The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 09, 2024

Filed:

May. 08, 2023
Applicant:

Rapid7, Inc., Boston, MA (US);

Inventors:

Vasudha Shivamoggi, Cambridge, MA (US);

Roy Donald Hodgman, Cambridge, MA (US);

Katherine Wilbur, Brookline, MA (US);

Assignee:

Rapid7, Inc., Boston, MA (US);

Attorney:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 21/552 (2013.01); H04L 63/1425 (2013.01); H04L 63/1441 (2013.01);
Abstract

Systems and methods are disclosed to implement a cyberattack detection system that monitors a computer network for lateral movement. In embodiments, the system uses network data from a computer network to build a baseline of connection behaviors for the network. Connection graphs are generated from new network data that indicate groups of nodes that made connections with one another during a last time interval. The graphs are analyzed for connection behavior anomalies and ranked to determine a subset of graphs with suspected lateral movement. Graphs with suspected lateral movement may be further analyzed to determine a set of possible attack paths in the lateral movements. The suspected attack paths are reported to network administrators via a notification interface. Advantageously, the disclosed system is able to detect potential lateral movements in localized portions of a network by monitoring for connection behavior anomalies in network data gathered from the network.


Find Patent Forward Citations

Loading…