Skip the navigation
)
News

Researchers find "massive" security flaws in cloud architectures

By Tim Greene
October 26, 2011 11:24 AM ET

Network World - German researchers say they found flaws in Amazon Web Services that they believe exist in many cloud architectures and enable attackers to gain administrative rights and to gain access to all user data.

While the researchers say they have told AWS about the security holes and AWS has fixed them, they believe the same types of attacks would be effective against other cloud services, "since the relevant Web service standards make performance and security incompatible."

A research team at Ruhr University Bochum used a variety of XML signature-wrapping attacks to gain administrative access of customer accounts, then create new instances of the customer's cloud, add images and delete them. In a separate exploit, the researchers used cross-site scripting attacks against the open-source, private-cloud software framework Eucalyptus.

MORE FLAWS: Amazon Web Services receives critical gov't certification

They also found the Amazon service to be susceptible to cross-site scripting attacks.

"It's not only a problem of Amazon's," says Juraj Somorovsky, one of the researchers. "These are general attacks. Public clouds are not so secure as they seem to be. These problems could be found in other cloud frameworks also."

Somorovsky says the researchers are working on a high-performance libraries that can be used with XML security to eliminate the vulnerability that was exploited with the XML signaturewrapping attacks. They will be ready sometime next year. Signature-wrapping attacks re-use validAmazon Web Services acknowledged it worked with the Ruhr University team to correct the problems they found. "...[N]o customers have been impacted," a spokesperson for AWS said in an email. "It is important to note that this potential vulnerability involved a very small percentage of all authenticated AWS API calls that use non-SSL endpoints and was not a potentially widespread vulnerability as has been reported."

Public cloud security: Mission impossible

AWS has posted a list of best practices that, if followed, would have protected customers from the attacks the Ruhr University team devised as well as other attacks. These are:

Only utilize the SSL-secured / HTTPS endpoint for any AWS service and ensure that your client utilities perform proper peer certificate validation. A very small percentage of all authenticated AWS API calls use non-SSL endpoints, and AWS intends to deprecate non-SSL API endpoints in the future.

Enable and use Multi-Factor Authentication (MFA) for AWS Management Console access.

Create Identity and Access Management (IAM) accounts that have limited roles and responsibilities, restricting access to only those resources specifically needed by those accounts.

Limit API access and interaction further by source IP, utilizing IAM source IP policy restrictions.

Regularly rotate AWS credentials, including Secret Keys, X.509 certificates, and Keypairs.

When utilizing the AWS Management Console, minimize or avoid interaction with other websites and follow safe Internet browsing practices, much as you should for banking or similarly important / critical online activities.

AWS customers should also give consideration to utilizing API access mechanisms other than SOAP, such as REST / Query.

Originally published on www.networkworld.com. Click here to read the original story.
Reprinted with permission from NetworkWorld.com. Story copyright 2012 Network World, Inc. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Cloud Computing White Papers
Finding the right cloud solutions for your organization
HP is driving the evolution of what we call the Instant-On Enterprise. It is an enterprise that embeds technology into everything it does...
Seven Priorities for Integrated Network Management - How HP Intelligent Management Center Delivers an Enterprise-class Solution
This white paper describes the major requirements for network management solutions to help the organizations become more profitable, efficient and reliable.

Intel and the...
Building Cloud-Optimized Data Center Networks white paper
Enterprises are turning to the Cloud to improve business agility, reduce expenses and accelerate business innovation. Cloud computing redefines the way IT assets...
Converged Storage: Utility Storage - The Ideal Platform for Virtual and Cloud Computing
Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also...
The Best Way to Build a Cloud -- HP CloudSystem Matrix and HP 3PAR Utility Storage provide solid, flexible foundation
Learn how HP CloudSystem Matrix and HP 3PAR Utility Storage provide a solid, flexible foundation for your cloud environment.

Intel and the Intel logo...
All Cloud Computing White Papers
Cloud Computing Webcasts
Unlock the Value of Cloud Computing with Workload Automation
Learn how to get the most from your cloud investment in our on-demand webinar from BMC and InformationWeek. You'll hear how integrating the...
Get the Most from Your Cloud Investment
Learn how to get the most from your cloud investment in our on-demand webinar from BMC and InformationWeek. You'll hear how integrating the...
Must have Tools and Techniques to Optimize the Sales Pipeline and Win more Deals
In this webcast, Vantage Point Performance's Michelle Vazzana will reveal how to coach your reps to better performing pipelines.
Sales Effectiveness in the New Sales Paradigm - A Webcast Featuring the Latest Forrester Research Study
In this webcast produced by the Sales Management Association (SMA), Forrester's Scott Santucci will explore the new sales paradigm and discuss how businesses...
Virtualization 101: Launching into Cloud Computing for SMBs
In the next year at least half of all small to mid- businesses will move to virtualization. Will yours be among them? The...
All Cloud Computing Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs