CPC H04L 63/1416 (2013.01) [G06N 5/04 (2013.01); H04L 43/10 (2013.01); H04L 67/06 (2013.01); H04L 41/0893 (2013.01)] | 20 Claims |
1. A computing platform comprising:
a processor; and
memory storing instructions that, when executed by the processor, cause the computing platform to:
identify, from real-time monitored network communications, a communication between the computing platform and a computing device;
determine, by an artificial intelligence engine and based on an indication of a risk factor associated with the communication and based on an indication of a user group, a probability that the communication corresponds to an unauthorized lateral movement event on a network, wherein the risk factor is associated with a network security risk and wherein the user group comprises a group of users having a same set of user group permissions on an enterprise network associated with the monitored network communications; and
trigger, based on the probability, an alert identifying the risk factor that the communication between the computing platform and the computing device corresponds to the unauthorized lateral movement event on the network, wherein the alert comprises a risk score corresponding to a weighted combination of a plurality of lateral movement parameters.
|