Whether planned and executed over time or forced overnight by the global pandemic, the worlds digital transformation has prompted a surge in the use of Software-as-a-Service (SaaS) solutions in organizations across the globe. The annual growth rate of the SaaS market iscurrently 18%, and as the global workforce becomes increasingly remote throughout 2020, this figure is only set to skyrocket.
SaaS solutions have been an entry point for cyber-attackers for some time but little attention is given to how the Techniques, Tools & Procedures (TTPs) in SaaS attacks differ significantly from traditional TTPs seen in networks and endpoint attacks.
This raises a number of questions for security experts: how do you create meaningful detections in SaaS environments that dont have endpoint or network data? How can you investigate threats in a SaaS environment? What does a good SaaS environment look like as opposed to one thats threatening? A global shortage in cyber skills already creates problems for finding security analysts able to work in traditional IT environments hiring security experts with SaaS domain knowledge is all the more challenging.
Meanwhile, SaaS consumers are left with limited options: use the native SaaS security controls provided in each SaaS solution and risk a lack of security maturity or go with a third-party SaaS security solution, often in the form of Cloud Access Security Brokers (CASBs). Both options are not without their security risks.
Here are two examples of attacks recently detected by AI in SaaS environments that are representative of the broader SaaS threat landscape, and illuminate the sharp distinction between a traditional network attack and a SaaS compromise.
Office365 Business email compromise
In what amounted to a classic business email compromise (BEC), an attacker infiltrated an employees Microsoft 365 account to access sensitive financial documents hosted in SharePoint, including pay slip and banking details. Having gained initial entry, the attacker proceeded to make configuration changes to the inbox, deleting items and making updates that would enable them to cover their tracks.
The employees account login was first observed from unusual IP ranges. The account in question had never logged in from Bulgaria before, and the peer accounts belonging to those from the same department had not exhibited similar behavioral traits. This in itself was a low-level anomaly and not necessarily indicative of malicious activity after all, in the context of an increasingly distributed workforce, employees might change locations frequently.
Yet the unusual login location was accompanied by an unusual login time and a new User-Agent. All of these anomalies called for a deeper analysis. It was then identified that the account was starting to access highly sensitive information, including payroll information on a Sharepoint.
The attacker tried to gain insights about payment information and credit card details, with the likely intention of changing the payroll details to an attacker-controlled bank account.
AI-powered security technology was able to put together these weak signals of a threat and illuminate the likely account compromise. The companys security team was then able to lock the account and alert the user, who subsequently changed their credentials.
Box.com Compromise
At a global supply company, unauthorized access to an employees Box.com file storage account was detected. The login took place in the US where the company does operate but from an unusual IP space and ASN. AI began to investigate the users activity.
The actor behind the account logged in to Box.com successfully, and proceeded to download expense reports, invoices, and other financial documents. These were files that were highly unusual for the account to access.
Cyber AI also found that the activity occurred at a highly unusual time for the legitimate user, and the location of the actors IP address was anomalous compared to the employees previous access locations for this particular SaaS service.
An understanding of user behavior and granular visibility within the Box.com application allowed the company to spot the subtle signs of account compromise. Moreover, AI-powered investigation outlined the narrative in its entirety, showing how each unauthorized file exposure was part of a connected incident and a key concern for the security team.
A new era in SaaS domain defense
Ultimately, traditional detection approaches with hard and fast rules for how SaaS domains should operate are not enough to ensure that SaaS applications remain secure. Keeping threat intelligence lists up to date is even more difficult, as most SaaS attacks dont involve any Command & Control just indiscriminate logins from remote devices. When it comes to points of entry for SaaS attacks, the possibilities are endless: VPN, Tor, other compromised devices, dynamic DNS or even virtual private servers for attackers to cover their tracks.
A more intricate and effective approach to SaaS security requires an understanding of the dynamic individual behind the account. SaaS applications are fundamentally platforms for humans to communicate allowing them to exchange and store ideas and information.
Abnormal, threatening behavior is therefore impossible to detect without a nuanced understanding of those unique individuals: where and when do they typically access a SaaS account, which files are they like to access, who do they typically connect with? As the attacks outlined serve to demonstrate, these are questions for an AI brain to contend with.
