Systems and methods for abnormal Classless Inter-Domain Routing (CIDR) access detection
Systems and methods for abnormal Classless Inter-Domain Routing (CIDR) access detection. The present systems and methods are configured to perform the steps of scanning one or more security groups associated with a cloud environment; assigning a score to one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups; and providing one or more suggested actions based on the score of the one or more CIDR groups.
1 . A method executed by one or more processors of a cloud-based security system, the method comprising steps of:
automatically scanning, by retrieving via cloud provider application programming interfaces (APIs), one or more security group rules, access control lists, and routing table configurations associated with a cloud environment;
determining, for each of one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups, a score based on a plurality of weighted categories, the categories including at least one of Internet Protocol (IP) reputation, geo-location, public exposure of an associated compute instance, vulnerability information, or exclusion of Internet Protocol (IP) addresses contained in a customer-defined allow list;
assigning the calculated score to each of the one or more CIDR groups; and
providing, via a user interface connected to the cloud-based security system, one or more suggested actions based on the score of the one or more CIDR groups, the one or more suggested actions comprising automatically modifying or removing a security group rule permitting access from a CIDR group having a score above a predefined threshold.
2 . The method of claim 1 , wherein the one or more suggested actions include removing a specific CIDR from a security group rule by issuing an update to the cloud provider API.
3 . The method of claim 2 , wherein suggesting the removal of the CIDR is based on the CIDR's score exceeding a predefined threshold and the CIDR not being included in a customer-defined allow list.
4 . The method of claim 1 , wherein the steps comprise:
calculating a score for each of the one or more CIDR groups within the one or more security groups based on analysis of associated access control lists (ACLs) and routing table configurations; and
assigning the calculated score to each of the one or more CIDR groups.
5 . The method of claim 4 , wherein each of the CIDR groups include one or more Internet Protocol (IP) addresses, and wherein the score is based on a risk associated with each of the IP addresses, the risk being determined from flow log data including traffic amount, session length, or session times.
6 . The method of claim 5 , wherein IP addresses in a customer allow list are excluded when calculating the score, the customer allow list being configurable via the user interface of the cloud-based security system.
7 . The method of claim 5 , wherein the score is based on a plurality of categories, wherein each of the categories is assigned a weight and a category score, the categories including at least one of: (i) Internet Protocol reputation, (ii) vulnerability severity of associated compute instances, or (iii) public exposure state of an instance.
8 . The method of claim 7 , wherein each of the categories include a plurality of parameters, the parameters determining the category score assigned to each of the categories, the parameters including at least one of: TOR network detection, VPN detection, or geolocation rarity of an Internet Protocol address.
9 . The method of claim 1 , wherein the steps further comprise:
performing the one or more suggested actions automatically including automatically disabling or modifying a security group rule in response to detection of a CIDR group with a score above the predefined threshold.
10 . The method of claim 1 , wherein the assigned score is a score between 0 and 100, and wherein the score indicates how risky a CIDR group is.
11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors of a cloud-based security system to perform steps of:
automatically scanning, by retrieving via cloud provider application programming interfaces (APIs), one or more security group rules, access control lists, and routing table configurations associated with a cloud environment;
determining, for each of one or more Classless Inter-Domain Routing (CIDR) groups within the one or more security groups, a score based on a plurality of weighted categories, the categories including at least one of Internet Protocol (IP) reputation, geo-location, public exposure of an associated compute instance, vulnerability information, or exclusion of Internet Protocol (IP) addresses contained in a customer-defined allow list;
assigning the calculated score to each of the one or more CIDR groups; and
providing, via a user interface connected to the cloud-based security system, one or more suggested actions based on the score of the one or more CIDR groups, the one or more suggested actions comprising automatically modifying or removing a security group rule permitting access from a CIDR group having a score above a predefined threshold.
12 . The non-transitory computer-readable medium of claim 11 , wherein the one or more suggested actions include removing a specific CIDR from a security group rule by issuing an update to the cloud provider API.
13 . The non-transitory computer-readable medium of claim 12 , wherein suggesting the removal of the CIDR is based on the CIDR's score exceeding a predefined threshold and the CIDR not being included in a customer-defined allow list.
14 . The non-transitory computer-readable medium of claim 11 , wherein the steps comprise:
calculating a score for each of the one or more CIDR groups within the one or more security groups based on analysis of associated access control lists (ACLs) and routing table configurations; and
assigning the calculated score to each of the one or more CIDR groups.
15 . The non-transitory computer-readable medium of claim 14 , wherein each of the CIDR groups include one or more Internet Protocol (IP) addresses, and wherein the score is based on a risk associated with each of the IP addresses, the risk being determined from flow log data including traffic amount, session length, or session times.
16 . The non-transitory computer-readable medium of claim 15 , wherein IP addresses in a customer allow list are excluded when calculating the score, the customer allow list being configurable via the user interface of the cloud-based security system.
17 . The non-transitory computer-readable medium of claim 15 , wherein the score is based on a plurality of categories, wherein each of the categories is assigned a weight and a category score, the categories including at least one of: (i) Internet Protocol reputation, (ii) vulnerability severity of associated compute instances, or (iii) public exposure state of an instance.
18 . The non-transitory computer-readable medium of claim 17 , wherein each of the categories include a plurality of parameters, the parameters determining the category score assigned to each of the categories, the parameters including at least one of: TOR network detection, VPN detection, or geolocation rarity of an Internet Protocol address.
19 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:
performing the one or more suggested actions automatically including automatically disabling or modifying a security group rule in response to detection of a CIDR group with a score above the predefined threshold.
20 . The non-transitory computer-readable medium of claim 11 , wherein the assigned score is a score between 0 and 100, and wherein the score indicates how risky a CIDR group is.