Cloud Security and Privacy Notes
Cloud Security and Privacy
The Cloud Security Question
- The core question is whether cloud security is simply a rehash of existing security problems, given that:
- Cloud networks use standard Internet protocols.
- Cloud storage systems employ standard protocols (e.g., NFS).
- Cloud utilizes standard operating systems running on VMs.
- Cloud applications have the same vulnerabilities as other applications.
Complexity and Increased Security Risks
- The cloud environment introduces complexities beyond traditional enterprise environments.
- This complexity subsequently increases security risks.
Factors Increasing Cloud Security Difficulty
Lack of Control and Visibility
- Traditional IT: IT staff have complete visibility and control over infrastructure, software, and configurations.
- Cloud environment:
- Tenants lack access and control over the underlying infrastructure.
- Tenants cannot easily determine the root cause of security problems.
- Tenants struggle to prevent future issues independently.
- Tenants must rely on the provider for security configuration and management.
- Risk of miscommunication exists when tenants describe security policies to providers who then configure security software.
Shared Infrastructure
- Traditional IT serves a single organization.
- Cloud facilities serve multiple tenants.
- Virtualization aims to guarantee isolation, but shared facilities increase security and privacy risks in practice.
- Breaches have occurred in cloud environments.
Interdependent Services
- Microservices architecture scales individual application components independently.
- While microservices can be protected individually, the sheer number and frequent communication among them increase the attack surface.
- This complexity makes detecting breaches more difficult.
Dynamic Execution Environment
- Orchestration systems automatically scale services based on demand.
- The environment's dynamic nature (instances growing and shrinking) makes it challenging to differentiate between normal and abnormal activity, such as a Denial of Service (DoS) attack.
Remote Access
- Traditional IT often involves access from fixed locations.
- Cloud systems require remote access for both internal and remote employees.
- VPNs and other security mechanisms aim to ensure safety, but remote access increases the attack surface.
- This is especially true when employees use their own devices and are responsible for security.
Reliance on Third-Party Software
- Traditional IT either develops software in-house or purchases it from trusted vendors.
- Cloud-native software relies heavily on open-source software and software from repositories.
- Open-source repositories are sometimes characterized as a "wild west" regarding security.
Understanding Cloud Security Approach
- Cloud security differs significantly from traditional IT security approaches.
- Understanding this difference requires knowing:
- How traditional security systems are structured.
- Why the traditional structure is insufficient for the cloud.
- The alternative structures used in cloud security.
Traditional Security Systems
Insiders vs. Outsiders
- Traditional systems categorize users as either insiders (employees, trusted contractors) or outsiders.
- This classification is based on privilege level, not physical proximity.
Perimeter Security
- Traditional systems define a perimeter to enforce the insider/outsider distinction.
- Example: separate Wi-Fi networks for employees and guests.
- Security policies are enforced at the perimeter.
Demilitarized Zones (DMZs)
- Handle external Internet connections.
- Direct incoming traffic to specific servers.
- Allow organizations to run public web servers without risking internal access.
Standing Privileges
- Traditional IT assigns fixed privilege levels to individuals.
- Example: IT staff have absolute privilege, employees have the next level, and guests have the lowest.
Insufficiency of Traditional Perimeter Security for Cloud
- Cloud systems place VMs and containers from multiple tenants on the same physical server and network.
- Physical boundaries are absent, making perimeter security inapplicable.
- Microservices complicate privilege management because a service may be called from several other services.
- Standing privileges are unsuitable because a staff member managing a database service should not automatically manage the network.
Principle of Least Privilege (PoLP)
- Used in cloud security to restrict privilege to the minimum necessary for a specific task.
- Instead of broad privileges, individuals are granted privileges for specific tasks.
- Example: administrative privilege for one microservice does not grant the ability to manage others.
Security for External Internet Connections
- Tenants cannot directly manage security on external Internet connections.
- Tenants must collaborate with cloud providers to specify security policies.
- Providers then configure the network and security systems accordingly.
Zero Trust Security Model
- Needed in perimeterless environments.
- Each individual is assigned a set of privileges for each service.
- Each request is validated instead of allowing access after a single login.
- Example: validating the user's identity when invoking a Docker command.
- Requires balancing authentication frequency with usability.
Extreme Implementation of Zero Trust
- Consider a web page that allows employees to find others' email addresses, involving an interface microservice and a database lookup microservice.
- A naive zero-trust implementation would force users to authenticate multiple times, even for a single task.
- The situation worsens if each subsystem maintains its own set of credentials.
Sensible Approach to Zero Trust
- Use a centralized mechanism to handle identity and privilege.
- One login per user.
- Central record of all privileges granted to the user.
- Subsystems use the centralized mechanism for authentication and privilege validation.
- Allows assigning specific privileges without coordinating all subsystems.
Identity Management System (IdM System)
- Also known as Identity and Access Management (IAM) system.
- Centralized security system that maintains a record of all credentials.
- Uses Single Sign-On (SSO), where each user has one set of credentials for all services.
- Stores user privileges alongside credentials.
- All services use the IdM to validate access.
- Requires encrypted access and can be replicated for scalability.
Avoiding Multiple Validations
- The IdM uses a capability scheme.
- The first service validates user credentials and obtains approval from the IdM.
- The IdM returns a digital capability.
- Subsequent services receive the digital capability along with the request.
Privileged Access Management (PAM)
- A special case of identity management.
- Controls access for IT staff members who install, configure, and operate systems.
