Detecting Structurally Anomalous Logins Within Enterprise Networks
Hossein Siadati, Nasir D. Memon
Abstract
Many network intrusion detection systems use byte sequences to detect lateral movements that exploit remote vulnerabilities. Attackers bypass such detection by stealing valid credentials and using them to transmit from one computer to another without creating abnormal network traffic. We call this method Credential-based Lateral Movement. To detect this type of lateral movement, we develop the concept of a Network Login Structure that specifies normal logins within a given network. Our method models a network login structure by automatically extracting a collection of login patterns by using a variation of the market-basket analysis algorithm. We then employ an anomaly detection approach to detect malicious logins that are inconsistent with the enterprise network's login structure. Evaluations show that the proposed method is able to detect malicious logins in a real setting. In a simulated attack, our system was able to detect 82% of malicious logins, with a 0.3% false positive rate. We used a real dataset of millions of logins over the course of five months within a global financial company for evaluation of this work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cc235b76-f1df-4b00-9f4d-cb19da3762faCited by top-tier papers4
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson et al.USENIX Security 2021 · 41 citations
- KnowGraph: Knowledge-Enabled Anomaly Detection via Logical Reasoning on Graph DataAndy Zhou, Xiaojun Xu, Ramesh Raghunathan, Alok Lal et al.CCS 2024 · 5 citations
- ShadowMove: A Stealthy Lateral Movement StrategyAmirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang et al.USENIX Security 2020
- Probabilistic Hash Embeddings for Online Learning of Categorical FeaturesAodong Li, Abishek Sankararaman, Balakrishnan NarayanaswamyAAAI 2026
Builds on1
Related papers
- How to Cover up Anomalous Accesses to Electronic Health RecordsXiaojun Xu, Qingying Hao, Zhuolin Yang, Bo Li et al.USENIX Security 2023
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
- Detecting Stuffing of a User's Credentials at Her Own AccountsKe Coby Wang, Michael K. ReiterUSENIX Security 2020
- Euler: Detecting Network Lateral Movement via Scalable Temporal Graph Link PredictionIsaiah J. King, H. Howie HuangNDSS 2022
- Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise NetworksJoseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra et al.S&P 2024 · 28 citations
