Whether planned and executed over time or forced overnight by the global pandemic, the worlds digital transformation has prompted a surge in the use of Software-as-a-Service (SaaS) solutions in organizations across the globe. The annual growth rate of the SaaS market iscurrently 18%, and as the global workforce becomes increasingly remote throughout 2020, this figure is only set to skyrocket.
SaaS solutions have been an entry point for cyber-attackers for some time but little attention is given to how the Techniques, Tools & Procedures (TTPs) in SaaS attacks differ significantly from traditional TTPs seen in networks and endpoint attacks.
This raises a number of questions for security experts: how do you create meaningful detections in SaaS environments that dont have endpoint or network data? How can you investigate threats in a SaaS environment? What does a good SaaS environment look like as opposed to one thats threatening? A global shortage in cyber skills already creates problems for finding security analysts able to work in traditional IT environments hiring security experts with SaaS domain knowledge is all the more challenging.
Meanwhile, SaaS consumers are left with limited options: use the native SaaS security controls provided in each SaaS solution and risk a lack of security maturity or go with a third-party SaaS security solution, often in the form of Cloud Access Security Brokers (CASBs). Both options are not without their security risks.
Here are two examples of attacks recently detected by AI in SaaS environments that are representative of the broader SaaS threat landscape, and illuminate the sharp distinction between a traditional network attack and a SaaS compromise.
Office365 Business email compromise
In what amounted to a classic business email compromise (BEC), an attacker infiltrated an employees Microsoft 365 account to access sensitive financial documents hosted in SharePoint, including pay slip and banking details. Having gained initial entry, the attacker proceeded to make configuration changes to the inbox, deleting items and making updates that would enable them to cover their tracks.
The employees account login was first observed from unusual IP ranges. The account in question had never logged in from Bulgaria before, and the peer accounts belonging to those from the same department had not exhibited similar behavioral traits. This in itself was a low-level anomaly and not necessarily indicative of malicious activity after all, in the context of an increasingly distributed workforce, employees might change locations frequently.
Yet the unusual login location was accompanied by an unusual login time and a new User-Agent. All of these anomalies called for a deeper analysis. It was then identified that the account was starting to access highly sensitive information, including payroll information on a Sharepoint.
The attacker tried to gain insights about payment information and credit card details, with the likely intention of changing the payroll details to an attacker-controlled bank account.
AI-powered security technology was able to put together these weak signals of a threat and illuminate the likely account compromise. The companys security team was then able to lock the account and alert the user, who subsequently changed their credentials.
Box.com Compromise
At a global supply company, unauthorized access to an employees Box.com file storage account was detected. The login took place in the US where the company does operate but from an unusual IP space and ASN. AI began to investigate the users activity.
The actor behind the account logged in to Box.com successfully, and proceeded to download expense reports, invoices, and other financial documents. These were files that were highly unusual for the account to access.
Cyber AI also found that the activity occurred at a highly unusual time for the legitimate user, and the location of the actors IP address was anomalous compared to the employees previous access locations for this particular SaaS service.
An understanding of user behavior and granular visibility within the Box.com application allowed the company to spot the subtle signs of account compromise. Moreover, AI-powered investigation outlined the narrative in its entirety, showing how each unauthorized file exposure was part of a connected incident and a key concern for the security team.
A new era in SaaS domain defense
Ultimately, traditional detection approaches with hard and fast rules for how SaaS domains should operate are not enough to ensure that SaaS applications remain secure. Keeping threat intelligence lists up to date is even more difficult, as most SaaS attacks dont involve any Command & Control just indiscriminate logins from remote devices. When it comes to points of entry for SaaS attacks, the possibilities are endless: VPN, Tor, other compromised devices, dynamic DNS or even virtual private servers for attackers to cover their tracks.
A more intricate and effective approach to SaaS security requires an understanding of the dynamic individual behind the account. SaaS applications are fundamentally platforms for humans to communicate allowing them to exchange and store ideas and information.
Abnormal, threatening behavior is therefore impossible to detect without a nuanced understanding of those unique individuals: where and when do they typically access a SaaS account, which files are they like to access, who do they typically connect with? As the attacks outlined serve to demonstrate, these are questions for an AI brain to contend with.
