US 12,328,324 B2
System for detecting lateral movement computing attacks
Tomer Rotstein, Haifa (IL); and Eran Shany, Haifa (IL)
Assigned to Microsoft Technology Licensing, LLC, Redmond, WA (US)
Filed by Microsoft Technology Licensing, LLC, Redmond, WA (US)
Filed on Dec. 14, 2022, as Appl. No. 18/081,641.
Claims priority of provisional application 63/414,243, filed on Oct. 7, 2022.
Prior Publication US 2024/0121249 A1, Apr. 11, 2024
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1416 (2013.01) [H04L 63/1425 (2013.01); H04L 63/20 (2013.01)] 16 Claims
OG exemplary drawing
 
1. A system comprising:
a processing unit;
a storage device comprising instructions, which when executed by the processing unit, configure the system to perform operations comprising:
detecting execution of a malicious SQL command at an SQL server;
receiving metadata associated with the indicator associated with the detected malicious SQL command, the metadata comprising:
the malicious SQL command,
a device identifier of a first computing device,
a process identifier associated with the malicious SQL command, and
a timestamp of the malicious SQL command execution;
receiving, from a second computing device, log activity data comprising:
a device identifier of the second computing device,
a process identifier and associated execution timestamp for a process executed on the second computing device, and
a user identifier associated with the process identifier;
matching the device identifier of the first computing device to the device identifier of the second computing device;
matching the process identifier and timestamp from the metadata with the process identifier and associated execution timestamp from the log activity data;
accessing the user identifier associated with the matched process identifier; and
transmitting an alert identifying the second computing device as a source of the malicious SQL command, and the accessed user identifier.