Systems and Methods for Detecting and Reacting to Malicious Activity in Computer Networks
Described herein are systems and methods for performing operations responsive to potentially malicious activity. Embodiments may include receiving an indication of the potentially malicious activity in a computer network; identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity; determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.
1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations responsive to potentially malicious activity, comprising:
receiving an indication of the potentially malicious activity in a computer network;
identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity;
determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and
invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.
2 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.
3 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing use settings of the defined policy for the at least one identified network account, the use settings controlling the ability of the at least one network account to send outgoing network communications.
4 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes invalidating credentials for the at least one identified network account.
5 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes taking an action on the at least one identified network account.
6 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing a parameter of the defined policy.
7 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes storing data associated with the potentially malicious activity.
8 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:
determining, based on data received in the indication, at least one related network account with a relationship criteria in common with the at least one identified network account;
determining at least one corresponding responsive operation for the related network account; and
invoking a corresponding responsive operation, the corresponding response action being implemented to broaden the scope of the invoked at least one responsive operation.
9 . The non-transitory computer readable medium of claim 1 , wherein the receiving further includes querying a network resource and obtaining the indication from the queried network resource.
10 . The non-transitory computer readable medium of claim 1 , wherein the identifying further includes querying a network resource and identifying the at least one associated network account from the queried network resource.
11 . The non-transitory computer readable medium of claim 1 , wherein the determining further includes reading a policy file, the policy file being a locally stored policy file or a remotely stored policy file.
12 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:
identifying a plurality of network accounts associated with the potentially malicious activity, each identified network account having at least one associated network communications policy;
determining, based on the identifying and according at least one associated network communications policy, at least one responsive operation with respect to the identified plurality of network accounts; and
invoking a plurality of responsive operations with respect to the plurality of network accounts, wherein differing responsive operations are applied to different network accounts.
13 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined to be a source of the potentially malicious activity.
14 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined to be a target of the potentially malicious activity.
15 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined based on a type of the potentially malicious activity.
16 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined based on data in the received indication of the potentially malicious activity.
17 . The non-transitory computer readable medium of claim 1 , wherein the operations further include changing network permissions for the at least one identified network account.
18 . The non-transitory computer readable medium of claim 1 , wherein identifying the at least one network account associated with the potentially malicious activity further includes:
identifying credential data associated with a potential network attack;
determining a privileged account from which the credential data originated; and
identifying, as the identified network account, the determined privileged account.
19 . A network system configured for cyber-attack remediation operations, the network system comprising:
at least one computer-readable memory storing instructions; and
at least one processor configured to execute the instructions to:
receive an indication of the potentially malicious activity in a computer network;
identify, based on data included in the indication, at least one network account associated with the potentially malicious activity;
determine, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and
invoke, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.
20 . The network system of claim 19 , wherein the at least one processor is configured to execute the instructions to:
determine, based on data received in the indication, at least one related network account with a relationship criteria in common with the at least one identified network account;
determine at least one corresponding responsive operation for the related network account; and
invoke a corresponding responsive operation, the corresponding response action being implemented to broaden the scope of the invoked at least one responsive operation.
21 . The network system of claim 19 , wherein the responsive operation includes taking an action on the at least one identified network account.
22 . The network system of claim 19 , wherein the responsive operation includes changing a parameter of the defined policy.
23 . The network system of claim 19 , wherein the responsive operation includes storing data associated with the potentially malicious activity.
24 . The network system of claim 19 , wherein the responsive operation includes a change to access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.
25 . The network system of claim 19 , wherein the responsive operation includes a change to use settings of the defined policy for the at least one identified network account, the use settings controlling the ability of the at least one network account to send outgoing network communications.
26 . A computer-implemented method for performing operations responsive to potentially malicious activity, comprising:
receiving an indication of the potentially malicious activity in a computer network;
identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity;
determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and
invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.
27 . The computer-implemented method of claim 26 , wherein the responsive operation includes taking an action on the at least one identified network account.
28 . The computer-implemented method of claim 26 , wherein the responsive operation includes changing a parameter of the defined policy.
29 . The computer-implemented method of claim 26 , wherein the responsive operation includes storing data associated with the potentially malicious activity.
30 . The computer-implemented method of claim 26 , wherein the responsive operation includes changing access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.