More here:
The Anatomy of a SaaS Attack: Catching and Investigating Threats with AI - Infosecurity Magazine
- Chocolate Artistry [Last Updated On: August 17th, 2024] [Originally Added On: April 4th, 2010]
- La Cabeza Circuitoide [Last Updated On: August 17th, 2024] [Originally Added On: April 5th, 2010]
- Stuntkid: Anatomically Correct [Last Updated On: August 17th, 2024] [Originally Added On: April 5th, 2010]
- "The Secret Museum" Exhibition Opening, Observatory, This Saturday, April 10, 7-10 PM [Last Updated On: April 6th, 2010] [Originally Added On: April 6th, 2010]
- "The Secret Museum" Exhibition Opening, Observatory, This Saturday, April 10, 7-10 PM [Last Updated On: August 17th, 2024] [Originally Added On: April 6th, 2010]
- Flat Surgery [Last Updated On: August 17th, 2024] [Originally Added On: April 7th, 2010]
- Job Opportunities at the Medical Museion, University of Copenhagen [Last Updated On: April 9th, 2010] [Originally Added On: April 9th, 2010]
- "The Secret Museum" Exhibition Opening, Observatory, TONIGHT! April 10, 7-10 PM [Last Updated On: April 10th, 2010] [Originally Added On: April 10th, 2010]
- Animal Body Worlds at the Neunkirchen Zoo, Saarland, Germany [Last Updated On: April 11th, 2010] [Originally Added On: April 11th, 2010]
- Congress for Curious People: Lectures Begin Tomorrow Night at the Coney Island Museum! [Last Updated On: April 12th, 2010] [Originally Added On: April 12th, 2010]
- Job Opportunities at the Medical Museion, University of Copenhagen [Last Updated On: August 17th, 2024] [Originally Added On: April 12th, 2010]
- Animal Body Worlds at the Neunkirchen Zoo, Saarland, Germany [Last Updated On: August 17th, 2024] [Originally Added On: April 12th, 2010]
- "The Secret Museum" Exhibition Opening, Observatory, TONIGHT! April 10, 7-10 PM [Last Updated On: August 17th, 2024] [Originally Added On: April 12th, 2010]
- Anatomic Fashion Friday: Skeleton Bodysuit [Last Updated On: August 17th, 2024] [Originally Added On: April 12th, 2010]
- Diabetes Ads [Last Updated On: August 17th, 2024] [Originally Added On: April 12th, 2010]
- Anatomia del corpo humano [Last Updated On: August 17th, 2024] [Originally Added On: April 13th, 2010]
- "The Brading Collection of Taxidermy, Waxworks, Costume and Similar Items," Duke's Auction House, Dorset, April 13th (Today!) [Last Updated On: August 17th, 2024] [Originally Added On: April 14th, 2010]
- Anatomy Pillow [Last Updated On: August 17th, 2024] [Originally Added On: April 14th, 2010]
- A Brief History of Automata, An Illustrated Lecture and Demonstration by Mike Zohn, Obscura Antiques and Oddities, TONIGHT! Coney Island Museum [Last Updated On: April 14th, 2010] [Originally Added On: April 14th, 2010]
- "The Brading Collection of Taxidermy, Waxworks, Costume and Similar Items," Duke's Auction House, Dorset, April 13th (Today!) [Last Updated On: April 15th, 2010] [Originally Added On: April 15th, 2010]
- A Brief History of Automata, An Illustrated Lecture and Demonstration by Mike Zohn, Obscura Antiques and Oddities, TONIGHT! Coney Island Museum [Last Updated On: August 17th, 2024] [Originally Added On: April 15th, 2010]
- Hip Pockets [Last Updated On: August 17th, 2024] [Originally Added On: April 15th, 2010]
- "A History of Taxidermy: Art, Science and Bad Taste," An Illustrated Presentation By Dr. Pat Morris, Congress for Curious People, Coney Island Museum [Last Updated On: August 17th, 2024] [Originally Added On: April 16th, 2010]
- “Wild Anatomy” by Rachel “Thirsty Fly” Caldwell [Last Updated On: August 17th, 2024] [Originally Added On: April 16th, 2010]
- Charles Wilson Peale and the Birth of the American Museum, Coney Island Museum, Tonight!!! [Last Updated On: April 16th, 2010] [Originally Added On: April 16th, 2010]
- "The Congress for Curious People," Epic 2-Day Symposium Begins Tomorrow!!! [Last Updated On: April 16th, 2010] [Originally Added On: April 16th, 2010]
- "A History of Taxidermy: Art, Science and Bad Taste," An Illustrated Presentation By Dr. Pat Morris, Congress for Curious People, Coney Island Museum [Last Updated On: April 17th, 2010] [Originally Added On: April 17th, 2010]
