Attacks/Breaches
4/25/2013
07:29 AM
Dark Reading
Dark Reading
Quick Hits
50%
50%

How Cybercriminals Attack The Cloud

What attacks are most likely against cloud computing environments? Here's a look -- and some advice

[Excerpted from "How Cybercriminals Attack the Cloud," a new report posted this week on Dark Reading's Cloud Security Tech Center.]

The adoption of cloud-based computing shows no signs of slowing. Indeed, cloud services are expanding at an incredible rate across all sectors of the economy, with the market for public cloud services expected to grow to $210 billion by 2016, according to Gartner.

And it's no wonder: The cloud is a compelling proposition for businesses and government agencies alike, offering easy access to shared, elastically allocated computing resources. The model creates savings on capital expenditures and reduces the running costs of operating a network, allowing enterprises to focus more on their core operations instead of IT.

However, what makes cloud computing so attractive to businesses -- the sharing of resources to achieve economies of scale -- also makes the model attractive to cybercriminals.

Cloud services concentrate so much data in one place that they become very attractive targets, justifying a large investment in a hacker's time and resources. Recent researchby the European Network and Information Securit Agency has led it to warn, "The proliferation of cloud computing and the sheer concentration of users and data on rather few logical locations are definitely an attractive target for future attacks."

What types of attacks are most common against cloud environments? Volumetric attacks aim to overwhelm a network's infrastructure with bandwidth-consuming

traffic or resource-sapping requests.

State-exhaustion attacks, such as TCP SYN flood and idle session attacks, abuse the stateful nature of TCP to exhaust resources in servers, load balancers and firewalls. Several cloud providers saw their firewalls fail last year during DDoS attacks.

Techniques such as amplification magnify the amount of bandwidth that can be used to target a potential victim. Suppose an attacker is able to generate 100 Mbps of traffic with his botnet. This may inconvenience or block access to a small site, but it would not impact a well-protected cloud hosted site or service.

The attacker could go to a botnet herder to rent access to its botnet, but this could get expensive. The attacker also could use manual and automated coordination techniques similar to those used by the Anonymous group, which notifies fellow "anons" of the time to start an attack so that it's big enough to affect the victim's resources.

By using an amplification technique called DNS reflection, an attacker's botnet can send out a DNS query of about 60 bytes to an open recursive DNS resolver that will gener-ate a response message sent to the victim of up to 4,000 bytes, increasing the amount of attack traffic by a factor of more than 60. The DNS protocol is ideal for this type of attack because queries can be sent with a spoofed source address -- using User Datagram Protocol, which doesn't require a handshake -- and a DNS response is significantly larger than the query itself.

To learn more about the different types of attacks made on cloud computing environments -- and what you can do about them -- download the free report.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4774
Published: 2015-05-25
Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.

CVE-2014-4778
Published: 2015-05-25
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

CVE-2014-6190
Published: 2015-05-25
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.

CVE-2014-6192
Published: 2015-05-25
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-8146
Published: 2015-05-25
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (hea...

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.