New Research Uses Behaviour Patterns to Spot Fake or Malicious Cloud Identities
Cloud environments now host a mix of human users, machine accounts and automated agents, making it hard for businesses to know who or what is actually doing what. Researchers at Unit 42 have tackled this by building a behavioural clustering model that studies activity patterns in cloud audit logs, rather than relying on naming conventions or assigned permissions, which attackers often exploit to disguise malicious activity as normal use.
The study analysed more than 40,000 identities across 125 cloud environments over two months, successfully grouping them into functional roles such as administrators, backup services, security tools and DevOps accounts. Using machine learning techniques, the researchers built a reliable behavioural map of AWS environments, and showed that simplified versions of this logic can be run using standard SQL queries, avoiding the need for constant, resource-heavy machine learning processing.
While the research focused on AWS CloudTrail logs, the same approach could be applied to other cloud providers, SaaS platforms and Kubernetes environments. This gives defenders a new way to spot suspicious behaviour, even when an account appears to have legitimate permissions or a harmless-sounding name.