Enterprise Cloud Network Security Notes
Cloud Computing Fundamentals
Definition: Cloud computing is an on-demand delivery of IT capabilities where the IT infrastructure and applications are provided to subscribers as a metered service over a network.
Core Characteristics of Cloud Computing:
On-demand self-service.
Broad network access.
Distributed storage.
Resource pooling.
Rapid elasticity.
Measured service.
Automated management.
Virtualization technology.
Cloud Computing Benefits and Models
Economic Benefits:
Business agility.
Less maintenance costs.
Acquire economies of scale.
Less capital expense.
Huge storage facilities for organizations.
Environment friendly.
Less total cost of ownership (TCO).
Less power consumption.
Operational Benefits:
Flexibility and efficiency.
Resilience and redundancy.
Scale as required.
Less operational problems.
Deploy applications quickly.
Backup and disaster recovery.
Automatic updates.
Security Benefits:
Less investment in security controls.
Efficient, effective, and swift response to security breaches.
Standardized open interface for managed security services (MSS).
Effective patch management and implementation of security updates.
Ability to dynamically scale defensive resources on demand.
Resource aggregation offers better manageability of security systems.
Rigorous internal audits and risk assessment procedures.
Staffing Benefits:
Streamline processes.
Efficient usage of resources.
Less personnel training.
Less IT Staff requirements.
Multiple users can utilize cloud resources.
Evolution of new business models.
Simultaneous sharing of resources.
Better disaster recovery preparedness.
Cloud Service Models
Cloud Consumers: Primary users include End Customers, Developers, and System Administrators (Sys Admins).
Infrastructure-as-a-Service (IaaS):
Provides virtual machines (VMs) and other abstracted hardware and operating systems controlled through a service API.
Examples: Amazon EC2, GoGrid, SunGrid, Windows SkyDrive, and Rackspace.
Platform-as-a-Service (PaaS):
Offers development tools, configuration management, and deployment platforms on demand used to develop custom applications.
Examples: Intel MashMaker, Google App Engine, Force.com, and Microsoft Azure.
Software-as-a-Service (SaaS):
Offers software to subscribers on demand over the internet.
Examples: Google Docs, Google Calendar, Salesforce CRM, Freshbooks, and Basecamp.
Shared Responsibilities by Service Type
On-Premise: The subscriber/tenant manages everything, including: Data, Interfaces, Applications, Middleware, Operating Systems, Virtual Machines, Virtual Network, Hypervisors, Processing & Memory, Data Storage, Network Interfaces, Facilities & Data Centers.
IaaS (Infrastructure as a Service):
Customer Manages: Data, Interfaces, Applications, Middleware, Operating Systems, Virtual Machines, Virtual Network.
Provider Manages: Hypervisors, Processing & Memory, Data Storage, Network Interfaces, Facilities & Data Centers.
PaaS (Platform as a Service):
Customer Manages: Data, Interfaces, Applications.
Provider Manages: Middleware, Operating Systems, Virtual Machines, Virtual Network, Hypervisors, Processing & Memory, Data Storage, Network Interfaces, Facilities & Data Centers.
SaaS (Software as a Service):
Customer Manages: Data, Interfaces.
Provider Manages: Applications, Middleware, Operating Systems, Virtual Machines, Virtual Network, Hypervisors, Processing & Memory, Data Storage, Network Interfaces, Facilities & Data Centers.
Cloud Deployment Models
The selection of a deployment model is based on enterprise requirements:
Public Cloud: Services are rendered over a public network available to the general population.
Private Cloud: Cloud infrastructure operated exclusively for a single organization.
Community Cloud: Shared infrastructure between several organizations from a specific community with common concerns such as security, compliance, or jurisdiction.
Hybrid Cloud: A composition of two or more clouds (private, community, or public) that remain unique entities but are bound together.
Multi-cloud: Utilizes numerous public clouds rather than combining private and public clouds.
NIST Cloud Deployment Reference Architecture
The NIST reference architecture defines five major actors:
Cloud Consumer: A person or organization that uses cloud computing services.
Cloud Provider: A person or organization providing services to interested parties. Includes functions like Service Layer (SaaS, PaaS, IaaS), Resource Abstraction/Control Layer, Physical Resource Layer (Hardware/Facility), and Cloud Service Management (Business Support, Provisioning/Configuration, Portability/Interoperability).
Cloud Auditor: A party for making independent assessments of cloud service controls, including security audits, privacy impact audits, and performance audits.
Cloud Carrier: An intermediary providing connectivity and transport services between consumers and providers.
Cloud Broker: An entity that manages cloud services (use, performance, delivery) and maintains relationships between providers and consumers. Roles include Service Intermediation, Service Aggregation, and Service Arbitrage.
