movement detection. A method includes identifying atomic tunnels in packets sent between devices; identifying tunnel constructs; determining a potentially malicious atomic tunnel among the atomic tunnels by comparing edges of each of the atomic tunnels to edges of previously observed tunnel constructs; determining a potentially malicious tunnel including the potentially malicious atomic tunnel; and mitigating the potentially malicious tunnel. Each atomic tunnel is a structure representing communications among the devices defined with respect to at least three nodes and at least two edges. Each node represents a respective device, and each edge represents a connection between two of the devices. Each atomic tunnel has two hops, where each hop is a level of communication in which a packet is sent from one device to another device. Each tunnel construct is a structure including at least one of the atomic tunnels.


