Detection of escalation paths in cloud environments
A method for detecting escalation paths in a cloud environment is provided. The method includes accessing a security graph representing cloud objects and their connections in the cloud environment; analyzing each cloud object to detect an escalation hop from a current cloud object to a next cloud object, wherein the analysis is based, in part, on a plurality of risk factors and reachability parameters determined for each cloud object; and marking the security graph with each identified escalation path in the security graph, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object.
1 . A method for detecting escalation paths in a cloud environment, comprising:
accessing a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;
determining for each cloud object a plurality of reachability parameters;
storing the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;
analyzing each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;
detecting, based on the analysis, an escalation hop from a current cloud object to a next cloud object; and
recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.
2 . The method of claim 1 , further comprising:
traversing the security graph from the source cloud object to analyze all available paths from the source cloud object.
3 . The method of claim 1 , wherein a detected escalation hop is an exploitation of a current analyzed cloud object to a cloud object connected thereto.
4 . The method of claim 3 , wherein a connection between two cloud objects includes any one of: a role connection, a network connection, a control connection, and a data connection.
5 . The method of claim 1 , wherein each of the plurality of risk factors is an available privilege escalation realizable due to by a vulnerability detected within a cloud object, wherein the plurality of risk factors are maintained in an enriched data set (EDS) associated with each cloud object.
6 . The method of claim 5 , wherein the vulnerability includes any one of: an exposed secret vulnerability, a network vulnerability, a known vulnerability, an unknown vulnerability, an identity vulnerability, and a technology product vulnerability.
7 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:
determining, for a current cloud object, if a combination of each of the plurality of risk factors and at least one of the reachability parameters leads to a privilege escalation to a cloud object having a different role than the current cloud object.
8 . The method of claim 1 , wherein the escalation is a secret escalation, and wherein analyzing each cloud object to detect an escalation hop further comprises:
determining if a secret noted in a risk factor of the plurality of risk factors provides access to the next cloud object, wherein the secret is included in an EDS of the current cloud object.
9 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:
detecting an escalation path leveraging multiple hops across identity and network access.
10 . The method of claim 1 , wherein analyzing each cloud object to detect an escalation hop further comprises:
detecting an escalation path leveraging multiple hops across different cloud computing platforms in the cloud environment.
11 . The method of claim 1 , wherein analyzing each cloud object includes performing static analysis of each cloud object.
12 . The method of claim 1 , wherein each cloud object is a node in the security graph.
13 . The method of claim 1 , wherein detecting the escalation paths includes any one of: deterministic detection and un-deterministic detection.
14 . The method of claim 1 , further comprising:
generating a severity ranking for each detected escalation path, based on any one of: a type of object, a type of accessible data, an internal network access, an external network access, and a combination thereof.
15 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for detecting escalation paths in a cloud environment, the process comprising:
accessing a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;
determining for each cloud object a plurality of reachability parameters;
storing the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;
analyzing each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;
detecting, based on the analysis, an escalation hop from a current cloud object to a next cloud object; and
recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.
16 . A system for detecting escalation paths in a cloud environment, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
access a security graph representing all cloud objects and their connections in the cloud environment, each cloud object being represented with an enriched data set (EDS) stored in the security graph;
determine for each cloud object a plurality of reachability parameters;
store the plurality of reachability parameters that are determined for each cloud object in the EDS of the respective cloud object for which the plurality of reachability parameters were determined;
analyze each cloud object of the security graph utilizing static analysis based on (i) a plurality of risk factors that are generated by performing a risk analysis for each individual one of the cloud objects and (ii) the reachability parameters of the each individual one of the cloud objects;
detect an escalation hop from a current cloud object to a next cloud object; and
recording for each cloud object of an escalation path a data feature in the security graph indicating the escalation path, wherein an escalation path is a collection of escalation hops from a source cloud object to a destination cloud object having a higher privilege than the source cloud object.
17 . The system of claim 16 , wherein the system is further configured to:
traverse the security graph from the source cloud object to analyze all available paths from the source cloud object.
18 . The system of claim 16 , wherein a detected escalation hop is an exploitation of a current analyzed cloud object to a cloud object connected thereto.
19 . The system of claim 18 , wherein a connection between two cloud objects includes any one of: a role connection, a network connection, a control connection, and a data connection.
20 . The system of claim 16 , wherein each of the plurality of risk factors is an available privilege escalation realizable due to by a vulnerability detected with a cloud object, wherein the risk factors are maintained in an enriched data set (EDS) associated with each cloud object.
21 . The system of claim 20 , wherein the vulnerability includes any one of: an exposed secret vulnerability, a network vulnerability, a known vulnerability, an unknown vulnerability, an identity vulnerability, and a technology product vulnerability.
22 . The system of claim 16 , wherein the system is further configured to:
determine, for a current cloud object, if a combination of each of the plurality of risk factors and at least one of the reachability parameters leads to a privilege escalation to a cloud object having a different role than the current cloud object.
23 . The system of claim 22 , wherein the privileged escalation is secrets escalation, and wherein the system is further configured to:
determine if a secret noted in a risk factor of the plurality of risk factors provides access to the next cloud object, wherein the secret is included in an EDS of the current cloud object.
24 . The system of claim 16 , wherein the system is further configured to:
detect an escalation path leveraging multiple hops across identity and network access.
25 . The system of claim 16 , wherein the system is further configured to:
detect an escalation path leveraging multiple hops across different cloud computing platforms in the cloud environment.
26 . The system of claim 16 , wherein the system is further configured to:
perform a static analysis of each cloud object.
27 . The system of claim 16 , wherein each cloud object is a node in the security graph.
28 . The system of claim 16 , wherein detecting the escalation paths includes any one of: deterministic detection and un-deterministic detection.