Detecting shadow information technology (IT) using network activity logs
Detecting shadow information technology (IT) using network activity logs, including: gathering, from a client device, first information describing network activity by the client device and second information describing application activity by the client device; identifying, based on the first information and the second information, user-initiated network activity; and identifying, from the user-initiated network activity, shadow information technology (IT) activity comprising access of an unauthorized software-as-a-service (SaaS) application.
1 . A method of detecting shadow information technology (IT) using network activity logs, the method comprising:
gathering, from a client device, first information describing network activity by the client device and second information describing application activity by the client device;
identifying, based on the first information and the second information, user-initiated network activity;
identifying, from the user-initiated network activity, shadow activity comprising access of an unauthorized software-as-a-service (SaaS) application, wherein identifying the shadow IT activity further comprises:
generating, for a user associated with the client device, a plurality of behavior models from historical access requests associated with the user, wherein generating the plurality of behavior models comprises:
classifying historical access request data according to one or more parameters, and
applying a clustering algorithm to the classified historical access request data to generate one or more data clusters for each behavioral model;
selecting, based on a parameter of a current access request, one of the plurality of behavior models associated with the user;
determining a deviation of the current access request from one or more data clusters of the selected behavior model; and
identifying the shadow IT activity based at least in part on the determined deviation.
2 . The method of claim 1 , wherein the second information is generated by a browser plugin implemented on the client device.
3 . The method of claim 1 , wherein identifying the user-initiated network activity comprises identifying, as the user-initiated network activity, a portion of the network activity identified in the application activity as being performed in response to a user input via a browser.
4 . The method of claim 1 , wherein identifying the shadow IT activity further comprises filtering, from the user-initiated network activity, accesses to one or more authorized SaaS applications to generate filtered user-initiated network activity.
5 . The method of claim 4 , wherein the client device is associated with a particular customer and the one or more authorized SaaS applications are registered via an identity provider associated with the particular customer.
6 . The method of claim 4 , wherein identifying the shadow IT activity further comprises identifying, as the shadow IT activity, a portion of the filtered user-initiated network activity accessing a SaaS application included in a listing of SaaS applications.
7 . The method of claim 6 , wherein the listing of SaaS applications maps a plurality of SaaS applications to one or more corresponding hostnames.
8 . The method of claim 1 , further comprising generating an alert indicating the shadow IT activity.
9 . The method of claim 1 , further comprising generating a report based on the shadow IT activity.
10 . The method of claim 1 , further comprising:
receiving an indication that the shadow IT activity is allowable; and
changing a status of the unauthorized application from unauthorized to authorized by updating a listing of authorized SaaS applications to include the unauthorized SaaS application.
11 . A non-transitory computer readable medium having stored thereon a computer program product for detecting shadow information technology (IT) using network activity logs, the computer program product including computer program instructions configurable to:
gather, from a client device, first information describing network activity by the client device and second information describing application activity by the client device;
identify, based on the first information and the second information, user-initiated network activity; and
identify, from the user-initiated network activity, shadow information technology (IT) activity comprising access of an unauthorized software-as-a-service (SaaS) application, wherein identifying the shadow IT activity further comprises:
generating, for a user associated with the client device, a plurality of behavior models from historical access requests associated with the user, wherein generating the plurality of behavior models comprises:
classifying historical access request data according to one or more parameters, and
applying a clustering algorithm to the classified historical access request data to generate one or more data clusters for each behavioral model;
selecting, based on a parameter of a current access request, one of the plurality of behavior models associated with the user;
determining a deviation of the current access request from one or more data clusters of the selected behavior model; and
identifying the shadow IT activity based at least in part on the determined deviation.
12 . The non-transitory computer readable medium of claim 11 , wherein the second information is generated by a browser plugin implemented on the client device.
13 . The non-transitory computer readable medium of claim 11 , wherein identifying the user-initiated network activity comprises identifying, as the user-initiated network activity, a portion of the network activity identified in the application activity as being performed in response to a user input via a browser.
14 . The non-transitory computer readable medium of claim 11 , wherein identifying the shadow IT activity further comprises filtering, from the user-initiated network activity, accesses to one or more authorized SaaS applications to generate filtered user-initiated network activity.
15 . The non-transitory computer readable medium of claim 14 , wherein the client device is associated with a particular customer and the one or more authorized SaaS applications are registered via an identity provider associated with the particular customer.
16 . The non-transitory computer readable medium of claim 14 , wherein identifying the shadow IT activity further comprises identifying, as the shadow IT activity, a portion of the filtered user-initiated network activity accessing a SaaS application included in a listing of SaaS applications.
17 . The non-transitory computer readable medium of claim 16 , wherein the listing of SaaS applications maps a plurality of SaaS applications to one or more corresponding hostnames.
18 . The non-transitory computer readable medium of claim 11 , wherein the steps further comprise generating an alert indicating the shadow IT activity.
19 . The non-transitory computer readable medium of claim 11 , wherein the steps further comprise generating a report based on the shadow IT activity.
20 . The non-transitory computer readable medium of claim 11 , wherein the steps further comprise:
receiving an indication that the shadow IT activity is allowable; and
changing a status of the unauthorized application from unauthorized to authorized by updating a listing of authorized SaaS applications to include the unauthorized SaaS application.