Remote Protocol Tunnel Detection for Malicious Lateral Movement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote system protocols like RDP are vulnerable to malicious tunneling, which can bypass firewalls and pose cybersecurity threats, necessitating a solution to detect and mitigate such malicious lateral movements.

Innovation Solution

A method and system for detecting malicious tunnels by identifying atomic tunnels based on packet data, classifying them using isomorphic graph structures, and performing mitigation actions on potentially malicious tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote system protocols are used to enable tunneling for convenient access, then ease of operation is improved, but cybersecurity reliability deteriorates due to vulnerability to malicious exploitation

Engineering Contradiction:
Improveconvenient access to remote computersVSAvoidcybersecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary detection system that monitors and analyzes tunneling traffic between devices. This intermediary layer inspectes packet data, identifies malicious lateral movement patterns, and blocks threatening connections while allowing legitimate remote access to continue, thus resolving the contradiction between maintaining operational convenience and ensuring security reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring tunneling traffic, comparing observed patterns against known malicious behaviors, and dynamically adjusting security responses. The detection system provides real-time feedback about potential threats, enabling the system to maintain both convenient access for legitimate users and reliable security against malicious exploitation

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If tunneling is allowed to bypass firewalls, then adaptability is improved, but harmful factors increase due to unauthorized actions

Engineering Contradiction:
Improveability to bypass firewallsVSAvoidunauthorized actions
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the tunneling traffic analysis into atomic tunnels, where each atomic tunnel represents a discrete communication path between two devices. By analyzing each atomic tunnel independently and identifying malicious patterns at this granular level, the system can selectively block harmful tunnels while allowing legitimate ones to maintain their adaptability for bypassing firewalls when authorized

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the 'color' or state of tunnel connections by marking them as legitimate or malicious based on pattern recognition. Legitimate tunnels continue to function with adaptability for bypassing firewalls, while malicious tunnels are identified and blocked, thus maintaining versatility for authorized access while eliminating unauthorized harmful actions

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS20260106890A1Malicious lateral movement detection using remote system protocols
Publication Date: 2026.04.16 ARMIS SECURITY LTD
  • US20260106890A1 patent drawing
  • US20260106890A1 patent drawing
  • US20260106890A1 patent drawing

AI summary

A system and method for malicious lateral movement detection. A method includes identifying atomic tunnels in packets sent between devices; identifying tunnel constructs; determining a potentially malicious atomic tunnel among the atomic tunnels by comparing edges of each of the atomic tunnels to edges of previously observed tunnel constructs; determining a potentially malicious tunnel including the potentially malicious atomic tunnel; and mitigating the potentially malicious tunnel. Each atomic tunnel is a structure representing communications among the devices defined with respect to at least three nodes and at least two edges. Each node represents a respective device, and each edge represents a connection between two of the devices. Each atomic tunnel has two hops, where each hop is a level of communication in which a packet is sent from one device to another device. Each tunnel construct is a structure including at least one of the atomic tunnels.