Methods and systems for attack generation on data lakes
In one aspect, a computerized method for attack generation on a data lake, comprises: for a data lake repository: providing an attack generation mimicry tool; with the attack generation mimicry tool: implementing a reconnaissance phase attack generation; implementing an infiltration phase attack generation on the data lake repository; implementing a hiding and data intelligence collection phase of the attack by hiding from any monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data is worth abusing or exfiltrating from the data lake repository; implementing data gathering phase of the attack that gathers data about other objects, attributes, and relationships in the data lake repository; and implementing the exfiltration of the data or the abuse of the data.
1 . A computerized method for attack generation on a data lake, comprising:
for a data lake repository:
providing an attack generation mimicry tool; and
with the attack generation mimicry tool:
implementing a reconnaissance phase attack generation;
implementing an infiltration phase attack generation on the data lake repository;
implementing a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine data to target for exfiltration from the data lake repository;
implementing data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and
implementing the exfiltration of the data to target for exfiltration.
2 . The computerized method of claim 1 , wherein a data lake comprises a computerized repository of data stored in a raw format.
3 . The computerized method of claim 1 , wherein the data lake comprises a plurality of object blobs.
4 . The computerized method of claim 1 , wherein implementing the reconnaissance phase attack generation further comprises:
generating a probe and a network access controls, a network authentication, and a network authorization setting.
5 . The computerized method of claim 4 , wherein implementing the reconnaissance phase attack generation further comprises:
probing the network access controls, the network authentication and the network authorization setting; and
generating a variance in machine and human identity behaviors.
6 . The computerized method of claim 1 , wherein implementing the infiltration phase attack generation on the data lake repository further comprises:
generating a privilege escalation by creating and escalating into a privileged access role.
7 . The computerized method of claim 6 , wherein implementing the infiltration phase attack generation on the data lake repository further comprises:
gaining access inside a data store of the data lake repository.
8 . The computerized method of claim 1 , wherein generating a hiding and data intelligence collection phase of the attack further comprises:
generating a plurality of defense evasion signals.
9 . The computerized method of claim 8 , wherein generating a hiding and data intelligence collection phase of the attack further comprises:
discovering a plurality of stores, a plurality of credentials and a plurality of integrations so that the attack generation tools hide from the monitoring tool of the data lake repository.
10 . The computerized method of claim 1 , wherein implementing data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository further comprises:
collecting data to target for exfiltration stored inside the data lake repository and preparing the data to target for exfiltration for an exfiltration operation.
11 . The computerized method of claim 1 further comprising:
deleting the exfiltrated data.
12 . The computerized method of claim 11 , wherein the deletion of the exfiltrated data impacts a CIA (confidentiality, integrity, availability) triad of the data.
13 . A non-transitory machine-readable medium including a program that, when performed by a computer system, enables the computer system to:
for a data lake repository:
provide an attack generation mimicry tool; and
with the attack generation mimicry tool:
implement a reconnaissance phase attack generation;
implement an infiltration phase attack generation on the data lake repository;
implement a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data to target for exfiltration from the data lake repository;
implement a data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and
implement the exfiltration of the data to target for exfiltration.
14 . The non-transitory machine-readable medium of claim 13 , wherein to implement the reconnaissance phase attack generation, the program further enables the computer system to:
generate a probe and a network access control, a network authentication, and a network authorization setting.
15 . The non-transitory machine-readable medium of claim 13 , wherein to implement the infiltration phase attack generation on the data lake repository, the program further enables the computer system to:
generate a privilege escalation by creating and escalating into a privileged access role.
16 . The non-transitory machine-readable medium of claim 13 , wherein to implement the hiding and data intelligence collection phase of the attack, the program further enables the computer system to:
generate a plurality of defense evasion signals.
17 . A system for attack generation on a data lake, comprising:
one or more processors; and
one or more memories connected to the one or more processors, the one or more memories including a program that, when executed by the one or more processors, enables the system to:
for a data lake repository:
provide an attack generation mimicry tool; and
with the attack generation mimicry tool:
implement a reconnaissance phase attack generation;
implement an infiltration phase attack generation on the data lake repository;
implement a hiding and data intelligence collection phase of an attack by hiding from a monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data to target for exfiltration from the data lake repository;
implement a data gathering phase of the attack that gathers data about objects, attributes, and relationships in the data lake repository other than the data targeted for exfiltration; and
implement the exfiltration of the data targeted for exfiltration.
18 . The system of claim 17 , wherein the program further enables the system to:
delete the exfiltrated data.
19 . The system of claim 17 , wherein to implement the infiltration phase attack generation on the data lake repository, the program further enables the system to:
generate a privilege escalation by creating and escalating into a privileged access role.
20 . The system of claim 17 , wherein to implement the hiding and data intelligence collection phase of the attack, the program further enables the system to:
generate a plurality of defense evasion signals.