Cyber security for software-as-a-service factoring risk
A cyber threat defense system can incorporate data from multiple Software-as-a-Service (SaaS) applications hosted by multiple third-party platforms to identify cyber threats across platforms. The system can collect third-party event data describing an administrative event of a SaaS application hosted by an associated third-party platform. The system can identify a user associated with the third-party event data based on a composite user profile constructed from user context data collected across the multiple SaaS applications to identify the user across multiple third-party platforms. The system can associate the user with a user risk profile based on the composite user profile. The system can identify whether the third-party event data corresponds to a cyber threat partially based on the user risk profile. The system can execute an autonomous response in response to the cyber threat using an autonomous response module factoring in the user risk profile.
1 . A method for a cyber threat defense system incorporating data across multiple Software-as-a-Service (SaaS) applications hosted by multiple third-party platforms to identify a cyber threat related to that SaaS application, comprising:
collecting at one or more SaaS modules, from one or more network devices that utilizes one or more SaaS applications, third-party event data describing an administrative event of a SaaS application hosted by an associated third-party platform;
identifying a user associated with the third-party event data based on a composite user profile constructed from user context data collected across the multiple SaaS applications to identify the user across multiple third-party platforms;
associating the user with a user risk profile based on the composite user profile;
identifying whether the third-party event data corresponds to a cyber threat partially based on the user risk profile;
using a user specific profile module to construct the composite user profile describing the user based on the user context data collected from multiple SaaS applications to associate with third-party event data from the one or more SaaS modules, wherein the user specific profile module applies a fuzzy classifier to the user context data from a context gatherer to match with separate user context data by generating an adjustable confidence score for a match between the user context data and the separate user context data and adjusting the confidence score based on the third-party event data from the one or more SaaS modules;
using a cyber threat module that references one or more machine learning models that are trained on a normal behavior of associated with the user and at least their SaaS activity, where the cyber threat module determines a threat risk parameter that factors in ‘what is a likelihood of a chain of two or more unusual behaviors of i) SaaS activity, ii) network activity, iii) user activity and iv) any combinations of these three, under analysis, that fall outside of being the normal behavior associated with the user;’ and thus, are likely malicious behavior indicative of the cyber threat; and
executing an autonomous response in response to the cyber threat using an autonomous response module factoring in the user risk profile.
2 . The method for the cyber threat defense system of claim 1 , further comprising:
assigning a user importance score to the user risk profile of the user based on the composite user profile to indicate a potential sphere of influence of the user.
3 . The method for the cyber threat defense system of claim 2 , further comprising:
assessing the potential sphere of influence of the user based on at least one of administrative permissions, lateral movement, action persistence, and file access.
4 . The method for the cyber threat defense system of claim 2 , further comprising:
generating a vulnerability score based on the third-party event data.
5 . The method for the cyber threat defense system of claim 4 , further comprising:
factoring the user importance score and the vulnerability score into the user risk profile to calculate a degree of damage.
6 . The method for the cyber threat defense system of claim 1 , further comprising:
adjusting a normal behavior benchmark based on the user risk profile.
7 . The method for the cyber threat defense system of claim 1 , further comprising:
registering creation of a virtual device by the user on the third-party platform with a virtual device sensor.
8 . The method for the cyber threat defense system of claim 1 , further comprising:
representing in a graphical user interface the third-party event data with a user interface module.
9 . The method for the cyber threat defense system of claim 1 , further comprising:
collecting user context data from multiple third-party platforms executing one or more of the SaaS applications to identify the user.
10 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the cyber threat defense system to instruct a computing device to perform the method of claim 1 .
11 . An apparatus for a cyber threat defense system, comprising:
a coordinator module configured to contextualize third-party event data from one or more software-as-a-service (SaaS) modules with probe data from one or more probe modules to create a combined data set for analysis;
a context gatherer for one or more SaaS modules configured to collect user context data from multiple third-party platforms executing SaaS applications to identify a user, which is used in creating a composite user profile;
a risk profile module configured to associate the user with a user risk profile based on the composite user profile;
a user specific profile module configured to construct the composite user profile describing the user based on the user context data collected from multiple SaaS applications to associate with third-party event data from the one or more SaaS modules, wherein the user specific profile module is configured to apply a fuzzy classifier to the user context data from the context gatherer to match with separate user context data by generating an adjustable confidence score for a match between the user context data and the separate user context data and adjust the confidence score based on the third-party event data from the one or more SaaS modules;
a cyber threat module that is configured to reference one or more machine learning models that are trained on a normal behavior of associated with the user and at least their SaaS activity, where the cyber threat module determines a threat risk parameter that factors in ‘what is a likelihood of a chain of two or more unusual behaviors of i) SaaS activity, ii) network activity, iii) user activity and iv) any combinations of these three, under analysis that fall outside of being the normal behavior;’ and thus, are likely malicious behavior indicative of a cyber threat; and
an autonomous response module configured to execute at least one autonomous response to the cyber threat identified by the cyber threat module, wherein a first autonomous response factors in the user risk profile from the risk profile module.
12 . The apparatus for the cyber threat defense system of claim 11 , further comprising:
one or more ports to connect to one or more probes monitoring multiple network devices that utilize third-party SaaS applications each hosted by a third-party platform,
wherein the one or more SaaS modules are configured to connect to one or more SaaS connectors, with each SaaS module configured to collect third-party event data describing an administrative event in a given third-party SaaS application, and
wherein the context gatherer is configured to at least one of actively request and passively receive the user context data from a first third-party platform via an application programming interface;
one or more probe modules configured to collect, from the one or more probes, probe data describing network-administrated activity, external to the given third-party SaaS application, executed by the user.
13 . The apparatus for the cyber threat defense system of claim 11 , further comprising:
where the cyber threat module is further configured to identify whether a breach state corresponds to the cyber threat based on the user risk profile.
14 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to match the user context data from the context gatherer with separate internal user context data from other context gatherers at internal service modules associated with other applications.
15 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to match the user context data from the context gatherer with separate external user context data from a second context gatherer for a second SaaS module associated with a second SaaS application.
16 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to generate a confidence score for a match between the user context data from the context gatherer with separate user context data from another context gatherer for an application module associated with another application.
17 . The apparatus for the cyber threat defense system of claim 16 , wherein the user specific profile module is configured to adjust the confidence score based on the third-party event data from one or more individual SaaS modules.
18 . The apparatus for the cyber threat defense system of claim 11 , wherein the user context data includes at least one of a user name, a display name, a full name, a language setting, work group, a job title, a role, license information, an authorized application, a registered device, a permissions level, a file access list, a click profile describing tendency to click on suspicious links, and a platform user risk assessment performed on the user by a third-party platform operator.
19 . The apparatus for the cyber threat defense system of claim 11 , wherein a first SaaS module is configured to monitor a user instruction to a resource controlled by a SaaS application and the user specific profile module is configured to confirm a user identity based on a comparison of the third-party event data to the user instruction.