- Charles Wilson Peale and the Birth of the American Museum, Coney Island Museum, Tonight!!! [Last Updated On: August 17th, 2024] [Originally Added On: April 17th, 2010]
- "The Congress for Curious People," Epic 2-Day Symposium Begins Tomorrow!!! [Last Updated On: August 17th, 2024] [Originally Added On: April 17th, 2010]
- Anatomic Fashion Friday: Lady Grey Jewelry [Last Updated On: August 17th, 2024] [Originally Added On: April 17th, 2010]
- "Stuffed Animals and Pickled Heads" Book and Lecture by Stephen Asma, Thursday April 22, Observatory [Last Updated On: August 17th, 2024] [Originally Added On: April 20th, 2010]
- "The Silken Web: The Erotic World of Paris, 1920-1946," Mel Gordon Lecture at Observatory, Tomorrow April 20th [Last Updated On: August 17th, 2024] [Originally Added On: April 20th, 2010]
- Marylin Monroe Exposed [Last Updated On: August 17th, 2024] [Originally Added On: April 20th, 2010]
- The Dance of Death, 1919, Attributed to Josef Fenneker [Last Updated On: April 20th, 2010] [Originally Added On: April 20th, 2010]
- "Stuffed Animals and Pickled Heads" Book and Lecture by Stephen Asma, Thursday April 22, Observatory [Last Updated On: April 21st, 2010] [Originally Added On: April 21st, 2010]
- "The Silken Web: The Erotic World of Paris, 1920-1946," Mel Gordon Lecture at Observatory, Tomorrow April 20th [Last Updated On: April 21st, 2010] [Originally Added On: April 21st, 2010]
- The Dance of Death, 1919, Attributed to Josef Fenneker [Last Updated On: August 17th, 2024] [Originally Added On: April 21st, 2010]
- Military Docs Pluck Live Shell From Soldier’s Head [Last Updated On: August 17th, 2024] [Originally Added On: April 21st, 2010]
- "The Rogue Taxidermy Kunstkammer," The Minnesota Association of Rogue Taxidermists, La Luz de Jesus, Los Angeles [Last Updated On: August 17th, 2024] [Originally Added On: April 22nd, 2010]
- "Museums, Monsters and the Moral Imagination" Lecture by Stephen Asma, Tonight!, Observatory [Last Updated On: April 22nd, 2010] [Originally Added On: April 22nd, 2010]
- "The Rogue Taxidermy Kunstkammer," The Minnesota Association of Rogue Taxidermists, La Luz de Jesus, Los Angeles [Last Updated On: April 23rd, 2010] [Originally Added On: April 23rd, 2010]
- "Museums, Monsters and the Moral Imagination" Lecture by Stephen Asma, Tonight!, Observatory [Last Updated On: August 17th, 2024] [Originally Added On: April 23rd, 2010]
- Feminal Artery [Last Updated On: August 17th, 2024] [Originally Added On: April 23rd, 2010]
- Anatomic Fashion Friday: Penis Trousers [Last Updated On: August 17th, 2024] [Originally Added On: April 24th, 2010]
- The First Full Facial Transplant [Last Updated On: August 17th, 2024] [Originally Added On: April 26th, 2010]
- "Anatomical Art: Dissection to Illustration," Exhibition Curated by Marie Dauenheimer, Arlington, Virginia [Last Updated On: April 26th, 2010] [Originally Added On: April 26th, 2010]
- "Anatomical Art: Dissection to Illustration," Exhibition Curated by Marie Dauenheimer, Arlington, Virginia [Last Updated On: August 17th, 2024] [Originally Added On: April 27th, 2010]
- John C. Miller [Last Updated On: August 17th, 2024] [Originally Added On: April 27th, 2010]
- "Three Unique Medical Museums in Northern Italy," Lecture by Marie Dauenheimer, Observatory, Saturday May 1 [Last Updated On: August 17th, 2024] [Originally Added On: April 28th, 2010]
- This Is Spinal Tape [Last Updated On: August 17th, 2024] [Originally Added On: April 28th, 2010]
- "Excellent Old-School Science Models," Life Magazine Photo Gallery [Last Updated On: April 28th, 2010] [Originally Added On: April 28th, 2010]
- "Three Unique Medical Museums in Northern Italy," Lecture by Marie Dauenheimer, Observatory, Saturday May 1 [Last Updated On: April 29th, 2010] [Originally Added On: April 29th, 2010]
- "Excellent Old-School Science Models," Life Magazine Photo Gallery [Last Updated On: August 17th, 2024] [Originally Added On: April 29th, 2010]
