Introduction
Cloud enables elasticity allowing users to dynamically avail resources based on the needs and only pay for what they use. Voila! a great invention for the digital world.
Allowing only authenticated services to scale up or down and ease of ramping up or down with immediate visibility to the authorized admins. The authentication, authorization, firewalls, audit and transaction visibility are crucial steps in cloud security.
Though we technically own the servers, but as we know mostly we don't have physical control on the servers, leading to additional care. Cloud security it is shared responsibility of the customer and the cloud service provider - CSP.
Today we shall discuss about cloud infrastructure and some of key elements in towards its security.
Region and Availability Zones
Uptime and availability are one of the two important aspects of cloud security. Regions are different geographic locations the service providers maintain their infrastructure. For each region there can be more than one Availability Zones - AZ. For example a cloud service provider could support two regions India and Australia, and in each of the regions there could multiple AZs for instance in India two AZs in Mumbai but different parts.
Each of the AZs are self contained and independent. Each having different power providers, separate network confirmations and so on. Making in reliable, if any one AZs downtime will not affect the other AZ.
As user we can take advantage of this, and could configure our application to the nearest region of our users in order to reduce latency. Also load balance either through active/active or active/standby configuration. Providing the flexibility to switch when there is an issue or overload requests, enabling high availability.
Each region cost may different of the services and not all regions would provide all the services. Also while selecting the region the compliance regulations needs to be considered.
Virtual Private Cloud (VPC)
In a public cloud space we can create a private isolated network known as VPC. It is just like the private cloud having both public and private subnets. The private does not exposing the IP addresses as public address and can be accessible only through restricted means. VPC is essentially at the network layer as a IAAS service.
An analogy, in a IT parks we have different organizations having different facilities such as parks, auditorium but the work area is private only employees or restricted person can enter. Here private area is similar to VPC, we have major control over it and as well its considered to be secure. Separation is security opportunity, eg the web servers can be accessed from anywhere but the database should be accessed only by the backend application servers.
Multiple subnets could be created in the single VPC, definitely within the range of IP addresses the VPC is created with. The subnet could be either private or public, this draws the line for the servers in these network not to access from public network.
VPC Gateway endpoints, allows connecting multiple VPCs keeping the data private without using the internet.
Virtual LAN (VLAN) is as like LAN way of partitioning the network as the group of servers connected can access each other without hitting internet. Here the partitioning occurs in the layer two of OSI model.
Virtual Private Network (VPN) uses encryption on top of the public network, making it secure and avoiding man-in-middle attacks.
Firewall
Security groups are acting as a “firewall” on instances. Using security group, we can control both the incoming and outgoing traffic. They are stateful, which means any traffic in is allowed to go out, can go back in. Supports only allow rules, means traffic cannot be explicitly blocked, rather only allow configured traffic in.
NACLs are acting as a “firewall” at the subnet level. We can associate a single NACL to multiple subnets, but only one NACL can be assigned a subnet.
These stateless as the inbound and outbound rules apply for all traffic. For example, if the output traffic is allowed our request would reach out, but if expect a response, sorry it would need to have the outbound rules specified. Supports all both allow and deny rules for both inbound and outbound traffic. Here we can specify only reference a CIDR range (no hostname).
Additionally we have services provided by CSPs to protect at different layers of OSI, such as WAF - web application firewall secures at layer 7, Network firewall protects at layer - 4 and so on. This could enhance the security blocking unusual API calls, not allowing or allowing access from certain geographic locations, track and report attempts made to access critical data.
IAM Policies
In cloud access to resources is governed by policies and their permissions centrally with audit enabled by default. Each policy can be attached to the entity, user, user group or a role.
There are two basic policies either we call it identity based policy or resource based policy. Under identity based policy permissions are given to the user, user group or role. And for the resource based policy these policies define who can access and what activities they are allowed to perform.
Stating access will be granted only when both the policies allow, if either is denied access will not be granted. By default all the access would be denied, explicit allow only grants the access. But if there is explicit deny it will get higher precedence and access will be denied.
Granular access policies can be set such as allow or disallow certain IP addresses, data and time, group, geographic locations, etc.
Managing Secrets
Applications that use API Keys, encryption keys or credentials should not have it hard coded. Cloud provides services to handle the secrets elegantly. Secrets are encrypted at rest and in transit.
