Invention Grant
- Patent Title: Lateral movement detection
- Patent Title (中): 横向运动检测
-
Application No.: US14490594Application Date: 2014-09-18
-
Publication No.: US09591006B2Publication Date: 2017-03-07
- Inventor: Ram Shankar Siva Kumar , Nguyen Song Khanh Vu , Marco DiPlacido , Vinod Nair , Aniruddha Das , Matt Swann , Keerthi Selvaraj , Sundararajan Sellamanickam
- Applicant: MICROSOFT CORPORATION
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agent Anand Gupta; Tom Wong; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Lateral movement detection may be performed by employing different detection models to score logon sessions. The different detection models may be implemented by and/or utilize counts computed from historical security event data. The different detection models may include probabilistic intrusion detection models for detecting compromised behavior based on logon behavior, a sequence of security events observed during a logon session, inter-event time between security events observed during a logon session, and/or an attempt to logon using explicit credentials. Scores for each logon session that are output by the different detection models may be combined to generate a ranking score for each logon session. A list of ranked alerts may be generated based on the ranking score for each logon session to identify compromised authorized accounts and/or compromised machines. An attack graph may be automatically generated based on compromised account-machine pairs to visually display probable paths of an attacker.
Public/Granted literature
- US20160088000A1 LATERAL MOVEMENT DETECTION Public/Granted day:2016-03-24
Information query