Perimeter
3/9/2011
10:24 AM
Adrian Lane
Adrian Lane
Commentary
50%
50%

Database Lockdown In The Cloud

In the cloud, we turn things around a bit and focus on data security rather than the database container

In this post, I'll describe the data-centric security life cycle. This approach is in contrast to many existing database security models, where the focus of the efforts is on securing the database container. This turns things around a bit and focuses on data security.

Most database security programs focus on patching and configuration of the database in order to protect infrastructure from vulnerabilities. Access controls limit data access depending on user roles and credentials. This model works well when we have a static database infrastructure and can rely on a set of services to fortify security.

But with cloud services, some of the basic infrastructure and trust relationships we have come to rely on are not available or require different deployment to work properly. For example, snapshots and machine images are designed to be recovered quickly, but the cloud does not inherently differentiate good from bad, meaning both intended and rogue instances can be booted and serve content. If you rely on your SAN or tape archival systems to encrypt data at rest, then you need to compensate for the lack of that built-in feature when moving to the cloud.

The goal is to reorient your security program to protect the information, minimizing reliance on security provided by the database, network, platform or places where it's stored. Since we don't necessarily know what the infrastructure is, where it is located, or who has access, we need to account for data security as data moves into and through the cloud. Domain 5 of the CSA Security Guidance (PDF) has a nice picture that illustrates the data centric security process. We define five phases or states: Definition, Storage, Use, Archival and Destruction.

As data moves from one phase to another, we apply specific protections that are appropriate to that phase. To start the process, we define data security measures as we discover data in, or move data to, the cloud. As data is stored, it's encrypted by the database or application, with access controls and rights management governing retrieval. Applications build in logical controls for the retrieval of information and rely on activity monitoring and rights management to enforce security policies. Use of DLP and content monitoring governs whether data can be moved, and encryption and application security controls secure authorized data exchanges. Finally, archival and destruction are managed by encryption, asset, and key management services to secure images that could reside on cheap storage in perpetuity.

Before I go into detail on each of these states, I need to quickly discuss why this is different and, hopefully, why it is more appropriate to cloud environments.

Each cloud delivery model (SaaS, PaaS, IaaS) has different security challenges. Log files in a multitenant IaaS or PaaS environment are not always available from your provider because they contain information from other users as well as your own. So not only are you unable to review the logs, they usually contain sensitive information. For SaaS we can't encrypt data prior to putting it in the cloud as we break the application. That means you are reliant on the provider to secure files and archives and to police their administrators.

In a nutshell, you don't really know who has access to your data or have the ability to audit the providers security controls. The data-centric security model is intended to wrap the data in a protective layer, reducing exposure and reliance on infrastructure security.

In the next post, I'll cover the definition and storage phases, and discuss specific technologies that are applied to secure data within that phase.

Adrian Lane is an analyst/CTO with Securosis LLC, an independent security consulting practice. Special to Dark Reading. Adrian Lane is a Security Strategist and brings over 25 years of industry experience to the Securosis team, much of it at the executive level. Adrian specializes in database security, data security, and secure software development. With experience at Ingres, Oracle, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0196
Published: 2015-06-29
CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVE-2015-0545
Published: 2015-06-29
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-1900
Published: 2015-06-29
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.

CVE-2014-4768
Published: 2015-06-28
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode.

CVE-2014-6198
Published: 2015-06-28
Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attackers to hijack the authentication of arbitrary users.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report