- Ventricle Vase [Last Updated On: August 17th, 2024] [Originally Added On: April 29th, 2010]
- "Imaging / Imagining the Skeleton," Symposium, Tomorrow, Friday, April 30, 1:00-4pm, CUNY Graduate Center [Last Updated On: August 17th, 2024] [Originally Added On: April 30th, 2010]
- Synthetic Being [Last Updated On: August 17th, 2024] [Originally Added On: April 30th, 2010]
- Tomorrow Night at Observatory! "Three Unique Medical Museums in Northern Italy," Lecture by Marie Dauenheimer [Last Updated On: April 30th, 2010] [Originally Added On: April 30th, 2010]
- "Imaging / Imagining the Skeleton," Symposium, Tomorrow, Friday, April 30, 1:00-4pm, CUNY Graduate Center [Last Updated On: May 1st, 2010] [Originally Added On: May 1st, 2010]
- Tomorrow Night at Observatory! "Three Unique Medical Museums in Northern Italy," Lecture by Marie Dauenheimer [Last Updated On: August 17th, 2024] [Originally Added On: May 1st, 2010]
- UIC’s Biomedical Visualization Program on CBS [Last Updated On: August 17th, 2024] [Originally Added On: May 1st, 2010]
- Kim Joon [Last Updated On: August 17th, 2024] [Originally Added On: May 1st, 2010]
- Head of Discovery and Engagement, Wellcome Library, Employment Opportunity [Last Updated On: August 17th, 2024] [Originally Added On: May 3rd, 2010]
- Talking While Driving [Last Updated On: August 17th, 2024] [Originally Added On: May 3rd, 2010]
- "Experimenting with Death: An Introduction to Terror Management Theory," Lecture, Observatory, Thursday May 6 [Last Updated On: August 17th, 2024] [Originally Added On: May 3rd, 2010]
- Skin Drawings [Last Updated On: August 17th, 2024] [Originally Added On: May 4th, 2010]
- Kabinett des Grotesken ("Cabinet of the Grotesque"), Berliner Medizinhistorisches Museum der Charité, Spiegel Online [Last Updated On: May 4th, 2010] [Originally Added On: May 4th, 2010]
- Head of Discovery and Engagement, Wellcome Library, Employment Opportunity [Last Updated On: May 5th, 2010] [Originally Added On: May 5th, 2010]
- "Experimenting with Death: An Introduction to Terror Management Theory," Lecture, Observatory, Thursday May 6 [Last Updated On: May 5th, 2010] [Originally Added On: May 5th, 2010]
- Kabinett des Grotesken ("Cabinet of the Grotesque"), Berliner Medizinhistorisches Museum der Charité, Spiegel Online [Last Updated On: August 17th, 2024] [Originally Added On: May 5th, 2010]
- WAD Magazine [Last Updated On: August 17th, 2024] [Originally Added On: May 5th, 2010]
- "The Saddest Object in the World," An Illustrated Meditation, Observatory, Friday, May 7th [Last Updated On: August 17th, 2024] [Originally Added On: May 6th, 2010]
- "An Atlas of Topographical Anatomy after Plane Sections of Frozen Bodies," Christian Wilhelm Braune, 1877 [Last Updated On: August 17th, 2024] [Originally Added On: May 6th, 2010]
- The Taxidermy of Mr. Walter Potter and his Museum of Curiosities, Melissa Milgrom [Last Updated On: August 17th, 2024] [Originally Added On: May 6th, 2010]
- Industrial Strength Lungs [Last Updated On: August 17th, 2024] [Originally Added On: May 6th, 2010]
- The Taxidermy of Mr. Walter Potter and his Museum of Curiosities, Melissa Milgrom [Last Updated On: May 6th, 2010] [Originally Added On: May 6th, 2010]
- Tonight!!! "Experimenting with Death: An Introduction to Terror Management Theory," Lecture, Observatory [Last Updated On: May 6th, 2010] [Originally Added On: May 6th, 2010]
- Original Fritz Kahn Posters and Key Booklet, Sotheby's Vintage Posters Auction, May 13 [Last Updated On: May 6th, 2010] [Originally Added On: May 6th, 2010]
- "The Saddest Object in the World," An Illustrated Meditation, Observatory, Friday, May 7th [Last Updated On: May 7th, 2010] [Originally Added On: May 7th, 2010]
- "An Atlas of Topographical Anatomy after Plane Sections of Frozen Bodies," Christian Wilhelm Braune, 1877 [Last Updated On: May 7th, 2010] [Originally Added On: May 7th, 2010]
- Tonight!!! "Experimenting with Death: An Introduction to Terror Management Theory," Lecture, Observatory [Last Updated On: August 17th, 2024] [Originally Added On: May 7th, 2010]