ATTACK PATH MONITORING AND RISK MITIGATION IN IDENTITY SYSTEMS
A method includes identifying, by at least one processing device, at least one security zone comprising an initial set of objects of a computing environment, determining, by the at least one processing device, whether at least one valid object for inclusion in the at least one security zone exists, in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding, by the at least one processing device, the at least one valid object to the initial set of objects, and performing, by the at least one processing device based on the set of attack paths, attack path risk mitigation.
1 . A method comprising:
identifying, by at least one processing device, at least one security zone comprising an initial set of objects of a computing environment;
determining, by the at least one processing device, whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates one or more actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path comprising a source object, and a target object that corresponds to an object of the initial set of objects;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding, by the at least one processing device, the at least one valid object to the initial set of objects; and
performing, by the at least one processing device based on the set of attack paths, attack path risk mitigation.
2 . The method of claim 1 , further comprising:
identifying, by the at least one processing device, the set of candidate objects that have the at least one control relationship to the at least one object of the initial set of objects;
determining, by the at least one processing device, whether the at least one valid object for inclusion in the at least one security zone exists within the set of candidate objects; and
in response to determining that at least one valid object exists within the set of candidate objects, adding, by the at least one processing device, the at least one valid object to the initial set of objects.
3 . The method of claim 1 , further comprising:
identifying, by the at least one processing device, the zero-cost attack path from a set of attack paths;
determining, by the at least one processing device, whether the source object is valid for inclusion in the at least one security zone; and
in response to determining that the source object is valid for inclusion in the at least one security zone, adding, by the at least one processing device, all objects of the zero-cost attack path to the initial set of objects.
4 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of a set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
5 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
6 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.
7 . The method of claim 1 , wherein performing attack path monitoring and computing environment risk mitigation comprises using an identity risk fabric to at least one of: amplify risk for a first object or reduce risk of a second object.
8 . The method of claim 1 , wherein the computing environment uses a hybrid identity system comprising a remote identity system and an on-premises identity system linked to the remote identity system.
9 . A system comprising:
a memory; and
at least one processing device communicatively coupled to the memory, to perform operations comprising:
identifying at least one security zone comprising an initial set of objects of a computing environment;
determining whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates one or more actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path comprising a source object, and a target object that corresponds to an object of the initial set of objects;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding the at least one valid object to the initial set of objects; and
performing, based on the set of attack paths, attack path risk mitigation.
10 . The system of claim 9 , wherein the operations further comprise:
identifying the set of candidate objects that have the at least one control relationship to the at least one object of the initial set of objects;
determining whether the at least one valid object for inclusion in the at least one security zone exists within the set of candidate objects; and
in response to determining that at least one valid object exists within the set of candidate objects, adding the at least one valid object to the initial set of objects.
11 . The system of claim 9 , wherein the operations further comprise:
identifying the zero-cost attack path from a set of attack paths;
determining whether the source object is valid for inclusion in the at least one security zone; and
in response to determining that the source object is valid for inclusion in the at least one security zone, adding all objects of the zero-cost attack path to the initial set of objects.
12 . The system of claim 9 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of a set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
13 . The system of claim 9 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
14 . The system of claim 9 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.
15 . The system of claim 9 , wherein performing attack path monitoring and computing environment risk mitigation comprises using an identity risk fabric to at least one of: amplify risk for a first object or reduce risk of a second object.
16 . A non-transitory computer readable storage medium comprising instructions that, when executed by a processor, cause the processor to perform operations comprising:
identifying at least one security zone comprising an initial set of objects of a computing environment;
determining whether at least one valid object for inclusion in the at least one security zone exists based on:
a set of candidate objects that are associated by at least one control relationship with at least one object of the initial set of objects, wherein the at least one control relationship indicates one or more actions performable by at least one candidate object of the set of candidate objects with respect to the at least one object of the initial set of objects; or
a zero-cost attack path comprising a source object, and a target object that corresponds to an object of the initial set of objects;
in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding the at least one valid object to the initial set of objects; and
performing, based on the set of attack paths, attack path risk mitigation.
17 . The non-transitory computer readable storage medium of claim 16 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
obtaining a set of risk metrics associated with the computing environment;
determining, for each attack path of a set of attack paths, a risk impact on the computing environment risk based on the set of risk metrics;
identifying, from each risk impact, an attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the attack path having the greatest risk impact on the computing environment.
18 . The non-transitory computer readable storage medium of claim 16 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting a change to an attack path;
determining a risk for implementing the change;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the change.
19 . The non-transitory computer readable storage medium of claim 16 , wherein performing attack path monitoring and computing environment risk mitigation comprises:
detecting anomalous behavior originating from an attack path;
determining a risk associated with the attack path;
determining whether the risk satisfies a threshold condition; and
in response to determining that the risk satisfies the threshold condition, addressing the anomalous behavior.
20 . The non-transitory computer readable storage medium of claim 16 , wherein performing attack path monitoring and computing environment risk mitigation comprises using an identity risk fabric to at least one of: amplify risk for a first object or reduce risk of a second object.