×

Lateral movement detection for network security analysis

  • US 10,476,898 B2
  • Filed: 05/31/2018
  • Issued: 11/12/2019
  • Est. Priority Date: 08/31/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, by a computer system, first data indicative of computer network activity of a plurality of users and network devices;

    assigning, by the computer system, usage similarity scores to the network devices based on the first data, the usage similarity scores being indicative of which of the network devices have been shared by a user or by a group of users who satisfy a similarity criterion;

    receiving, by the computer system, second data indicative of computer network activity of a particular user of the plurality of users; and

    detecting, by the computer system and in response to the second data, an anomaly indicative that the particular user has interacted with a particular network device with which the particular user does not normally interact, based on the usage similarity scores.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×