Cloud
3/12/2014
04:05 PM
Bill Kleyman
Bill Kleyman
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
Google+
RSS
E-Mail

Your Cloud Was Breached. Now What?

You're not happy. You just experienced a breach. Here's how to keep calm and secure your cloud.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Bill Kleyman
50%
50%
Bill Kleyman,
User Rank: Apprentice
3/14/2014 | 11:16:26 AM
Re: Leave the intruder alone for a little while longer?
@Charlie - I was just waiting for someone to give me a solid use-case. The advanced nature of today's modern infrastructure allows us to do great things with technology. Virtualization, cloud, and a distributed platform optimizes data flow and application delivery.

However, all of this presents new types of targets. So, we have a few scenarios here...

There are a number of different types of cloud-based attacks that can and do happen. These include port attacks, DDoS, application-specific threats, database attacks and much more.

So the answer really depends on the attack and who it's against. Let's look at this example - According to a recent Arbor Networks report, DDoS attacks originally targeted Spamhaus on 16th March, 2013. Spamhaus engaged the services of CloudFlare (http://blog.cloudflare.com/) who were able to mitigate the initial attacks successfully. The attacks then escalated between 19th and 21st March exhausting the capabilities of CloudFlare. The report goes on to say that the attacks also moved on to target next-hop addresses at IX's around the world (AMS-IX, DEC-IC, HK-IX, Equinix and LINX) causing congestion and a perceived Internet slow down in some geographies. ISPs around the world have worked to deploy filters to mitigate the impact of the attacks.

In this case, it was a scramble to halt this type of congestion and attack.

In other cases, very specific attacks may target a service or an application. During this attack a malicious piece of software or user continue to run and operate on the system. In these cases you still need to isolate the application or data point to identify and quantify the ramifications of the attack. If it's a VM, snapshotting it will allow you to see present-state metrics around the attack. Of course, governance and compliance play a big role as well. 

Basically, there will be cases where a security professional will want to regain control, monitor, and remediate a potential attack. 
Bill Kleyman
50%
50%
Bill Kleyman,
User Rank: Apprentice
3/14/2014 | 10:56:51 AM
Re: Thanks for great post.
I second that :) Much appreciated!
Charlie Babcock
50%
50%
Charlie Babcock,
User Rank: Moderator
3/13/2014 | 12:34:24 PM
Leave the intruder alone for a little while longer?
Bill, your description of needing to be prepared to preserve the server and storage as is for forensic analysis is extremely interesting. Nice job of that. But tell me, doesn't that assume the damage caused by the breach is a fait accompli and over? What if an intruder or active malware is still at work? Do you have to allow it to continue as you go about snapshotting and recording? That would be hard to do.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
3/13/2014 | 11:21:43 AM
Re: Thanks for great post.
thanks for the complement for Bill, Eddiemayan. What did you like about the post? Tell us what you learned, or what you will do differently after reading it.
Eddie Mayan
50%
50%
Eddie Mayan,
User Rank: Apprentice
3/13/2014 | 8:03:26 AM
Thanks for great post.
Thanks for great post.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0485
Published: 2014-09-02
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

CVE-2014-3861
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

CVE-2014-3862
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

CVE-2014-5076
Published: 2014-09-02
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVE-2014-5136
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.