Systems and methods for cloud service security risk assessment
In some implementations, a system receives a request to assess security risk associated with a cloud service. The system identifies, based on the request, one or more application programming interface (API) actions associated with the cloud service. The system determines respective security category information for the one or more API actions and/or respective security risk scores for the one or more API actions. The system generates, based on the respective security category information and/or the respective security risk scores, security risk mitigation information. The system causes, based on the security risk mitigation information, one or more actions to be performed. As an example, the system may send the security risk mitigation information to a device, which may allow for presentation of the security risk mitigation information or implementation of code that is included in the security risk mitigation information.
1 . A system for cloud service security risk assessment, the system comprising:
one or more memories; and
one or more processors, communicatively coupled to the one or more memories, configured to:
receive a request to assess security risk associated with a cloud service;
identify, based on the request, one or more application programming interface (API) actions associated with the cloud service;
determine respective security category information and respective security risk scores for the one or more API actions by applying a machine learning model to API action feature information associated with the one or more API actions;
generate, based on the respective security category information and the respective security risk scores for the one or more API actions, security risk mitigation information; and
cause, based on the security risk mitigation information, one or more actions to be performed.
2 . The system of claim 1 , wherein the one or more processors, to determine the respective security category information and the respective security risk scores for the one or more API actions, are configured to:
determine, for each API action of the one or more API actions, respective API action feature information; and
determine security category information and a security risk score for each API action of the one or more API actions by applying the machine learning model to the respective API action feature information.
3 . The system of claim 2 , wherein the machine learning model is trained based on a security requirements profile, API action feature information associated with a plurality of historical API actions, security category determination information associated with the plurality of historical API actions, and security risk score determination information associated with the plurality of historical API actions.
4 . The system of claim 1 , wherein the one or more processors, to generate the security risk mitigation information, are configured to:
generate the security risk mitigation information by applying a machine learning model to the respective security category information and the respective security risk scores for the one or more API actions.
5 . The system of claim 1 , wherein the security risk mitigation information includes one or more security risk mitigation recommendations, and
wherein the one or more processors, to cause the one or more actions to be performed, are configured to:
send, to a device, the security risk mitigation information,
wherein sending the security risk mitigation information to the device allows the device to present the one or more security risk mitigation recommendations via a display of the device.
6 . The system of claim 1 , wherein the security risk mitigation information includes security risk mitigation code, and
wherein the one or more processors, to cause the one or more actions to be performed, are configured to:
send, to a device, the security risk mitigation information,
wherein sending the security risk mitigation information allows the device to implement the security risk mitigation code in a cloud environment associated with the cloud service.
7 . The system of claim 1 , wherein the security risk mitigation information includes security risk monitoring code, and
wherein the one or more processors, to cause the one or more actions to be performed, are configured to:
send, to a device, the security risk mitigation information,
wherein sending the security risk mitigation information allows the device to implement the security risk monitoring code in association with monitoring the cloud service.
8 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a system for cloud service security risk assessment, cause the system to:
identify one or more application programming interface (API) actions associated with a cloud service;
determine respective security category information for the one or more API actions and respective security risk scores for the one or more API actions by applying a machine learning model to API action feature information associated with the one or more API actions;
generate, based on the respective security category information for the one or more API actions and the respective security risk scores for the one or more API actions, security risk mitigation information; and
cause, based on the security risk mitigation information, one or more actions to be performed.
9 . The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions, that cause the system to determine the respective security category information for the one or more API actions and the respective security risk scores for the one or more API actions, cause the system to:
determine, for each API action of the one or more API actions, respective API action feature information; and
determine at least one of security category information or a security risk score for each API action of the one or more API actions by applying the machine learning model to the respective API action feature information.
10 . The non-transitory computer-readable medium of claim 9 , wherein the machine learning model is trained based on a security requirements profile, API action feature information associated with a plurality of historical API actions, and at least one of security category determination information associated with the plurality of historical API actions or security risk score determination information associated with the plurality of historical API actions.
11 . The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions, that cause the system to generate the security risk mitigation information, cause the system to:
generate the security risk mitigation information by applying a machine learning model to the respective security category information for the one or more API actions and the respective security risk scores for the one or more API actions.
12 . The non-transitory computer-readable medium of claim 8 , wherein the security risk mitigation information includes one or more security risk mitigation recommendations, and
wherein the one or more instructions, that cause the system to cause the one or more actions to be performed, cause the system to:
send, to a device, the security risk mitigation information to allow for presentation of the one or more security risk mitigation recommendations by the device.
13 . The non-transitory computer-readable medium of claim 8 , wherein the security risk mitigation information includes security risk mitigation code, and
wherein the one or more instructions, that cause the system to cause the one or more actions to be performed, cause the system to:
send, to a device, the security risk mitigation information to allow for implementation of the security risk mitigation code in a cloud environment associated with the cloud service.
14 . The non-transitory computer-readable medium of claim 8 , wherein the security risk mitigation information includes security risk monitoring code, and
wherein the one or more instructions, that cause the system to cause the one or more actions to be performed, cause the system to:
send, to a device, the security risk mitigation information to allow for implementation of the security risk monitoring code in association with monitoring the cloud service.
15 . A method, comprising:
determining, by a system for cloud service security risk assessment, security category information for an application programming interface (API) action associated with a cloud service and a security risk score for the API action by applying a machine learning model to API action feature information associated with the API action;
generating, by the system and based on the security category information for the API action and the security risk score for the API action, security risk mitigation information; and
causing, by the system and based on the security risk mitigation information, one or more actions to be performed.
16 . The method of claim 15 , wherein determining the security category information for the API action and the security risk score for the API action comprises:
determining the API action feature information associated with the API action.
17 . The method of claim 15 , wherein generating the security risk mitigation information comprises:
generating the security risk mitigation information by applying a machine learning model to the security category information for the API action and the security risk score for the API action.
18 . The method of claim 15 , wherein the security risk mitigation information includes one or more security risk mitigation recommendations, and
wherein causing the one or more actions to be performed comprises:
sending, to a device, the security risk mitigation information to allow for presentation of the one or more security risk mitigation recommendations.
19 . The method of claim 15 , wherein the security risk mitigation information includes security risk mitigation code, and
wherein causing the one or more actions to be performed comprises:
sending, to a device, the security risk mitigation information to allow for implementation of the security risk mitigation code in association with the cloud service.
20 . The method of claim 15 , wherein the security risk mitigation information includes security risk monitoring code, and
wherein causing the one or more actions to be performed comprises:
sending, to a device, the security risk mitigation information to allow for implementation of the security risk monitoring code in association with monitoring the cloud service.