IP Library Granted Patent US 11,736,503
Granted Patent B2
US 11,736,503 · App. 17/013,209 · Granted Aug 22, 2023

Detection of anomalous lateral movement in a computer network

Inventor: Anirudh Kondaveeti (Redwood City, CA)
Assignee: Salesforce, Inc.
H04L63/1425H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,736,503
App. No.
17/013,209
Granted
Aug 22, 2023
Kind
B2
Abstract

Various embodiments of methods for detecting anomalous activity in a computer network are disclosed. A method includes a computer system receiving an indication of a current session establishing a secure channel to a computing device within a network. The computer system evaluates information relating to the current session, as well as information relating to one or more other sessions. Using this information, the computing system performs monitoring to detect the presence of anomalous lateral movement within the network, for example based on detecting multiple user credentials. Based on the evaluating performed, the computer system generates a score for the current session and reports whether the score is indicative of anomalous lateral movement.

Claims (39)

1. A method comprising:

receiving, at a computer system, session information relating to a current session and one or more previous sessions in which a network is accessed by a particular user;

evaluating, by the computer system, network activity, wherein the evaluating includes:

a first evaluation of a point of an entry into the network for the current session, wherein the point of entry is a host within the network at which the current session originated, wherein the first evaluation includes generating a prevalence value for the point of entry that is determined by aggregating user activity from different users based on a number and quality of links to the point of entry, and wherein the first evaluation further includes comparing the prevalence value to a threshold; and

a second evaluation of timing of the current session relative to previous session timing for the particular user, wherein the second evaluation includes determining whether timing information for the current session deviates from timing information for prior sessions of the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and

determining, by the computer system, whether a score based on the evaluating is indicative of whether anomalous lateral movement is present within the network.

2. The method of claim 1 , wherein the second evaluation is based on a user profile created using history data in secure shell session (SSH) logs for the particular user.

3. The method of claim 1 , wherein the second evaluation is performed by applying principal component analysis on data in a user profile in order to determine timing anomalies for login activities of the particular user.

4. The method of claim 1 , wherein the evaluating includes:

a further evaluation of whether the particular user has an active Wi-Fi or virtual private network (VPN) connection to the network.

5. The method of claim 1 , wherein the evaluating includes:

a further evaluation of whether network activity associated with the particular user is anomalous relative to network activity of other users designated as peers to the particular user.

6. The method of claim 5 , wherein the other users are designated as peers to the particular user based on a common job function.

7. The method of claim 5 , wherein the other users are designated as peers to the particular user based on historical data.

8. The method of claim 1 , wherein the evaluating includes:

a third evaluation of whether the particular user has an active Wi-Fi or virtual private network (VPN) connection to the network; and

a fourth evaluation of whether network activity associated with the particular user is anomalous relative to network activity of other users designated as peers to the particular user.

9. A non-transitory, computer-readable medium having program instructions stored thereon that are capable of causing a computing system to implement operations comprising:

determining that a particular user has a current session active with a computing device of a network;

evaluating information to detect anomalous lateral movement within the network, wherein the information relates to the current session and one or more additional sessions within the network, and wherein the evaluating includes:

assessing a point of entry for the current session, wherein the point of entry is a host within the network at which the current session originated, using an algorithm that determines a prevalence of the point of entry relative to other computer systems in the network, wherein determining the prevalence includes assessing paths through the network for each of a plurality of users active during a particular time period, aggregating user path information to generate a prevalence score for the point of entry, and comparing the prevalence score to a threshold value;

assessing, using history information for the particular user, whether timing information for the current session deviates from timing information for prior sessions of the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and

determining whether the evaluating is indicative of anomalous lateral movement within the network.

10. The computer-readable medium of claim 9 , wherein the history information is based on secure shell (SSH) session logs for the particular user.

11. The computer-readable medium of claim 9 , wherein assessing timing of the current session includes performing a principal component analysis algorithm on the history information for the particular user.

12. The computer-readable medium of claim 9 , wherein the evaluating further includes assessing behavior of the particular user during the current session.

13. The computer-readable medium of claim 9 , wherein the evaluating further includes assessing whether the particular user has an active WiFi or VPN connection to the network.

14. The computer-readable medium of claim 9 , wherein the evaluating further includes assessing whether network activity of the particular user is anomalous relative to network activity of peers of the particular user.

15. A method, comprising:

receiving, at a computer system, session information relating to a current session and one or more previous sessions in which a network is accessed;

evaluating, by the computer system, network activity that includes network activity associated with a particular user, wherein the evaluating includes determining a score based on:

a first sub-model that ranks a point of entry for the particular user relative to other network computer systems by generating a prevalence value for the point of entry using user graphs and a population graph that aggregates user activity in the network, wherein the point of entry is a host within the network at which the current session originated; and

a second sub-model that determines whether timing information of the current session deviates from timing information of prior sessions for the particular user by comparing previous session times of the particular user with session times of the current session, wherein the previous session times include respective start times and durations of the prior sessions; and

determining, by the computer system based on the score, whether anomalous lateral movement is present within the network.

16. The method of claim 15 , wherein the evaluating further includes using a third sub-model that determines whether permissible network connection types are currently active.

17. The method of claim 16 , wherein the permissible network connection types include WiFi and VPN.

18. The method of claim 17 , wherein the permissible network connection types are WiFi connection, VPN connection, and wired connection.

19. The method of claim 15 , wherein the second sub-model uses history information from secure shell (SSH) logs.

20. The method of claim 15 , wherein the evaluating further includes using a fourth sub-model that detects anomalous activity during the current session relative to peers of the particular user.

Assignments (2)
CHANGE OF NAME Recorded Jun 29, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 064166/0847 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2020
From: KONDAVEETI, ANIRUDH
To: SALESFORCE.COM, INC.
Reel/Frame 053699/0341 →
Continuity (2)
Provisional Application 62924647 · Oct 22, 2019
Related Publication 20210120026A1 · Apr 22, 2021
Cited By (1)
US 12,363,137