Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

May 12, 2014

Keystone Security and Architecture Review: Keith Newstadt

Pertinent notes from the Keystone Security and Architecture Review at the OpenStack Summit in Atlanta, 2014.

Keystone is the gatekeeper for OpenStack and allows authentication to all OpenStack services. 


Keystone:



  • Is the single point of authentication for all OpenStack services
  • Offers SSO to OpenStack services
  • Is the common API layer on top of various authentication protocols
  • Reduces exposure of credentials

Basically:
  • User authenticates by sending credentials --> Keystone
  • Keystone sends a token once authenticated --> User
  • Keystone shares token --> OpenStack service
  • Service validates identity of user via token
Users identity credentials are sent to the LDAP server that then confirms the user ID and associated roles. Services can also authenticate with Keystone and act on a user's behalf. This presents different problems that can be mitigated by securing cached credentials, limiting the scope of this delegation, expiring tokens and direct management of Keystone and OpenStack.

Of course, as with any software, Keystone has an attack surface that opens it up to spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privileges. Newstadt suggests "Supply chain management":

Download --> build --> deploy --> patch
The key is the last step to ensure that the software deployed is free of vulnerabilities.

There has also been considerable interest in using industry standards including SAML, OpenID and OAUTH because they provide SSO, improved integration, control over user credentials and a unified user experience.


Newstadt's parting thoughts:
Protect credentials everywhere. Think about how they can be attacked.Securing Keystone is an ongoing process.Share findings and ideas. This is how we'll improve Keystone and security in OpenStack.

OpenStack Session: Security for Private Clouds (Bryan Payne)

Private clouds need security too, not just public clouds. Attack vectors are no longer limited to edge devices. "Found" USB keys loaded with malware can open up the cloud environment to attack from within an organization not to mention poorly designed security controls and policies. The bottom line is that no one wants a bot net running in their data center!

The way around this is to apply security principles to the environment. Logically separate specific use environments; make use of VPNs

Also, understanding the environment is key. Basically:
Orchestration + Known hardware = Secure infrastructure
[Applying security best practices at the outset and consistently throughout the life cycle of the environment with known hardware can help service providers (IT or actual CSPs) to protect the environment.]

Payne identified some of the biggest threats to clouds:
API endpoints
Web dashboard
Information leakage*
VM breakout*
Hardware sharing
Default images
Secondary attacks

*Easily the biggest threats according to Payne.

Information leakage can be mitigated by using TLS to protect communications between API endpoints, the web dashboard, Log feeds, AD/LDAP and external storage. VM breakouts can be basically prevented by using mandatory access controls, removing unnecessary privileges from the physical node and by hardening the build, the compiler and physical nodes.

Other attacks of concern include control plane compromise (mitigated by layered security via bi-directional firewalling, limiting data propagation, unique passwords everywhere) and upstream vulnerabilities (mitigated by security audits, aggressive security update policies).

Ultimately, cloud needs to be secure at least as everything else in the enterprise and deserves our attention. That said, I don't think we should despair because of complexity; rather, we've been through this before as web browsing, e-commerce and virtualization came into their own over the past 20 years.

Oct 15, 2012

Live Blog -- Cloud Launch: Peter Coffee

Peter Coffee kicking off this afternoon by NOT talking about cloud directly... And talking about social media and email. More importantly, Coffee said that Canadian brands can be global brands today because of social media. As a measure of this theory, Facebook traffic has exploded whereas coporate website traffic has declined markedly. Google "Yourfavoritedomainname + sucks" and you'll find out exactly how much customers don't like an organisation.

A few thoughts from Coffee on social customers:
  • Prospective service providers seek public feedback
  • Buyers collaborate on competitor research
  • Customers tell the world when they're not happy
Companies need to react and adapt to this new competitive environment and push the customer satisfaction metric to the lowest possible level in the organisation.

Coffee also peered into the future by using a healthcare model that used event driven demand to shape the dlivery of services. He gave another example of using educational modeling by using instantaneous quizzing of students to determine whether the content is effective. This could be interesting because the nature of our demand for services has changed: service providers are being asked to provide services when desired. This is important for healthcare because on-demand healthcare is causing the congestion we see in emergency rooms and walk-in clinics.

IT departments, according to Coffee, do not adhere to the concept of social customers and are basically the opposite of social. Of course, this is the ultimate reason why cloud computing still faces adoption challenges in Canada and continues to do so, albeit to a lesser extent, in the US. How does IT adapt to this in order to become a purveyor of value instead of a consumer of capital?

Even though we haven't heard much about community clouds recently, Coffee brought up the concept of securing environments to the highest common level as a way of showing value to a given market segment and quoted Forrester as stating that multi-tennant architectures can be more secure than individual VMs. Luckily, he qualified this by saying transparency is the key to earning trust from customers. Trust is an important concept because cloud + security are not commonly understood yet even though AAA and the CIA triad are basic concepts that can be applied to cloud computing. Shock! Horror!

May 16, 2011

Shouldn't companies WANT to protect their assets?

Last week, CNET reported on the White House's proposed cyber security law "[that is] designed to force companies to do more to fend off cyberattacks".

The law seems to address shortcomings in critical infrastructure security moreso than private industry though there does appear to be language that requires the disclosure of security breaches by private companies. this approach, presumably, would provide consumers with information regarding a business' security policy and could affect the choices consumers make. This non-regulatory position adopted by the White House is interesting because as it echoes the Canadian Radio and Television Commission's (CRTC) position of letting market forces shape the industry.

Is a non-regulatory approach appropriate? Would the US Government randomly audit companies to determine their level of security? Would that be sufficient to force companies to do more to ensure security? Probably not, given the number of companies in t he US and the rate at which new vulnerabilities are discovered. Requiring companies to disclose breaches could work if market forces are adequately informed.

