Sunday, January 22, 2017

Cloud Security and Risk Part 2

In Part 1 we discussed Risk, Security and Cloud Computing at a high level. Having been part of design teams as a contributor as well as project manager to include security and assessment team management over the last few years; I still find the same repeatable security concerns and issues directed at the Cloud. So here is my take of a few of them with respect to a Private Cloud environment. Remember a private cloud can be housed within the infrastructure of a service provider (more cost effective for you) or within your own in house network. Some of these thoughts can be translated into the Public Cloud environments, although some additional controls may be in order.

It is a given that security of data is a major concern for any entity considering a move toward a Cloud Computing environment. How will my data be kept secured from unauthorized access, modification or distribution can be a nagging concern.Data loss, modification, or mis-placement will affect the entire organizational structure up to and possibly including shareholder value.

Major cloud providers therefore are going to great lengths these days to ensure that there are essential mitigative controls and response processes in place, in the event of a security breach, which in most instances will include their client either actively or passively with updates in a pre-defined time-frame.

Some of these updates can include, alerting, centralized logging, smart monitoring (not just signature based events) observing traffic to and from the client location into their private cloud environment. They will typically have processes are in place whereby all these systems are auditable and are aligned to established industry standards and aligned with emergency change management protocols.

One thing that I like to look at is a service provider’s security policy (which is typically based off the ISO 27000 series) as well as an independent auditors SAS 70 report. The SAS 70 report for example will identify and test control in place to secure the environments both physical and logical, test access control privileges, test backup and recovery as well as a data protection at rest to name a few. One thing that is of importance here is getting clarification as to how data in motion is secured going into the cloud from the client's site as well as how the CSP provisions user rights and manage administrative access.

However before transferring data to the cloud some things you should ask yourself are, have you identified classified and defined ownership of your data before considering a move to the cloud?

Once there is some structure and organization with regard to data classification and ownership you have taken a step to securing your data and assigned some control as you move to a private cloud. This combined with a CSP’s stringent controls implemented, can ensure that anyone accessing your data is identified, tracked and most importantly..auditable.

Always remember your CSP wants your business and in this light will ensure that they endeavour to make you happy by the manner with which they manage your data as well as with the service they provide within this sphere.

In almost all of my articles I have mentioned Service Level Agreements. As Cloud Services mature so will the SLAs implemented to protect your data. This will allow you to move your data without concern for lock in, incompatibility between CSPs or data loss; an assurance that will become common showing that CSPs are targeting all major areas of concern to earn your business and ensure the confidentiality, integrity and availability of your data.

In closing I wanted to share one question that I have been asked frequently, the one about hypervisor security and the potential of rootkit injection within this area; an attack which can possibly allow data exfiltration without a timely alert.

While there is always the possibility of a crack occurring in any one system, be assured that researchers and practitioners are constantly looking for ways to ensure the security of data.

With that said, I have seen the successful implementation of the Altor software firewall which for the VMware folks can be integrated via VMsafe application programming interfaces.

According to the manufacturer the firewall can see traffic as it moves through the hypervisor between virtual machines (VM) on the same physical host. I think this is a good baseline and will allow us to track and create auditable records for any notification of an unauthorised or suspicious event occurring.

For more on this software hypervisor firewall and the hypervisor environments it can impact, see the VGW Series by Juniper Networks.

Reference

http://www.juniper.net/us/en/products-services/software/security/vgw-series/

Virtualization and the Cloud Computing Ecosystem

Last week at the 7th International Cloud Expo in Santa Clara, I sat on a panel discussing virtualization and the cloud. As a follow on to my contribution, it is my intention to expand on the position of virtualization and the cloud ecosystem.

It is generally accepted that the concept of cloud computing or, at least the amalgamation of services that infer the cloud ecosystem, lends to the premise of improvements in managing deployed services. This due to an assumed increase in efficiencies resulting from the sharing of hardware resources at one end of the spectrum.

According to NIST[1] There are five essential characteristics of Cloud Computing viz: 

-On-demand self-service

-Broad network access

-Resource pooling

-Rapid elasticity

-Measured Service

Of these cloud-computing attributes, virtualization can be said to possess all except the ability to implement services through the utilization of Internet Technologies[2]

It is a known fact that the dynamic consolidation of application workloads through virtualization will increase server utilization. This in turn will reduce demands on power and system resources, especially within large-scale server clusters deployment that can support cloud based application services. 

As we know with any system the surface area an attacker can target for attack increases with the introduction of a virtualization layer. This in turn will increase the vulnerability factor of the system for, in addition to the guest operating system being at risk, the hypervisor and VMM will also be prone to attack.