- Staff members have administrative or superuser privileges, a potential vulnerability point.
- An attacker forging staff credentials can gain access to confidential data or cause significant damage.
- Also known as Role-Based Access Control (RBAC).
Privileged Access Management Systems
- Handle identity management for privileged access.
- Limit staff member privileges to specific systems.
- Logs all access attempts, successful attempts, and accesses.
- The log can be used to:
- Detect attempted attacks.
- Track individual actions in case of a compromised staff member.
Primary and Secondary Privilege
- Some PAM systems define two types of privilege:
- Primary responsibility for systems and services routinely managed.
- Secondary responsibility for systems managed when the primary person is unavailable.
- The PAM system alerts the individual's manager when accessing a system where they have only secondary responsibility.
- Aims to report suspicious activity and allow managers to determine if the activity was legitimate.
Effect of AI on Security
- AI has positively and negatively influenced security.
Negative Impacts
- Attackers use AI to create more sophisticated attacks.
- Example: Using ML to mimic an executive's voice and trick employees into transferring data.
Positive Impacts
- Security analytics software analyzes activity logs (e.g., PAM logs) for anomalous incidents.
- ML is applied to network traffic to detect DDoS attacks.
Context-Aware Security Analysis
- ML detects suspicious access by considering context.
- Example: A user typically accesses a database through the HR system. If the user accesses the database directly, the system flags the access as suspicious.
Remote Access
- Applies to:
- Employees working outside the organization
- Organizations using public cloud providers
- Questions that arise:
- How to keep data confidential when employees download items to their own devices.
- How to ensure confidentiality of communication between an employee's device and the cloud data center.
Requirements for Remote Access
Communication Confidentiality
- Prevent eavesdropping, especially on Wi-Fi.
- Encrypt all data before transfer.
- Use a Virtual Private Network (VPN).
Protecting Business Data
- Encrypt company data in case devices are lost or stolen.
- Technologies available to automatically encrypt data.
Enforce Workflow Security
- Data moves between the cloud and employee devices.
- Each data set has specific security and compliance requirements.
- Define a security policy for each workflow and keep the policy with the data.
Compliance in a Cloud Environment
- Standard security systems ensure confidentiality, integrity, and availability.
- Organizations must comply with regulations on data collection, storage, and transmission.
- Examples: Medical facilities (HIPAA), Colleges and universities (FERPA), Financial institutions (BSA, FACTA).
Privacy
- Keeping sensitive information about individuals safe from public dissemination.
- Differs from confidentiality.
Deduction
- Privacy can be violated even if names are removed due to deduction.
- Example: If a graph shows average income by age group and only one person is in their 20s, revealing the average income reveals the individual's income.
The Complexities of Privacy Protection
- Privacy protection can't focus solely on presented data.
- Individuals can be identified by combining data from multiple sources.
- Difficult question: "Will publishing new information make it possible to deduce private information about individuals?"
- Colin Bennett: "Protecting privacy in the computer age is like trying to change a tire on a moving car."
Security Holes and Unexpected Attacks on Privacy
- Security and privacy are intertwined.
- Attackers target cloud-based email accounts to steal credentials.
- Stolen credentials launch attacks against web applications.
- In 2020, Threatpost reported that stolen credentials were used in 21% of web application attacks, exposing over 60 million personal records.
- Cloud infrastructure is shared by multiple applications from a single tenant and applications from multiple tenants.
- Common points of concern include:
- Shared storage infrastructure
- Shared computational infrastructure
- Shared communication infrastructure
- Two main security weaknesses: Back doors and Side channels.
Back Doors
- Special concern when using third-party systems.
- A back door has been designed to allow an attacker unauthorized access.
- Example: The SolarWinds attack in 2020.
Side Channels
- Flaws in virtualization hardware can allow VMs to pass information.
- Side channels can arise unexpectedly on shared infrastructure.
- Examples:
- Communicating by measuring processor usage.
- Communicating by measuring network delays.
Example of a Side Channel: Meltdown
- The Meltdown security vulnerability used a flaw in Intel processors.
- Combined with a cache side-channel attack, Meltdown allowed programs to bypass checks and access all memory, including OS items.
Traditional Security Approach
- In traditional IT, the IT staff handles all security.
- They:
- Assess requirements
- Formulate policies
- Choose implementations
- Select security technologies and tools
- Maintain confidentiality of policies and tools.
Security in a Cloud Environment
- Tenants must:
- Use provider-offered policies and configuration mechanisms
- Learn to use provider-offered security tools
- Provider interfaces:
- Include many confusing details
- Differ between providers
- Small mistakes lead to security problems.
- A 2019 Verizon report indicated misconfiguration of storage systems caused significant data exposures.
Change in Philosophy
- Old: Trust no outsiders.
- New:
- View the cloud provider as a partner
- Share security policies and work with the provider
- Report incidents to enable root cause analysis
Improved Security for Remote Access
- Many employees and SaaS users work remotely.
- Remote access may use unsecured networks (e.g., Wi-Fi).
- A 2019 Gartner report noted VPNs alone may not be sufficient.
- Suggested combining tools into a single service, termed Secure Access Service Edge (SASE).
- By July 2023, HPE Aruba Networking stated SASE is a strategic imperative.
SASE
- Pronounced "sassy"
- Vaguely defined
- Supported by vendors and adopted by some customers.
- Moves security to the "edge" (remote user location).
- Offers users:
- Easier configuration
- Fewer tools to manage
- Lower cost potential