Attack path monitoring and risk mitigation in identity systems
A method includes generating, by a processing device, at least one security zone comprising a set of objects of a computing environment using at least one identity system, and identifying, by the processing device, a set of attack paths leading to the at least one security zone. Each attack path of the set of attack paths includes a respective target object accessible via a respective source object through at least one control relationship, and each target object is included within the set of objects of the at least one security zone. The method further includes performing, by the processing device based on the set of attack paths, attack path monitoring and risk mitigation.
1 . A method comprising:
defining, by a processing device, at least one security zone comprising an initial set of objects of a computing environment, the computing environment using a hybrid identity system comprising a remote identity system and an on-premises identity system linked to the remote identity system;
identifying, by the processing device, a set of attack paths leading to the at least one security zone, each attack path of the set of attack paths comprising a respective target object accessible via a respective source object through at least one relationship;
determining, by the processing device, whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates certain actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path of the set of attack paths, wherein the zero-cost attack path comprises the respective source object, and an object of the initial set of objects that corresponds to the respective target object of the zero-cost attack path;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding, by the processing device, the at least one valid object to the initial set of objects; and
performing, by the processing device based on the set of attack paths, attack path monitoring and risk mitigation.
2 . The method of claim 1 , further comprising:
identifying, by the processing device, the set of candidate objects that have the at least one control relationship to the at least one object of the initial set of objects;
determining, by the processing device, whether the at least one valid object for inclusion in the at least one security zone exists within the set of candidate objects; and
in response to determining that at least one valid object exists within the set of candidate objects, adding, by the processing device, the at least one valid object to the initial set of objects.
3 . The method of claim 1 , further comprising:
identifying, by the processing device, the zero-cost attack path from the set of attack paths;
determining, by the processing device, whether the source object of the zero-cost attack path is valid for inclusion in the at least one security zone; and
in response to determining that the source object is valid for inclusion in the at least one security zone, adding, by the processing device, all objects of the zero-cost attack path to the initial set of objects.
4 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of the set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
5 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path of the set of attack paths;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
6 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path of the set of attack paths;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.
7 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises using an identity risk fabric to at least one of: amplify risk for a first object or reduce risk of a second object.
8 . A system comprising:
a memory; and
a processing device communicatively coupled to the memory, to perform operations comprising:
defining at least one security zone comprising an initial set of objects of a computing environment, the computing environment using a hybrid identity system comprising a remote identity system and an on-premises identity system linked to the remote identity system;
identifying a set of attack paths leading to the at least one security zone, each attack path of the set of attack paths comprising a respective target object accessible via a respective source object through at least one relationship;
determining whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates certain actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path of the set of attack paths, wherein the zero-cost attack path comprises the respective source object, and an object of the initial set of objects that corresponds to the respective target object of the zero-cost attack path;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding the at least one valid object to the initial set of objects; and
performing, based on the set of attack paths, attack path monitoring and risk mitigation.
9 . The system of claim 8 , wherein the operations further comprise:
identifying the set of candidate objects that have the at least one control relationship to the at least one object of the initial set of objects;
determining whether the at least one valid object for inclusion in the at least one security zone exists within the set of candidate objects; and
in response to determining that at least one valid object exists within the set of candidate objects, adding the at least one valid object to the initial set of objects.
10 . The system of claim 8 , wherein the operations further comprise:
identifying the zero-cost attack path from the set of attack paths;
determining whether the source object of the zero-cost attack path is valid for inclusion in the at least one security zone; and
in response to determining that the source object is valid for inclusion in the at least one security zone, adding all objects of the zero-cost attack path to the initial set of objects.
11 . The system of claim 8 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of the set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
12 . The system of claim 8 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path of the set of attack paths;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
13 . The system of claim 8 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path of the set of attack paths;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.
14 . The system of claim 8 , wherein performing attack path monitoring and computing environment risk mitigation comprises using an identity risk fabric to at least one of: amplify risk for a first object or reduce risk of a second object.
15 . A non-transitory computer readable storage medium comprising instructions that, when executed by a processor, cause the processor to perform operations comprising:
defining at least one security zone comprising an initial set of objects of a computing environment, the computing environment using a hybrid identity system comprising a remote identity system and an on-premises identity system linked to the remote identity system;
identifying a set of attack paths leading to the at least one security zone, each attack path of the set of attack paths comprising a respective target object accessible via a respective source object through at least one relationship;
determining whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates certain actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path of the set of attack paths, wherein the zero-cost attack path comprises the respective source object, and an object of the initial set of objects that corresponds to the respective target object of the zero-cost attack path;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding the at least one valid object to the initial set of objects; and
performing, based on the set of attack paths, attack path monitoring and risk mitigation.
16 . The non-transitory computer readable storage medium of claim 15 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of the set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
17 . The non-transitory computer readable storage medium of claim 15 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path of the set of attack paths;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
18 . The non-transitory computer readable storage medium of claim 15 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path of the set of attack paths;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.