123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> Computers >> View Article

100,000 Tweets In 1 Day – How One Company Discovered A Security Breach Using Big Data Analytics

Profile Picture
By Author: Lauren Ellis
Total Articles: 35
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

As the recent breach involving millions of Target customer credit cards illustrates, security breaches leave a pattern of activity that is mathematically unusual. As cyber criminals increasingly use the cloud as an attack vector, these attacks also create anomalous activities that indicate something is wrong. In mathematical terms, they produce outliers that are several standard deviations away from normal user activity. A breach is usually at the edge of the bell curve and stands out as unusual.

The challenge for today’s companies is to identify these anomalous events quickly and then take immediate steps to investigate, take action, and limit the damage. With billions of transactions to look at, how do companies find the needles in very large haystacks? They need scalable cloud analytics to analyze large volumes of transaction data and automatically find anomalous activity.

Interesting Usage Anomalies Actually Evidence of Breaches
Using Skyhigh’s cloud analytics, Fortune 2000 companies have identified security breaches and taken corrective action before they threatened their businesses. Here ...
... are some of the most creative attacks we’ve uncovered:

Malware stealing data via Twitter – At a large financial institution, Skyhigh identified a single IP address at the company that was sending over 100,000 tweets per day. The corporate Twitter account only had few thousand tweets since inception. Investigating further, they discovered that it was malware exfilterating data 140 characters at a time via a Twitter account.

Command and control using GoToMyPC – At a retail company, Skyhigh identified a single device attempting to connect to GoToMyPC 11 million times in a single week. After investigating, they discovered the computer was infected with malware and attempting to connect so it could be used to infiltrate the company.

Blocked attempts to use Facebook – At an energy company, a single device made 3.8 million attempts to access Facebook, all of which were blocked. The computer was infected with malware and was attempting to connect to exfiltrate data from the company.

Author :
Lauren Ellis is a research analyst covering the technology industry’s top trends & topics, focusing on Cloud Security, Cloud Computing, Data Loss Prevention etc.,

Total Views: 528Word Count: 346See All articles From Author

Add Comment

Computers Articles

1. Spark Matrix™: Multi-carrier Parcel Management Solutions
Author: Umangp

2. Best Odoo Erp Software Company In Dubai For Business Growth
Author: Mayur Meheshwari

3. Top Challenges Faced By Equipment Rental Companies In The Uae — And How Erp Solves Them
Author: Al murooj solutions

4. Spark Matrix™: Intelligent Virtual Assistants (iva)
Author: Umangp

5. Pos Software Designed For Retail Operations
Author: EPOS Direct

6. Erp System That Reduces Stress And Improves Productivity
Author: Shalijah

7. Spark Matrix™: Global Service Parts Planning Application
Author: Umangp

8. Spark Matrix™: Enterprise Information Archiving
Author: Umangp

9. Textideo: Transforming Text Into Engaging Ai-powered Videos For Modern Creators
Author: Ethan Walker

10. Spark Matrix™: Enterprise Ai Search
Author: Umangp

11. What Identity Governance Really Means In Modern Enterprises
Author: Mansoor Alam

12. Strategies For Successful Site Selection In Clinical Trials
Author: Giselle Bates

13. Simplifying Business Purchases With Smart, Reliable Procurement Solutions
Author: suma

14. How Businesses In Dubai Are Scaling Faster With Modern Erp Software
Author: Al murooj solutions

15. How To Choose The Right Weapon Tracking System: 7 Must-have Features
Author: 3PL Insights

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: