English
Related papers

Related papers: Hopper: Modeling and Detecting Lateral Movement (E…

200 papers

Authenticated lateral movement via compromised accounts is a common adversarial maneuver that is challenging to discover with signature- or rules-based intrusion detection systems. In this work a behavior-based approach to detecting…

Cryptography and Security · Computer Science 2021-04-30 Brian A. Powell

Lateral Movement refers to methods by which threat actors gain initial access to a network and then progressively move through said network collecting key data about assets until they reach the ultimate target of their attack. Lateral…

Adversarial lateral movement via compromised accounts remains difficult to discover via traditional rule-based defenses because it generally lacks explicit indicators of compromise. We propose a behavior-based, unsupervised framework…

Cryptography and Security · Computer Science 2021-08-06 Brian A. Powell

Lateral movement is a crucial component of advanced persistent threat (APT) attacks in networks. Attackers exploit security vulnerabilities in internal networks or IoT devices, expanding their control after initial infiltration to steal…

Cryptography and Security · Computer Science 2024-11-18 Jiajun Zhou , Jiacheng Yao , Xuanze Chen , Shanqing Yu , Qi Xuan , Xiaoniu Yang

Lateral movement attacks are a serious threat to enterprise security. In these attacks, an attacker compromises a trusted user account to get a foothold into the enterprise network and uses it to attack other trusted users, increasingly…

Cryptography and Security · Computer Science 2019-05-06 Pin-Yu Chen , Sutanay Choudhury , Luke Rodriguez , Alfred Hero , Indrajit Ray

Ransomware impact hinges on how easily an intruder can move laterally and spread to the maximum number of assets. We present a graph-theoretic formulation that casts lateral movement as a path-closure problem over a probability semiring to…

Discrete Mathematics · Computer Science 2025-11-10 Satyam Tyagi , Ganesh Murugesan

Lateral movement is a tactic that adversaries employ most frequently in enterprise IT environments to traverse between assets. In operational technology (OT) environments, however, few methods exist for lateral movement between…

Cryptography and Security · Computer Science 2025-12-30 Richard Derbyshire

Until two decades ago, industrial networks were deemed secure due to physical separation from public networks. An abundance of successful attacks proved that assumption wrong. Intrusion detection solutions for industrial application need to…

Cryptography and Security · Computer Science 2019-07-10 Simon D. Duque Anton , Daniel Fraunholz , Hans Dieter Schotten

We present the first large-scale characterization of lateral phishing attacks, based on a dataset of 113 million employee-sent emails from 92 enterprise organizations. In a lateral phishing attack, adversaries leverage a compromised…

Cryptography and Security · Computer Science 2019-10-03 Grant Ho , Asaf Cidon , Lior Gavish , Marco Schweighauser , Vern Paxson , Stefan Savage , Geoffrey M. Voelker , David Wagner

Anomaly detection in event logs is a promising approach for intrusion detection in enterprise networks. By building a statistical model of usual activity, it aims to detect multiple kinds of malicious behavior, including stealthy tactics,…

Cryptography and Security · Computer Science 2022-06-29 Corentin Larroche , Johan Mazel , Stephan Clémençon

Given a large enterprise network of devices and their authentication history (e.g., device logons), how can we quantify network vulnerability to lateral attack and identify at-risk devices? We systematically address these problems through…

Social and Information Networks · Computer Science 2020-01-31 Scott Freitas , Andrew Wicker , Duen Horng Chau , Joshua Neil

Local Process Model (LPM) discovery is focused on the mining of a set of process models where each model describes the behavior represented in the event log only partially, i.e. subsets of possible events are taken into account to create…

Machine Learning · Computer Science 2017-12-20 Niek Tax , Natalia Sidorova , Wil M. P. van der Aalst , Reinder Haakma

Lateral Movement (LM) attacks continue to pose a significant threat to enterprise security, enabling adversaries to stealthily compromise critical assets. However, the development and evaluation of LM detection systems are impeded by the…

Cryptography and Security · Computer Science 2025-08-06 Anas Mabrouk , Mohamed Hatem , Mohammad Mamun , Sherif Saad

Most enterprise applications use logging as a mechanism to diagnose anomalies, which could help with reducing system downtime. Anomaly detection using software execution logs has been explored in several prior studies, using both classical…

Machine Learning · Computer Science 2023-11-01 Nadun Wijesinghe , Hadi Hemmati

The rapid detection of attackers within firewalls of enterprise computer net- works is of paramount importance. Anomaly detectors address this problem by quantifying deviations from baseline statistical models of normal network behav- ior…

Cryptography and Security · Computer Science 2016-09-02 Justin Grana , David Wolpert , Joshua Neil , Dongping Xie , Tanmoy Bhattacharya , Russel Bent

In the last decade, an impressive increase in software adaptions has led to a surge in log data production, making manual log analysis impractical and establishing the necessity for automated methods. Conversely, most automated analysis…

Software Engineering · Computer Science 2025-11-19 Shayan Hashemi , Mika Mäntylä

Lateral movement of advanced persistent threats has posed a severe security challenge. Due to the stealthy and persistent nature of the lateral movement, defenders need to consider time and spatial locations holistically to discover latent…

Networking and Internet Architecture · Computer Science 2020-10-07 Linan Huang , Quanyan Zhu

We present a large-scale characterization of attacker activity across 111 real-world enterprise organizations. We develop a novel forensic technique for distinguishing between attacker activity and benign activity in compromised enterprise…

Cryptography and Security · Computer Science 2020-07-29 Neil Shah , Grant Ho , Marco Schweighauser , M. H. Afifi , Asaf Cidon , David Wagner

In appearance-based localization and mapping, loop closure detection is the process used to determinate if the current observation comes from a previously visited location or a new one. As the size of the internal map increases, so does the…

Robotics · Computer Science 2024-07-23 Mathieu Labbé , François Michaud

Knowledge on joint impedance during walking in various conditions is relevant for clinical decision-making and the development of robotic gait trainers, leg prostheses, leg orthotics and wearable exoskeletons. Whereas ankle impedance during…

‹ Prev 1 2 3 10 Next ›