It will be interesting to see how this legislation is applied to the cloud and which of the parties, vendor or consumer, will be held accountable for maintaining appropriate levels of security given that most contracts currently put that burden squarely on the shoulders of consumers.

The fact that legislation is even required to force companies to maintain adequate cyber security systems begs the question: wouldn't companies WANT to protect their assets anyway?!

Apr 2, 2011

Takeaway #5 from Cloud Connect 2011 - Security schmecurity?

Security remains an important issue for cloud adopters. But to what extent is security truly preventing them from adopting cloud based services? Is it really that big of a deal?

Of course security is a real issue in IT; as a company doing business on the Internet, security is one of those things that, if you get it wrong, your business can be seriously hurt by the consequences. Security threats range in complexity but all have one thing in common: people are the main security threat, always have been, and always will be, through ignorance, accidental misconfiguration, or malicious behavior.

So why, then, is security in the cloud such a big deal? Governance. There is a lack of visibility into the security of cloud based services generally due to the nature of the contracts and the remedies offered as well as the lack of regulation whether it be industry, government, or some combination of the two.  In Canada, privacy law requires that the owner of private information (the organization(s) to whom the individual has provided the information) ensure that the information is held in confidence by whatever vendor/service provider makes legal use of that information. This means that the Government has mandated industry to regulate itself by making the organizations liable for any disclosure of that information including that by a third party such as a cloud services provider.

At its core, this is an issue of risk tolerance; how tolerant is an organization to risk. The answer to this question is not complete without considering the tolerance to the magnitude of the impact to the organization (say $ for argument's sake). Basically, The greater the risk and the greater the impact, the more reluctant organizations will be. This is the basis for a basic risk response matrix.
(There are obviously more complex risk tolerance matrices, but it is sufficient for the purposes of this posting. Accept=make use of cloud based services as is. Mitigate=take measures to offset risks such as including remedies in contracts. Avoid=don't make use of cloud based services.)

There are those, even some at Cloud Connect 2011, that are claiming that security is a non issue. Unfortunately, most organizations are still worried about it and beg to differ. Countless polls prove this point. That said, this shouldn't be anything new to us. This very same argument/concern/issue has been dealt with before. At least twice: during the rise of e-commerce as we know it and again around the increase in outsourcing. Why is cloud any different? Let's figure out a way to secure our services, federate them, govern them, and then let's move on!

OK, so I oversimplified. The point is, there is too much discussion and not enough action. SaaS vendors have caught on. Their contracts address the issue of security. So, if customers want it, why aren't more vendors providing it, and why are yet others claiming that it's not a big deal?

Mar 7, 2011

GRC/security in cloud computing

Jinesh just echoed some thoughts I've been incubating regarding security and risk: GRC/security boils down to risk tolerance. If you have a high tolerance to risk, then there is no problem using AWS; if you have low tolerance to risk, involve your security team early and often and make them a part of the decision making process.

Comment from the audience: "My legal wants to redline the AWS contract but I don't think Amazon would go for that." According to Jinesh, Amazon has a legal team that is available to address legal concerns. I will have to look into this given the work that the team at QMUL did on cloud based services contracts.

May 31, 2010

Cloud Security Alliance - Canada Chapter

I've decided that I'm going to start working on building the Cloud Security Alliance (CSA) - Canada Chapter. There seems to be interest so I thought I would write up a quick entry to see if anyone was interested in joining the Canadian chapter.

The CSA is a fledgling organization dedicated to "promote the use of best practices for providing security within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing." As of this posting, there are 2 official chapters and 5 chapters in development. In addition, there are several working groups:
Group 1. Architecture and Framework
Group 2. Governance, Risk Management, Compliance, Audit, Physical, BCM, DR
Group 3. Legal and eDiscovery
Group 4. Portability & Interoperability and Application Security
Group 5. Identity and Access Mgt, Encryption & Key Mgt
Group 6. Data Center Operations and Incident Response
Group 7. Information Lifecycle Management & Storage
Group 8. Virtualization and Technology Compartmentalization
Editorial Group
Educational Working Group
Solution Provider Advisory Council

It's obvious to me that the questions of governance and security (issues important to me) are not going to go away by themselves. Nor should it be left solely to industry to develop competing views/models/tools - it's simply inefficient. It behooves us, the denizens of the industry, to help in those efforts.

Please let me know if you are interested in joining the CSA - Canada Chapter by sending your coordinates (name, company, title, email, phone) to pano(dot)xinos(at)gmail(dot)com.

[Edit: added working groups. --PX--]

May 14, 2010

Organizational Governance and Cloud Based Services

InformationWeek published a story on their site about how IT departments are 'losing ground' on cloud computing. The premise is that individuals in the organization are adopting cloud services with or without IT's knowledge and/or approval.

The article suggests that this is a security issue which, at the end of the day, it is. But, security is a part of information and organizational governance and, as such, this should be treated as a governance issue. If IT can't control usage of cloud services by the organization, is this a failure of IT or the organization? I can understand why someone would just use a credit card to get what they needed done sooner than later. However, this is no excuse for ignoring organizational business practice and compliance policies. In some organizations this would be grounds for dismissal.

Granted, IT departments can be slow. How, then, can IT help resolve this problem? How can IT be part of the solution? Clearly, employees need to be sensitized to the risks and issues surrounding their use of cloud based services in the organization and who better to do so than IT? Of course, this should not be taken to mean that IT should scare the bejeesus about of them, rather this should be an ooprtunity for IT to move closer to the employees and the business by seriously considering cloud based services and their impact on the organization, good or bad.

A great quote from the article: "Hello: it's 2010 and do you know where your data resides?"