Amazon cloud exploited

Powered by SC Magazine
 

But the problems lie with customers, not Amazon.

Scientists from the Centre for Advanced Security Research Darmstadt (CASED) claimed to have found major security vulnerabilities in Amazon's cloud virtual machines published by customers.

Surveying 1100 public Amazon Machine Images (AMIs), which are used to provide cloud services, it found that around 30 percent were vulnerable and could allow attackers to manipulate or compromise web services or virtual infrastructures.

It claimed that the main failure lies in the ‘careless and error-prone manner' in which Amazon's customers handle and deploy AMIs.

The research group, led by professor Ahmad-Reza Sadeghi at CASED, found that even though Amazon Web Services (AWS) provides its customers with very detailed security recommendations on its web pages, at least one third of the machines under consideration have flawed configurations.

The research team reported that it was able to extract critical data such as passwords, cryptographic keys and certificates from the analysed virtual machines.

“The problem clearly lies in the customers' unawareness and not in Amazon Web Services," Sadeghi said. "We believe that customers of other cloud providers endanger themselves and other cloud users similarly by ignoring or underestimating security recommendations.”

AWS has informed affected customers and will publish guidance on how to manage private keys.

SafeNet director of European solutions Mike Smart said cloud computing is "virgin territory" and more organisations are going to make similar simple mistakes.

"...user education [is] a real priority for service providers and the industry as a whole," he said.

“End users should go further and ensure their digital keys are never used on the cloud, but are held and used within hardware security modules in their premises.

"This kind of technology is widely used within the financial sector and has evolved to the point where it can be used much more widely to secure all kinds of secure infrastructure including those associated with private or public clouds."

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


Amazon cloud exploited
 
 
 
Top Stories
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  28%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1079

Vote