Follow this link:
The Anatomy of a SaaS Attack: Catching and Investigating Threats with AI - Infosecurity Magazine
- Anatomy Of A Bitcoin Bear Market: Expert Trader Reveals The Signals To Watch Out For | Bitcoinist.com - Bitcoinist.com - April 19th, 2025 [April 19th, 2025]
- 'Grey's Anatomy' Recap: Are Winston Ndugu and Jules Millin the Next Power Couple at Grey-Sloan? - TV Insider - April 19th, 2025 [April 19th, 2025]
- Greys Anatomy Taps Piper Perabo for Three-Episode Arc Whats Her Connection to Amelia? - TVLine - April 19th, 2025 [April 19th, 2025]
- The anatomy of an NPR headline - VPM - April 19th, 2025 [April 19th, 2025]
- Anatomy of the system: Criminal case is finally (almost) over - nrtoday.com - April 19th, 2025 [April 19th, 2025]
- Grey's Anatomy Season 21, Episode 15 Review: Im Glad The Characters Are Showing Off Their Silly Sides In The Shows Funniest Episode In A Long Time -... - April 19th, 2025 [April 19th, 2025]
- Jessie Buckley to Narrate Leah Hazards Novel The Anatomy of Us for Audible (EXCLUSIVE) - Variety - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeo reveals why shell never leave Greys Anatomy for good: It doesnt make any sense - New York Post - April 19th, 2025 [April 19th, 2025]
- Greys Anatomy season 21 episode 15: Where to watch free tonight - MassLive - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeo says leaving 'Grey's Anatomy' would mean that others get to 'profit' off her hard work - Business Insider - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeo on Why It Would Make No Sense to Walk Away From Greys Anatomy - Rolling Stone - April 19th, 2025 [April 19th, 2025]
- In the Human Anatomy Lab, Experiential Learning Prepares Future Health Care Leaders - U of G News - April 19th, 2025 [April 19th, 2025]
- Window washers platform crashes into hospital: How to watch Greys Anatomy without cable - PennLive.com - April 19th, 2025 [April 19th, 2025]
- Riley Greene, Colt Keith and the anatomy of a slump - The Athletic - The New York Times - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeo reveals she gets a little bit annoyed when Greys Anatomy fans call her Meredith - The Independent - April 19th, 2025 [April 19th, 2025]
- Revisiting the 20-Year History of the Music of Greys Anatomy - Shondaland - April 19th, 2025 [April 19th, 2025]
- Yellowstone Star Piper Perabo Joins the Cast of Greys Anatomy in Recurring Role - EntertainmentNow - April 19th, 2025 [April 19th, 2025]
- Seriously? Greys Anatomy Is Making Us Take Sides, and It Feels Like [Bleep] - TVLine - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeos honest reason for never leaving Greys Anatomy branded weird - The Independent - April 19th, 2025 [April 19th, 2025]
- The body as a manifesto: Schiaparellis use of anatomy - HIGHXTAR. - April 19th, 2025 [April 19th, 2025]
- Ellen Pompeo reveals one frustration with Grey's Anatomy fans: "I do get a little bit annoyed" - Digital Spy - April 19th, 2025 [April 19th, 2025]
- On Set: Greys Anatomy Stars Sharing Their Hidden Talents - Shondaland - April 19th, 2025 [April 19th, 2025]
- Anatomy of a Shot | The Gorge: Building the Blast - DNEG - April 19th, 2025 [April 19th, 2025]
- The countries with longest anatomy measurements (7+ inches) and what this means for your health - Journe Mondiale - April 10th, 2025 [April 10th, 2025]
- 21 "Grey's Anatomy" Behind-The-Scenes Facts That'll Make You Watch The Show In A Whole New Way - BuzzFeed - April 10th, 2025 [April 10th, 2025]
- Anatomy of Exile by Zeeva Bukai reflects on the elusive nature of home - jweekly.com - April 10th, 2025 [April 10th, 2025]
- Sex toys and exploding cosmetics: Anatomy of a 'hybrid war' on the West - Reuters - April 10th, 2025 [April 10th, 2025]
