ML Model Detecting Malicious SaaS Activity via Access Patterns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The lack of communication between SaaS services used by an organization creates a security 'void' that can be exploited by malicious actors, and job titles often do not accurately reflect an individual's actual job role or changes in job responsibilities.
Innovation Solution
A machine learning model is trained using access information from SaaS management platforms to predict job titles and detect malicious activities by correlating access patterns with job roles, even across multiple SaaS services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If job titles are used to define responsibilities and authority, then clarity in the workplace is improved, but job titles do not accurately reflect actual job roles or changes in responsibilities
Solution Approach 1:
The system performs preliminary analysis of access patterns and user behavior before making job title assignments or updates. By pre-processing access data from multiple SaaS services and analyzing it through machine learning models, the system prepares accurate job role predictions in advance, ensuring that job titles reflect actual responsibilities before they are formally assigned or updated in the organization.
Solution Approach 2:
The system implements continuous feedback loops where access patterns and user behaviors are monitored, analyzed, and used to update job title predictions over time. The machine learning models are retrained with new access data, creating a feedback mechanism that ensures job titles remain accurate and reflective of current responsibilities, automatically adapting to role changes without manual intervention.
2Reliability
If SaaS services operate independently without communication, then service autonomy is maintained, but security vulnerabilities arise that can be exploited by malicious actors
Solution Approach 1:
The system introduces a centralized machine learning-based analysis platform as an intermediary that receives access data from multiple independent SaaS services. This intermediary correlates access patterns across services without requiring the services themselves to communicate directly, maintaining their autonomy while enabling security analysis that spans across all services to detect malicious activities that would be invisible within individual services alone.
3Measurement precision
If access data from multiple SaaS services is collected and analyzed, then detection of malicious activities is improved, but data processing complexity increases
Solution Approach 1:
The system develops a universal machine learning framework that can process and analyze access data from multiple different SaaS services using a single, unified approach. The machine learning models are designed to handle diverse data formats and access patterns from various services through standardized processing pipelines, enabling multi-service analysis without requiring separate complex processing systems for each service.
Data Source
AI summary
A machine learning model is trained using information pertaining to accesses of data items at a software-as-a-service (SaaS) management platform. A first training input is generated. The first training input includes first access data identifying a multiple data items accessed at the SaaS management platform by a subset of multiple user accounts associated with a client organization. A first target output is generated. The first target output indicates, for each of the subset of user accounts, whether an occurrence of malicious activity is detected at the SaaS management platform. The training data is provided to train the machine learning model on (i) a set of training inputs including the first training input, and (ii) a set of target outputs including the first target output.


