System and method thereof for enhanced collection of data of third-party applications
The disclosed system and methods are used for collecting information of third-party applications. A search is performed for detecting uniform resource locator (URL) that is associated with a web page allowing to download at least one third-party application. The search is based on URL patterns that are previously and uniquely determined for each digital data source. An identifier, e.g., client ID, of a third-party application is extracted from each URL of a web page which allows to download a third-party application. Then, the system initiates a software as a service (SaaS) instance in a cloud-based computing environment. The system provides to the third-party application access credentials to access the SaaS instance and extract attributes and behavior data of the third-party application based on at least the actions performed by the third-party application in the SaaS instance.
1 . A method for collecting and storing data of third-party applications, the method comprising:
searching, by a management server in at least one digital web source of a plurality of digital web sources, for a uniform resource locator (URL) that is associated with a web page allowing to download at least one third-party application;
extracting an identifier of a third-party application from the URL;
executing, by a monitoring agentless application (MAA) executing on the management server, a software as a service (SaaS) instance in a cloud-based computing environment of the SaaS, wherein the SaaS instance is an isolated instance initiated by the MAA and populated with simulated information and resources;
providing to the third-party application access credentials to access the SaaS instance, wherein the MAA provides the access credentials to the third-party application for accessing the isolated SaaS instance as a SaaS add-on;
extracting behavior data from the SaaS instance based on at least an action performed by the third-party application in the SaaS instance, wherein the behavior data is indicative of interactions of the third-party application with the simulated information and resources in the isolated SaaS instance; and
updating a third-party application catalog with the behavior data of the third-party application.
2 . The method of claim 1 , wherein the search is based on a predetermined uniform resource locator (URL) pattern, wherein each URL pattern is uniquely associated with a respective digital web source of the plurality of digital web sources, and wherein searching comprises automatically creating an addition to at least one of the URL patterns to detect web pages allowing to download or connect the third-party application.
3 . The method of claim 1 , further comprising:
extracting a predetermined set of attributes of the third-party application that operates on top of the SaaS instance, wherein extracting the predetermined set of attributes comprises accessing an application programming interface (API) of the isolated SaaS instance and requesting attribute data based on a closed list of attribute types classified as having a highest contribution to a threat indicator.
4 . The method of claim 1 , further comprising:
determining whether the extracted attributes and/or the behavior data of the third-party application provide amount of data that is above a predetermined threshold value about the third-party application.
5 . The method of claim 4 , further comprising:
collecting from one or more sources complementary information about the third-party application upon determination that the extracted attributes and the behavior data provide information that is below the predetermined threshold value.
6 . A non-transitory computer-readable medium storing instructions for collecting and storing data of third-party applications, wherein, responsive to execution by one or more processors, the instructions cause the one or more processors to perform steps of:
searching, by a management server in at least one digital web source of a plurality of digital web sources, for a uniform resource locator (URL) that is associated with a web page allowing to download at least one third-party application;
extracting an identifier of a third-party application from the URL;
initiating, by a monitoring agentless application (MAA) executing on the management server, a software as a service (SaaS) instance in a cloud-based computing environment of the SaaS, wherein the SaaS instance is an isolated instance initiated by the MAA and populated with simulated information and resources;
providing to the third-party application access credentials to access the SaaS instance, wherein the MAA provides the access credentials to the third-party application for accessing the isolated SaaS instance as a SaaS add-on;
extracting behavior data from the SaaS instance based on at least an action performed by the third-party application in the SaaS instance, wherein the behavior data is indicative of interactions of the third-party application with the simulated information and resources in the isolated SaaS instance; and
updating a third-party application catalog with the behavior data of the third-party application.
7 . The non-transitory computer-readable medium of claim 6 , wherein the search is based on a predetermined uniform resource locator (URL) pattern, wherein each URL pattern is uniquely associated with a respective digital web source of the plurality of digital web sources, and wherein searching comprises automatically creating an addition to at least one of the URL patterns to detect web pages allowing to download or connect the third-party application.
8 . The non-transitory computer-readable medium of claim 6 , wherein the steps further include:
extracting a predetermined set of attributes of the third-party application that operates on top of the SaaS instance, wherein extracting the predetermined set of attributes comprises accessing an application programming interface (API) of the isolated SaaS instance and requesting attribute data based on a closed list of attribute types classified as having a highest contribution to a threat indicato.
9 . The non-transitory computer-readable medium of claim 6 , wherein the steps further include:
determining whether the extracted attributes and/or the behavior data of the third-party application provide amount of data that is above a predetermined threshold value about the third-party application.
10 . The non-transitory computer-readable medium of claim 9 , wherein the steps further include:
collecting from one or more sources complementary information about the third-party application upon determination that the extracted attributes and the behavior data provide information that is below the predetermined threshold value.
11 . A management server comprising:
one or more processors; and
memory storing instructions that, when executed, cause the one or more processors to:
search, at least one digital web source of a plurality of digital web sources, for a uniform resource locator (URL) that is associated with a web page allowing to download at least one third-party application;
extract an identifier of a third-party application from the URL;
initiate, by a monitoring agentless application (MAA) executing on the management server, a software as a service (SaaS) instance in a cloud-based computing environment of the SaaS, wherein the SaaS instance is an isolated instance initiated by the MAA and populated with simulated information and resources;
provide to the third-party application access credentials to access the SaaS instance, wherein the MAA provides the access credentials to the third-party application for accessing the isolated SaaS instance as a SaaS add-on;
extract behavior data from the SaaS instance based on at least an action performed by the third-party application in the SaaS instance, wherein the behavior data is indicative of interactions of the third-party application with the simulated information and resources in the isolated SaaS instance; and
update a third-party application catalog with the behavior data of the third-party application.
12 . The management server of claim 11 , wherein the search is based on a predetermined uniform resource locator (URL) pattern, wherein each URL pattern is uniquely associated with a respective digital web source of the plurality of digital web sources, and wherein searching comprises automatically creating an addition to at least one of the URL patterns to detect web es allowing to download or connect the third-party application.
13 . The management server of claim 11 , wherein the instructions that, when executed, further cause the one or more processors to:
extract a predetermined set of attributes of the third-party application that operates on top of the SaaS instance, wherein extracting the predetermined set of attributes comprises accessing an application programming interface (API) of the isolated SaaS instance and questing attribute data based on a closed list of attribute types classified as having a highest contribution to a threat indicator.
14 . The management server of claim 11 , wherein the instructions that, when executed, further cause the one or more processors to:
determine whether the extracted attributes and/or the behavior data of the third-party application provide amount of data that is above a predetermined threshold value about the third-party application.
15 . The management server of claim 14 , wherein the instructions that, when executed, further cause the one or more processors to:
collect from one or more sources complementary information about the third-party application upon determination that the extracted attributes and the behavior data provide information that is below the predetermined threshold value.