AskAnAlien

Cloud Security
Securing Data in the Cloud: What's So Different?
AT&T Cybersecurity
Q5: How do you monitor cloud activity / usage / appropriateness?
Garrett Gross
One way is to look at it form a user level. i.e. "Why is my new helpdesk employee cloning databases and creating new users??"
Javvad Malik v2.0
By checking the monthly usage bills... :)
SPCoulson
as Javvad said - usage bills.
Javvad Malik v2.0
Although some provides are better at alerting than others.
Javvad Malik v2.0
It's not a consistent experience.
Garrett Gross
@J4vv4D You're right - Usage is actually a great indicator of compromise. Hijacked machines are usually used for high volume/quick return attacks (bitcoin mining, hosting 2nd stage malware, etc)
Martin Hepworth
push it down to the business heads. But then I work for a tech company...also work with finance to monitor the billls
SPCoulson
unusual admin access at unusual times of the day - but its identifying that : "what does unusual look like"
Javvad Malik v2.0
Yep - Rich Mogul wrote a good piece on his experience when he accidentally left AWS access keys on github https://securosis.co...
Javvad Malik v2.0
@maxsec A fortunate position indeed!
Javvad Malik v2.0
@SPCoulson Baselining behvaiour has never been easy. But a good way to find statistical outliers
Garrett Gross
@SPCoulson Which leaves a lot of folks scratching their heads. While they may be security pros, they aren't necessarily cloud experts.
SPCoulson
@J4vv4D but how many orgs have the tech to do this 'right' ?
SPCoulson
@garretthgross exactly - masters of none.
Javvad Malik v2.0
@SPCoulson If they have tech, they lack skills or resources... unfortunately.
Garrett Gross
@SPCoulson I think the number is irrelevant. Percentage-wise? Thats the operative figure IMO
SPCoulson
@J4vv4D very true - ISO27 - resources ?
Martin Hepworth
tech isn;t the be-all and end-all, Just a tool that helps
Javvad Malik v2.0
@maxsec And a fool with a tool ... is still a fool!
Martin Hepworth
yes jav-mate, but policy ;-)
John Furrier
software using unstructured data is huge; Spark in memory has implications here
Garrett Gross
@J4vv4D I thought I told you to not call me that in public? ;)
Javvad Malik v2.0
@maxsec haha - please don't undo my years of therapy! :)
SPCoulson
@J4vv4D Is that a Mr T quote ? A fool with a tool is still a fool ?!
AT&T Cybersecurity
Q2: What criteria are most important when evaluating cloud providers?
Garrett Gross
IMHO, to make sure your resource needs are met without sacrificing visibility into the environment
SPCoulson
A2 @alienvault Confidentiality, Integrity and Availability of your data (ISO27001) plus speed of access.
Jitender Arora
it depends the type of business trying to evaluate cloud. E.g. Regulated business is looking to consider control framework, online retail business will look at resilience and capacity etc
Javvad Malik v2.0
Understood - regulation aside, are there min req's you'd recommend?
SPCoulson
A2 @alienvault compliance to your data standards, location of data (UK, US, DE), resilience of solution, uptime
Jitender Arora
Law firms will look at security, resilience and cost.. It varies depending on industry sector. One constant is Cost :-)
Martin Hepworth
Another vote for, 27001 helps. AS does up front and available privacy policies etc
SPCoulson
Cost versus Risk - the best balancing act in the world.
Javvad Malik v2.0
haha can't avoid costs for sure. Do you think security is in top considerations?
SPCoulson
The issue with compliance is that it isnt security and security isnt secure.
Jitender Arora
regulation aside - Cost, Resilience, Flexible costing model, Security, Elasticity etc
Garrett Gross
You can also ask yourself "does managing my cloud environment get in the way of managing my environment?"
SPCoulson
@J4vv4D no, but it is in there. Cost, ROI, Speed, Resilience, Security. and possibly in that order
Jitender Arora
If a cloud provider offers standard certification and follows industry best practice, it's a bonus and an important consideration
SPCoulson
They may have the certifcates but how well implemented are they and to what scope. Some ISPs exclude their DCs.
Javvad Malik v2.0
@SPCoulson @jee2uu ah the dreaded scope - indeed an important oversight.
Jitender Arora
One important consideration is how quickly I can get my environment and data back if things go wrong... Because it will go wrong
Jitender Arora
@SPCoulson Certification scope is always an important factor if you want to consider it as a selection criteria. Too much oversight need negates clouds business case. Requirement define relevance of consideration factors
SPCoulson
The vendor can get crafty with their scope too - have experienced it.
AT&T Cybersecurity
Q4: How are you identifying vulnerabilities in the cloud? #secchat
Garrett Gross
This is especially tricky since you arent really supposed to be vuln testing in the cloud. Example - from AWS http://amzn.to/1eJfW...
SPCoulson
A4 I'd love to say "using @alienvault " of course, but that would be cheesy (and untrue).
Javvad Malik v2.0
I'd ask secondary q, are cloud vulns different from on-prem vulns?
Kate Brew
it is a tricky question!!!
SPCoulson
@J4vv4D nope a hole is a hole irrelevant of where it is.
Javvad Malik v2.0
@SPCoulson Cheesy, like Titanic - untrue... no :)
Jitender Arora
@J4vv4D No cloud vulnerabilities are not different from on premise. It's about control around fixing them. You can do a lot at application stack level but not a lot at Infra level on a cost effective cloud model. You get what you paid for ;-)
Garrett Gross
A way around that, though, is intelligent parsing of the logs (cloudtrail, ELB, S3, etc). You can detect loads of activity without getting the internet police on you. Only problem with doing that yourself is - have you SEEN cloud logs??
SPCoulson
ps. wrong hashtag !
Javvad Malik v2.0
@garretthgross I once saw cloud logs... I was legally blind for 3 days after that!
Javvad Malik v2.0
Cool - so original q then - how do you find vulns in your cloud? :D
Kate Brew
@garretthgross how are cloud logs different from regular log files?
Jitender Arora
@J4vv4D Good conversation folks. It's time to get back to the day job. Have fun
SPCoulson
@J4vv4D Great question actually - some clouds have shared infrastructure so comes with it's own set of problems.
Javvad Malik v2.0
Thanks for your contributions @jee2uu
SPCoulson
@J4vv4D divining rods and good luck ! plus whatever tin the vendor is reselling and hope it's at the right price !
Martin Hepworth
In the cloud infrastructure or the stuff we're running on top of it?
Martin Hepworth
or even with the SaaS type apps we use??? all diff as to how we can test, and have time to!