Thursday, March 21, 2013

Cloud Views

Special guest on episode 103 was Andi Mann.

Cloud View started out as a news letter. Later it moved to twitter as #cloudview with cloud security as the topic. Cloud View is hosted on http://smartenterpriseexchange.com and they have a dozen episodes available on YouTube.

Where is the firewall in a cloud environment?

Earlier you knew from where people were accessing your data since nobody outside your firewall had access. Nowadays you need to know who is accessing your data because access is not restricted by network segments anymore.

We have several layers of identity:
  • username/password
  • 2 factor
  • multiple factors
After all the breaks ins at major sites (PSN, iCkiud9,) Many think that username is not good enough anymore, but it's still the only credentials you need for 99% of the web servers on the internet.

Who is responsible for security?
- Everybody?
- The board?

News from the RSA conference.


Audio: Cloud Virtualization Security Roundtable, episode 103
http://www.virtualizationpractice.com/resources/virtualization-security-podcast/
http://www.talkshoe.com/talkshoe/web/talkCast.jsp?masterId=34217&cmd=t

Friday, February 1, 2013

Security monitoring in a cloud environment

You have a level of visibility in a traditional enterprise that you lose in a public cloud. Today the solution seems to be be host based IDS (agent inside your VMs).

How can an IAAS end user be able to do non host based IDS without the cloud provider having to do it for you? As a tenant you're limited in what you can do and you don't normally have access to the physical network.

Collecting logs from all your systems in your part of the IAAS cloud can also give you some insight that can make you feel ok.

Most of the SAAS providers do however not provide any ability to gather logs related to specific cloud applications. People are accessing SAAS cloud applications simultaneously from all over the world. 70% of the SAAS applications do not utilize SAML for authentication. Typically it's the SAAS providers that have been around the longest that implement SAML such as Google, Amazon and Salesforce.

For IAAS you can implement controls in a reasonable way, but most of the SAAS and PAAS clouds have very limited capabilities to withdrawing logs.

If you have a requirement stating that you need real time monitoring it would need the ability to withdraw logs in real time.

These topics are being discussed in episode 99 of the Cloud Security Virtualization Roundtable.


Audio: Virtualization Security Roundtable, episode 99
http://www.virtualizationpractice.com/resources/virtualization-security-podcast/
http://www.talkshoe.com/talkshoe/web/talkCast.jsp?masterId=34217&cmd=t

Tuesday, December 18, 2012

REST API security

Special guest in episode 98 is George Reese who is Founder and CTO of enStratus. Topic this time is API security, and especially for the REST API. One of the things that are commonly used for communications between systems in the cloud is the REST API.

For many systems it seems that security is an afterthought, and that's the case also for the REST API. It is using SSL, but it's having several weakness points including username/password for system<->system communications, no transaction verification, etc. He has also written a utilities that are freely available on github that can be used to test different implementations of the REST API. He has used it to uncover several bugs that may give permissions to do operations without having the needed credentials.

For more info, check out episode 98 of Cloud Virtualization Security Roundtable.

Audio: Virtualization Security Roundtable, episode 98

http://www.virtualizationpractice.com/resources/virtualization-security-podcast/
http://www.talkshoe.com/talkshoe/web/talkCast.jsp?masterId=34217&cmd=t


Wednesday, December 12, 2012

Cloud Security: Aligning the business in 12 steps

The special guest on episode 97 was Omar Khawaja who has a 12 step program for moving to the cloud.

There are also a discussions on these topics:

  • IT departments can't sit there in their cathedral, they have to respond to the needs of their users - in a secure way.
  • Employees' expectations from IT in the enterprise has changed during the past 5 years
  • Telling people not to do something that they can easily do will not stop them doing it. Corporate policy has not prevented users from storing company internal information in  Google docs or on their iPhone.
  • User experience matters. You want productive users and you do not want strict control from the IT department prevent them from doing their job efficiently.
  • People just want to get their job done and don't understand the impact of wrongdoing.
  • Security policies have to change.

The 12 steps that Omar presents is also available here:
http://www.slideshare.net/ok4/cloud-security-a-businesscentric-approach-in-in-12-steps





Texiwill has also written an article about this roundtable discussion here: http://www.virtualizationpractice.com/12-step-program-to-enter-the-cloud-19397/