Secrets management protects and manages the access to the applications and services. IAM policies makes sure one has access to secrets.
Central Logging
Monitoring and audit is crucial phase of cybersecurity. Cloud provides framework and services to manage and enable monitoring granular level.
IAM access, policy change, infrastructure changes are some of the common tasks where the logging is default enabled and aggregated in the central location. But these would not be sufficient, cloud provides APIs to write more and customized logs based on the user's requirement.
These centralized logs can be further used for further inspecting and analysis, as well integrate with any SEIM Solution. Intuitive reports could be created from these logs.
Cloud Access Security Broker (CASB)
Each cloud service provider provides a set of tools enabling the security tools. But there could be gaps or the requirements could not be matched by them. And as the data resides with the cloud service provider maintaining security and adhering security policies becomes important. In such scenarios on premises or third party offerings - CASB come to a rescue, fill in the gaps and compliment cloud security services. This is placed between the cloud consumer and cloud provider.
CASB provides security software as a service addressing cloud service risks, enforce security policy, threat protection, data security, comply with regulations. This can be implemented as software running either locally or in cloud. CASB operates on four primary characteristics:
- Visibility: Visibility on the entire processes running on cloud and if it authorized. Validation and avoiding misconfigurations.
- Compliance: Following organization own or mandated policies, like HIPAA, PCI
- Threat prevention: Allow only authenticated and authorized users to the granular level, including multi level approvals or multi factor authentication.
- Data security: Protect and encrypt the sensitive data at rest and in transit. Ensure APIs is secure, where the attackers can exploit the interfaces.
CASB along with next-generation secure-web gateways (SWGs) monitoring and management of web APIs and user/entity behaviour analytics (UEBA) provide the capability to deliver static and dynamic access to the management.
CASB is evolving into on huge service known as Secure Access Service Edge (SASE) architecture. SASE combines multiple security and networking technologies to provide comprehensive web and cloud security. Security Service Edge (SSE) is the convergence of multiple cloud-based security services as part of a Secure Access Service Edge (SASE) architecture.
Security Awareness
Structural awareness solutions help manage risk and apply protections to systems and data.
- Cloud compliance and best practices: Visualization and continual assessment of the environment, including the ability to enforce known good standards
- Instance and container visibility: Monitoring and protection of containers through their life cycle
- Virtual private network: Secure access to applications running in a VPC for remote employees
- Secure data: Encryption and key management solutions to protect data and meet regulatory compliance standards
- Vulnerability assessment and management: Visibility into the attack surface to discover and resolve security issues
- Software composition analysis: Management and security for open-source licenses
- Operational intelligence: Aggregation and correlation for the analysis of data across security, performance, and availability
- DevSecOps: Automated and continuous process management for continual integration and delivery of secure applications
- Cyber risk management: Prioritized insight into the threats, vulnerabilities, and impacts of cloud assets
- Container security: Minimal or hardened operating system that is specifically designed to run containers. Running similar security demand services on a same host, limit the scope of intrusion.
- Backup: Maintaining backups ensuring availability by following the legal requirements such as holding information for 7 years, data should saved our of country.
- Permissions: Authentication and authorization at granular level and constant audit to ensure there is no break.
Situational awareness solutions detect security events and are capable of responding, recovering, and helping with continual improvement.
- Firewalls and proxies: Provide fine-grained inspection of traffic for potential threats at both the network and application levels
- Endpoint detection and response: Protect endpoints, including cloud workloads from zero-day and other attacks
- Intrusion detection systems: Monitor networks and workloads for security events
- Backup and restoration: Protect data from errors, failures, and accidental deletion
- Disaster recovery: Provides additional flexibility to quickly recover from a disaster, ensuring that cloud workloads are available
- Security information and event management: Ingests, correlates, and prioritizes events for deeper visibility into anomalous behavior and threat mitigation
- Workload isolation: Provides dynamic security control for microservices, containers, and other workloads
References and Credits
https://www.cloudcodes.com/blog/wp-content/uploads/2020/05/cloud-security-for-dummies.png'
https://www.cloudflare.com/en-in/learning/cloud/what-is-a-virtual-private-cloud/
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/cloud-security-controls/