Cyber security for instant messaging across platforms
A cyber threat defense system can incorporate data from an instant messaging platform with multiple other platforms in a client system to identify cyber threats across the client system. The system can have one or more instant messaging modules to collect instant messaging data from one or more network entities that utilizes one or more instant messaging platforms. A user specific profile module can identify a user of the client system associated with the user account based on a composite user profile constructed from user context data collected across multiple platforms of the client system. A risk profile module can associate the user with a user risk profile based on the composite user profile. The risk profile module can apply one or more artificial intelligence classifiers to the instant message based on the user risk profile. A cyber threat module is configured to identify whether the instant messaging data corresponds to a cyber threat partially based on the user risk profile. An autonomous response module can execute an autonomous response in response to the cyber threat factoring in the user risk profile.
1 . A method for a cyber threat defense system incorporating data across multiple platforms used by a client system to identify a cyber threat, comprising:
collecting, from one or more network entities that utilize one or more instant messaging platforms, instant messaging data describing an instant message and associated with a user account on at least a first instant messaging platform, where the instant messaging data is collected into one or more instant message modules;
generating a composite user profile from user context data collected across multiple platforms of the client system, where the composite user profile for the multiple platforms of the client system factors in data from i) the instant messaging platform and ii) at least one of a System-as-a-Service (SaaS) platform, a cloud platform, an information technology network, and an email platform, associated with the user;
identifying a user of the client system associated with the user account based on the composite user profile and contextualizing the instant messaging data under analysis with at least a portion of the user context data;
associating the user with a user risk profile, wherein the user risk profile is based on a combination of (i) a user importance score that identifies at least a number of services and resource that the user can affect and (ii) a vulnerability score directed to a determination of vulnerabilities based on analysis of the instant message data by one or more artificial intelligence classifiers to calculate a degree of damage attributable to the user in response to the cyber threat;
performing an autonomous response to the cyber threat by an autonomous response module interacting with the one or more instant messaging modules, the autonomous response is based, at least in part, on the user risk profile; and
wherein the collecting of the instant messaging data is conducted by (i) gathering a messaging archive for the client system using a web hook authorized by the instant messaging platform and (ii) translating the instant messaging data into a universal format.
2 . The method for the cyber threat defense system of claim 1 , further comprising:
applying one or more artificial intelligence classifiers to the instant message data based on the user risk profile; and
identifying that the instant messaging data under analysis by the cyber threat defense system corresponds to the cyber threat partially based on the user risk profile.
3 . The method for the cyber threat defense system of claim 2 , further comprising:
accessing the messaging archive to collect the instant messaging data for the user account.
4 . The method for the cyber threat defense system of claim 1 , further comprising:
polling an application programming interface of the instant messaging platform for the instant messaging data associated with the user account.
5 . The method for the cyber threat defense system of claim 1 , further comprising:
directing a mobile device management sub-module in the one or more instant message modules to gather a messaging archive from the instant messaging platform.
6 . The method for the cyber threat defense system of claim 1 , wherein the autonomous response directed by the autonomous response module is at least one of logging out the user, limiting access to a suspect message, deleting the suspect message, and revoking a permission level for the user.
7 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the cyber threat defense system to instruct a computing device to perform the method of claim 1 .
8 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a cyber threat defense system to instruct a computing device to perform operations comprising:
collecting, from one or more network entities that utilize one or more instant messaging platforms, instant messaging data describing an instant message and associated with a user account on at least a first instant messaging platform, wherein the instant messaging data is collected into one or more instant message modules and the collecting of the instant message data is conducted by at least (i) gathering a messaging archive for a client system using a web hook authorized by the instant messaging platform and (ii) translating the instant messaging data into a universal format;
generating a composite user profile from user context data collected across multiple platforms of the client system, where the composite user profile for the multiple platforms of the client system factors in data from i) the instant messaging platform and ii) at least one of a System-as-a-Service (SaaS) platform, a cloud platform, an information technology network, and an email platform, associated with the user;
identifying a user of the client system associated with the user account based on the composite user profile and contextualizing the instant messaging data under analysis with at least a portion of the user context data;
associating the user with a user risk profile based on the composite user profile, wherein the composite user profile is based on a combination of (i) a user importance score that identifies at least a number of services and resource that the user can affect and (ii) a vulnerability score directed to a determination of vulnerabilities based on analysis of the instant message data by one or more artificial intelligence classifiers to calculate a degree of damage attributable to the user in response to the cyber threat; and
performing an autonomous response to the cyber threat by an autonomous response module interacting with the one or more instant messaging modules, the autonomous response is based, at least in part, on the user risk profile.
9 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:
accessing the messaging archive to collect the instant messaging data for the user account.
10 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:
providing a client authorization to the web hook for the instant messaging platform.
11 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:
polling an application programming interface of the instant messaging platform for the instant messaging data associated with the user account.
12 . The non-transitory computer readable medium of claim 8 , wherein the operations performed by the computing device further comprising:
directing a mobile device management sub-module in the one or more instant message modules to gather a messaging archive from the instant messaging platform.
13 . The non-transitory computer readable medium of claim 8 , wherein the autonomous response directed by the autonomous response module is at least one of logging out the user, limiting access to a suspect message, deleting the suspect message, and revoking a permission level for the user.