惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog RSS Feed
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Engineering at Meta
Engineering at Meta
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
M
MIT News - Artificial intelligence
IT之家
IT之家
博客园 - 【当耐特】
U
Unit 42
云风的 BLOG
云风的 BLOG
L
LangChain Blog
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
B
Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
宝玉的分享
宝玉的分享
N
Netflix TechBlog - Medium

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Enhance corporate application security with AWS Verified ...
Bowen Chen · 2023-04-28 · via Datadog | The Monitor blog

AWS Verified Access makes it easy and more secure for organizations to grant local or remote access to corporate applications without the use of a VPN. By using Verified Access, you can assign group policies to manage your organizations’ application access and administrative privileges at scale.

As a SIEM partner for the launch of AWS Verified Access, we’re pleased to announce that you can now integrate Verified Access logs with Datadog Cloud SIEM for analysis and real-time threat detection. You can monitor suspicious application access attempts with three Cloud SIEM detection rules for Verified Access and leverage Datadog’s out-of-the-box (OOTB) authentication dashboard to identify anomalous patterns.

In this post, we’ll cover how you can visualize authentication activity and investigate Verified Access logs in Datadog. We’ll also discuss how to enhance your security coverage and trace the footprint of malicious actors using Cloud SIEM Investigator and detection rules.

As users across your organization access multiple applications on a daily basis, they generate large volumes of authentication logs that can be difficult to effectively monitor. To help you get insights into AWS Verified Access activity, Cloud SIEM will automatically analyze all of your Verified Access logs in real time and evaluate them against three out-of-the-box detection rules. Cloud SIEM uses these rules to generate a security signal when it detects an anomalous number of failed application authentication attempts from a host, user, or IP address.

User our OOTB detection rules to alert you to anamlous authentication activity.

After a signal is generated, you can investigate by inspecting it in the Signals Explorer. Each signal includes context regarding its origins, such as the geolocation and domain of the failed authentication attempt. You can then follow the recommendations linked in the “Suggested Actions” tab to continue investigating by viewing a dashboard for the affected host machine or logs relating to the signal.

Choose to investigate security signals in the Signals Explorer.

The Authentication Events dashboard helps you visualize trends in Verified Access security signals alongside other authentication-related events across all your applications.

Visualize authentication activity using Datadog’s OOTB dashboard.

If you want to investigate a recent application authentication attempt rejected by Verified Access, you can inspect it from the log activity widget in the dashboard. Clicking “view in context” enables you to view other Verified Access logs generated in the same time frame, from the same host.

View authentication events in context with other logs generated from the same host, around the same time.

Trace malicious actors with Datadog Cloud SIEM

Verified Access detection rules generate security signals that can alert you to malicious entities attempting to breach your system. But once their activity is detected, you’ll still need to investigate the scope of the impact. After identifying a compromised IAM user or role, you can use Cloud SIEM Investigator to track their recent digital footprint across your AWS infrastructure. Investigator enables you to better visualize the scope of services impacted in data breach incidents and failed event types that could indicate a malicious actor’s objective. By using the Investigator for context, DevOps engineers can quickly coordinate with security teams to verify whether the failed events were false positives (from activity such as load testing) or truly stemmed from compromised credentials.

Trace a user’s digital footprint using the Cloud SIEM investigator.

Get started with AWS Verified Access and Datadog

AWS Verified Access allows organizations to securely connect employees to corporate applications. As part of our ongoing security and observability partnership with AWS, Datadog’s Verified Access integration enables you to increase visibility across your infrastructure and take immediate action if a breach occurs. You can also leverage our Security Lake integration to forward Verified Access logs to Datadog, where they can be analyzed by Cloud SIEM. To learn more about the Verified Access integration, you can view our documentation.

If you don’t already have a Datadog account, sign up for a free 14-day trial today.