Amazon Macie: A machine learning service to discover and protect sensitive data
aws.amazon.com
aws.amazon.com
I suppose that its in Amazon's best interest to not have people hacking accounts and spinning up the maximum amount of EC2s to mine Bitcoins.
Note - AWS is monitoring AccessKey use and API thresholds to keep you informed.
>Harvest.ai’s flagship, patent-pending AI product is called MACIE Analytics. It uses AI to monitor how a customer’s intellectual property is being accessed in real-time, assessing who is looking at, copying or moving particular documents, and where they are when they’re doing this, in order to identify suspicious patterns of behavior and flag potential data breaches before they’ve taken place. It bills the service as a way to combat the risk of insider attacks.
did they get the idea after seeing what happens at NSA with contractors/whoever downloading data to wherever?
Data insight is targeted at more user oriented unstructured content repositories (CIFS, NFS, SharePoint, OneDrive, SharePoint Online, Box), but the fundamentals are very similar: content classifiaction, data profiling, risk scoring, access pattern anomaly detection, access control remediation.
[0] https://www.veritas.com/product/information-governance/data-...
Instead of futzing with machine learning, use network or crypto controls to prevent access, and have a different chain of command manage that access in your company.
(We recently released our AWS Lambda integration — you can now record all Lambda function invocations with us!)
Disclaimer: I’m a Software Engineer with the AWS CloudTrail team.
GuardDuty is looking for specific threats/attacks and can combine multiple sources of telemetry for more advanced correlation. E.g. A combination of VPC Flows + CloudTrail + DNS that trigger an alert when formed together while a single CloudTrail event may not have.
If GD weren't so expensive, I wouldn't really care that much. But GD is so expensive that it can be hard to recommend, which is especially weird since the pricing for Macie CT is so low --- even weirder when you note that the pricing for Macie S3 is so high!
They let you turn on GuardDuty for free for 30 days and give you an estimate your bill so that helps.
Which pricing dimension is of concern?
DLP API scans are not limited to 20MB and can scale up to virtually any size. API results can be used for programmatic automation of alerts, IAM/ACL settings, or other remediation and can be sent automatically into BigQuery for detailed analysis or reporting. In addition to classification, Google’s DLP API provides data masking tools for structured and unstructured data including format-preserving encryption, bucketing, and tokenization. This helps developers reduce unnecessary PII when collecting, storing, or sharing data.
(Note: I am the Product Manager for DLP API at Google Cloud)
On the other hand, Macie has a GUI wizard. DLP API is an API. So if you can't code and just want to scan S3 then Macie might be for you, until Google DLP builds a GUI, if there's demand for that.
Someone should do a comparison of how successful each engine is at picking up sensitive data. I suspect Google DLP will be tuned better, but someone should do the test on a dummy data set and release results. That would be the most interesting comparison.
I work for Google.