ABOUT THE AUTHOR


Gary Audin
Gary Audin is the President of Delphi, Inc. He has more than 40 years of computer, communications and security...
Read Full Bio >>
SHARE



Gary Audin | January 06, 2012 |

 
   

Cloud Security; A Study

Cloud Security; A Study German researchers find potential vulnerabilities.

German researchers find potential vulnerabilities.

A group of German researchers from Ruhr-University Bochum, NEC Europe, and Cologne University found holes in Amazon Web Services' (AWS) cloud architecture that allowed hackers to become administrators and then access user data, according to a paper published by the researchers. AWS was informed of the flaws and has fixed them.

The ongoing issue is that similar flaws may exist in other cloud architectures. Not only are public clouds at risk, those enterprises planning or operating private clouds are at risk as well. The potential danger for private cloud may be greater because of the dependence on cloud products that may not have the same level support as found at AWS.

The researches have published a paper, "All Your Clouds are Belong to us--Security Analysis of Cloud Management Interfaces". The paper was published by the Association of Computing Machinery (ACM). The paper focuses on Amazon's EC2 and S3 control interfaces; it does not analyze other cloud services or products. It discussed the attacks performed, the vulnerability analysis, attack prerequisites, attack rationale, and assessment. The paper even provides an attack scenario for Twitter that demonstrates that many high profile and popular applications that use AWS were susceptible to these attacks. The paper has a long list of useful references to support its conclusions.

The paper is highly technical in content. For most readers of NoJitter, the content may appear to be beyond their interest. However, since many enterprises have moved applications to the cloud or are considering a private cloud, the content and conclusions are very relevant.

When I performed my survey of cloud based communications providers, Cloud/Hosted Communications Providers: Survey Results, I located more than one provider that uses the Amazon EC2 as their platform to deliver their communications features and functions. This means that the enterprise should be aware of this class of vulnerabilities and discuss them with their cloud communications service provider.

The researchers used a technique called "signature wrapping". XML signature wrapping is defined at WS-Attacks.org as follows:

"Web services offer designers enormous flexibility when it comes to employing integrity features. Usually in order to guarantee message integrity, certain predefined parts of the SOAP [Simple Object Oriented Protocol] message get signed. Let's assume that a web service client sends a signed message to the receiving web service. Ideally any malicious modification of the signed data is detected by the receiving web service unless the attacker is able to break the signature algorithm itself. However, when executing a XML Signature Wrapping attack, an attacker is able to change the content of the signed part without invalidating the signature."

The control interfaces can then be compromised with signature wrapping. The result of signature wrapping is that the party that has gained administrative access can create, change, and delete user data while appearing to be legitimate.

A second form of attack was analyzed that deals with browser based front ends. Cross Site Scripting (XSS) allows an attacker to perform an automated attack that steals user names and passwords from AWS.

This paper demonstrates that as complexity increases in the cloud so do vulnerabilities. Control interfaces have become very attractive targets. Fortunately, the paper also provides a number of countermeasures that can be employed by the cloud architects, designers and operators, whether the cloud is public or private.



COMMENTS




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Did you know you can style comments using HTML tags and upload your avatar photo? To upload your avatar photo, first complete your Disqus profile. Once your profile is complete, you may add your avatar photo. (Hide this hint)
Enterprise Connect Tour 2012
In response to the booming demand for SIP Trunks—and for information about SIP Trunks—Enterprise Connect is launching a four-city “road show” on this vital topic.
May 22: San Francisco
June 6: Chicago
June 27: New York
Enterprise Connect 2012 Roundup
Read blog posts and watch videos captured live at the industry's leading event, and catch up on all the post-show analysis too.
Enterprise Connect Webinar
In this webinar, you will learn how to make sense of the array of Hosted PBX offerings and home in on the key elements to look for in an enterprise-grade hosted solution. .
Enterprise Connect Orlando 2013
Enterprise Connect Orlando 2013 takes place March 18-21, 2013 at the Gaylord Palms Hotel. We'll be opening registration shortly. Stay tuned!
Upcoming Events
May 23, 2012
The explosion of new hosted and cloud communications offerings can be confounding. With the potential for cost savings and productivity enhancements, adopting the right Hosted PBX solution can make a ...
May 9, 2012
SIP Trunking and unified communications strategies are important components of enterprise telecommunication strategies. Enterprise Session Border Controllers (E-SBCs) play a critical role in maximizin...
April 25, 2012
Unified Communications (UC) is becoming mainstream in the enterprise, enabling real-time, collaborative communications via a host of new media and applications. But this transition will bring challeng...

Sign up to the No Jitter email newsletters

  • Catch up with the blogs, features and columns from No Jitter, the online community for the IP communications industry. Each Thursday, we'll send you a synopsis of the high-impact articles, podcasts and other material posted to No Jitter that week, with links for quick access.

  • A quick hit of original analysis by the experts who bring you Enterprise Connect, the leading event in Enterprise Communications & Collaboration. Each Wednesday, this enewsletter delivers to your email box a thought-provoking, objective take on the latest news and trends in the industry.

Your email address is required for membership. For details about the user information, please read the UBM Privacy Statement

As an added benefit, would you like to receive relevant 3rd party offers about new products/services and discounted offers via email? Yes

* = Required Field