Unsupervised anomalous access detection using sentence-based feature embeddings
Techniques for unsupervised anomalous access detection using sentence-based feature embeddings are described. Entity data describing users having access to a particular computing resource is obtained from a computing system and utilized, according to a sentence template, to construct descriptive sentences in a natural language format. The sentences are used to create dense vector embeddings via a sentence transformer machine learning (ML) model. The dense vector embeddings are used as input to an unsupervised anomaly detection ML model to detect anomalous users, which can be presented to an administrator.
1 . A computer-implemented method comprising:
receiving a request, at an anomalous access service (AAS) of a cloud provider network, to determine whether a permission for a user to access a computing resource hosted in the cloud provider network is anomalous;
generating, by the AAS, a string value based on a template and at least some metadata associated with the user, the string value comprising a natural language sentence, the natural language sentence including, from the metadata, at least a job title of the user and a geographic location of the user;
transforming, by the AAS, the string value into a vector embedding based on use of a first machine learning (ML) model, wherein the first ML model is a sentence transformer model;
determining, by the AAS, that the permission for the user to access the computing resource is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model comprises an unsupervised anomaly detection model that was trained based on a collection of embeddings corresponding to other users;
causing, by the AAS, an indication to be presented, via a user interface, that the user having the permission to access the computing resource is anomalous;
receiving, at the cloud provider network, a request to remove or disable the permission to access the computing resource for the user; and
updating, by the cloud provider network, a permissions datastore to remove or disable the permission to access the computing resource for the user.
2 . The computer-implemented method of claim 1 , wherein determining that the permission to access the computing resource is anomalous comprises:
obtaining an anomaly score as a result of providing the vector embedding as the input to the second ML model; and
determining that the anomaly score meets or exceeds a threshold value.
3 . The computer-implemented method of claim 2 , wherein:
the threshold value is a user-configured value provided by a different user; or
the threshold value is determined as part of a training of the second ML model.
4 . A computer-implemented method comprising:
receiving a request, at an anomalous access service (AAS) of a cloud provider network, to determine whether an access or permission involving a user for a computing resource hosted in the cloud provider network is anomalous;
generating, by the AAS, a string value based on a template and at least some metadata associated with the user, the string value comprising a natural language sentence;
transforming, by the AAS, the string value into a vector embedding based on use of a first machine learning (ML) model;
determining, by the AAS, that the access or permission is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model was trained using other vector embeddings generated based on sentences corresponding to other users; and
causing, by the AAS, an indication of the determination to be provided.
5 . The computer-implemented method of claim 4 , wherein determining that the access or permission is anomalous comprises obtaining an anomaly score as a result of providing the vector embedding as the input to the second ML model.
6 . The computer-implemented method of claim 5 , wherein determining that the access or permission is anomalous further comprises determining that the anomaly score meets or exceeds a threshold value.
7 . The computer-implemented method of claim 6 , wherein the threshold value is a user-configured value provided by a different user.
8 . The computer-implemented method of claim 6 , wherein the threshold value is determined as part of the training of the second ML model.
9 . The computer-implemented method of claim 4 , wherein the metadata comprises employee information of an organization, and wherein the method further comprises obtaining, by the AAS, the metadata from the electronic directory.
10 . The computer-implemented method of claim 9 , wherein the string value includes a textual description of one or more of:
a job title of the user;
a work location of the user;
a job title of a manager of the user;
a department name or department identifier of the user; or
an amount of time that the user has been with the organization or within a subgroup of the organization.
11 . The computer-implemented method of claim 4 , wherein the metadata comprises computing activity metadata collected from one or more host computing devices of the cloud provider network.
12 . The computer-implemented method of claim 4 , wherein the request pertains to a proposed addition of the user to a group of an organization or a proposed configuration of permissions for the user.
13 . The computer-implemented method of claim 4 , wherein:
the first ML model is a sentence transformer model; and
the second ML model is an unsupervised anomaly detection model.
14 . The computer-implemented method of claim 4 , further comprising:
selecting, by the AAS based on the request, at least one of the first ML model or the second ML model for use.
15 . A system comprising:
a first one or more computing devices to implement a storage service in a multi-tenant cloud provider network, the storage service to store metadata associated with a user; and
a second one or more computing devices to implement an anomalous access service (AAS) in the multi-tenant cloud provider network, the AAS including instructions that upon execution cause the AAS service to:
receive a request to determine whether an access or permission involving the user for a computing resource hosted in the cloud provider network is anomalous;
obtain the metadata from the storage service;
generate a string value based on a template and at least some of the metadata associated with the user, the string value comprising a natural language sentence;
transform the string value into a vector embedding based on use of a first machine learning (ML) model;
determine that the access or permission is anomalous, comprising providing the vector embedding as an input to a second ML model, wherein the second ML model was trained using other vector embeddings generated based on sentences corresponding to other users; and
cause an indication of the determination to be provided.
16 . The system of claim 15 , wherein to determine that the access or permission is anomalous the AAS is at least to obtain an anomaly score as a result of providing the vector embedding as the input to the second ML model.
17 . The system of claim 16 , wherein to determine that the access or permission is anomalous the AAS is at least further to determine that the anomaly score meets or exceeds a threshold value.
18 . The system of claim 17 , wherein the threshold value is a user-configured value provided by a different user.
19 . The system of claim 17 , wherein the threshold value is determined as part of a training of the second ML model.
20 . The system of claim 15 , wherein the string value includes a textual description of one or more of:
a job title of the user;
a work location of the user;
a job title of a manager of the user;
a department name or department identifier of the user; or
an amount of time that the user has been with an organization or within a subgroup of the organization.