Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

1/18/2017
10:30 AM
Bill Kleyman
Bill Kleyman
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
Google+
RSS
E-Mail vvv
50%
50%

Cloud Security & IoT: A Look At What Lies Ahead

In the brave new world of cloud, security teams must be as agile as possible. This means leveraging proactive monitoring tools, locking down access points, and forecasting requirements

In the cloud – just as in the physical world – the evolving threat dynamic is moving beyond services, users, and applications to new attack targets in the Internet of Things ranging from CCTV installations, refrigerators – and possibly even drones. This new paradigm will present many challenges for organizations; consider this, Gartner recently predicted that by 2018, 25% of corporate data traffic will flow directly from mobile devices to the cloud, bypassing enterprise security controls.

So, what does this mean for the modern organization? Where should companies be focusing their efforts when working to secure their cloud and IT environments? The new digital challenge is that our configurations and workloads will be at risk, requiring out-of-the-box thinking and new security strategies. Here are four examples of what I mean:

Greater Focus on Endpoints and Users
We all remember the good old days of traditional AV. We’re pretty far beyond that now with the next-generation of new endpoint protection (EPP) and endpoint detection and response (EDR) systems. This will require advanced capabilities around sandboxing, cloud integration, and intelligent threat analytics that offer new ways to secure users, your mobile environment, and how data interacts with endpoints.

Companies like Trend Micro, CrowdStrike, CarbonBlack, and others fall into the EPP/EDR market. They’ve introduced a new generation of endpoint security that integrates with overall managed security solutions and utilize machine-learning capabilities and security artificial intelligence to look into malformed files, deep metadata analytics, and even powerful offline capabilities. This helps mobile users leveraging a variety of devices to be secure and still consume digital content from their organizations.

Security Automation and Orchestration
Automated IT systems you can incorporate into your security architectures will be a big business in 2017 and beyond. With security workflow automation, you can intelligently control massive settings and environment changes encompassing multiple data centers and global locations. In other words, instead of manual process and configurations, you can use automation tools to ensure you have the right security policies in place. The great impact here is that you can have heterogeneous security systems all automatically managed by a single system.

The other big automation security control factor revolves around users. Today, there are powerful user-control automation systems which can integrate with human resource and business processes. I often see organizations working with hundreds, sometimes thousands, of contacts. Managing user identities isn’t always easy – and many times it’s a very manual process. This needs to stop. Rogue accounts, lost users, misconfigured permissions, and forgotten access controls are ALL security holes. Today’s automation software tools allow organizations to onboard and offboard entire subsets of users. Plus, they will integrate with HR systems and even alert administrators as well as HR when new users are created or removed.

Internal Security Lifecycle Management
This falls into the manual category of security control. New tools around security event and information management (SIEM) give administrators a lot more control around their security ecosystem. Remember, it’s not just a firewall any longer. We have app firewalls, security analytics, network forensics and intelligence, and a lot of other tools helping keep our infrastructure secure. Aggregating logs and events is going to be critical to catch problems before they become major issues. Furthermore, you’ll be able to control updates, patches, and see which systems need to be updated. Even in large organizations, you can still find old Cisco or Juniper devices which haven’t patched in ages. How much do you know about what’s going in your cloud ecosystem?

Testing, cloud-to-cloud security, and file watermarking
Cloud and virtualization have made it much easier to test out new types of security systems. If you’re planning on new cloud deployments or are working with an expanding data footprint, it’s critical for you to look at new technologies aimed at new wave IT initiatives that help with cloud vulnerability management, compliance, visibility, app security, and even penetration testing. There are other technologies that will interrogate the requesting source, and help further lock down data being sent down via authentication, watermarking, and advanced access rights management. The point is that emerging security technologies are specifically taking aim at new types of cloud and physical threats. Don’t be afraid to test out these systems or work with a partner to help guide the way.

At the end of the day, my biggest piece of advice is for organizations to remain agile with your cloud security. This means leveraging proactive monitoring tools, locking down access points and forecasting requirements. No environment will ever be 100% safe. Your goal should be to create as much visibility into your environment you can, and have contingency plans for as many security events as possible.

Related Content:

 

  Bill Kleyman brings more than 15 years of experience to his role as Executive Vice President of Digital Solutions at Switch. Using the latest innovations, such as AI, machine learning, data center design, DevOps, cloud and advanced technologies, he delivers solutions ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
RDP Bug Takes New Approach to Host Compromise
Kelly Sheridan, Staff Editor, Dark Reading,  7/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14248
PUBLISHED: 2019-07-24
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
CVE-2019-14249
PUBLISHED: 2019-07-24
dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHT_GROUP), as demonstrated by dwarfdump.
CVE-2019-14250
PUBLISHED: 2019-07-24
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
CVE-2019-14247
PUBLISHED: 2019-07-24
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
CVE-2019-2873
PUBLISHED: 2019-07-23
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox...