The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 10, 2019

Filed:

Jun. 14, 2017
Applicant:

Microsoft Technology Licensing, Llc, Redmond, WA (US);

Inventors:

Jack Wilson Stokes, III, Northbend, WA (US);

Robert James Mead, Cheltenham, GB;

Tim William Burrell, Cheltenham, GB;

Ian Hellen, Seattle, WA (US);

John Joseph Lambert, Issaquah, WA (US);

Weidong Cui, Redmond, WA (US);

Andrey Marochko, Redmond, WA (US);

Qingyun Liu, Goleta, CA (US);

Assignee:
Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01); G06F 11/30 (2006.01); H04L 29/06 (2006.01); H04L 12/26 (2006.01); H04L 29/08 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); H04L 43/045 (2013.01); H04L 63/145 (2013.01); H04L 63/1425 (2013.01); H04L 63/1466 (2013.01); H04L 63/0807 (2013.01); H04L 67/10 (2013.01); H04L 2463/146 (2013.01);
Abstract

Graph-based detection systems and techniques are provided to identify potential malicious lateral movement paths. System and security events may be used to generate a network connection graph and detect remote file executions and/or other detections, for use in tracking malicious lateral movement across a computer network, such as a compromised computer network. Lateral movement determination across a computer network may be divided into two subproblems: forensic analysis and general detection. With forensic analysis, given a malicious node, possible lateral movement leading into or out of the node is identified. General detection identifies previously unknown malicious lateral movement on a network using a remote file execution detector, and/or other detectors, and a rare path anomaly detection algorithm.


Find Patent Forward Citations

Loading…