惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
U
Unit 42
D
Docker
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Recent Announcements
Recent Announcements
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
V
Visual Studio Blog
I
InfoQ
Google DeepMind News
Google DeepMind News
小众软件
小众软件
L
LangChain Blog
C
Check Point Blog
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
J
Java Code Geeks
罗磊的独立博客

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Detect and respond to evolving attacks with Attacker Clus...
2025-02-26 · via Datadog | The Monitor blog

In today’s threat landscape, detecting and responding to distributed attacks is more challenging than ever. Attackers often operate in stealth, using coordinated strategies to blend into normal traffic and evade detection. To address this issue, Datadog App and API Protection (AAP) has a new clustering feature designed to identify and group attacker behaviors during distributed attacks. By capturing and analyzing subtle patterns in malicious activity, Attacker Clustering empowers organizations to uncover complex threats and respond with precision.

Attacker Clustering addresses the complexity of distributed attacks by grouping attacker behaviors into distinct clusters for account takeover signals and fraud security signals. The clustering algorithm analyzes patterns from attributes such as user agents or Datadog Attacker fingerprints, enabling accurate detection of stealthy threats while filtering out normal traffic. This approach provides a holistic view of attacker strategies, helping security teams quickly identify and respond to coordinated attacks.

In this post, we’ll explain how Attacker Clustering can help you:

Track evolving attacker strategies

As attackers continuously refine their tactics to bypass security measures, tracking these evolving strategies becomes increasingly complex. Security teams often face a shifting landscape where attacker patterns can change during an attack. Legacy defense mechanisms can fall short against dynamic and agile adversaries, which require real-time detection and adaptation to new attack behaviors.

Datadog’s attacker clustering mechanism plays a crucial role in tracking these changes in attack strategy by continuously analyzing the characteristics of attacks over time. By clustering attack behaviors, the system helps identify current attack trends and adapts to how these trends evolve.

When an attack is detected, the system automatically clusters attributes—such as user agents, headers, session IDs, and request body hashes—based on shared occurrences. The result is an Attacker Attributes table that presents these clusters and shows the key attributes of the attack. For example, notice the attributes for cluster redundant-lightcoral-abacus in the following image.

An Attacker Attributes table. Cluster redundant-lightcoral-abacus has attributes that include a user agent string that indicates a bot.

Through constant monitoring of attack-related attributes, Datadog tracks subtle variations in attacker behavior. Each attack is analyzed not only by its immediate attributes but also by how these attributes change over time. The clustering mechanism captures the evolution of tactics, such as attackers switching user agents, or other identifiable patterns that attackers use to avoid detection.

The following image shows how the attributes for cluster redundant-lightcoral-abacus changed when the attacker switched user agents.

An Attacker Attributes table. Cluster redundant-lightcoral-abacus has attributes that include a user agent string that indicates Firefox version 89.

As new patterns emerge, the system adapts to these changes and reconfigures its clusters to reflect the most relevant behaviors. The ability to track these shifts allows for proactive defense measures, enabling teams to update their blocking and detection strategies based on the latest attacker tactics.

Streamline incident response

Incident response teams are constantly under pressure to respond quickly and accurately to evolving security threats, such as distributed account takeovers and fraud attempts. However, the large volume of data generated by security systems often makes it difficult for these teams to prioritize threats and take decisive action. Analysts can struggle to identify the most critical attack indicators amidst a sea of unrelated noise, which can delay response times and leave systems vulnerable.

Attacker Clustering helps cut through the noise by providing clear, actionable insights that enable security teams to:

  • Quickly identify attacker patterns, such as the shared attributes across multiple suspicious requests
  • Understand which attributes are most strongly associated with malicious activity
  • Define a targeted blocking strategy based on the key characteristics of the attack

The attacker clustering mechanism aggregates requests and identifies frequent attributes that match the attacker pattern. Those attributes are correlated with Datadog threat intelligence feeds to help reduce noise and suggest a blocking strategy that aims to minimize impact on legitimate traffic.

Security teams can use this information to block specific attributes, such as user agents, and stop attacks in their tracks. This streamlined approach helps incident response teams focus on the most pressing threats, reducing response time and minimizing the potential impact of attacks.

A security signal shows a service, security traces, attacker attributes, and other information. The screen also shows possible next steps to take, including the option to block user agents.

Get started with Attacker Clustering today

Attacker Clustering in Datadog AAP transforms how security teams detect, analyze, and respond to threats. By using an advanced algorithm that groups related activities, the feature enables faster and more effective incident response. Attacker Clustering identifies evolving attacker patterns, provides clear and actionable insights, and automates suggestions for how to block and mitigate threats.

If you don’t already have a Datadog account, sign up for a 14-day free trial today.