Invention Grant
- Patent Title: Detecting and trail-continuation for attacks through remote desktop protocol lateral movement
-
Application No.: US16903785Application Date: 2020-06-17
-
Publication No.: US10887337B1Publication Date: 2021-01-05
- Inventor: Eun-Gyu Kim , Rushikesh Patil , Sandeep Siroya , Niloy Mukherjee
- Applicant: Confluera, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: Confluera, Inc.
- Current Assignee: Confluera, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Goodwin Procter LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
Infrastructure attacks involving lateral movement are identified by monitoring system level activities using software agents deployed on respective operating systems, and constructing, based on the system level activities, an execution graph comprising execution trails. A logon session between a remote connection client executing on a first operating system and a remote connection server executing on a second operating system is identified. Behavior exhibited from the logon session is attributed to a first global execution trail in the execution graph. A reconnection to the logon session between a remote connection client executing on a third operating system and the remote connection server is then identified, and, thereafter, behavior exhibited from the logon session is attributed to a second global execution trail in the execution graph.
Information query