Slack developed Anomaly Event Response (AER), an automated security system that detects suspicious user behavior in real-time and immediately terminates compromised sessions. The system monitors billions of daily events for threats like Tor access, excessive downloading, data scraping, and unusual API patterns. AER reduces response time from days/hours to minutes by automatically ending sessions when high-confidence threats are detected, while providing configurable detection rules and notification preferences for enterprise customers.

9m read timeFrom slack.engineering
Post cover image
Table of contents
The Shared Responsibility of Securing SlackDesign PhilosophySystem Architecture & Technical Deep-DiveKey Findings & ImpactConclusion

Sort: