Preventing network resource takeover
Security data associated with a specified entity is received by one or more processing devices of a security analytics platform. The security data is parsed and a network domain name that is not associated with any computing resources associated with the specified entity is identified. An association is created between the network domain name and a computing resource controlled by the security analytics platform, thus preventing a third party from exploiting the network domain name.
1 . A method, comprising:
receiving, by one or more processing devices of a security analytics platform, security data associated with a specified entity;
identifying, by parsing the security data, a network domain name that is not associated with any computing resources associated with the specified entity;
creating, by the one or more processing devices, an association between the network domain name and a computing resource controlled by the security analytics platform, wherein the association is maintained by the security analytics platform to prevent a third party from exploiting the network domain name;
generating a notification of the association for an owner of the network domain name; and
removing the association between the network domain name and the computing resource controlled by the security analytics platform responsive to receiving a request of the owner of the network domain name.
2 . The method of claim 1 , wherein identifying the network domain name further comprises determining whether each network domain name referenced by the security data is associated with a computing resource.
3 . The method of claim 1 , wherein creating the association between the network domain name and the computing resource controlled by the security analytics platform is based on one or more settings received from the specified entity.
4 . The method of claim 3 , wherein the one or more settings received from the specified entity specify a remediation action associated with the network domain name.
5 . The method of claim 1 , further comprising: selecting the computing resource controlled by the security analytics platform based on a computing resource type associated with the network domain name.
6 . The method of claim 1 , further comprising:
creating a new computing resource associated with the specified entity; and
creating an association between the network domain name and the new computing resource, thus preventing a third party from exploiting the network domain name.
7 . The method of claim 1 , wherein the association is created automatically by the security analytics platform without receiving authorization from the owner of the network domain name prior to notifying the owner of the network domain name.
8 . The method of claim 1 , further comprising selecting the computing resource controlled by the security analytics platform based on a type of association with the network domain name.
9 . A method comprising:
receiving, by one or more processing devices of a security analytics platform, security data associated with a specified entity;
identifying, by parsing the security data, a computing resource that is not associated with a valid network domain name;
creating, by the security analytics platform, an association between the computing resource and a network domain name controlled by the security analytics platform, wherein the association is maintained by the security analytics platform to prevent a third party from exploiting the computing resource;
generating a notification of the association for an owner of the computing resource; and
transferring ownership of the network domain name to the owner of the computing resource responsive to receiving a request of the owner of the computing resource.
10 . The method of claim 9 , wherein creating the association between the computing resource and the network domain name further comprises registering the network domain name to an entity controlled by the security analytics platform.
11 . The method of claim 9 , wherein identifying the computing resource further comprises determining whether each computing resource referenced by the security data is associated with a network domain name.
12 . The method of claim 9 , wherein creating an association between the computing resource and the network domain name controlled by the security analytics platform is based on one or more settings received from the specified entity to specify a remediation action associated with the computing resource.
13 . The method of claim 9 , further comprising: selecting the network domain name controlled by the security analytics platform based on a network domain name type associated with the computing resource.
14 . The method of claim 9 , wherein identifying the computing resource further comprises determining whether the computing resource is associated with a resolvable network domain name.
15 . The method of claim 9 , further comprising selecting the network domain name controlled by the security analytics platform based on a type associated with the computing resource.
16 . A system comprising:
a non-transitory memory;
one or more processing devices of a security analytics platform operatively coupled to the non-transitory memory, the one or more processing devices to perform operations comprising:
receiving, by the one or more processing devices, security data associated with a specified entity;
identifying, by parsing the security data, a first digital asset that is not associated with any other digital asset associated with the specified entity;
creating, by the one or more processing devices, an association between the first digital asset and a second digital asset controlled by the security analytics platform, wherein the association is maintained by the security analytics platform to prevent a third party from exploiting the first digital asset;
generating a notification of the association for an owner of the first digital asset; and
removing the association between the first digital asset and the second digital asset responsive to receiving a request of the owner of the first digital asset.
17 . The system of claim 16 , wherein identifying the first digital asset further comprises determining whether each digital asset referenced by the security data is associated with any other digital asset.
18 . The system of claim 16 , the one or more processing devices to perform operations further comprising: notifying the owner of the first digital asset of the association.
19 . The system of claim 16 , the one or more processing devices to perform operations further comprising: removing the association between the first digital asset and the second digital asset responsive to receiving a command from the owner of the first digital asset.
20 . The system of claim 16 , the one or more processing devices to perform operations further comprising: selecting the second digital asset controlled by the security analytics platform based on a digital asset type associated with the first digital asset.