ABOUT THE AUTHOR


Dave Michels
SHARE



Dave Michels | April 19, 2010 |

 
   

The Dark Side of the Cloud

The Dark Side of the Cloud

A major SIP attack launched from Amazon's EC2 cloud raises questions about cloud security.



A major SIP attack launched from Amazon's EC2 cloud raises questions about cloud security.

The Amazon Elastic Compute Cloud (EC2) service is a poster child of the cloud revolution. Making massively scalable resources available without significant capital investment is a revolutionary concept that's ideal for bursty businesses such as Intuit's TurboTax. Telephony related firms such as Twilio and Ribbit rely on Amazon's services to instantly expand as their customers and projects require.

EC2 is a web infrastructure service that provides instant application-ready infrastructure that charges by usage instead of capacity. According to the EC2 website, "Amazon EC2 reduces the time required to obtain and boot new server instances to minutes, allowing you to quickly scale capacity, both up and down, as your computing requirements change."

The elasticity and scalability associated with EC2 were unheard of just a few years ago, and are still astounding. But what happens when those resources are used for evil instead of good?

Last week, a major SIP attack was launched from the EC2 cloud. It was a brute force attack that searched for open SIP ports in order to unrelentingly pound on phone systems searching for valid credentials.

Brute force attacks such as these are not uncommon--and sometimes are actually intended or act as a denial of service attack (DoS). But this is the era of the cloud, and "massively scalable" applies to attacks as well. One blogger reported the attack was on track to consume 6-10 GBs of traffic in one day on his WAN.

What Happened
Amazon Web Services (AWS) offers what's known as Infrastructure as a Service (IaaS) and is just one form of cloud computing. Though AWS is rather small in Amazon's portfolio, it is experiencing rapid growth and could conceivably overtake its e-commerce business in the future. Amazon's IaaS offering includes highly scalable virtual servers, storage, and networking services available on-demand without a contract and charged with a pay-as-you-use model. It allows organizations (and individuals) to develop core applications and capabilities without having to build, fund, and manage the capital equipment and physical aspects of a data center. Numerous success stories exist. Consider Netflix, which is experiencing a major shift in business model from physical DVD rental to real-time video streaming. Neflix selected Amazon's EC2 service for infrastructure rather than build-out a data center.

Last week, a number of telecom administrators noticed a major attack on their systems. Administrators started discussing over Twitter and VoIP groups a development that was to become a three-day attack. The widespread assault was coming from Amazon EC2 at an amazing rate.

SIP attacks are not new, but it is clear that cloud technology brings a new level of capability, capacity, and anonymity to the security problem. All it takes to unlock Internet services capable of mass destruction is a credit card.

It appears the intent of the attack was only to scan for valid SIP credentials. A valid SIP registration can be sold, used for toll-fraud, used to masquerade as the victim, or as a means to bypass surveillance such as wiretapping.

There was no indication the attack specifically targeted particular users or phone systems--rather it likely hit Internet sites scanning for UDP access on port 5060. Asterisk systems log such attempts visibly, and the Asterisk community of users reached out to each other. In particular, administrators Fred Posner and Stuart Sheldon independently blogged their observations and reported the matter to Amazon. Posner blogged: "The [brute force attack] complaints mentioned this weekend show an excessive amount of traffic; with some providers claiming 6GB of traffic dedicated to such attacks. Since we ourselves received an attack from an Amazon hosted server, we also reported and complained to the Amazon NOC/Abuse depts."



COMMENTS




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Did you know you can style comments using HTML tags and upload your avatar photo? To upload your avatar photo, first complete your Disqus profile. Once your profile is complete, you may add your avatar photo. (Hide this hint)

Sign up to the No Jitter email newsletters

  • Catch up with the blogs, features and columns from No Jitter, the online community for the IP communications industry. Each Thursday, we'll send you a synopsis of the high-impact articles, podcasts and other material posted to No Jitter that week, with links for quick access.

  • A quick hit of original analysis by the experts who bring you Enterprise Connect, the leading event in Enterprise Communications & Collaboration. Each Wednesday, this enewsletter delivers to your email box a thought-provoking, objective take on the latest news and trends in the industry.

Your email address is required for membership. For details about the user information, please read the UBM Privacy Statement

As an added benefit, would you like to receive relevant 3rd party offers about new products/services and discounted offers via email? Yes

* = Required Field
Enterprise Connect Orlando 2012
Enterprise Connect is proud to announce the following industry leaders will deliver keynote addresses at Enterprise Connect Orlando:
--Steven J. Bandrowczak, Vice President & General Manager, Avaya Networking
--OJ Winge, Senior VP/GM,Video & Collaboration, Cisco
--Kirk Koenigsbauer, Corporate VP, Office Business Group, Microsoft
--Alistair Rennie, GM, Lotus Software and Collaboration Solutions, IBM Software Group
Enterprise Connect Webinars
Wednesday, Nov. 30, 2 PM EST/11 AM PST

This presentation reviews best practices and tools for implementing data center clouds, including how to pin-point and resolve problems, and minimize cost while maximizing performance and usability.
Virtual Enterprise Connect
This in-depth Virtual Event will feature detailed presentations by technology experts who can help you plan your Lync-based UC migration and get the most out of all that Lync has to offer..
Enterprise Connect Orlando 2012
The Enterprise Connect conference program has been published! Our confernce is designed with one over-riding objective: To help you make the best decisions as you migrate your enterprise communications and collaboration.
Trending Now
Upcoming Events
February 15, 2012
For employees away from the office—whether on the go, at a remote location, or telecommuting from home—success depends on connecting the right people with the right information anywhere to a...
February 1, 2012
Have your video implementation projects fallen short of your expectations in user satisfaction or utilization? Reaping the benefits depends on not only on selecting the technology, but on careful plan...
January 18, 2012
As your enterprise moves into its Unified Communications migration, you’ll need to meet short-, medium- and long-term goals that provide investment protection, return on investment, and real bus...