Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

2/24/2017
02:00 PM
Kaushik Narayan
Kaushik Narayan
Commentary
50%
50%

IaaS: The Next Chapter In Cloud Security

Organizations adopting IaaS must update their approach to security by using the shared responsibility model.

Companies in industries from manufacturing to financial services to the public sector trust cloud providers with their critical data. The rapid growth of software-as-a-service (SaaS) applications such as Office 365 and Salesforce depended on trust. But the floodgates of SaaS adoption didn't open until IT security professionals became convinced that cloud providers could produce equivalent or better security compared to traditional software. Where challenges remain is on the enterprise side; Gartner predicts 95% of cloud security incidents will be the customer’s fault.

Now a second wave of cloud adoption is reaching its swell, with the edge around enterprises disappearing into infrastructure-as-a-service (IaaS) offerings. For IaaS, organizations need to update their approach to security by using the shared responsibility model.  

Updating the Shared Responsibility Model for IaaS
Cloud-first companies use SaaS tools for different functions: Office 365 for collaboration, Workday for human resources, and Salesforce for customer relationship management. Every organization also possesses anywhere from a handful to thousands of internally developed applications for employees, customers, and partners. Organizations are eliminating their data centers and moving these proprietary applications to IaaS cloud offerings en masse, leading to an IaaS growth rate double that of SaaS.

Even companies that have taken a proactive approach to SaaS security must reevaluate their capabilities when it comes to applications hosted on IaaS platforms. SaaS and IaaS platforms operate under different shared-responsibility models, or the allocation of security capabilities between cloud provider and customer. Many security vulnerabilities that SaaS providers address fall on the shoulders of the enterprise customer for applications hosted on IaaS services.

Furthermore, business pressure to move quickly means security teams may have little to no oversight on IaaS security; developer teams don't have extra resources to dedicate to updating security for existing on-premises applications slated to migrate to the cloud. Proprietary applications don't have dedicated security solutions like SaaS apps do, nor do they have APIs that integrate out of the box with security products. While in the past we have thought of startups and cloud service providers as the companies dealing with AWS, Azure, or Google Cloud Platform security, today the Fortune 2000 are contending with the challenges of securing apps in the cloud.

IaaS security threats come from both inside and outside the organization. Hackers target corporate IaaS accounts to steal data or computing resources. This vector can be exploited through stealing credentials, gaining misplaced access keys, or leveraging misconfigured service settings. One researcher discovered over 10,000 AWS credentials on GitHub. Hacked accounts can be used to mine Bitcoin or hold companies for ransom, as in the worst-case scenario of hosting company Code Spaces.

Internally, a malicious employee with access to IaaS accounts can cause immense damage by stealing, altering, or deleting data on the platform. Human error and negligence can expose corporate data and resources to attackers. Healthcare company CareSet made a configuration error that resulted in hackers exploiting its Google Cloud Platform account to launch intrusion attacks against other targets. After a few days without remediation, Google temporarily shut down the company's account. Organizations can't incorrectly assume that IaaS environments are secure out of the box. In every case above, the cloud provider is powerless to address the customer's vulnerability.

IaaS Security Action Plan
Keeping data safe in proprietary applications on IaaS platforms requires an extra step beyond SaaS security: protecting the computing environments themselves. Securing environments on AWS, Google Cloud Platform, Microsoft Azure, or other IaaS platforms begins with a configuration audit. Here are four categories of configurations critical to securing IaaS usage:

1. Authentication: Multifactor authentication is a necessary control for any application with sensitive corporate information, especially cloud applications exposed to the Internet. Companies should enable multifactor authentication for root accounts and Identity and Access Management users to reduce the risk of account compromises. Heightened authentication can require a user to enter an additional login step before they commit an action such as deleting an S3 bucket.

2.  Unrestricted Access: Unnecessarily exposing AWS environments increases the threat of various methods of attack including denial-of-service, man-in-the-middle, SQL injections, and data loss. Checking for unrestricted access to Amazon Machine Images, Relational Database Service instances, and Elastic Compute Cloud can protect intellectual property and sensitive data, as well as prevent service outages.

3. Inactive Accounts: Inactive and unused accounts pose unnecessary risk to IaaS environments. Auditing and eliminating inactive accounts can prevent account compromise and misuse at little cost to productivity.

4. Security Monitoring: One of the top fears of moving computing to the cloud is loss of visibility and forensics. Turning on an audit trail like AWS's CloudTrail logging establishes a behavior monitoring tool for active threats and forensic investigations. This is also a basic compliance requirement for any large company and can be a deal breaker for moving an application to IaaS.

Of these four categories, security monitoring is the most complex and robust. Machine learning tools can be tuned to detect a range of behavior indicative of a threat. APIs can enable monitoring based on session locations, excessive activity, or brute-force logins. At first glance, moving applications to the cloud can appear to forfeit control. With a proactive, cloud-based security strategy, however, applications on IaaS can be just as secure as their on-premises counterparts, or even more so.

Related Content:

 

Kaushik Narayan is a Co-Founder and CTO at Skyhigh Networks, a cloud security company, where he is responsible for Skyhigh's technology vision and software architecture. He brings over 18 years of experience driving technology and architecture strategy for enterprise-class ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.