Methods and systems for detecting hiding and data intelligence gathering in data lakes and cloud warehousing
In one aspect, a computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising: implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse; implementing a discovery process in the data lake or the cloud warehouse; implementing a data gathering process in the data lake or the cloud warehouse; and performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.
1 . A computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising:
implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;
implementing a discovery process in the data lake or the cloud warehouse;
implementing a data gathering process in the data lake or the cloud warehouse; and
performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.
2 . The computerized method of claim 1 , wherein implementing the hiding and data intelligence collection analysis phase comprises:
analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.
3 . The computerized method of claim 2 , wherein the truncate command is implemented on an access_history table, a login_history table and a Query_history table.
4 . The computerized method of claim 1 , wherein implementing the discovery process in the data lake or the cloud warehouse further comprises a plurality of metadata operations.
5 . The computerized method of claim 4 , wherein the plurality of metadata operations comprise a discovery operation.
6 . The computerized method of claim 5 , wherein the discovery operation comprises a show operation.
7 . The computerized method of claim 5 , wherein the discovery operation comprises an explain operation.
8 . The computerized method of claim 5 , wherein implementing the data gathering process in the data lake or the cloud warehouse further comprises:
within the cloud warehouse, identifying a plurality of lateral movements.
9 . A system for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising:
one or more processors; and
a non-transitory computer-readable medium storing software that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;
implementing a discovery process in the data lake or the cloud warehouse;
implementing a data gathering process in the data lake or the cloud warehouse; and
performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.
10 . The system of claim 9 , wherein the operation of implementing the hiding and data intelligence collection analysis phase comprises:
analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.
11 . The system of claim 10 , wherein the truncate command is implemented on an access_history table, a login_history table, and a Query_history table.
12 . The system of claim 9 , wherein the operation of implementing the discovery process in the data lake or the cloud warehouse further comprises performing a plurality of metadata operations.
13 . The system of claim 12 , wherein the plurality of metadata operations comprises a discovery operation, and wherein the discovery operation comprises a show operation or an explain operation.
14 . The system of claim 9 , wherein the operation of implementing the data gathering process in the data lake or the cloud warehouse further comprises:
within the cloud data warehouse, identifying a plurality of lateral movements.
15 . A non-transitory computer-readable medium storing software that, when executed by one or more processors, cause the one or more processors to perform operations for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, the operations comprising:
implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse;
implementing a discovery process in the data lake or the cloud warehouse;
implementing a data gathering process in the data lake or the cloud warehouse; and
performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.
16 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the hiding and data intelligence collection analysis phase comprises:
analyzing a hiding and data intelligence collection phase of an attack and implementing a defense evasion analysis using a truncate command.
17 . The non-transitory computer-readable medium of claim 16 , wherein the truncate command is implemented on an access_history table, a login_history table, and a Query_history table.
18 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the discovery process in the data lake or the cloud warehouse further comprises performing a plurality of metadata operations.
19 . The non-transitory computer-readable medium of claim 18 , wherein the plurality of metadata operations comprises a discovery operation, and wherein the discovery operation comprises a show operation or an explain operation.
20 . The non-transitory computer-readable medium of claim 15 , wherein the operation of implementing the data gathering process in the data lake or the cloud warehouse further comprises:
within the cloud data warehouse, identifying a plurality of lateral movements.