For clarification any virtualized system will include a new layer of software - the virtual machine monitor(VMM).Within the virtualized environment, current virtualization research assuming that the virtualized environment (VMM) has knowledge of the software being virtualized (the guest OS) however there is no verification of whether the memory layout of the running VM matches the symbol tables[3]

This can cause a problem especially with the increase of "intelligent malware systems" and the potential for false positives or worse yet no alarms or responses that will ensure cause for concern. In turn such a weakness can extend into the cloud ecosystem with the potential for malicious outcomes.

Worth mention at this juncture is research completed by Steinberg and Kauer [4] and their secure virtualization hardware: NOVA.

NOVA takes an extreme microkernel-like approach to virtualization by moving most functionality to user level. Because our entire system adheres to the principle of least privilege, we achieve a trusted computing base that is at least an order of magnitude smaller than that of other full virtualization environments.[4] 

We all need to bear in mind that in today's rapidly evolving technology ecosystem, cost savings in any environment only goes so far to keep an enterprise competitive. Thus virtualization whilst important in any IT environment, is not the only path to cloud computing.

An argument to support a cloud computing ecosystem that minimises virtualized arguments can be drawn from a study conducted by Wang and Ng [5] which stated that "unstable network characteristics are caused by virtualization and processor sharing on server hosts."

In this climate, what virtualization can accomplish for any enterprise, after the realization of server virtualization cost savings is capped (savings from capital and power expenses, server sprawl reduction,utilization rates); will be to provide that most strategic path to a cloud computing build-out - be it a private or public cloud ecosystem for an enterprise.

So with the importance of virtualization within, as well as its impact on cloud computing, can we mitigate these security concerns as more enterprises move toward cloud adoption? 

Cloud computing incorporates different dimensions of implementation as it can traverse a path beyond that driven solely by server virtualization. For instance some cloud services can be obtained at various levels within the IT stack, e.g. SaaS. So then, how do we ramp up and mitigate or manage risk that will arise in these settings?

This can lead one to consider the point that for cloud-computing, security applies to two layers in the software stack.[3]

According to Yuecel Karabulut [6] cloud security architectures,need to be designed on the premise that this ecosystem is dynamic, he stated that "as new threats emerge, code considered secure today may not be secure tomorrow."

Regardless of platform infrastructure, Karabulut went on to say that "the cloud still runs pieces of software;therefore a good start toward security within the cloud ecosystem, is to work on ensuring that software security is aligned to a defined SDLC process and that this process is adhered to from requirements analysis to testing."[6]

He further postulated that encryption within the cloud can improve trust and security parameters. A cloud vendor managing a customers encrypted data will only have access to metadata and not the customers encrypted content.

This can lead to a win-win situation for both vendors and customers as this will encourage scalability from no need for specialised software, there will be a reduction in processor load, and users will be freed from knowing the identities, and by extension the public keys, of individuals authorised for access.

As cloud computing incorporates aspects of web-services; another direction can be to understand the attack surfaces of Cloud applications and systems and reduce [6] or remove if possible vectors to known attack paths that will affect any one web-service and by extension a cloud-computing service.

In closing I wanted to touch on another study I recently reviewed. The researchers introduced

a new architecture for secure introspection the aim of which was to integrate discovery and integrity measurement of code and data starting from hardware state.[3] One purpose of this architecture was to address both the semantic gap present in virtual -machine introspection and the information gap specific to cloud computing[3] 
 


Source :Cloud Security is Not (Just) Virtualization Security pg 99 [3] 

This system in a nutshell proposed to integrate aspects of virtualization, secure introspection, known security metrics, known risks and flaws within this environment as well as those that can potentially exist within the cloud-computing environment.

In essense researchers Christodorescu, Sailer, Schales, Sgandurra and Zamboni has proposed an architecture which can mitigate and/or manage risk in a dynamic and responsive manner within the cloud-computing environment, as one of its functions.

References 

[1] csrc.nist.gov/groups/SNS/cloud-computing/cloud-def-v15.doc

[2] http://en.wikibooks.org/wiki/Internet_Technologies

[3] Cloud Security is Not (Just) Virtualization Security ACM 978-1-60558-784-4/09/11

[4]Steinberg, Kauer April '10: NOVA: A Micro-Hypervisor based Secure Virtualization Architecture

[5] Wang, Ng:The Impact of Virtualization on Network Performance of Amazon EC2 Data Center,5-10

[6] Yuecel Karabulut - Chief Security Advisor & Head of Security Strategy, SAP: 7th International Cloud Expo Santa Clara Ca. Nov 10

A Walk through the 7th international Sys-Con Cloud Expo

Last Wednesday I had the distinct honor of being part of one of Jeremy Geelan's Panel of Expert segment at the 7th annual Cloud Expo in Santa Clara. To be honest I when I got the email, despite the pleasure of being considered to present my trade, I was not too excited about visiting another series of booths and presentations that was more of the same.

