Agentless file integrity monitoring for data managed by a cloud-based filesystem service
Data platforms described herein are configured to perform security monitoring of cloud compute environments, including agentless compute environments or compute environments that include certain agentless assets. For example, an illustrative data platform may identify a designated file for file integrity monitoring, the designated file stored in the cloud compute environment and managed by a cloud-based filesystem service. The data platform may access log data that is produced by the cloud-based filesystem service and that indicates a change to the designated file. Based on this log data, the data platform may perform a file integrity monitoring operation with respect to the designated file, and may apply a product of that file integrity monitoring operation to the security monitoring of the cloud compute environment that is being performed. Corresponding methods, systems, and products are also disclosed.
1 . A method comprising:
identifying, by a data platform configured to perform security monitoring of a cloud compute environment, a designated file for file integrity monitoring, the designated file stored in the cloud compute environment and managed by a cloud-based filesystem service;
accessing, by the data platform, log data in the form of provider-emitted change-event records that are produced and stored within the cloud-based filesystem service and accessed via an application programming interface (API) of the cloud-based file system service, the change-event records identifying a write operation affecting the designated file;
generating a notification utilizing a notification system of an operating system running on the data platform corresponding to the change to the designated file;
performing, by the data platform and based on the log data, a file integrity monitoring operation with respect to the designated file; and
applying, by the data platform, a product of the file integrity monitoring operation to the security monitoring of the cloud compute environment.
2 . The method of claim 1 , wherein the cloud compute environment includes:
a first agentless compute asset that is granted access to the designated file by the cloud-based filesystem service and from which the log data is accessed; and
a second agentless compute asset that is further granted access to the designated file by the cloud-based filesystem service and that executes a change actor responsible for the change to the designated file.
3 . The method of claim 1 , wherein:
the performing of the file integrity monitoring operation includes determining that the change to the designated file is indicative of a security threat to the cloud compute environment; and
the applying of the product of the file integrity monitoring operation to the security monitoring includes generating an alert that indicates the security threat and facilitates examination of the change to the designated file.
4 . The method of claim 1 , wherein:
the performing of the file integrity monitoring operation includes determining that the change to the designated file is indicative of a security threat to the cloud compute environment; and
the applying of the product of the file integrity monitoring operation to the security monitoring includes performing an automatic action configured to protect against a data leak associated with the designated file.
5 . The method of claim 4 , wherein:
the security threat is determined to be associated with an attack attempting to enact a data leak associated with the designated file; and
the automatic action includes quarantining a change actor responsible for the change to the designated file to disallow the change actor from accessing or effecting further changes to files within the cloud compute environment.
6 . The method of claim 1 , further comprising constructing, by the data platform, a graph comprising a plurality of nodes connected by a plurality of edges, each node of the plurality of nodes representing a logical entity and each edge of the plurality of edges representing a behavioral relationship between nodes connected by the edge;
wherein the applying of the product of the file integrity monitoring operation to the security monitoring includes updating the graph based on the product of the file integrity monitoring operation.
7 . The method of claim 1 , wherein the file integrity monitoring operation includes:
determining a first checksum for the designated file, the first checksum associated with a point in time after the change to the designated file occurs; and
at least one of:
comparing the first checksum with a second checksum for the designated file, the second checksum associated with a point in time before the change to the designated file occurs, or
comparing the first checksum with a third checksum associated with a known malicious file.
8 . The method of claim 1 , wherein:
the log data further indicates one or more additional changes to the designated file; and
the file integrity monitoring operation includes:
determining that the change to the designated file occurs within a threshold amount of time to each of the one or more additional changes to the designated file, and
the applying of the product of the file integrity monitoring operation to the security monitoring includes aggregating, based on the determining, information about the change and the one or more additional changes.
9 . The method of claim 1 , wherein:
the log data further indicates one or more additional changes to the designated file; and
the file integrity monitoring operation includes:
analyzing the change to the designated file to determine one or more properties from a set of properties including a file type of the file that has changed, an entity responsible for the change to the file, and an indicator of how the file is changed, and
filtering the change and the one or more additional changes to the designated file based on the one or more properties.
