Cloud Security Panel – Cloud Expo
November 9, 2011, Cloud Expo, Santa Clara, CA–A panel moderated by Jocelyn Graham from cloudNow looked at the issues of security in the cloud. The panel included
Jill Singer from the National Reconnaissance Office, Melissa Siems from McAfee, Kristen Lovejoy from IBM, and Jamie Dos Santos from Terremark Federal Group.
Singer opened with comments on cloud elements. The myths of the cloud include being like a fog, because you cannot see into its working elements; lose of control; alignment changes and workforce issues. Visibility is enabled by sensor points within the system. These sensors also enhance control and increase collaboration. The workforce can adapt to the changes by well crafted worker enrichment activities. They have shown these in public and government cooperative efforts including the military and NIST.
Lovejoy offered an example from some clients on how to know about cloud services. Clouds are like the plague, about 10 percent of the population becomes infected, but those using good hygiene are relative safe. Users need a way to check the system for security and need to have clean image(s) of the data stored in separate locations.
Siems suggested that standards are important. Users should have an annual security audit and the security system needs daily updates. Scan technologies have to be in place to detect any system-level changes and all of the operations need to be transparent.
Singer then looked at the security landscape. The areas of concern include the OS, entry points, and shared environments. A system needs to have memory forensics to constantly monitor and evaluate potential threats. The security systems need to know of all the entry points.
Lovejoy added that break-ins need to be addressed by being prepared and using the available information on threats. The public cloud is more prone to intrusions than a private one, because it is easy to spin services and images. The average time to breach in an unsecured system is 7 minutes. As a result, cloud managers have to use technology and education to get their developers to be mindful of security. In addition, the users need to understand that they cannot use weak or default passwords because simple tools like ssh can exploit them.
Dos Santos added that when you are migrating into the cloud, you need to do a security inventory check because the security issues move with the data.
Singer noted that government procedures require security teams to be embedded with the operational teams so they will have to work together. The mix of skill sets helps to identify and correct breaches. A recent test proved that the combined teams could find and correct malware issues more quickly than each individually.
Siems suggested that security companies are moving into the applications areas to pre-empt intrusions. Dos Santos observed that this is not a traditional IT environment. People have to expect the worst in any environment and be prepared for any and all breaches. In the areas of third-party exposures, users need to make sure that their provider capabilities and data security match. They need to use data tagging and know where the data exists and use the power of the laws. Lovejoy noted that some nation-states do not respect the rule of law and work to learn where the data centers are located. They will try to break in despite the rules of law.
In response to the question of when to move sensitive data, Siems suggested that sensitive data should be kept inside the private system and expose it to the cloud only as needed. Singer offered shared cloud systems should have all data encrypted. The challenge is to get better encryption and key management tools to handle the volume of data.
Lovejoy responded to a query on challenges by stressing developer education. Having certified, knowledgeable security technicians for the infrastructure is not good enough for the complex systems. We need tools for configuration management and need to develop security platforms for clone systems and data. Siems added a need for conservation and the IT users should use a drop box for any data sharing.
Dos Santos replied to a query on return of data by noting that this is not a provider responsibility. Users need to have a set of procedures to get the data back and zero out the storage space when you leave the resource. Lovejoy offered data expunge is more important than copying.
Should cloud service providers have administrative access?
Singer opined that it depends upon the application. Provider services are needed for SaaS and some level of access is to be expected. At the same time, the data is the responsibility of the company, so all security should be enhanced with encryption.
Standards?
Dos Santos said that it depends on the end user and the market. Customers need to tell the provider what is needed. Lovejoy noted that third-party cloud security is an evolving area. It is best to start with infrastructure standards and add on others as appropriate. Singer appended that standards from the government agencies like NIST and DoD are not unreasonable for commercial users. The IT systems in the Federal space are increasing adoption of cloud services. Dos Santos highlighted the issue when data leave the US, noting that other countries may not honor US standards.
Providers providing security?
Singer offered that any additional security is probably good. It depends upon the space and implementation. Users have to perform due diligence and check the physical location(s) of the data centers. Dos Santos considered that security is just another utility like power and computers. Siems agreed with the others and stated that the user should have a check list of requirements and expected solutions.
Lessons on migration and security?
Singer observed that application migration is the perfect opportunity for an end-to-end asset inventory. Low utilization and high complexity applications should not move. Low security applications should be identified and fixed before the move. Take advantage of the down time for everything. Siems agreed that migration should be piecemeal to control access before, during, and after the transfer. Lovejoy offered that new business services should migrate to the cloud first. If the provider offers security services, take them, especially if the assed provider offers forensics, notification, and monitoring. Dos Santos noted the potential privacy issues. As the work and workforce change, the differences in administration can lead to increased breaches of knowledge. One issue is to institute more active monitoring for the cloud services.
Is centralized security viable? What about security information agents?
Lovejoy responded that yes, they are needed, because the data sources change. Many external machines have infections, so you need the cloud to check the reputations of those external machines. Dos Santos added the IT managers needs to correlate any external users with existing known users.
What’s in the future? Promising technologies and business models?
Dos Santos suggested Shield VM and SAFE for memory forensics and infrastructure. Joyant for a non-hypervisor cloud service. Lovejoy suggested predictive analytics and post-facto forensics to identify a breached asset to determine what and where breaches happened and stop them. Siems offered more security to leverage identities, devices, and people within a given context. Singer noted encryption for large data sets. Identification and asset management for smart data to understand the user context and provide variable access services.


