Cloud Security and Privacy Notes

Cloud Security and Privacy

The Cloud Security Question

  • The core question is whether cloud security is simply a rehash of existing security problems, given that:
    • Cloud networks use standard Internet protocols.
    • Cloud storage systems employ standard protocols (e.g., NFS).
    • Cloud utilizes standard operating systems running on VMs.
    • Cloud applications have the same vulnerabilities as other applications.

Complexity and Increased Security Risks

  • The cloud environment introduces complexities beyond traditional enterprise environments.
  • This complexity subsequently increases security risks.

Factors Increasing Cloud Security Difficulty

Lack of Control and Visibility
  • Traditional IT: IT staff have complete visibility and control over infrastructure, software, and configurations.
  • Cloud environment:
    • Tenants lack access and control over the underlying infrastructure.
    • Tenants cannot easily determine the root cause of security problems.
    • Tenants struggle to prevent future issues independently.
    • Tenants must rely on the provider for security configuration and management.
  • Risk of miscommunication exists when tenants describe security policies to providers who then configure security software.
Shared Infrastructure
  • Traditional IT serves a single organization.
  • Cloud facilities serve multiple tenants.
  • Virtualization aims to guarantee isolation, but shared facilities increase security and privacy risks in practice.
  • Breaches have occurred in cloud environments.
Interdependent Services
  • Microservices architecture scales individual application components independently.
  • While microservices can be protected individually, the sheer number and frequent communication among them increase the attack surface.
  • This complexity makes detecting breaches more difficult.
Dynamic Execution Environment
  • Orchestration systems automatically scale services based on demand.
  • The environment's dynamic nature (instances growing and shrinking) makes it challenging to differentiate between normal and abnormal activity, such as a Denial of Service (DoS) attack.
Remote Access
  • Traditional IT often involves access from fixed locations.
  • Cloud systems require remote access for both internal and remote employees.
  • VPNs and other security mechanisms aim to ensure safety, but remote access increases the attack surface.
  • This is especially true when employees use their own devices and are responsible for security.
Reliance on Third-Party Software
  • Traditional IT either develops software in-house or purchases it from trusted vendors.
  • Cloud-native software relies heavily on open-source software and software from repositories.
  • Open-source repositories are sometimes characterized as a "wild west" regarding security.

Understanding Cloud Security Approach

  • Cloud security differs significantly from traditional IT security approaches.
  • Understanding this difference requires knowing:
    • How traditional security systems are structured.
    • Why the traditional structure is insufficient for the cloud.
    • The alternative structures used in cloud security.

Traditional Security Systems

Insiders vs. Outsiders
  • Traditional systems categorize users as either insiders (employees, trusted contractors) or outsiders.
  • This classification is based on privilege level, not physical proximity.
Perimeter Security
  • Traditional systems define a perimeter to enforce the insider/outsider distinction.
  • Example: separate Wi-Fi networks for employees and guests.
  • Security policies are enforced at the perimeter.
Demilitarized Zones (DMZs)
  • Handle external Internet connections.
  • Direct incoming traffic to specific servers.
  • Allow organizations to run public web servers without risking internal access.
Standing Privileges
  • Traditional IT assigns fixed privilege levels to individuals.
  • Example: IT staff have absolute privilege, employees have the next level, and guests have the lowest.

Insufficiency of Traditional Perimeter Security for Cloud

  • Cloud systems place VMs and containers from multiple tenants on the same physical server and network.
  • Physical boundaries are absent, making perimeter security inapplicable.
  • Microservices complicate privilege management because a service may be called from several other services.
  • Standing privileges are unsuitable because a staff member managing a database service should not automatically manage the network.

Principle of Least Privilege (PoLP)

  • Used in cloud security to restrict privilege to the minimum necessary for a specific task.
  • Instead of broad privileges, individuals are granted privileges for specific tasks.
  • Example: administrative privilege for one microservice does not grant the ability to manage others.

Security for External Internet Connections

  • Tenants cannot directly manage security on external Internet connections.
  • Tenants must collaborate with cloud providers to specify security policies.
  • Providers then configure the network and security systems accordingly.

Zero Trust Security Model

  • Needed in perimeterless environments.
  • Each individual is assigned a set of privileges for each service.
  • Each request is validated instead of allowing access after a single login.
  • Example: validating the user's identity when invoking a Docker command.
  • Requires balancing authentication frequency with usability.

Extreme Implementation of Zero Trust

  • Consider a web page that allows employees to find others' email addresses, involving an interface microservice and a database lookup microservice.
  • A naive zero-trust implementation would force users to authenticate multiple times, even for a single task.
  • The situation worsens if each subsystem maintains its own set of credentials.

Sensible Approach to Zero Trust

  • Use a centralized mechanism to handle identity and privilege.
  • One login per user.
  • Central record of all privileges granted to the user.
  • Subsystems use the centralized mechanism for authentication and privilege validation.
  • Allows assigning specific privileges without coordinating all subsystems.

Identity Management System (IdM System)

  • Also known as Identity and Access Management (IAM) system.
  • Centralized security system that maintains a record of all credentials.
  • Uses Single Sign-On (SSO), where each user has one set of credentials for all services.
  • Stores user privileges alongside credentials.
  • All services use the IdM to validate access.
  • Requires encrypted access and can be replicated for scalability.

Avoiding Multiple Validations

  • The IdM uses a capability scheme.
  • The first service validates user credentials and obtains approval from the IdM.
  • The IdM returns a digital capability.
  • Subsequent services receive the digital capability along with the request.

Privileged Access Management (PAM)

  • A special case of identity management.
  • Controls access for IT staff members who install, configure, and operate systems.
  • Staff members have administrative or superuser privileges, a potential vulnerability point.
  • An attacker forging staff credentials can gain access to confidential data or cause significant damage.
  • Also known as Role-Based Access Control (RBAC).

