Identifying Security Platform Product Abuse with Machine Learning

📅 2026-09-18
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究使用机器学习方法识别SaaS行业中安全平台产品滥用问题,通过收集多模态数据并设计适应实际部署的系统来解决这一罕见但日益增长的问题。
📝 Abstract
Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platforms within customer environments or conduct bypass experiments on the product itself. Threat actors can leverage living-off-the-land (LOTL) attacks to avoid using cumbersome, frequently detected malware. Remediating this threat requires collecting multiple data modalities across different types of databases, addressing a cold-start problem in the intrinsic rarity of such sophisticated but dangerous events, and designing within the constraints of real-world deployment (e.g., cost, user behavior, performance, etc). To wit, we provide the first study of such a whole-system defense, especially with respect to a deployed and operational capability. Our results show an increase in product abuse coverage by 35\%, a 30\% reduction in monthly alerts, and adaptability to changes in malicious actors' behavior. We review both the constraints we considered in designing the system to meet operational requirements and a retrospective evaluation of the value of explainable features and counterfactual performance on previously identified attacks.
Problem

Research questions and friction points this paper is trying to address.

Product Abuse
SaaS Industry
Threat Actors
Living-off-the-land Attacks
Security Platforms
Innovation

Methods, ideas, or system contributions that make the work stand out.

Machine Learning
Product Abuse
Living-off-the-land (LOTL) Attacks
Cold-start Problem
Explainable Features
🔎 Similar Papers