Using an identity-application-resource polygraph to monitor a compute environment
An illustrative method includes monitoring activities within a compute environment and generating a logical graph model using at least a portion of the monitored activities. The logical graph model includes a set of nodes representative of one or more identities, applications, and resources in the compute environment and a set of edges representative of connections between nodes interconnected by the edges. An operation associated with security of the compute environment is performed using the generated logical graph model.
1 . A method comprising:
monitoring activities within a compute environment;
generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes representative of logical entities in the compute environment and a set of edges representative of connections between nodes interconnected by the edges, wherein the set of nodes comprises: one or more nodes representative of one or more identities, one or more nodes representative of one or more applications, and one or more nodes representative of one or more resources within the compute environment; and
performing, using the generated logical graph model, one or more operations associated with security of the compute environment, wherein the one or more operations associated with security of the compute environment include causing a display device to display at least a portion of the logical graph model, including depictions of one or more of the set of nodes and one of more of the set of edges, within a user interface.
2 . The method of claim 1 , wherein the generating the logical graph model comprises determining one or more identities that used one or more applications to access one or more resources within the compute environment.
3 . The method of claim 1 , wherein the set of nodes of logical graph model comprises:
a first type of indicator associated with each node of the one or more nodes representative of the one or more identities;
a second type of indicator associated with each node of the one or more nodes representative of the one or more applications; and
a third type of indicator associated with each node of the one or more nodes representative of the one or more resources.
4 . The method of claim 1 , wherein the set of edges of the logical graph model comprises:
one or more edges representative of one or more connections from the one or more identities to the one or more applications; and
one or more edges representative of one or more connections from the one or more applications to the one or more resources.
5 . The method of claim 1 , wherein the generating the logical graph model comprises clustering one or more nodes of the set of nodes based on an attribute of the one or more nodes.
6 . The method of claim 1 , wherein the one or more operations associated with security of the compute environment include detecting an anomaly based on a change to one or both of the set of nodes or the set of edges of the logical graph model.
7 . The method of claim 6 , wherein the change comprises an addition of one or both of a new node to the set of nodes or a new edge to the set of edges.
8 . The method of claim 6 , wherein the change comprises a change to an attribute of a node in the set of nodes.
9 . The method of claim 6 , further comprising generating an alert based on the detected anomaly.
10 . The method of claim 1 , wherein the one or more operations associated with security of the compute environment include tracking one or more identity transitions that occur over time with respect to an identity, wherein each of the one or more identity transitions includes a transition by a user from being associated with one identity to being associated with another identity.
11 . The method of claim 1 , wherein the one or more operations associated with security of the compute environment include providing a recommendation of a set of permissions that specify how an identity is entitled to interact with one or more applications or resources within the compute environment.
12 . The method of claim 1 , further comprising filtering, based on receiving user input, the logical graph model to determine the at least the portion of the logical graph model to display.
13 . The method of claim 1 , wherein the monitoring activities within the compute environment comprises collecting runtime workload data with an agent configuration deployed within the compute environment.
14 . The method of claim 1 , wherein the monitoring activities within the compute environment comprises collecting non-runtime workload data with an agentless workload scanning configuration.
15 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:
monitoring activities within a compute environment;
generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes representative of logical entities in the compute environment and a set of edges representative of connections between nodes interconnected by the edges, wherein the set of nodes comprises: one or more nodes representative of one or more identities, one or more nodes representative of one or more applications, and one or more nodes representative of one or more resources within the compute environment; and
performing, using the generated logical graph model, one or more operations associated with security of the compute environment, wherein the one or more operations associated with security of the compute environment include causing a display device to display at least a portion of a representation of the logical graph model, including depictions of one or more of the set of nodes and one of more of the set of edges, within a user interface.
16 . A method comprising:
accessing permissions data representative of a set of permissions that specify how one or more identities are entitled to interact with one or more resources within a compute environment;
generating, based on at least a portion of the set of permissions, a logical graph model comprising a set of nodes representative of logical entities in the compute environment and a set of edges representative of a behavioral relationship between nodes interconnected by the edges, wherein the set of nodes comprises one or more nodes representative of the one or more identities and one or more nodes representative of the one or more resources within the compute environment; and
performing, using the generated logical graph model, one or more operations associated with security of the compute environment.
17 . The method of claim 16 , wherein the one or more operations associated with security of the compute environment include determining one or more identities entitled to access a selected resource of the one or more resources within the compute environment.
18 . The method of claim 16 , wherein the one or more operations associated with security of the compute environment include determining one or more potential identity transitions that allows an identity of the one or more identities to access a resource of the one or more resources, wherein each of the one or more potential identity transitions includes a transition by a user from being associated with one identity to being associated with another identity.
19 . The method of claim 16 , wherein the one or more operations associated with security of the compute environment include removing at least one permission of the set of permissions.
20 . The method of claim 16 , wherein the one or more operations associated with security of the compute environment include causing a display device to display at least a portion of the logical graph model, including depictions of one or more of the set of nodes and one of more of the set of edges, within a user interface.