Its been two years since I went to my last technology trade show, I know, I know, what was I thinking ? Right?!

By not participating in the deluge of suave marketing and sales pitches that comes around several times a year,with the "we have the answers to all your technology needs" chorus by devout technology vendors, I practically faced a tidal wave of withdrawal from this self imposed exile. What?

Arriving late, I braced myself for mass confusion and perhaps harried and annoyed staff. This stemming from experiences at other technology events. On arriving however and much to my surprise, I found the event well organised, with staff that was extremely courteous and knowledgeable.

There were also some world class researchers, technologists and presenters in the lineup and one member of staff even walked me to a venue without hesitance, when she noticed me staring down the breakout map in consternation.

Suffice it to say as I move into my new role at a Big Four firm, I will be blocking my calender for the 2011 series of Sys-Con Cloud Expos, at least for the breakout sessions.

Whilst I did not visit all sessions that were offered, some constrained by time others by choice, sessions that stood out were those by GoGrid, Unisys,Rackspace,Amazon & SAP. Of course as a technologist I expected more from Amazon; however SAP true to its reputation had a renowned researcher-its Chief Security Advisor/ Head of Security Strategy present an extremely engaging technical discussion on Cloud Security.

As a researcher of client solutions, I will be remiss if I don't mention one startup that really impressed me. This company I believe will emerge as a leader within the new technology space when the dust settles. It's name is Tilera and they are the producers of the manycore processor series; I actually made it to their booth on reference from a real-time traffic intelligence expert I ran into, whose primary aim at this Expo was to look at their systems.

Based on the stellar presentations I was able to attend by smaller firms, I found myself wanting to hear what the bigger players were doing. Unfortunately, at least from those of us on the observation deck, the two that I attended seemed unable to hook their anchor and appeared to be filling space with buzzwords and generic information. No, I will not name names...yet. But I will say that after one presentation from an established company that launched its cloud offering a while aback; 8 out of the 10 people I spoke to after were not very impressed. The other two were indifferent.

I must confess that I typically take great pains to avoid the cacophony of sales pitches, glossy pictures and the self-anointed experts, more so when they are plugging their version of a mass promoted product in a seemingly desperate attempt to claim a piece of the "gravy train" of the moment.

Over the years I find myself gravitating to the engineers and technicians who actually handle the products and know their merits and limitations from real world implementations - People I can actually learn something from, who don't repeat the brochure verbatim to me.

One presenter almost had me falling off my chair with his intensity and obviously mirror rehearsed "speech," another told me offhandedly ,"oh you represent the customers interest", well I do! Everyone is a customer at one point in time; and a customer always want the best deal for their money.

In these instances, should I dare infringe on their space as they regurgitate their well practised presentations?

Or as a technologist, should I obviate their omniscience and suggest solutions that are practical to any one customer's need, which in turn could then be implemented to ensure proper OPEX utilization?

Not I said the rabbit as he jumped down the hole.....Alice?

Governance, Risk Management and Compliance (GRC) and the Cloud

As we become more technology dependent, more so in today's "cloud"-driven environment, IT security needs to evolve from the traditional sense of digital security.

We should see the advent and acceptance of a more holistic, flexible and adaptive model of security that focuses more on managing information security, people and processes in a natural evolution from the traditional model of implementation, monitoring and updating.

According to Teubner and Feller [1] "Governance is understood as securing a responsible corporate management, having its roots in value-based management."

With regard to Risk Management, Marshall Krantz said it best:

"Faced with threats from all quarters - recession and credit crunch, heated global competition, continuing Sarbanes-Oxley pressures - companies are making intensive risk management a top priority "[2]

We can also assert that Compliance constraints aim to ensure that an enterprise satisfies all pertinent legal reporting responsibilities and regulatory transparency demands.

