|By Gilad Parann-Nissany||
|January 29, 2014 09:15 AM EST||
To say that cloud security for cloud computing is gaining traction would be the understatement of our era. Whether in public clouds, private clouds, or hybrid scenarios – it seems like everyone is in the cloud. Healthcare providers, eCommerce, disaster recovery services, data storage . . . the types of cloud services available seem to cover every base. What would Darwin think about his “Survival of the Fittest” evolving from animal species to businesses who take advantage of the flexibility, elasticity, and cost-effectiveness of cloud computing?
But, there are dangers in the cloud computing jungle and cloud security measures must be put in place to eliminate and resolve them. According to the Cloud Security Alliance, three types of threats have worsened between 2010 and today.
- Data Breaches
- Data Loss
- Account or Service Traffic Hijacking
Let’s explore how proper cloud security can protect you from these top threats.
1. Data Breaches
The attack can originate from many sources:
- Malevolent hackers
- Fierce competitors
- Insiders: employees, subcontractor, vendors, etc.
Regardless of the origin, the attack must be stopped before it causes damage.
Of course, you must put in place cloud security measures like anti-virus, firewalls, strict password policies, and accurate logs. But hackers can be deviously conniving. In November 2012, researchers from the University of North Carolina, the University of Wisconsin and RSA Corporation released a paper describing how a virtual machine could use side channel timing information to extract private cryptographic keys being used in other virtual machines on the same physical server. Whether your potential attackers are as sophisticated, there are ways to stop them from causing damage.
Encrypting your data, for example, is a security measure you MUST insist on. If you do it right, even if a breach does occur, your data will not be readable – and will therefore not be usable.
Encrypting data is relatively easy. Adhere to best practices like AES-256 and SHA-2. These techniques provide the best assurance that data has not been tampered with. SSL/TLS must always be enabled. IPsec communications should be allowed.
But once your data is encrypted, the cloud security challenge is to ensure the data cannot be decrypted. If your data is encrypted well, but the encryption keys are also accessible to attackers (stored in the same location or stored with a cloud provider, for example), the encryption does not matter.
The best practice here is to use split key management and homomorphic key encryption. The first splits your encryption key in parts. One part is handled by the cloud security application and one part is always handled only by you. BOTH parts are required to decrypt your data. This way, even if one part is used illicitly, your data cannot be breached. The second measure, homomorphic key encryption, is the only way to ensure that the key itself is encrypted, even while in use.
By using these two best practices, your cryptographic keys cannot be compromised.
2. Data Loss
Almost as terrifying as your data being accessed by outsiders (or insiders gone bad) is losing your data. Of course, losing data doesn’t allow anyone else to use it, but it also does not allow you to use it. Can your business perform without its data?
Data loss can occur as a result of virus or hacker attack, but it can also come from an accidental deletion by a cloud provider, a natural disaster like an earthquake, fire, flood, tornado…
Best practice here, of course, is backup. You could back up your data on physical devices outside of the cloud, but then you lose a lot of the benefits of using the cloud. Opting for an online backup and disaster recovery protocol is a great solution, but it opens another possible entry point for attackers (see the data breach section, above).
Solving this challenge does not have to be . . . well, challenging. The same best practices we dexcribed above apply here as well. Encrypt data before uploading or transferring it to a cloud backup or cloud disaster recovery platform. And always use split key management and homomorphic key encryption.
3. Account or Service Traffic Hijacking
Phishing, fraud, and exploitation of software vulnerabilities can cause your credentials to be stolen. With stolen credentials, attackers can often access critical areas of deployed cloud computing services, allowing them to compromise the confidentiality, integrity and availability of those services. In April 2010, Amazon experienced a Cross-Site Scripting (XSS) bug that allowed attackers to hijack credentials from the site. Even Amazon is a target!
How do you eliminate the risk of your credentials being stolen? Easy! Don’t trust anyone with them. Your encryption keys should always be under your own control. Do not allow your cloud provider to control your keys. Ever.
Another important factor to consider here is not avoiding such hijacking, but also mitigating the damages in case it occurs. A way to do this is to segment your encryption. Each encryption project can contain as much (or as little) data as required, across multiple disks, databases, file servers and object storage.
Conclusion: Top Threats and Top Solutions
Yes, there are threats to operating in the cloud (let’s face it: there are threats to operating any business), but with current technologies offering ways to thwart the top threats of data breaches, data loss, and hijacking, the benefits of cloud computing far outweigh the risks.
The time to institute strong cloud security and encryption is now – before an attack. Don’t think that it cannot (or will not) happen to you because you are too powerful or too big (or too small). It happened to Amazon. It happens to businesses every day. And these types of catastrophes have the ability to exhaust budgets, destroy reputations, and in some cases – eradicate a business.
SYS-CON Events announced today that Isomorphic Software will exhibit at DevOps Summit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Isomorphic Software provides the SmartClient HTML5/AJAX platform, the most advanced technology for building rich, cutting-edge enterprise web applications for desktop and mobile. SmartClient combines the productivity and performance of traditional desktop software with the simp...
Aug. 30, 2016 05:45 AM EDT Reads: 2,443
Why do your mobile transformations need to happen today? Mobile is the strategy that enterprise transformation centers on to drive customer engagement. In his general session at @ThingsExpo, Roger Woods, Director, Mobile Product & Strategy – Adobe Marketing Cloud, covered key IoT and mobile trends that are forcing mobile transformation, key components of a solid mobile strategy and explored how brands are effectively driving mobile change throughout the enterprise.
