Invention Grant
- Patent Title: Attack monitoring service that selectively analyzes connection graphs for suspected attack paths
-
Application No.: US18144357Application Date: 2023-05-08
-
Publication No.: US11956260B2Publication Date: 2024-04-09
- Inventor: Vasudha Shivamoggi , Roy Donald Hodgman , Katherine Wilbur
- Applicant: Rapid7, Inc.
- Applicant Address: US MA Boston
- Assignee: Rapid7, Inc.
- Current Assignee: Rapid7, Inc.
- Current Assignee Address: US MA Boston
- Agent Ashwin Anand
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F21/55

Abstract:
Systems and methods are disclosed to implement a cyberattack detection system that monitors a computer network for lateral movement. In embodiments, the system uses network data from a computer network to build a baseline of connection behaviors for the network. Connection graphs are generated from new network data that indicate groups of nodes that made connections with one another during a last time interval. The graphs are analyzed for connection behavior anomalies and ranked to determine a subset of graphs with suspected lateral movement. Graphs with suspected lateral movement may be further analyzed to determine a set of possible attack paths in the lateral movements. The suspected attack paths are reported to network administrators via a notification interface. Advantageously, the disclosed system is able to detect potential lateral movements in localized portions of a network by monitoring for connection behavior anomalies in network data gathered from the network.
Public/Granted literature
- US20230275909A1 Attack monitoring service that selectively analyzes connection graphs for suspected attack paths Public/Granted day:2023-08-31
Information query