Cloud Security: Shared Responsibility Model
Core Concept: Traditional security measures do not change with cloud adoption, but the focus does. Implementation of cloud does not change the protocols required in traditional networks but changes the security focus of consumers.
Shared Responsibility: Responsibility is divided between the Cloud Provider and the Cloud Customer. If consumers fail to secure their functions, the entire security model fails.
Responsibility Matrix:
Physical, Infrastructure, Hypervisor: Always Provider responsibility.
Network Traffic, Operating System: Varies (Customer in IaaS; Provider in SaaS/PaaS).
Applications: Varies (Customer in IaaS/PaaS; Provider in SaaS).
Data, User Access: Always Customer responsibility.
Consumer vs. Provider Security Elements
Customer Responsibilities:
User security and monitoring: Identity and Access Management (IAM).
Information security: Data encryption and key management.
Application-level security.
Data storage security.
Monitoring, logging, and compliance.
Provider Responsibilities:
Securing shared infrastructure: Routers, switches, load balancers, firewalls.
Hypervisors and storage networks.
Management consoles, DNS, and directory services.
Platform security: NoSQL, Message Queues, etc.
Guest OS firewall/hardening (in some models).
Identity and Access Management (IAM)
IAM involves managing digital identities and access rights to cloud resources:
Processes: Creating, managing, and removing identities.
Components: User Management (lifecycle, approvals), Authorization Management (roles/rules), Authentication Management, Data Management and Provisioning, Monitoring/Auditing/Reporting, and Federation.
Cloud Data and Network Security
Data Storage Security Techniques:
Local data encryption: Ensuring confidentiality of sensitive data.
Key management: Generating, using, protecting, storing, backing up, and deleting encryption keys.
Strong password management: Changing passwords at regular intervals.
Periodic assessments: Monitoring data security controls.
Cloud data backup: Taking local backups to prevent data loss.
Network Security Challenges: Lack of network visibility in monitoring suspicious activities.
Network Security Features:
Encrypting data-in-transit.
Multi-factor authentication (MFA).
Firewall layers installation.
Data loss prevention (DLP) enablement.
Security Methods:
DMZs and subnets.
Resource isolation using routing tables.
Securing DNS configurations.
Limiting inbound/outbound traffic.
Intrusion Detection/Prevention Systems (IDS/IPS).
Monitoring and Logging
Monitoring Activities: Monitoring unauthorized data access, including data replication, file name changes, classification changes, and ownership changes.
Cloud Monitoring Plan:
Identify metrics and events.
Use a single platform for all data reporting.
Monitor usage, fees, and user experience.
Log Management Questions: Efficient management requires asking:
Who is accessing the network?
What assets are they accessing?
From where are they accessing the asset?
When are they doing this?
Are there established permissions to allow their activity?
Log Management Best Practices: Aggregate all logs to log analytics or SIEM, control collection frequency to maintain application performance, and ensure system scalability.
Compliance and CSP Evaluation
Compliance Considerations: Know jurisdiction requirements, conduct regular risk assessments, and monitor compliance programs before crises occurs.
Evaluating CSPs: Perform a gap analysis against maturity and transparency. Check against standards: ISO 27001, PCI DSS, HIPAA, and SOX.
Evaluation Criteria: Disclosure of security policies, architecture, security automation, and governance responsibility.
Specific Cloud Platform Security Models
AWS (Amazon Web Services):
Three Shared Responsibility Models: Infrastructure Services, Container Services, and Abstract Services.
AWS IAM: Controls access by establishing rules and permissions for users/applications.
Microsoft Azure Cloud:
Customer always retains responsibility for Data Governance, Client Endpoints, and Account/Access Management.
Responsibility for Network, OS, and Identity Infrastructure varies by service type (IaaS vs PaaS vs SaaS).
Azure IAM: Features Single Sign-On (SSO), conditional access, and MFA.
Google Cloud Platform (GCP):
Google Responsibility: Hardware, Hardened Kernel/IPC, Storage/Encryption, and Physical Network.
User Responsibility: Content, Access Policies, and Usage.
GCP IAM: Provides granular access to specific resources to prevent unauthorized access.
General Security Best Practices and CASB
Best Practices:
Enforce data protection, backup, and retention.
Enforce SLAs for patching and vulnerability remediation.
Vendors should undergo AICPA SAS 70 Type II audits.
Check public domain blacklists.
Prohibit credential sharing.
Implement strong authentication and key management.
Cloud Access Security Broker (CASB):
On-premise or cloud-hosted solutions enforcing security between consumers and providers.
Features: Visibility, Data security, Threat protection, and Compliance.
Specific Solutions:
Forcepoint CASB: Features discovery, risk scoring, data classification, and anomaly detection.
McAfee MVISION Cloud.
Cisco Cloudlock.
Bitglass Cloud Security.