With technologies evolving as rapidly as they are, combined with complexities caused by:

1.The constant drumbeat of global integration

2.Possibility of vendor conflicts of interest

3.Increasing demands for transparency

4.Multinational or country specific regulations

5.and new organizational threats cropping up faster than measures for mitigation are implemented;

enterprises must take appropriate steps to integrate governance, risk management and compliance as part of their modus operandi. A main source of contention within IT governance, is the use of multiple vendors for IT resources, where the objectives of vendors may not necessarily align with that of an enterprise; this can lead to notable governance issues for an enterprise.

According to a SETLabs briefing [3] "Governance Risk and Compliance (GRC) is fast emerging as the next biggest business requirement that is most likely to ensconce itself in the psyche of enterprises."

The briefing also mentioned the concept of Integrated GRC. The aim of which is to improve collaboration between all identified stakeholder, as well as increase the level of GRC integration. This is turn will improve on legacy siloed GRC systems which has been shown to decrease transparency and agility in governance.

Its objective is directed at increasing market competitiveness, reducing risk and improving compliance.

From this we can gather that the traditionally accepted progression of GRC will also need to adapt and evolve; more so as enterprises engage more services within the sphere of cloud computing - in other words an adaptive approach to GRC.

It is understood that in terms of risk management, IT security etc, the board of directors holds ultimate responsibility when it comes to safeguarding enterprise assets. This does not mean that other individuals are exempt from responsibility, far from it, in fact there should be a top down approach to ownership and accountability when is comes to ensuring the safety of company assets.

Edward Humphreys [4] stated that "security incidents occurs because of flaws , gaps or vulnerabilities somewhere in management framework, chain of policy,direction and implementation."

As technologies evolve and cloud computing becomes more accepted and implemented one can question whether there will be a blurring of responsibilities between the technical and non technical aspects of information security management and by extension GRC.

Von Solms [4] made a statement a few years ago that "a separation between operational and compliance management of information security becomes essential." But will this work in today's environment, or do we need to adapt to evolving technologies that will span outside the traditional realm of GRC and IT Security Management?

My quest for an answer,at least relating to GRC and the cloud computing ecosystem led me to a company called Agiliance and a conversation with their CEO, Joe Fantuzzi about their Risk Vision OpenGRCTM platform. Accordingly, this

platform's foundation supports six integrated applications and over 100,000 controls via standards and regulatory content. It also allows a user the capability to create target reports, import and export files seamlessly,while preserving file structure; has SQL and web services APIs for I/O with any applications, databases, files and systems as well as gives a user access up-to-date laws and regulations with 100,000+ controls and sub-controls.

What caught my attention however was his explanation of their "Cloud Risk Management - RiskVision Cloud Risk Software Services."

This service made allowances for ensuring an accountable implementation of enterprise policy and security assessments within the cloud, as well as, implementing compliance and risk scores with incident management that measure and test enterprise risk, compliance posture, threat levels,vendor risk and policy conformity.

Fantuzzi also spoke about the company's vision for deployment into the cloud and defined their take on Cloud Risk Governance Stages,where he demonstrated their target assessment for both public and private cloud environments in terms of cloud adoption states of readiness, operations and audit.

From an observational viewpoint, its Cloud Risk Operational Monitoring portion appeared to be effectively positioned for application within the cloud ecosystem.

Walking thorough the product, Fantuzzi also demonstrated allowances for seemless functional operations within several virtual environments, with threat/vulnerabilities connectors that were aligned with ongoing technical and vulnerability checks.

One purpose was to ensure continuous compliance checks as well as maintain ongoing monitoring for potential attacks - zero day or otherwise.

He also mentioned an objective of this product is to provide a user with prioritized risk actions and a 360 view of risk posture. Important factors when is comes to ensuring proper governance and management of risk in our compliance driven environments.

I am certain that those of you familiar with NISTs Standards Acceleration to Jumpstart Cloud Adoption of Cloud Computing (SAJAAC), can see this product aligning and growing with SAJAAC as the cloud ecosystem evolves and possible see it as a good utility for both the public and private cloud environments in terms of a cloud step regarding GRC management.

References 

[1]Teubner, A. and Feller, T. 2008. Information Technology,Governance and Compliance Wirtschaftsinformatik. 50, 5 (2008), 400-406.

[2] Krantz, M. 2008. Survival in the Age of Risk http://www.cfo.com/article.cfm/11917608/1/c_2984351?f=related

[3] SETLabs Briefings Vol 6 No 3 2008.Pg 39

[4] Edward Humphreys :Information Security Management Standard: Compliance, governance and risk management. Elsevier Information Security Technical Report 13 (2008) 247-255

[5]Information Security Governance - Compliance Management vs operational management - S.H. (Basie) von Solms: Elsevier Computers and Security (2005) 24, 443-447