Invention Grant
- Patent Title: Lateral movement candidate detection in a computer network
-
Application No.: US17350689Application Date: 2021-06-17
-
Publication No.: US11658992B2Publication Date: 2023-05-23
- Inventor: Satheesh Kumar Joseph Durairaj , Stanislav Miskovic , Georgios Apostolopoulos
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: SPLUNK INC.
- Current Assignee: SPLUNK INC.
- Current Assignee Address: US CA San Francisco
- Agency: Perkins Coie LLP
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/901 ; G06N5/02 ; G06F21/31 ; G06N20/00 ; H04L41/142 ; H04L41/14 ; H04L41/22 ; G06N5/022 ; G06N7/00

Abstract:
A lateral movement application identifies lateral movement (LM) candidates that potentially represent a security threat. Security platforms generate event data when performing security-related functions, such as authenticating a user account. The disclosed technology enables greatly increased accuracy identification of lateral movement (LM) candidates by, for example, refining a population of LM candidates based on an analysis of a time constrained graph in which nodes represent entities, and edges between nodes represent a time sequence of login or other association activities between the entities. The graph is created based on an analysis of the event data, including time sequences of the event data.
Public/Granted literature
- US20210314337A1 LATERAL MOVEMENT CANDIDATE DETECTION IN A COMPUTER NETWORK Public/Granted day:2021-10-07
Information query