Approaches to documenting and visualizing indications of risk discovered through an analysis of digital activities performed across different services and using the same for detecting threats
Introduced here is a network-accessible platform (or simply “platform”) that is designed to monitor digital activities that are performed across different services to ascertain, in real time, threats to the security of an enterprise. In order to surface insights into the threats posed to an enterprise, the platform can apply machine learning models to data that is representative of digital activities performed on different services with respective accounts. Each model may be trained to understand what constitutes normal behavior for a corresponding employee with respect to a single service or multiple services. Not only can these models be autonomously trained for the employees of the enterprise, but they can also be autonomously applied to detect, characterize, and catalog those digital activities that are indicative of a threat.
1 . A method performed by a threat detection platform for surfacing indications of risk discovered through analysis of digital activities performed with multiple accounts associated with an individual across multiple Software-as-a-Service (SaaS) services, the method comprising:
for each of the multiple SaaS services,
acquiring, via a corresponding one of multiple application programming interfaces (APIs), data relating to digital activities performed with a corresponding one of the multiple accounts; and
canonicalizing the data into a standardized format such that:
(i) each of the digital activities is represented by a separate data structure, and
(ii) a series of data structures, having the same form and arranged in temporal order, is created for each of the multiple SaaS services;
applying a machine learnt model to the multiple series of data structures created for the multiple SaaS services,
wherein the machine learnt model is trained to understand what constitutes normal behavior of the individual with respect to the multiple SaaS services;
identifying digital activities for which an output produced by the machine learnt model indicates a variation from the normal behavior of the individual;
for each of the identified digital activities,
storing information related to that identified digital activity in a data structure; and
causing display, on an interface, of a text-based visual indicium that includes (i) a natural language description of that identified digital activity and (ii) an indication of a SaaS service of the multiple SaaS services that is associated with that identified digital activity; and
generating a timeline by arranging text-based visual indicia produced for the identified digital activities in temporal order for display on the interface.
2 . The method of claim 1 , further comprising:
determining, based on an automated analysis of the timeline, that a given account of the multiple accounts is likely to have been compromised.
3 . The method of claim 2 , further comprising:
generating, in response to said determining, a summary of a threat posed by compromise of the given account,
wherein the summary specifies (i) a primary entity and (ii) one or more digital activities that resulted in the determination being made.
4 . The method of claim 3 , wherein the primary entity is the individual, the given account, or a communication or a document involved in the one or more digital activities.
5 . The method of claim 1 ,
wherein the data is streamed from the multiple SaaS services via the multiple APIs as the digital activities are performed, and
wherein said applying, said identified, said storing, and said causing are performed in real time, such that the timeline is updated in real time.
6 . The method of claim 1 , wherein the timeline allows for aggregated viewing and analyzing of the identified digital activities performed across the multiple SaaS services.
7 . The method of claim 1 ,
wherein the individual is one of multiple employees of an enterprise, and
wherein said acquiring, said canonicalizing, said applying, said identifying, said storing, and said causing are performed for each of the multiple employees, such that a separate timeline is generated for each of the multiple employees.
8 . The method of claim 1 ,
wherein the data is acquired from the multiple SaaS services in real time as the digital activities are performed with the multiple accounts, and
wherein said canonicalizing, said applying, said identifying, said storing, and said causing are performed in response to said acquiring, such that the timeline is dynamically updated, so as to allow a user to monitor activity across the multiple SaaS services in real time.
9 . The method of claim 1 , further comprising:
receiving input that is indicative of an instruction, provided through interface, to address compromise of an account of the multiple accounts through execution of a remediation action.
10 . The method of claim 9 , wherein the individual is an employee of an enterprise, wherein the instruction is representative of a request to (i) reset a password of the account, (ii) terminate active sessions, if any, of the account, or reset connections, if any, of the account with a network associated with the enterprise.
11 . The method of claim 10 , further comprising:
for each of the identified digital activities,
transmitting a notification to an appropriate person in real time, so that the appropriate person is able to immediately address any potential threat.
12 . The method of claim 11 , wherein the appropriate person is a security professional that is associated with the enterprise.
13 . The method of claim 11 , wherein the appropriate person is the individual with a corresponding account that performed that identified digital activity.