Techniques for cross entity correlation of user accounts in cloud computing environments
A system and method for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control is presented. The method includes detecting a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment; detecting an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external entity is managed by an entity which is external to the cloud computing environment; detecting a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal; generating a representation in a security database of the detected principal and of the external identity; connecting the representation of the detected principal with the representation of the external identity based on the hint; and applying a control on the representation.
1 . A method for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control, comprising:
detecting a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;
detecting an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;
detecting a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;
generating a representation in a security database linking the detected principal and of the external identity;
connecting the representation of the detected principal with the representation of the external identity based on the hint; and
applying a control on the representation.
2 . The method of claim 1 , further comprising:
detecting the hint in a log of the cloud computing environment, wherein the log includes a plurality of event records, each event record including an identifier of a resource deployed in the cloud computing environment.
3 . The method of claim 1 , further comprising:
detecting in the hint an association between a first principal and the detected principal, wherein the first principal is deployed in another cloud computing environment.
4 . The method of claim 1 , further comprising:
detecting a first event associated with the detected principal;
detecting a second event associated with a second principal, the second principal connected to the external identity; and
detecting a cybersecurity threat based on the first event and the second event.
5 . The method of claim 4 , further comprising:
detecting in the first event in the cloud computing environment; and
detecting the second event in another cloud computing environment.
6 . The method of claim 5 , further comprising:
initiating a remediation action based on the detected cybersecurity threat.
7 . The method of claim 6 , further comprising:
initiating the remediation action in any one of: the cloud computing environment, the another cloud computing environment, or a combination thereof.
8 . The method of claim 1 , further comprising:
querying an identity and access management (IAM) service to detect the external identity.
9 . The method of claim 1 , further comprising:
applying the control to each identity associated with the canonical user.
10 . A non-transitory computer-readable medium storing a set of instructions for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control, the set of instructions comprising:
one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:
detect a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;
detect an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;
detect a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;
generate a representation in a security database linking the detected principal and of the external identity;
connect the representation of the detected principal with the representation of the external identity based on the hint; and
apply a control on the representation.
11 . A system for performing cross-entity correlation of activity in a cloud computing environment for applying a cybersecurity control comprising:
a processing circuitry;
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
detect a principal in the cloud computing environment, wherein the principal is deployed in the cloud computing environment and the cloud computing environment is implemented on cloud computing infrastructure;
detect an external identity to the cloud computing environment, wherein the external identity associated with a canonical user and the external identity is provided and managed by an entity provider which is external to the cloud computing environment, wherein the external identity corresponds to a primary identity used across multiple cloud computing environments and wherein detecting the external identity comprises querying the identity provider that is external to the cloud computing environment;
detect a hint in an event of the cloud computing environment, wherein the hint associates the external identity with the detected principal;
generate a representation in a security database linking the detected principal and of the external identity;
connect the representation of the detected principal with the representation of the external identity based on the hint; and
apply a control on the representation.
12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect the hint in a log of the cloud computing environment, wherein the log includes a plurality of event records, each event record including an identifier of a resource deployed in the cloud computing environment.
13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect in the hint an association between a first principal and the detected principal, wherein the first principal is deployed in another cloud computing environment.
14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a first event associated with the detected principal;
detect a second event associated with a second principal, the second principal connected to the external identity; and
detect a cybersecurity threat based on the first event and the second event.
15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect in the first event in the cloud computing environment; and
detect the second event in another cloud computing environment.
16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
initiate a remediation action based on the detected cybersecurity threat.
17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
initiate the remediation action in any one of: the cloud compute environment, the another cloud computing environment, or a combination thereof.
18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
query an identity and access management (IAM) service to detect the external identity.
19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
apply the control to each identity associated with the canonical user.