Skip to main content

Unmasking Cloud Identities: Behavioral Clustering for Detection

4 min read Runtime Rebel Intel
Primary source: unit42.paloaltonetworks.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Cloud identity mapping is challenging, leading to undetected malicious activity from human, machine, and autonomous agent identities.
  • The methodology applies to cloud environments, focusing on AWS CloudTrail, but is extensible to other providers and SaaS.
  • Implement behavioral clustering to identify true functional roles from audit logs and integrate findings into automated threat detection.

Advertisement

A significant challenge for security professionals in expanding cloud environments is accurately mapping the functional roles of numerous human, machine, and autonomous agent identities. Traditional methods often fall short, leaving organizations vulnerable to sophisticated threats. To address this, Unit 42 has developed a behavioral clustering model designed to extract activity patterns directly from cloud audit logs, enhancing visibility and bolstering automated threat detection mechanisms.

The Challenge of Cloud Identity Mapping

In dynamic cloud environments, identifying the true functional role of an identity is rarely straightforward. Resource naming conventions or assigned identity and access management (IAM) policies frequently do not reflect an identity’s actual behavior. Attackers actively exploit this ambiguity by using masquerading techniques, such as leveraging pre-existing permission profiles and benign labels, to conceal malicious activity. This makes it difficult for security teams to discern between legitimate operations and potential threats.

The sheer volume of identities operating across complex cloud infrastructures poses a critical question: how do organizations effectively understand and monitor behavior? The core issue lies in distinguishing between an identity’s capabilities (what it can do based on permissions) and its active behavior (what it actually does). For instance, an identity enumerating all resources might be a legitimate security tool or an anomalous backup service indicating a potential breach. Accurate mapping cloud identities to functional roles is paramount for effective security.

Behavioral Clustering for Enhanced Threat Detection

Model Overview and Methodology

Unit 42’s behavioral clustering model uses unsupervised machine learning algorithms, specifically Uniform Manifold Approximation and Projection (UMAP) and Hierarchical Density-Based Spatial Clustering of Applications with Noise (HDBSCAN), to build a reliable behavioral map. This approach automatically categorizes a vast collection of cloud identities into distinct, clustered groups based on their invoked operations.

Researchers examined the behavior of over 40,000 identities from 125 cloud environments over a two-month period, mapping these identities to functional roles such as administrators, backup services, security tooling, and DevOps. While the research specifically focused on AWS CloudTrail data, the methodology is designed to be easily extended to audit logs from other cloud providers, Software as a Service (SaaS) platforms, Kubernetes, and similar environments, as detailed by Unit 42.

Practical Application: Admin Console Users and Behavioral Context

To demonstrate the model’s practical utility, Unit 42 conducted an in-depth analysis of the dataset’s largest cluster: administrator console users in Amazon Web Services (AWS). A defining characteristic of this cluster was that roughly 94% of identities invoked ConsoleLogin, an AWS Management Console sign-in event. In contrast, fewer than 1% of identities in any other cluster performed this operation. This stark difference highlights how behavioral patterns provide significantly richer context for automated cloud threat detection mechanisms.

By understanding these behavioral patterns, organizations can differentiate between expected and anomalous activities. The model helps decode the functional role associated with each behavioral cluster through a combination of analytical methods, ensuring that cloud identities sharing similar operational traits are accurately grouped. This form of AWS CloudTrail behavioral analysis offers a crucial layer of insight beyond static configuration reviews.

Lightweight Heuristic Logic for Scalable Detection

Beyond just identifying clusters, the research demonstrates how lightweight heuristic logic can be extracted directly from the clustering map. This logic can be implemented using standard SQL, allowing organizations to classify functional identity roles at scale. This capability delivers continuous operational visibility without the need to continuously run a resource-intensive machine learning pipeline, making advanced behavioral analysis accessible and efficient for ongoing security operations.

Recommendations for Defenders

For security professionals, these findings underscore the importance of moving beyond static assessments and focusing on the dynamic behavior of identities within cloud environments. Defenders should prioritize the following actions:

  • Prioritize Behavioral Analytics: Integrate behavioral clustering and analytics into cloud security monitoring strategies to gain deeper insights into identity roles and activity patterns.
  • Leverage Audit Logs: Ensure comprehensive collection and analysis of cloud audit logs (e.g., AWS CloudTrail, Azure Monitor, GCP Cloud Audit Logs) as the foundational data for behavioral models.
  • Establish Behavioral Baselines: Develop a baseline understanding of normal operational behavior for various identity types within your environment. This enables the rapid detection of deviations that may indicate compromise or misuse.
  • Automate Threat Detection: Implement automated mechanisms that incorporate behavioral context to improve the accuracy and speed of identifying potential security breaches, reducing false positives, and focusing resources on genuine threats.

Related: Okta’s Permiso Acquisition: Bolstering Identity Threat Detection, AWS AgentCore Harness Default Settings Allow Credential Exfiltration

Advertisement

Advertisement