发明名称 LATERAL MOVEMENT DETECTION
摘要 Lateral movement detection may be performed by employing different detection models to score logon sessions. The different detection models may be implemented by and/or utilize counts computed from historical security event data. The different detection models may include probabilistic intrusion detection models for detecting compromised behavior based on logon behavior, a sequence of security events observed during a logon session, inter-event time between security events observed during a logon session, and/or an attempt to logon using explicit credentials. Scores for each logon session that are output by the different detection models may be combined to generate a ranking score for each logon session. A list of ranked alerts may be generated based on the ranking score for each logon session to identify compromised authorized accounts and/or compromised machines. An attack graph may be automatically generated based on compromised account-machine pairs to visually display probable paths of an attacker.
申请公布号 WO2016044359(A1) 申请公布日期 2016.03.24
申请号 WO2015US50312 申请日期 2015.09.16
申请人 MICROSOFT TECHNOLOGY LICENSING, LLC 发明人 SIVA KUMAR, RAM SHANKAR;VU, NGUYEN SONG KHANH;DIPLACIDO, MARCO;NAIR, VINOD;DAS, ANIRUDDHA;SWANN, MATT;SELVARAJ, KEERTHI;SELLAMANICKAM, SUNDARARAJAN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址