- Patent Title: Lateral movement detection through graph-based candidate selection
-
Application No.: US15582645Application Date: 2017-04-29
-
Publication No.: US10462169B2Publication Date: 2019-10-29
- Inventor: Satheesh Kumar Joseph Durairaj , Stanislav Miskovic , Georgios Apostolopoulos
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: SPLUNK INC.
- Current Assignee: SPLUNK INC.
- Current Assignee Address: US CA San Francisco
- Agency: Perkins Coie LLP
- Main IPC: G08B23/00
- IPC: G08B23/00 ; G06F12/16 ; G06F12/14 ; G06F11/00 ; H04L29/06 ; G06N20/00 ; G06F16/901

Abstract:
A lateral movement application identifies lateral movement (LM) candidates that potentially represent a security threat. Security platforms generate event data when performing security-related functions, such as authenticating a user account. The disclosed technology enables greatly increased accuracy identification of lateral movement (LM) candidates by, for example, refining a population of LM candidates based on an analysis of a time constrained graph in which nodes represent entities, and edges between nodes represent a time sequence of login or other association activities between the entities. The graph is created based on an analysis of the event data, including time sequences of the event data.
Public/Granted literature
- US20180316704A1 LATERAL MOVEMENT DETECTION THROUGH GRAPH-BASED CANDIDATE SELECTION Public/Granted day:2018-11-01
Information query