Want Better Cloud Security? Make Your Detections Multi-Dimensional
It took decades for the security community to get the upper hand against attacks on endpoints, and cloud environments pose an even bigger detection challenge. Where endpoint attacks often involve malware to package attacker capabilities, cloud attacks succeed through seemingly legitimate requests to the cloud provider. In the hustle and bustle of an enterprise cloud environment, atomic (one-dimensional) detections face a harsh tradeoff between low accuracy and overwhelming noise. Correlating between cloud and non-cloud activity can provide fidelity for effective detection coverage. Subscribed A recent study of cloud threat detection by Invictus IR should be a wake-up call for any SOC with a cloud footprint to secure. The researchers ran 32 well-known attack techniques in AWS, each leaving traces in the CloudTrail logs. Despite having access to evidence of the attack, the researchers found that “GuardDuty only triggered for just three of the simulated attacks, which is very limited. Esp
Want Better Cloud Security? Make Your Detections Multi-Dimensional How detection engineers are using data from other sources to secure their clouds Omer Singer Feb 29, 2024 4 Share It took decades for the security community to get the upper hand against attacks on endpoints, and cloud environments pose an even bigger detection challenge. Where endpoint attacks often involve malware to package attacker capabilities, cloud attacks succeed through seemingly legitimate requests to the cloud provider. In the hustle and bustle of an enterprise cloud environment, atomic (one-dimensional) detections f
Explore this link on the map →related reading
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Cloud Detection And Response Tools Do Not Existforrester.com
- Compromised Cloud Compute Credentials: Case Studies From the Wildunit42.paloaltonetworks.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- The Top Cloud Security Trends to Watch for in 2023orca.security
- My Methodology to AWS Detection Engineering (Part 1: Object Selection)chesterlebron.blogspot.com
- What is Cloud Detection and Response (CDR)? | Wizwiz.io
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com
- Creating Cost-Effective, Scalable Detectionsrippling.com