User activity auditing of resource traversal across connected company nodes
Based on occurrence of audit trigger events that include uploading, downloading, modifying, copying, and pasting of resources across browsers at nodes of a company, audit records are generated that indicate user identifiers, time stamps, metadata, and content associated with the resources. The audit records specify trajectories/traversals of resources across the company that are used to determine associated users and data breaches. Pairs of audit records in the traversals have same hashes of content/metadata of a corresponding resource.
1 . A method comprising:
monitoring activity across a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein monitoring activity of the plurality of users comprises,
detecting events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and
generating records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and
determining a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein identifying the traversal of the resource comprises identifying a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.
2 . The method of claim 1 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises identifying the sequence of the records arranged sequentially according to the time stamps indicated in the records.
3 . The method of claim 2 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises:
identifying a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and
identifying a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.
4 . The method of claim 2 , wherein identifying the sequence of the records corresponding to the traversal of the resource comprises:
identifying a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and
identifying a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.
5 . The method of claim 1 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.
6 . The method of claim 1 , wherein determining the traversal of the resource comprises identifying an initial record in the sequence of the records that indicates an initial download of the resource.
7 . The method of claim 1 , wherein determining the traversal of the resource comprises identifying a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.
8 . The method of claim 1 , further comprising:
identifying at least a subset of the plurality of users being indicated in the sequence of the records; and
associating the subset of users with the potential security breach.
9 . A non-transitory machine-readable medium having program code stored thereon, the program code comprising instructions to:
monitor activity across a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein the instructions to monitor activity of the plurality of users comprise instructions to,
detect events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and
generate records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and
determine a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein the instructions to identify the traversal of the resource comprise instructions to identify a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.
10 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to identify the sequence of the records arranged sequentially according to the time stamps indicated in the records.
11 . The non-transitory machine-readable medium of claim 10 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to:
identify a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and
identify a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.
12 . The non-transitory machine-readable medium of claim 10 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions to:
identify a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and
identify a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.
13 . The non-transitory machine-readable medium of claim 9 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.
14 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to determine the traversal of the resource comprise instructions to identify an initial record in the sequence of the records that indicates an initial download of the resource.
15 . The non-transitory machine-readable medium of claim 9 , wherein the instructions to determine the traversal of the resource comprise instructions to identify a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.
16 . The non-transitory machine-readable medium of claim 9 , wherein the program code further comprises instructions to:
identify at least a subset of the plurality users indicated in the sequence of the records; and
associate the subset of users with the potential security breach.
17 . A apparatus comprising:
a processor; and
a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,
monitor activity of a plurality of users at a plurality of browser instances running on respective ones of a plurality of nodes in a network corresponding to a company, wherein the instructions to monitor activity of the plurality of users comprise instructions executable by the processor to cause the apparatus to,
detect events at the plurality of browser instances that trigger auditing of activity of the plurality of users; and
generate records corresponding to the events, wherein each record indicates a time stamp of the corresponding one of the events, an identifier of a resource corresponding to the event, and a hash of at least a portion of content of the resource corresponding to the event; and
determine a traversal of a resource through the plurality of nodes corresponding to a potential security breach based on the records, wherein the instructions to identify the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify a sequence of the records based on the time of day indicated in the records and based on each consecutive pair of records in the sequence indicating at least one of a same hash of at least a portion of content and a same identifier of the resource of the determined traversal.
18 . The apparatus of claim 17 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify the sequence of the records arranged sequentially according to the time stamps indicated in the records.
19 . The apparatus of claim 18 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to:
identify a first record of the records corresponding to a first node of the plurality of nodes at a first time stamp, wherein the first record indicates uploading the resource from the first node to a second node of the plurality of nodes; and
identify a second record of the records corresponding to the second node and the resource at a second time stamp subsequent to the first time stamp.
20 . The apparatus of claim 18 , wherein the instructions to identify the sequence of the records corresponding to the traversal of the resource comprise instructions executable by the processor to cause the apparatus to:
identify a first record of the records that indicates a modification of the resource at a second node of the plurality of nodes, wherein the first record comprises at least one of a first identifier and a first hash of at least a portion of content corresponding to the resource prior to the modification and at least one of a second identifier and a second hash of at least a portion of content corresponding to the resource subsequent to the modification; and
identify a second record of the second node or a third node subsequent to the first record that indicates at least one of the second identifier and the second hash.
21 . The apparatus of claim 17 , wherein the events at the plurality of browser instances comprise at least one of downloading resources, modifying resources, copying resources, pasting resources to a clipboard, and uploading resources.
22 . The apparatus of claim 17 , wherein the instructions to determine the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify an initial record in the sequence of the records that indicates an initial download of the resource.
23 . The apparatus of claim 17 , wherein the instructions to determine the traversal of the resource comprise instructions executable by the processor to cause the apparatus to identify a final record in the sequence of the records that indicates an upload of the resource to an entity external to the company.