INTELLIGENT CLOUD STORAGE SECURITY
A newly created or modified object is sent to a networked local or remote server for analysis. While the object is being analyzed for vulnerabilities, the object is locked and made inaccessible to users, devices, and networks. If the object is identified as malicious, it may be marked for review, deleted, placed in quarantine, or have its permissions changed so that it cannot cause harm by propagating through the environment. Conversely, if the object is identified as safe, the risk of ransomware attacks may also be mitigated by replicating the object across multiple cloud storage platforms.
1 . A non-transitory computer-readable medium including stored instructions, the instructions, when executed by a computing system, causing the computing system to perform operations comprising:
receiving data for storage in a cloud storage object;
locking the cloud storage object;
sending an event to a cloud storage security system, the event including information describing the new data;
receiving an event response from the cloud storage security system; and
performing a security action based on the event response.
2 . The non-transitory computer-readable medium of claim 1 , wherein the cloud storage object is a preexisting cloud storage object and the data is a change to the preexisting cloud storage object.
3 . The non-transitory computer-readable medium of claim 1 , wherein the event includes one or more of an identifier of the cloud storage object, a type of the cloud storage object, an owner of the cloud storage object, a total size of the cloud storage object, a size of a change to the cloud storage object, or a source of the change to the cloud storage object.
4 . The non-transitory computer-readable medium of claim 1 , the operations further comprising sending a copy of the cloud storage object to a scanner, wherein the event response includes results of a scan performed by the scanner on the copy of the cloud storage object.
5 . The non-transitory computer-readable medium of claim 4 , wherein the results of the scan indicate that the data storage object is safe, and the security action comprises unlocking the data storage object responsive to the results of the scan indicating that the data storage object is safe.
6 . The non-transitory computer-readable medium of claim 4 , wherein the results of the scan indicate that a threat was detected in the data storage object, and the security action comprises one or more of: sending a notification of the threat to a client device of a user associated with the data storage object, quarantining the data storage object, deleting the data storage object, changing access permissions for the data storage object, or locking access to a cloud storage platform in which the data object is stored.
7 . The non-transitory computer-readable medium of claim 4 , wherein the scan performed by the scanner is a platform-agnostic scan.
8 . A method comprising:
receiving data for storage in a cloud storage object;
locking the cloud storage object;
sending an event to a cloud storage security system, the event including information describing the new data;
receiving an event response from the cloud storage security system; and
performing a security action based on the event response.
9 . The method of claim 8 , wherein the event includes one or more of an identifier of the cloud storage object, a type of the cloud storage object, an owner of the cloud storage object, a total size of the cloud storage object, a size of a change to the cloud storage object, or a source of the change to the cloud storage object.
10 . The method of claim 8 , further comprising sending a copy of the cloud storage object to a scanner, wherein the event response includes results of a scan performed by the scanner on the copy of the cloud storage object.
11 . The method of claim 10 , wherein the results of the scan indicate that the data storage object is safe, and the security action comprises unlocking the data storage object responsive to the results of the scan indicating that the data storage object is safe.
12 . The method of claim 10 , wherein the results of the scan indicate that a threat was detected in the data storage object, and the security action comprises one or more of: sending a notification of the threat to a client device of a user associated with the data storage object, quarantining the data storage object, deleting the data storage object, changing access permissions for the data storage object, or locking access to a cloud storage platform in which the data object is stored.
13 . A non-transitory computer-readable medium including stored instructions, the instructions, when executed by a computing system, causing the computing system to perform operations comprising:
receiving, from a cloud storage platform, an event identifying a cloud storage object;
determining, using the event, to scan the cloud storage object;
responsive to determining to scan the cloud storage object, downloading a copy of the cloud storage object from the cloud storage platform;
scanning the copy of the cloud storage object using a platform-agnostic scanner; and
providing instructions to the cloud storage platform to perform a security action, the security action determined using results of the scan of the copy of the cloud storage object.
14 . The non-transitory computer-readable medium of claim 13 , wherein the event includes one or more of an identifier of the cloud storage object, a type of the cloud storage object, an owner of the cloud storage object, a total size of the cloud storage object, a size of a change to the cloud storage object, or a source of the change to the cloud storage object.
15 . The non-transitory computer-readable medium of claim 13 , wherein determining to scan the cloud storage object comprises:
identifying a policy that applies to the cloud storage object;
applying the policy to one or more attributes of the cloud storage object to determine whether to can the cloud storage object, wherein the one or more attributes includes at least one of size, frequency of access, total number of accesses, time since last use, frequency of edits, source, or storage location.
16 . The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:
recording activities of a plurality of platform-agnostic scanners that includes the platform-agnostic scanner;
determining, based on the activities of the plurality of platform-agnostic scanners, that the platform-agnostic scanner is available to scan the copy of the cloud storage object; and
instructing the platform-agnostic scanner to scan the copy of the cloud storage object.
17 . The non-transitory computer-readable medium of claim 16 , wherein the operations further comprise:
predicting demand for scanning jobs based on historical data of scanning jobs performed by the plurality of platform-agnostic scanners; and
adding or removing an additional platform-agnostic scanner to the plurality of platform-agnostic scanners based on the predicted demand.
18 . The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise sending, to the cloud storage platform and responsive to determining to scan the cloud storage object, an instruction to lock the cloud storage object.
19 . The non-transitory computer-readable medium of claim 13 , wherein the security action comprises unlocking the data storage object responsive to the results of the scan indicating that the cloud storage object is safe.
20 . The non-transitory computer-readable medium of claim 13 , wherein the results of the scan indicate that a threat was detected in the cloud storage object, and the security action comprises one or more of: sending a notification of the threat to a client device of a user associated with the data storage object, quarantining the data storage object, deleting the data storage object, changing access permissions for the data storage object, or locking access to a cloud storage platform in which the data object is stored.