Cross-platform security threat detection
In various embodiments, a process for cross-platform security threat detection includes determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis. The process includes identifying, among the plurality of events, a group of cross-platform events related to the specific event; and analyzing at least the group of cross-platform events to detect a potential security threat. The process includes providing a security threat analysis result associated with the identified group of cross-platform events.
1 . A method, comprising:
determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;
identifying, among the plurality of events, a group of cross-platform events related to the specific event;
analyzing at least the group of cross-platform events to detect a potential security threat; and
providing a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities.
2 . The method of claim 1 , wherein the group of cross-platform events includes at least one event associated with a first platform and at least one event associated with a second platform.
3 . The method of claim 1 , wherein events included in the group of cross-platform events related to the specific event are related by at least one of: being associated with a particular user, being a notable event, or being associated with a particular entity.
4 . The method of claim 1 , wherein identifying the group of cross-platform events related to the specific event includes filtering events to determine a subset of notable events that are relevant to the specific event.
5 . The method of claim 4 , wherein the filtering is based at least on a similarity between the specific event and other events in the group of cross-platform events with respect to at least one of: time, internet protocol (IP) address, or type.
6 . The method of claim 1 , wherein analyzing at least the group of cross-platform events to detect the potential security threat includes using at least one detector to detect the potential security threat.
7 . The method of claim 6 , wherein each of at least a subset of the at least one detector is configured to detect a respective type of potential security threat.
8 . The method of claim 6 , wherein the at least one detector utilizes rule-based pattern analysis.
9 . The method of claim 6 , wherein the at least one detector detects the potential security threat in response to at least one of:
at least a first number of sign-ins are observed for a user within a time span, at least one sign-in exceeds an abnormal score, and at least one sign-in exceeds a risk score; or
fewer than the first number of sign-ins are observed for the user within the time span, and at least one sign-in exceeds a risk score.
10 . The method of claim 1 , further comprising determining a confidence score associated with the security threat analysis result.
11 . The method of claim 1 , wherein the security threat analysis result includes a history of specific events associated with the detection of the potential security threat.
12 . The method of claim 1 , wherein at least a portion of the security threat analysis result is logged without presenting the security threat analysis result on a user interface.
13 . The method of claim 1 , wherein:
the user interface includes an event card for each event in a group of events associated with the potential security threat; and
the event card includes a dynamically generated reason for why a respective event is included in the group of events.
14 . The method of claim 1 , wherein:
the user interface includes a set of events associated with the automatically generated narrative; and
the set of events is a subset of the plurality of events from the plurality of different digital service platforms meeting the criterion for the multievent analysis.
15 . The method of claim 1 , wherein the user interface specifies a confidence associated with the security threat analysis result.
16 . A system, comprising:
a processor configured to:
determine that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;
identify, among the plurality of events, a group of cross-platform events related to the specific event;
analyze at least the group of cross-platform events to detect a potential security threat; and
provide a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities; and
a memory coupled to the processor and configured to provide the processor with instructions.
17 . The system of claim 16 , wherein analyzing at least the group of cross-platform events to detect the potential security threat includes using at least one detector to detect the potential security threat.
18 . The system of claim 16 , wherein events included in the group of cross-platform events related to the specific event are related by at least one of: being associated with a particular user, being a notable event, or being associated with a particular entity.
19 . The system of claim 16 , wherein identifying the group of cross-platform events related to the specific event includes filtering events to determine a subset of notable events that are relevant to the specific event.
20 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;
identifying, among the plurality of events, a group of cross-platform events related to the specific event;
analyzing at least the group of cross-platform events to detect a potential security threat; and
providing a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities.