Invention Grant
- Patent Title: Graph-based detection of lateral movement
-
Application No.: US16573944Application Date: 2019-09-17
-
Publication No.: US11044264B2Publication Date: 2021-06-22
- Inventor: Satheesh Kumar Joseph Durairaj , Stanislav Miskovic , Georgios Apostolopoulos
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: Splunk Inc.
- Current Assignee: Splunk Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Perkins Coie LLP
- Main IPC: G08B23/00
- IPC: G08B23/00 ; G06F12/16 ; G06F12/14 ; G06F11/00 ; H04L29/06 ; G06N20/00 ; G06F16/901 ; H04L12/24 ; G06N5/02 ; G06N7/00

Abstract:
A lateral movement application identifies lateral movement (LM) candidates that potentially represent a security threat. Security platforms generate event data when performing security-related functions, such as authenticating a user account. The disclosed technology enables greatly increased accuracy identification of lateral movement (LM) candidates by, for example, refining a population of LM candidates based on an analysis of a time constrained graph in which nodes represent entities, and edges between nodes represent a time sequence of login or other association activities between the entities. The graph is created based on an analysis of the event data, including time sequences of the event data.
Public/Granted literature
- US20200014718A1 GRAPH-BASED DETECTION OF LATERAL MOVEMENT Public/Granted day:2020-01-09
Information query