System and method for source trust-based detection of cybersecurity issues in a computing environment
A system or method for trust-aware cybersecurity detection is presented. The method includes receiving from a computing environment a plurality of cybersecurity signals; detecting in a first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue; determining a trust score of the resource based at least on the identifier; selecting a response action based on the cybersecurity issue; adapting the response action based on the trust score; and initiating the adapted response action in the computing environment.
1 . A method for trust-aware cybersecurity detection, comprising:
generating a representation of a computing environment including a plurality of entities;
determining a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;
detecting a disk of the resource;
generating an inspectable disk based on the detected disk;
statically analyzing the inspectable disk for a cybersecurity object associated with the resource;
receiving from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;
detecting in the first cybersecurity signal of the plurality of cybersecurity signals, a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;
selecting a response action based on the cybersecurity issue;
adapting the response action to the cybersecurity issue based on the determined trust score; and
initiating the adapted response action in the computing environment.
2 . The method of claim 1 , further comprising:
detecting a code repository in the computing environment, the code repository including a plurality of code objects; and
generating the static analysis result based on statically analyzing a code object of the plurality of code object.
3 . The method of claim 1 , further comprising:
detecting a software image repository in the computing environment, the software image repository including a plurality of software images; and
generating the static analysis result based on statically analyzing a software image of the plurality of software images.
4 . The method of claim 1 , further comprising:
detecting in the computing environment an event log, the event log including a plurality of event records;
extracting the plurality of event records from the event log; and
receiving a second cybersecurity signal of the plurality of cybersecurity signals based on the extracted plurality of event records.
5 . The method of claim 1 , further comprising:
selecting the response action from a plurality of response actions, each response action corresponding to the cybersecurity issue.
6 . The method of claim 5 , further comprising:
selecting the response action further based on the trust score.
7 . A non-transitory computer-readable medium storing a set of instructions for trust-aware cybersecurity detection, the set of instructions comprising:
one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:
generate a representation of a computing environment including a plurality of entities;
determine a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;
detect a disk of the resource;
generate an inspectable disk based on the detected disk;
statically analyze the inspectable disk for a cybersecurity object associated with the resource;
receive from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;
detect in the first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;
select a response action based on the cybersecurity issue;
adapt the response action to the cybersecurity issue based on the determined trust score; and
initiate the adapted response action in the computing environment.
8 . A system for trust-aware cybersecurity detection comprising:
a processing circuitry;
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
generate a representation of a computing environment including a plurality of entities;
determine a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;
detect a disk of the resource;
generate an inspectable disk based on the detected disk;
statically analyze the inspectable disk for a cybersecurity object associated with the resource;
receive from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;
detect in the first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;
select a response action based on the cybersecurity issue;
adapt the response action to the cybersecurity issue based on the determined trust score; and
initiate the adapted response action in the computing environment.
9 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a code repository in the computing environment, the code repository including a plurality of code objects; and
generate the static analysis result based on statically analyzing a code object of the plurality of code object.
10 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a software image repository in the computing environment, the software image repository including a plurality of software images; and
generate the static analysis result based on statically analyzing a software image of the plurality of software images.
11 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect in the computing environment an event log, the event log including a plurality of event records;
extract the plurality of event records from the event log; and
receive a second cybersecurity signal of the plurality of cybersecurity signals based on the extracted plurality of event records.
12 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
select the response action from a plurality of response actions, each response action corresponding to the cybersecurity issue.
13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
select the response action further based on the trust score.