- Doctor Odyssey Has Higher Ratings Than Grey's Anatomy, So Why Was It At The Risk Of Being Canceled When Shonda Rhimes' Show Was Already Renewed -... - April 10th, 2025 [April 10th, 2025]
- Anatomy of a housing proposal toppled by NIMBYs - The Portland Press Herald - April 10th, 2025 [April 10th, 2025]
- The Anatomy of a New Distribution Branch - Roofing Contractor - April 10th, 2025 [April 10th, 2025]
- 'Grey's Anatomy' Is Returning for Season 22: Get the Scoop - TV Insider - April 10th, 2025 [April 10th, 2025]
- Greys Anatomy: Has Owen Broken the Open Relationship Rules Already? - TV Insider - April 10th, 2025 [April 10th, 2025]
- Greys Anatomy Season 21, Episode 13 Review: Im More Excited Than Ever For The Last 5 Episodes Thanks To A Few Storyline Advancements - Screen Rant - April 10th, 2025 [April 10th, 2025]
- 'Grey's Anatomy': Teddy Makes a Tearful Admission as She and Owen Navigate Their Open Marriage - People.com - April 10th, 2025 [April 10th, 2025]
- Greys Anatomy, Shifting Gears Among Five ABC Renewals, Doctor Odyssey in Limbo - hollywoodreporter.com - April 10th, 2025 [April 10th, 2025]
- Effect of Virtual Reality Simulation on Anatomy Learning Outcomes: A Systematic Review - Cureus - April 10th, 2025 [April 10th, 2025]
- Greys Anatomy Renewed For Season 22 By ABC With Veteran Cast Poised To Return - Deadline - April 10th, 2025 [April 10th, 2025]
- Grey's Anatomy: Kim Raver Talks Teddy and Owen's Open Marriage - Us Weekly - April 10th, 2025 [April 10th, 2025]
- Greys Anatomy: Sophia Bush Discusses Cass And Teddys Long-Awaited Tryst & Whether Theres More To Come Between Them - Deadline - April 10th, 2025 [April 10th, 2025]
- 9-1-1, Greys Anatomy, The Rookie, Shifting Gears, Will Trent Renewed at ABC - Variety - April 10th, 2025 [April 10th, 2025]
- 7 Times the Greys Anatomy Surgeons Did the Impossible - Shondaland - April 10th, 2025 [April 10th, 2025]
- Grey's Anatomy Is Bound To Repeat A Controversial George Plot From 18 Years Ago (But With A Twist) - Screen Rant - April 10th, 2025 [April 10th, 2025]
- Ellen Pompeo Reveals The Exact Moment Her Daughter Stopped Watching 'Grey's Anatomy' - HuffPost - April 10th, 2025 [April 10th, 2025]
- Anatomy Of A Market Crisis: Tariffs, Markets And The Economy - Seeking Alpha - April 10th, 2025 [April 10th, 2025]
- Pulse Bosses on Danny and Xanders Messy Power Dynamic, Greys Anatomy Comparisons and Season 2 Plans - Variety - April 10th, 2025 [April 10th, 2025]
- Bare Anatomy parent Innovist raises Rs 136 crore from ICICI Venture, others - The Economic Times - April 10th, 2025 [April 10th, 2025]
- T.R. Knight Was 'Scared' to Film Meredith and George's 'Humiliating' Grey's Anatomy Sex Scene (Exclusive) - People.com - April 10th, 2025 [April 10th, 2025]
- "Thats My Home": Ellen Pompeo Reveals Whether She Has Plans To Exit 'Grey's Anatomy' for Good - Collider - April 10th, 2025 [April 10th, 2025]
- TVs Current Medical Dramas, Ranked: Our Diagnoses for The Pitt, Watson, Doc Greys Anatomy and More - TVLine - April 10th, 2025 [April 10th, 2025]
- Anatomy of a Market Crisis: Tariffs, Markets and the Economy - Investing.com - April 10th, 2025 [April 10th, 2025]
- Who Will Save Greys Anatomy Now That Ellen Pompeo Is Gone? - The Daily Beast - April 10th, 2025 [April 10th, 2025]
- 19 Most Memorable (and Heart-Wrenching!) 'Grey's Anatomy' Episodes of All Time - PEOPLE - March 30th, 2025 [March 30th, 2025]
- 16 stars you forgot were on Grey's Anatomy before their big break (including future Oscar nominees) - Entertainment Weekly News - March 30th, 2025 [March 30th, 2025]
- "I Cried When He Died": Shonda Rhimes Is Still Deeply Impacted By Killing One Grey's Anatomy Character - Screen Rant - March 30th, 2025 [March 30th, 2025]
