Lack of abuse detection allows cloud instances to be used like botnets
Some cloud providers don't detect attacks launched from their networks, researchers say
IDG News Service - Some cloud providers fail to detect and block malicious traffic originating from their networks, which provides cybercriminals with an opportunity to launch attacks in a botnet-like fashion, according to a report from Australian security consultancy firm Stratsec.
Researchers from Stratsec, a subsidiary of British defense and aerospace giant BAE Systems, reached this conclusion after performing a series of experiments on the infrastructure of five "common," but unnamed, cloud providers.
The experiments involved sending different types of malicious traffic from remotely controlled cloud instances (virtual machines) to a number of test servers running common services such as HTTP, FTP and SMTP.
In one test case, services running on a targeted server were accessible from the Internet, but the server was located in a typical network environment, behind a firewall and an IDS (intrusion detection system). The goal of this particular test was to see how the cloud provider would respond to the presence of outbound malicious traffic originating from its network.
In a different experiment, the targeted test server was set up inside a separate cloud instance from the same provider in order to test if the provider would detect malicious traffic sent over its own internal network.
A third experiment involved the targeted server running inside a cloud instance at a different cloud provider in order to test how that provider would deal with incoming malicious traffic.
The experiments involved sending malformed network packets and performing aggressive port scanning; sending malware to the victim host via a reverse shell; performing a denial of service attack against a Web server running on the targeted host, performing a brute-force FTP password cracking attack; launching SQL injection, cross-site scripting, path traversal and other attacks against popular Web applications running on the targeted host; and sending known exploit payloads to various services running on the host.
In one experiment, some types of malicious activity, like port scanning, were executed for 48 hours in order to see if a large traffic volume and longer attack duration would trigger a response from the cloud provider.
"The results of the experiment showed that no connections were reset or terminated when transmitting inbound and outbound malicious traffic, no alerts were raised to the owner of the accounts, and no restrictions were placed on the Cloud instances," Stratsec senior consultant Pedram Hayati said Monday in a blog post.
Based on these results, Hayati concluded that cybercriminals could easily create and use botnets that run on cloud instances.
Such botnets would be relatively easy to set up and administer if one learns the cloud provider's API (application programming interface), would take less time to build than traditional botnets because replicating cloud instances can be done very fast, would be more stable because cloud instances have a very good uptime, would be more effective because of the increased computing power and bandwidth available to the cloud instances and wouldn't cost much, Hayati said.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Seven Contact Center Trends You Can't Ignore Rapid changes are underway in the world of traditional contact centers. It starts with the disruptive nature of social media and mobile apps,...
- Top Ten Reasons Customers Choose Siemens Enterprise Communications to Help Transform their Business Trusted by over 75% of the Fortune 500, Siemens Enterprise Communications is the only vendor to provide the complete range of Voice, UCC...
- Amplify collective effort. Dramatically improve performance. Discover why now is the time to revisit the untapped potential of team performance and leverage team collaboration as a vital corporate asset.
- The Untapped Potential of Virtual Teams The results from a recent global research study show that while the vast majority of organizations rely on remote, distributed and mobile team...
- Modernizing Wireless Infrastructure for Today's Mobile and Data Driven Enterprise Find out some of the compelling drivers and unique challenges that the Georgia Dome had to address to prepare the stadium for a...
- 5 Ways to Keep the Heart of Your IT Beating Strong in 2013 Your IT investments should bring you some combination of results, relief, and reward. So how do you make sure your ongoing data center... All Networking White Papers | Webcasts
The old PacBell building at 140 New Montgomery Street, San Francisco, (@140nm) was wired for connectivity long before the needs of a tenant like Yelp would make 21st century demands. But even this telecom landmark needs some major infrastructure improvements to support the companies it expects to move in soon. more