10 . The method of claim 1 , wherein the cloud compute environment includes:
a first compute asset that is agentless and is granted access to the designated file by the cloud-based filesystem service, the first compute asset providing access to the log data; and
a second compute asset that hosts an agent and is further granted access to the designated file by the cloud-based filesystem service, the second compute asset responsible for the change to the designated file and the agent configured to locally perform an additional file integrity monitoring operation based on a notification received by the agent in response to the agent having registered to be notified by an operating system of the second compute asset when the change to the designated file occurs.
11 . The method of claim 1 , wherein:
the cloud compute environment includes a particular compute asset that hosts an agent and provides the log data accessed by the data platform; and
an additional file integrity monitoring operation is performed locally by the agent based on a notification received by the agent in response to the agent having registered to be notified by an operating system of the particular compute asset when the change to the designated file occurs.
12 . The method of claim 11 , wherein the applying of the product of the file integrity monitoring operation to the security monitoring includes:
determining that the product of the file integrity monitoring operation is redundant with a product of the additional file integrity monitoring operation; and
based on the determining, abstaining from applying the product of the additional file integrity monitoring operation to the security monitoring of the cloud compute environment.
13 . The method of claim 1 , wherein the cloud-based filesystem service is implemented by Amazon Web Services (AWS) FSX.
14 . The method of claim 1 , wherein the cloud-based filesystem service is implemented by Google Cloud Filestore.
15 . The method of claim 1 , wherein the cloud-based filesystem service is implemented by Microsoft Azure Files or Microsoft Azure NetApp Files.
16 . A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions for performing a process comprising:
identifying a designated file for file integrity monitoring, the designated file stored in a cloud compute environment and managed by a cloud-based filesystem service;
accessing log data in the form of provider-emitted change-event records that are produced and stored within the cloud-based filesystem service and accessed via an application programming interface (API) of the cloud-based file system service, the change-event records identifying a write operation affecting the designated file;
generating a notification utilizing a notification system of an operating system running on the data platform corresponding to the change to the designated file;
performing, based on the log data, a file integrity monitoring operation with respect to the designated file; and
applying a product of the file integrity monitoring operation to security monitoring of the cloud compute environment that is being performed by a data platform executing the computer instructions.
17 . The computer program product of claim 16 , wherein the cloud compute environment includes:
a first agentless compute asset that is granted access to the designated file by the cloud-based filesystem service and from which the log data is accessed; and
a second agentless compute asset that is further granted access to the designated file by the cloud-based filesystem service and that executes a change actor responsible for the change to the designated file.
18 . The computer program product of claim 16 , wherein:
the performing of the file integrity monitoring operation includes determining that the change to the designated file is indicative of a security threat to the cloud compute environment; and
the applying of the product of the file integrity monitoring operation to the security monitoring includes generating an alert that indicates the security threat and facilitates examination of the change to the designated file.
19 . The computer program product of claim 16 , wherein:
the performing of the file integrity monitoring operation includes determining that the change to the designated file is indicative of a security threat to the cloud compute environment; and
the applying of the product of the file integrity monitoring operation to the security monitoring includes performing an automatic action configured to protect against a data leak associated with the designated file.
20 . A method comprising:
identifying, by a data platform configured to perform security monitoring of a cloud compute environment, a designated file for file integrity monitoring, the designated file stored in the cloud compute environment and managed by an Amazon Web Services (AWS) FSx cloud-based filesystem service;
accessing, by the data platform, CloudTrail data produced by the AWS FSx cloud-based filesystem service and stored within the AWS FSx cloud-based filesystem service, the CloudTrail data indicating a change to the designated file and accessed via an application programming interface of the AWS FSx cloud-based filesystem service;
generating a notification corresponding to the change to the designated file utilizing the AWS FSx cloud-based filesystem service; and
performing, by the data platform and based on the CloudTrail data, a file integrity monitoring operation with respect to the designated file.