Perimeter
11/6/2013
04:22 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Prototype Encrypts Data Before Shipping It To The Cloud

'CloudCapsule' shields file contents from the OS, malware, and the cloud provider

[UPDATED with more details, 11/9/13]

Researchers at Georgia Tech have built a prototype that encrypts files before they are sent to the cloud for storage.

The so-called "CloudCapsule" system can be used with cloud storage services, such as Dropbox and Google Drive, for locking down files prior to their storage in the cloud and for accessing them without a proxy. The technology can be used for desktops, laptops, and mobile devices, but the researchers initially have built a prototype for just mobile devices -- specifically, iOS.

"We thought its greatest utility would be in the mobile space," given the explosion in BYOD, says Paul Royal, associate director of the Georgia Tech Information Security Center (GTISC), where the prototype was created. "This lets us combine the process isolation [feature] present in mobile OSes with a seamless and transparent way of encrypting data you want to place into the cloud."

It's the classic conundrum with the cloud: balancing utility with security. According to a new report published today by GTISC, corporate information stored in the cloud is typically secured solely with what the cloud storage provider offers. And encrypting data in the cloud via private-key encryption typically makes the cloud less useful, the report says.

In the desktop scenario, CloudCapsule basically uses a virtual machine instance that lets a user from the same machine go into encrypted mode and access encrypted files stored in the cloud. The operating system and malware have no "knowledge" of the data, according to GTISC, nor can the cloud provider read the files.

The mobile version, meanwhile, uses the process isolation feature in the mobile OS, GTISC's Royal says.

"CloudCapsule is an interesting approach and from the details available ... it seems specific to DHS, which may not be ideal for other users. A potential issue that enterprises might encounter is in the deployment," says Paige Leidig, senior vice president at CipherCloud, a cloud security firm.

Leidig says CloudCapsule would be difficult to scale compared with a single gateway model -- the approach CipherCloud takes -- because it's deployed on endpoints. "The other potential problem for the endpoint approach is key management -- if the user loses the keys, they would need to be revoked and replaced, which adds more complexity, especially for large enterprises with hundreds of thousands of users," Leidig said an email interview.

But searching encrypted information remains problematic. GTISC researchers also have been working on techniques for "searchable encryption" so users can more easily find their protected data and files in the cloud. "We are trying to design types of encryption that support ... performance requirements" of real-world users, GTISC's Royal says. "Consider a person who needs to encrypt data before it goes into the cloud, but would still like to do basic keyword searches over that data. That's something we've been working on at GTISC."

Striking a balance between securing the data and indexing or searching it is complicated, he says. "There are going to be fundamental tradeoffs between security and efficiency," he says. "In some cases, there's a desire not to introduce significant overhead, so, for example, in some cases, we are turning the problem on its head and asking a person who would use this in the real world what they consider acceptable performance."

[The cyberespionage gang out of China who recently hacked into media outlet networks is now using Dropbox and WordPress in its attacks rather than via traditional email phishing attacks and server compromise. See Dropbox, WordPress Used As Cloud Cover In New APT Attacks .]

Georgia Tech researchers also have built an email encryption prototype called "Very Good Privacy," a more user-friendly option than the existing Pretty Good Privacy email encryption tool. Very Good Privacy software sits atop the user interface and supports data encryption in texting/messaging apps such as email.

The tool intercepts and encrypts the text as it's typed in, before it gets to the email service. "Plain text never gets entered into an application," Royal says. But the look and feel of the process remains unchanged for the user, so it's transparent, he says.

Royal says VGP and PGP are actually complementary: unlike PGP, VGP does not use key exchange, for example.

The full Georgia Tech Emerging Cyber Threats Report for 2014 is available here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7407
Published: 2014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-3675
Published: 2014-10-22
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

CVE-2014-3676
Published: 2014-10-22
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

CVE-2014-3677
Published: 2014-10-22
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

CVE-2014-3828
Published: 2014-10-22
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.