SaaS Applications Have a Mind of Their Own

Do you understand the risk associated with multi-cloud solutions?

Multi-cloud environments are common and popular because they simplify what used to be complicated workflows, and they help organizations stay connected in an efficient manner. They do, however, also pose a significant cybersecurity challenge because they allow users to play multiple roles and have numerous constantly changing privileges.

This is simply how modern corporation’s work. The challenge quickly becomes how do you keep track of all the users and their constantly changing privileges. CISOs are tearing their hair out because they know they need to give proper access to their teams, while also having the capability to provide reporting to executive boards regarding employee access profiles, activities and privileges. Unfortunately, the current systems do not equip the practitioners with compliance reports across environments, systems, applications, and all personas of users.

Current identity and access management solutions often fail to recognize users' activities and privileges across multiple cloud environments, making clean decommissioning difficult and leaving traces of potential vulnerabilities.

SaaS Applications Have a Mind of Their Own
The maturity of the SaaS applications runs the gamut, and not all provide native integration into the centralized IAM solutions. Current IAM/PAM and SIEM solutions often focus on single-user activities and struggle to manage the scale and complexity of changing privileges and access requests.

Organizations simply must leverage customers’ existing investments into the SaaS applications rather than create a parallel directory and access management infrastructure just for those new SaaS applications.

Remote Workforce is Here to Stay
The pandemic brought us the remote workforce, and it is here to stay. This development has refocused the need for supporting the remote workforce without compromising security – a considerable challenge from a user access perspective. Remote access adds another layer of complexity to privileged access management by increasing the number of vulnerability points, and available software solutions are unequipped to effectively manage the lineage of the users and remediate unauthorized access problems in real-time.

Why Organizations Should Care about Privilege Abuse
Inside-Out Defense has observed diverse consequences from the above challenges in our engagements spanning several industries. Though the use cases have varied, these are some of the common patterns of privilege access abuse:

  • Users launching privilege escalation.
  • Lateral movements.
  • Privilege persists launched through 3rd party accounts over compromised zombie user accounts to orchestrate data exfiltration.
  • IP counterfeiting.
  • HIPAA compliance abuse and undue access to patient diagnostic data.
  • PoS systems DDoS.
  • Malicious third-party access.
  • Unmanaged systems orchestrating attacks at scale.

In a nutshell, IAM/PAM and SIEM solutions, as we know them, are being outsmarted by faster threats and more determined threat actors. Legacy vendors mainly focus on single-user activities to determine potential red flags and aggregate them for further processing without considering the individual user's overall context and activities across the environments.

Secondly, they usually integrate with a workflow system, generating a backlog of access requests that cannot scale with increased user activities. Users' privileges constantly change; they usually do not and shouldn’t persist. Enterprises direly need to address these challenges by providing a privilege abuse defense at the “time of use” by continuously detecting privilege abuse behaviors in real-time and remediating abuses in line.

About the Author

Venkat Thummisi is the co-founder and CTO, at Inside Out Defense.

Featured

Featured Cybersecurity

Webinars

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3