Aug. 30, 2016 03:45 AM EDT Reads: 458
With so much going on in this space you could be forgiven for thinking you were always working with yesterday’s technologies. So much change, so quickly. What do you do if you have to build a solution from the ground up that is expected to live in the field for at least 5-10 years? This is the challenge we faced when we looked to refresh our existing 10-year-old custom hardware stack to measure the fullness of trash cans and compactors.
Aug. 30, 2016 02:30 AM EDT Reads: 1,854
The emerging Internet of Everything creates tremendous new opportunities for customer engagement and business model innovation. However, enterprises must overcome a number of critical challenges to bring these new solutions to market. In his session at @ThingsExpo, Michael Martin, CTO/CIO at nfrastructure, outlined these key challenges and recommended approaches for overcoming them to achieve speed and agility in the design, development and implementation of Internet of Everything solutions wi...
Aug. 30, 2016 02:00 AM EDT Reads: 2,237
Cloud computing is being adopted in one form or another by 94% of enterprises today. Tens of billions of new devices are being connected to The Internet of Things. And Big Data is driving this bus. An exponential increase is expected in the amount of information being processed, managed, analyzed, and acted upon by enterprise IT. This amazing is not part of some distant future - it is happening today. One report shows a 650% increase in enterprise data by 2020. Other estimates are even higher....
Aug. 30, 2016 01:30 AM EDT Reads: 3,049
With over 720 million Internet users and 40–50% CAGR, the Chinese Cloud Computing market has been booming. When talking about cloud computing, what are the Chinese users of cloud thinking about? What is the most powerful force that can push them to make the buying decision? How to tap into them? In his session at 18th Cloud Expo, Yu Hao, CEO and co-founder of SpeedyCloud, answered these questions and discussed the results of SpeedyCloud’s survey.
Aug. 30, 2016 01:15 AM EDT Reads: 2,344
Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more business becomes digital the more stakeholders are interested in this data including how it relates to business. Some of these people have never used a monitoring tool before. They have a question on their mind like “How is my application doing” but no id...
Aug. 30, 2016 01:00 AM EDT Reads: 1,936
Smart Cities are here to stay, but for their promise to be delivered, the data they produce must not be put in new siloes. In his session at @ThingsExpo, Mathias Herberts, Co-founder and CTO of Cityzen Data, will deep dive into best practices that will ensure a successful smart city journey.
Aug. 30, 2016 12:00 AM EDT Reads: 1,666
DevOps at Cloud Expo, taking place Nov 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 19th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long dev...
Aug. 29, 2016 10:00 PM EDT Reads: 2,490
Identity is in everything and customers are looking to their providers to ensure the security of their identities, transactions and data. With the increased reliance on cloud-based services, service providers must build security and trust into their offerings, adding value to customers and improving the user experience. Making identity, security and privacy easy for customers provides a unique advantage over the competition.
Aug. 29, 2016 08:30 PM EDT Reads: 2,446
Qosmos has announced new milestones in the detection of encrypted traffic and in protocol signature coverage. Qosmos latest software can accurately classify traffic encrypted with SSL/TLS (e.g., Google, Facebook, WhatsApp), P2P traffic (e.g., BitTorrent, MuTorrent, Vuze), and Skype, while preserving the privacy of communication content. These new classification techniques mean that traffic optimization, policy enforcement, and user experience are largely unaffected by encryption. In respect wit...
Aug. 29, 2016 08:15 PM EDT Reads: 1,875
SYS-CON Events announced today that StarNet Communications will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. StarNet Communications’ FastX is the industry first cloud-based remote X Windows emulator. Using standard Web browsers (FireFox, Chrome, Safari, etc.) users from around the world gain highly secure access to applications and data hosted on Linux-based servers in a central data center. ...
Aug. 29, 2016 08:00 PM EDT Reads: 925
SYS-CON Events announced today that 910Telecom will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Housed in the classic Denver Gas & Electric Building, 910 15th St., 910Telecom is a carrier-neutral telecom hotel located in the heart of Denver. Adjacent to CenturyLink, AT&T, and Denver Main, 910Telecom offers connectivity to all major carriers, Internet service providers, Internet backbones and ...
Aug. 29, 2016 07:00 PM EDT Reads: 1,984
Traditional on-premises data centers have long been the domain of modern data platforms like Apache Hadoop, meaning companies who build their business on public cloud were challenged to run Big Data processing and analytics at scale. But recent advancements in Hadoop performance, security, and most importantly cloud-native integrations, are giving organizations the ability to truly gain value from all their data. In his session at 19th Cloud Expo, David Tishgart, Director of Product Marketing ...
Aug. 29, 2016 06:45 PM EDT Reads: 850
StarNet Communications Corp has announced the addition of three Secure Remote Desktop modules to its flagship X-Win32 PC X server. The new modules enable X-Win32 to safely tunnel the remote desktops from Linux and Unix servers to the user’s PC over encrypted SSH. Traditionally, users of PC X servers deploy the XDMCP protocol to display remote desktop environments such as the Gnome and KDE desktops on Linux servers and the CDE environment on Solaris Unix machines. XDMCP is used primarily on comp...
Aug. 29, 2016 06:15 PM EDT Reads: 803