×

LATERAL MOVEMENT DETECTION THROUGH GRAPH-BASED CANDIDATE SELECTION

  • US 20180316704A1
  • Filed: 04/29/2017
  • Published: 11/01/2018
  • Est. Priority Date: 04/29/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • accessing, by a computer system, event data indicative of events related to a plurality of entities associated with a network;

    identifying, by the computer system, based on the event data, lateral movement candidate entities by identifying a subset of the plurality of entities as being associated with particular events that indicate lateral movement in the network;

    creating, by the computer system, based on the event data, a graph data structure that is indicative of a sequence of events associated with the lateral movement candidate entities; and

    analyzing, by the computer system, the graph data structure to identify a potential security threat by identifying a subset of the lateral movement candidate entities that are associated with a particular sequence of events.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×