- See the Best Greys Anatomy Behind-the-Scenes Photos to Celebrate 20 Years of the Medical Drama - PEOPLE - March 30th, 2025 [March 30th, 2025]
- Katherine Heigl, Jeffrey Dean Morgan reunite to talk Grey's Anatomy , from Denny's death to ghost sex - Entertainment Weekly News - March 30th, 2025 [March 30th, 2025]
- Sandra Oh Is Changing Her Tune on a Potential Return to 'Grey's Anatomy' - PEOPLE - March 30th, 2025 [March 30th, 2025]
- The Scrapped Grey's Anatomy Spin-Off Would Have Ruined The Show's Best Characters - SlashFilm - March 30th, 2025 [March 30th, 2025]
- Anatomy of a flood: The Derna tragedys lessons for Libyan governance - Brookings Institution - March 30th, 2025 [March 30th, 2025]
- 19 Years Later, Shonda Rhimes Still Isnt Over This Greys Anatomy Death (and Neither Are We) - Collider - March 30th, 2025 [March 30th, 2025]
- The perfect palliative balm of Greys Anatomy - Financial Times - March 30th, 2025 [March 30th, 2025]
- 15 Behind-the-Scenes Facts You Didn't Know About Grey's Anatomy, 20 Years After It Premiered - MSN - March 30th, 2025 [March 30th, 2025]
- I Have Zero Endings: Shonda Rhimes Has No Idea How (or When) Greys Anatomy Will End - Collider - March 30th, 2025 [March 30th, 2025]
- My Only Allegiance Is to the Story: Shonda Rhimes Explains Why Shes Killed So Many Beloved Greys Anatomy Characters - Collider - March 30th, 2025 [March 30th, 2025]
- 'Grey's Anatomy' star Ellen Pompeo says $20 million salary brings 'true independence': 'I don't have to do anything I don't want to do' - CNBC - March 30th, 2025 [March 30th, 2025]
- 'I love your song from "Grey's Anatomy"': How the ABC medical drama's soundtrack changed these artists' musical careers - Yahoo... - March 30th, 2025 [March 30th, 2025]
- Shonda Rhimes On The 'Grey's Anatomy' & 'Scandal' Spinoffs That Never Materialized: "We Thought About A Lot Of Things" - Deadline - March 30th, 2025 [March 30th, 2025]
- Shades of Gray in Twenty Years of Greys Anatomy - Books, Health and History - March 30th, 2025 [March 30th, 2025]
- Linda Lowy talks casting Shondaland, from Grey's Anatomy to the best audition she's ever seen - Entertainment Weekly News - March 30th, 2025 [March 30th, 2025]
- Shonda Rhimes is 'forever bitter' about having to fight for 'Grey's Anatomy' musical episode - Entertainment Weekly News - March 30th, 2025 [March 30th, 2025]
- Greys Anatomy: Is It Finally Time for Owen & Teddy to Call it Quits? (POLL) - TV Insider - March 30th, 2025 [March 30th, 2025]
- After 18 Years, Meredith Finally Proves Ellis' Most Hurtful Criticism Wrong In Grey's Anatomy Season 21 - Screen Rant - March 30th, 2025 [March 30th, 2025]
- Arte France Boards Movistar Plus+s The Anatomy of a Moment, From The Plagues Alberto Rodrguez - Variety - March 30th, 2025 [March 30th, 2025]
- Makes Me Just Go, Hmm: Christinas Potential Greys Anatomy Return Addressed By Sandra Oh, Who Admits Her Stance Has Softened After Years Of Hard No -... - March 30th, 2025 [March 30th, 2025]
- Shonda Rhimes Reveals "A Bunch" Of Never Made Grey's Anatomy Spinoffs, Including One Based On The Shepherd Family - Screen Rant - March 30th, 2025 [March 30th, 2025]
- Anatomy of a Massacre - by Theo Padnos - Persuasion - Persuasion | Yascha Mounk - March 30th, 2025 [March 30th, 2025]
- We Thought About a Lot of Things: Shonda Rhimes Discusses Greys Anatomy Spin-Offs That Never Were - Collider - March 30th, 2025 [March 30th, 2025]
- 'Grey's Anatomy' Redefined the Medical Drama on TV - Collider - March 30th, 2025 [March 30th, 2025]
- Greys Anatomy turns 20: How Katherine Heigl pulled off her Emmy upset and remains the only series regular to win - Gold Derby - March 30th, 2025 [March 30th, 2025]
- Why Shonda Rhimes Scrapped Spinoffs of Greys Anatomy and Scandal - TheWrap - March 30th, 2025 [March 30th, 2025]