Automatic risk remediation in multi-cloud environment
The technology disclosed relates to analysis of security posture of a cloud environment. In particular, the disclosed technology relates to a system and method of risk event detection and remediation. An event is detected in a cloud environment and a pre-defined risk signature is obtained that identifies one or more entities in the cloud environment and represents an instance of a risk event relative to the one or more entities. The pre-defined risk signature includes a reference to a remediation workflow having one or more commands for one or more remediation actions in the cloud environment. Th pre-defined risk signature is determined to have a threshold match to the event and, based on the determination that the pre-defined risk signature has a threshold match to the event, the remediation workflow is obtained based on the reference. The one or more commands are executed in the cloud environment.
1 . A computer-implemented method comprising:
detecting an event in a cloud environment;
obtaining a pre-defined risk signature that identifies one or more entities in the cloud environment and represents an instance of a risk event relative to the one or more entities, the pre-defined risk signature comprising a reference to a remediation workflow having one or more commands for one or more remediation actions in the cloud environment, wherein the one or more entities comprise one or more of cloud accounts, compute resources, storage resources, or roles;
accessing one or more of permissions data or access control data for pairs of compute resources and storage resources in the cloud environment;
determining that the pre-defined risk signature has a threshold match to the event based on the one or more of permissions data or access control data;
based on the determining that the pre-defined risk signature has a threshold match to the event, obtaining the remediation workflow based on the reference; and
executing the one or more commands in the cloud environment.
2 . The computer-implemented method of claim 1 , and further comprising:
identifying context information based on an infrastructure graph; and
executing the remediation workflow with an input condition that is based on the context information.
3 . The computer-implemented method of claim 1 , wherein the reference comprises a pointer.
4 . The computer-implemented method of claim 1 , wherein the remediation workflow comprises a metacommand.
5 . The computer-implemented method of claim 1 , and comprising:
configuring an orchestration engine to deploy an event log scanner to detect the event;
receiving, by the orchestration engine, event metadata representing the event; and
executing, by the orchestration engine, the remediation workflow.
6 . The computer-implemented method of claim 5 , wherein the orchestration engine comprises a control plane backend in the cloud environment.
7 . A computing system comprising
at least one processor; and
memory storing instructions executable by the at least one processor, wherein the instructions, when executed, cause the computing system to:
detect an event in a cloud environment;
obtain a pre-defined risk signature that identifies one or more entities in the cloud environment and represents an instance of a risk event relative to the one or more entities, the pre-defined risk signature comprising a reference to a remediation workflow having one or more commands for one or more remediation actions in the cloud environment, wherein the one or more entities comprise one or more of cloud accounts, compute resources, storage resources, or roles;
access one or more of permissions data or access control data for pairs of compute resources and storage resources in the cloud environment;
determine that the pre-defined risk signature has a threshold match to the event based on the one or more of permissions data or access control data;
based on the determination, obtain the remediation workflow based on the reference; and
execute the one or more commands in the cloud environment.
8 . The computing system of claim 7 , wherein the instructions, when executed, cause the computing system to:
identify context information based on an infrastructure graph; and
execute the remediation workflow with an input condition that is based on the context information.
9 . The computing system of claim 7 , wherein the reference comprises a pointer.
10 . The computing system of claim 7 , wherein the remediation workflow comprises a metacommand.
11 . The computing system of claim 7 , wherein the instructions, when executed, cause the computing system to:
configure an orchestration engine to deploy an event log scanner to detect the event;
receive, by the orchestration engine, event metadata representing the event; and
execute, by the orchestration engine, the remediation workflow.
12 . The computing system of claim 11 , wherein the orchestration engine comprises a control plane backend in the cloud environment.
13 . A multi-cloud risk event detection and remediation system comprising:
at least one processor; and
memory storing instructions executable by the at least one processor, wherein the instructions, when executed, cause the multi-cloud risk event detection and remediation system to provide:
a command library component configured to obtain, from each respective cloud provider of a plurality of cloud providers, a command library that is specific to the respective cloud provider;
a remediation workflow generator component configured to generate, for a selected cloud provider of the plurality of cloud providers, a remediation workflow that includes a set of commands from the command library that is specific to the selected cloud provider;
a risk signature generator component configured to generate a risk signature that identifies one or more entities in a cloud environment of the selected cloud provider and represents an instance of a risk event relative to the one or more entities;
a mapping component configured to generate a mapping between the risk signature and the remediation workflow; and
a remedial action component configured to execute the set of commands from the remediation workflow for a detected event in the cloud environment based on the mapping.
14 . The multi-cloud risk event detection and remediation system of claim 13 , wherein the mapping comprises a reference in the risk signature.
15 . The multi-cloud risk event detection and remediation system of claim 14 , wherein the reference includes a pointer to the remediation workflow.
16 . The multi-cloud risk event detection and remediation system of claim 13 , and further comprising a matching component configured to:
determine that the detected event has a threshold match to the risk signature; and
obtain the remediation workflow using the mapping.
17 . The multi-cloud risk event detection and remediation system of claim 16 , wherein the risk signature includes a plurality of elements representing the one or more entities and relationships between the one or more entities, and wherein the matching component is configured to determine that the risk signature has the threshold match to the detected event by identifying, from the detected event, a threshold number of elements from the plurality of elements.
18 . The computing system of claim 7 , wherein the pre-defined risk signature includes a plurality of elements representing the one or more entities and relationships between the one or more entities, and wherein the instructions cause the computing system to determine that the pre-defined risk signature has the threshold match to the event by identifying, from the event, a threshold number of elements from the plurality of elements.
19 . The computer-implemented method of claim 1 , and further comprising:
obtaining a command library that is specific to a cloud provider of the cloud environment; and
generating the remediation workflow that includes a set of commands from the command library.
20 . The computer-implemented method of claim 1 , wherein the pre-defined risk signature includes a plurality of elements representing the one or more entities and relationships between the one or more entities, and wherein determining that the pre-defined risk signature has the threshold match to the event comprises identifying, from the event, a threshold number of elements from the plurality of elements.