US 12,407,699 B2
Artificial intelligence-based lateral movement identification tool
Steven E. Sinks, Scottsdale, AZ (US); and Jonathan Sheedy, Poynton (GB)
Assigned to Bank of America Corporation, Charlotte, NC (US)
Filed by Bank of America Corporation, Charlotte, NC (US)
Filed on Dec. 4, 2023, as Appl. No. 18/528,321.
Application 18/528,321 is a continuation of application No. 18/176,080, filed on Feb. 28, 2023, granted, now 11,888,720, issued on Jan. 30, 2024.
Application 18/176,080 is a continuation of application No. 17/466,997, filed on Sep. 3, 2021, granted, now 11,632,321, issued on Apr. 18, 2023.
Application 17/466,997 is a continuation of application No. 16/934,266, filed on Jul. 21, 2020, granted, now 11,146,472, issued on Oct. 12, 2021.
Prior Publication US 2024/0106729 A1, Mar. 28, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 43/10 (2022.01); G06N 5/04 (2023.01); H04L 9/40 (2022.01); H04L 67/06 (2022.01); H04L 41/0893 (2022.01)
CPC H04L 63/1416 (2013.01) [G06N 5/04 (2013.01); H04L 43/10 (2013.01); H04L 67/06 (2013.01); H04L 41/0893 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A computing platform comprising:
a processor; and
memory storing instructions that, when executed by the processor, cause the computing platform to:
identify, from real-time monitored network communications, a communication between the computing platform and a computing device;
determine, by an artificial intelligence engine and based on an indication of a risk factor associated with the communication and based on an indication of a user group, a probability that the communication corresponds to an unauthorized lateral movement event on a network, wherein the risk factor is associated with a network security risk and wherein the user group comprises a group of users having a same set of user group permissions on an enterprise network associated with the monitored network communications; and
trigger, based on the probability, an alert identifying the risk factor that the communication between the computing platform and the computing device corresponds to the unauthorized lateral movement event on the network, wherein the alert comprises a risk score corresponding to a weighted combination of a plurality of lateral movement parameters.