惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Cloudflare Blog
L
LangChain Blog
WordPress大学
WordPress大学
V
V2EX
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Stack Overflow Blog
Stack Overflow Blog
J
Java Code Geeks
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
腾讯CDC
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Docker
Recent Announcements
Recent Announcements
GbyAI
GbyAI
博客园 - 叶小钗
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
T
The Blog of Author Tim Ferriss
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
Y
Y Combinator Blog
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Find and remediate identity risks with Datadog Cloud Secu...
2023-11-27 · via Datadog | The Monitor blog

Editor’s note: Datadog CIEM has been renamed Cloud Security Identity Risks to better reflect its expanded capabilities. All references have been updated accordingly.

Identity and access management (IAM) systems are necessary for authenticating and authorizing access to your environment. However, their mismanagement is one of the leading causes of breaches and insider threats today. Engineering teams must rapidly provision identities and permissions to keep pace with infrastructure growth—consequently, the ratio of non-human or machine identities to every human identity is also increasing at a substantial rate. This complexity makes it difficult to keep IAM configurations up to date and protect your environment against IAM-based attacks.

That’s why we’re excited to announce Datadog Cloud Security Identity Risks, a Cloud Infrastructure Entitlement Management (CIEM) solution that enables you to proactively identify and quickly remediate identity and access risks in your AWS environment (with support planned for other cloud providers) before a threat actor can exploit them. In this post, we’ll show you how Cloud Security Identity Risks enables you to secure your infrastructure from IAM-based attacks.

Surface identity risks based on best practices and research

Cloud Security Identity Risks enables you to identify and address identity risks in order to reduce their impact. It accomplishes this by leveraging your environment’s current IAM configuration and resource usage—along with the latest industry best practices and attack vectors—to automatically detect and prioritize identity risks for users, roles, groups, policies, EC2 instances, and Lambda functions. The types of risks that Cloud Security Identity Risks detects include:

  • Administrative privileges
  • Permissions gaps
  • Large blast radius
  • Privilege escalation
  • Cross-account access

Datadog’s Security Research team routinely curates the list of identity risks that Cloud Security Identity Risks detects so that our users can remain proactive in their defenses as new identity-based risks are identified.

As you sort through your IAM risk findings, you can review individual at-risk resources or address one identity risk at a time by grouping all resources (e.g., users, roles, groups, policies) that carry that risk, as seen in the following screenshot.

List of identity risks in Cloud Security

Get deeper insights to efficiently mitigate identity risks

For every identified risk, Cloud Security Identity Risks provides a detailed description of the issue and suggested remediation steps. In the following screenshot, Cloud Security Identity Risks has identified several IAM roles with unused permissions, which a threat actor can leverage to gain access to your services and resources.

Identity risk detail side panel

Cloud Security Identity Risks also provides advanced insights for each identified risk, providing you with additional context for understanding its scope. For example, the following screenshot shows a list of all provisioned permissions for an IAM role that Cloud Security Identity Risks has identified as unused.

List of permissions for IAM role

In this example, you can see that several permissions have not been used in the recent past. In these cases, you may want to remove the permissions that are no longer necessary for that role. Roles should be assigned permissions based on the principle of least privilege, which recommends granting only the set of permissions that are needed to accomplish a specific task.

You can see AWS’ suggested remediation steps by clicking the “Fix in AWS” button to navigate to the console. Alternatively, you can click “Remediate” to get a suggested downsized policy based on the actual usage.

Suggested downsized access policy

To create a case and assign the remediation to someone, click on “Create Jira Issue.” To ensure consistent and easy remediation, you can also leverage Workflow Automation to initiate a workflow, with or without human involvement, in response to any identity risk.

Take action on identity risk

Datadog includes several out-of-the-box Workflow Blueprints related to IAM to help you respond to identity-related risks. For example, if you discover an inactive AWS IAM user with excessive privileges, you can initiate a workflow that disables or deletes that user.

Delete/disable IAM role Workflow blueprint

Secure your environment with Datadog Cloud Security

Cloud Security Identity Risks is now generally available for organizations using AWS—check out our documentation to get started, or head to the Identity Risks Explorer. You can also check out the Cloud Security documentation for more information about getting started with Datadog Cloud Security. If you don’t already have a Datadog account, you can sign up for a 14-day free trial today.