Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

4/28/2020
08:05 AM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

New Startup Accurics Tackles Cloud Infrastructure Security

Accurics offers a free product to prevent "drift" between infrastructure defined through code and infrastructure running in the cloud.

Cloud security startup Accurics emerged from stealth today to tackle the challenges of securing cloud infrastructure throughout the DevOps life cycle. Accurics has raised $5 million in funding from investors including ClearSky, WestWave Capital, Firebolt Ventures, and Secure Octane.

The company is also releasing a free version of its platform, which aims to minimize "drift" between infrastructure defined through code and infrastructure computing running in the cloud. As organizations adopt new technologies like containers and serverless, cloud infrastructure is becoming increasingly immutable, and infrastructure is rarely modified after it's deployed. If something needs to be modified after deployment, new infrastructure has to be provisioned.

Broad and fast adoption of cloud technologies is driving innovation, says Accurics co-founder and CEO Sachin Aggarwal, but it introduces new challenges in protecting more complex cloud stacks.

Security issues in cloud deployments are often ignored because finding and fixing problems is expensive and complicated. Security teams grapple with multiple management interfaces, driving the risk of manual errors. Hybrid and multicloud deployments can worsen the problem.

As cloud deployments increase, so do issues with consistency. Technologies such as Docker, Terraform, Kubernetes, and OpenFaaS manage infrastructure through code and reduce manual errors, but they make it difficult to maintain governance across the cloud stack. Then there is cloud drift: In environments where change is constant, little is locked down. Privileged users can make infrastructure changes in production, but even legitimate changes can be risky.

"What happens is once cloud is provisioned, there's a tendency for highly privileged users to go and make changes in the cloud," Aggarwal tells Dark Reading. "That could be a good change or a bad change." A drift from the original configuration could indicate an employee needed to make a change in production and didn't have time to redeploy a new cloud version. It could also indicate an attacker is moving laterally throughout the environment.

Accurics aims to protect the full cloud-native stack throughout the DevOps life cycle, from when it's defined in code through the life cycle of infrastructure employed in production. Its platform scans code such as Terraform, Kubernetes YAML, Dockerfile, and OpenFaaS YAML to detect and remediate misconfigurations, policy violations, and potential breach paths before cloud infrastructure is provisioned. It also monitors infrastructure deployed across AWS, Azure, and Google Cloud Platform to alert to changes in production that could introduce security drift.

"The idea is to provide enough data to a customer [showing] something has changed and moved from its original state," Aggarwal explains. Once Accurics detects a change, it conducts an analysis to see whether it should be embedded into the code base or rolled back if it's bad. Over time, it's meant to eliminate drift and protect the cloud stack by reconciling changes to the cloud infrastructure that could introduce risk through the baseline defined through code.

"It's becoming evident that people are using or relying on automation more than on manual processes," he continues. 

In addition to monitoring for, and responding to, risky changes in production, Accurics scans the infrastructure as code for violations of common compliance and security practices, such as SOC 2, GDPR, PCI, HIPAA, ISO, CIS Benchmark, and AWS best practices. This is an area in which Paolo Montini, LendingClub's chief data officer and head of cyber risk management, found Accurics helpful.

LendingClub is a digital online marketplace built to connect borrowers and investors, and its position as a financial technology company forces it to juggle innovation, cybersecurity, and compliance. The company has been running since 2006 – a long time for a fintech firm – and its tech stack is "huge," with some 500 to 600 internal applications, Montini says. Over the years of developing, patching, and maintaining new and legacy systems, a situation where something is broken somewhere will arise. The challenge, he says, is finding and fixing the problems.

"On one side, as a tech company, we need to be agile – to move fast and move quickly – so we are looking for a solution that can deploy a new product, new services, and new systems supporting our operations in a quick and easy way," Montini explains. "At the same time, this usually introduces more risk. We need to be sure that even though we're agile and move quickly with deployments, we do this in a secure way."

LendingClub was looking for a product that would help the company balance agility and security. Montini liked that Accurics aligned with LendingClub's priority for security by design and checked for different policies, regulations, and frameworks before deployment. What's more, he adds, the platform accounts for human error that can lead to misconfiguration.

"You're always going to be dependent on human beings at the end of the day, and the human factor unfortunately introduces unpredictability and introduces mistakes," he adds. Combined with the need for agility and innovation, the likelihood of misconfiguration increases. When LendingClub ran Accurics for the first time, it detected misconfigurations despite IT execs' insistence that everything in production had been reviewed, and they had a process to track it.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's featured story: "5 Ways to Prove Security's Worth in the Age of COVID-19"

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
dthankachan
50%
50%
dthankachan,
User Rank: Author
4/28/2020 | 11:53:42 AM
Exciting company
Great use case and truly novel. Solid post.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14180
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are...
CVE-2020-14177
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from versio...
CVE-2020-14179
PUBLISHED: 2020-09-21
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from...
CVE-2020-25789
PUBLISHED: 2020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
CVE-2020-25790
PUBLISHED: 2020-09-19
** DISPUTED ** Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes the significance of this report because "admins are considered trustworthy"; however, the behavior "contradicts our secu...