Privileged Access Management Systems

  • Handle identity management for privileged access.
  • Limit staff member privileges to specific systems.
  • Logs all access attempts, successful attempts, and accesses.
  • The log can be used to:
    • Detect attempted attacks.
    • Track individual actions in case of a compromised staff member.

Primary and Secondary Privilege

  • Some PAM systems define two types of privilege:
    • Primary responsibility for systems and services routinely managed.
    • Secondary responsibility for systems managed when the primary person is unavailable.
  • The PAM system alerts the individual's manager when accessing a system where they have only secondary responsibility.
  • Aims to report suspicious activity and allow managers to determine if the activity was legitimate.

Effect of AI on Security

  • AI has positively and negatively influenced security.
Negative Impacts
  • Attackers use AI to create more sophisticated attacks.
  • Example: Using ML to mimic an executive's voice and trick employees into transferring data.
Positive Impacts
  • Security analytics software analyzes activity logs (e.g., PAM logs) for anomalous incidents.
  • ML is applied to network traffic to detect DDoS attacks.

Context-Aware Security Analysis

  • ML detects suspicious access by considering context.
  • Example: A user typically accesses a database through the HR system. If the user accesses the database directly, the system flags the access as suspicious.

Remote Access

  • Applies to:
    • Employees working outside the organization
    • Organizations using public cloud providers
  • Questions that arise:
    • How to keep data confidential when employees download items to their own devices.
    • How to ensure confidentiality of communication between an employee's device and the cloud data center.

Requirements for Remote Access

Communication Confidentiality
  • Prevent eavesdropping, especially on Wi-Fi.
  • Encrypt all data before transfer.
  • Use a Virtual Private Network (VPN).
Protecting Business Data
  • Encrypt company data in case devices are lost or stolen.
  • Technologies available to automatically encrypt data.
Enforce Workflow Security
  • Data moves between the cloud and employee devices.
  • Each data set has specific security and compliance requirements.
  • Define a security policy for each workflow and keep the policy with the data.

Compliance in a Cloud Environment

  • Standard security systems ensure confidentiality, integrity, and availability.
  • Organizations must comply with regulations on data collection, storage, and transmission.
  • Examples: Medical facilities (HIPAA), Colleges and universities (FERPA), Financial institutions (BSA, FACTA).

Privacy

  • Keeping sensitive information about individuals safe from public dissemination.
  • Differs from confidentiality.
Deduction
  • Privacy can be violated even if names are removed due to deduction.
  • Example: If a graph shows average income by age group and only one person is in their 20s, revealing the average income reveals the individual's income.

The Complexities of Privacy Protection

  • Privacy protection can't focus solely on presented data.
  • Individuals can be identified by combining data from multiple sources.
  • Difficult question: "Will publishing new information make it possible to deduce private information about individuals?"
  • Colin Bennett: "Protecting privacy in the computer age is like trying to change a tire on a moving car."

Security Holes and Unexpected Attacks on Privacy

  • Security and privacy are intertwined.
  • Attackers target cloud-based email accounts to steal credentials.
  • Stolen credentials launch attacks against web applications.
  • In 2020, Threatpost reported that stolen credentials were used in 21% of web application attacks, exposing over 60 million personal records.

Common Points of Contact

  • Cloud infrastructure is shared by multiple applications from a single tenant and applications from multiple tenants.
  • Common points of concern include:
    • Shared storage infrastructure
    • Shared computational infrastructure
    • Shared communication infrastructure
  • Two main security weaknesses: Back doors and Side channels.

Back Doors

  • Special concern when using third-party systems.
  • A back door has been designed to allow an attacker unauthorized access.
  • Example: The SolarWinds attack in 2020.

Side Channels

  • Flaws in virtualization hardware can allow VMs to pass information.
  • Side channels can arise unexpectedly on shared infrastructure.
  • Examples:
    • Communicating by measuring processor usage.
    • Communicating by measuring network delays.

Example of a Side Channel: Meltdown

  • The Meltdown security vulnerability used a flaw in Intel processors.
  • Combined with a cache side-channel attack, Meltdown allowed programs to bypass checks and access all memory, including OS items.

Traditional Security Approach

  • In traditional IT, the IT staff handles all security.
  • They:
    • Assess requirements
    • Formulate policies
    • Choose implementations
    • Select security technologies and tools
    • Maintain confidentiality of policies and tools.

Security in a Cloud Environment

  • Tenants must:
    • Use provider-offered policies and configuration mechanisms
    • Learn to use provider-offered security tools
  • Provider interfaces:
    • Include many confusing details
    • Differ between providers
  • Small mistakes lead to security problems.
  • A 2019 Verizon report indicated misconfiguration of storage systems caused significant data exposures.

Change in Philosophy

  • Old: Trust no outsiders.
  • New:
    • View the cloud provider as a partner
    • Share security policies and work with the provider
    • Report incidents to enable root cause analysis

Improved Security for Remote Access

  • Many employees and SaaS users work remotely.
  • Remote access may use unsecured networks (e.g., Wi-Fi).
  • A 2019 Gartner report noted VPNs alone may not be sufficient.
  • Suggested combining tools into a single service, termed Secure Access Service Edge (SASE).
  • By July 2023, HPE Aruba Networking stated SASE is a strategic imperative.

SASE

  • Pronounced "sassy"
  • Vaguely defined
  • Supported by vendors and adopted by some customers.
  • Moves security to the "edge" (remote user location).
  • Offers users:
    • Easier configuration
    • Fewer tools to manage
    • Lower cost potential