In the landmark essay "Selling Wine Without Bottles, The Economy of Mind on the Global Net", written in 1992-1993 (http://www.virtualschool.edu/mon/ElectronicFrontier/WineWithoutBottles.html), John Barlow anticipates and lays out the fundamental intellectual property issues that plague our current digital world. Barlow eloquently and precisely frames the core questions:
"If our property can be infinitely reproduced and instantaneously distributed all over the planet without cost, without our knowledge, without its even leaving our possession, how can we protect it? How are we going to get paid for the work we do with our minds? And, if we can't get paid, what will assure the continued creation and distribution of such work?
Barlow concludes his insightful essay with an assertion that has clearly come to pass:
"Cryptography...is the "material" from which the walls, boundaries--and bottles--of Cyberspace will be fashioned."
Barlow also anticipated the rise of Arxan Technologies (and other similar companies)) when he stated that:
"Cryptography will enable a lot of protection technologies which will develop rapidly in the obsessive competition which has always existed between lock-makers and lock-breakers."
We here at Arxan can certainly attest to the "obsessive competition" as we engage in virtual and digital hand to hand combat with the crackers striving to steal our customer's software and/or data.
The fascinating point Barlow made in 1993 that I'd like to explore today is the following:
"A social over-reliance on protection by barricades rather than conscience will eventually wither the latter by turning intrusion and theft into a sport, rather than a crime. This is already occurring in the digital domain as is evident in the activities of computer crackers."
Let's turn now to some recent news about the movie Avatar and it's release on Blu Ray disc. This release was protected using a technology called BD+. Unfortunately, the cracking community managed to procure (read "steal") an early copy, successfully cracked the protection, and published the movie through bit torrent sites. Here's a fascinating "news" report on the availability of the movie "for free" as a torrent download (which occured within a day or two of the public release of the blu ray disks for purchase):
http://torrentfreak.com/avatar-most-pirated-blu-ray-film-ever-100427/
So within a matter of just a few weeks, Avatar has become the most pirated movie ever.
What does it require for this to occur? It requires exactly what Barlow predicted: a withering of basic personal ethics of property ownership at the individual level. We now have a culture where people view the casual theft of intellectual property as completely acceptable. The heart of it seems to be a vast difference in perspective in people's minds and ethics between a physical object and a digital object.
What drives this difference in perspective and behavior? Is it the removal of risk of "getting caught stealing"? I personally believe this is a significant enabling factor, yet not the fundamental driver of this widespread contagion of theft. I believe it is a subtle, and simple. People fundamentally do not view creation of a (perfect) copy of something as theft. Morals are still wrapped around the physical-ness of goods and physical-ness of possession. Stealing means taking something so that I have it and you no longer have it. This notion of physical theft being "wrong" is deeply rooted in most individual's ethical system. Hence, most people (including those illegally downloading Avatar) would not steal the Avatar blu ray disk from a store, even if they knew they could do so without risk of being caught. They would be taking a "real thing" that belongs to another (the store), and that violates their sense of morals and ethics. But download the same movie for free? Hey, no one has been ripped off! No one has "lost" anything! So "it isn't theft". And besides, if it's wrong (illegal) to download it for free, it wouldn't be available on the network for free would it? Once again, "it must not be theft". Of course, this entire line of thinking is dead wrong. Every aspect of it's free availability is illegal, and access of this stolen property is itself theft.
So while I and my colleagues toil and sweat to provide the "digital locks" that will help prevent (or perhaps more realistically, deferred for a longer period of time) the cracking of the high value digital content in our world, I think it's paramount that we as a society strive to re-tool our ethics and attitudes. This battle must be fought on all fronts, not purely a technology front. How does this kind of change occur? Simple: it changes when you and I put simple social pressure on our family and friends regarding this kind of theft. "Come watch Avatar tonight at my place?" "Hey yea; you got it on Blu Ray?" "Yea, I downloaded it last night, it's awesome." "Oh...well, hey, that's theft and it's wrong, I'm sorry, I can't watch that with you." For me, it's takes the form of remonstrating with my son when he tells me of a friend who is downloading this or that PC video game for free: "that's wrong son, it is theft, and you are not allowed to do the same nor are you allowed to play his stolen games".
Social pressure is that simple and I believe it can be very effective at evolving and shaping attitudes and behaviors. It's really up to us to drive change in our culture to respect these new forms of property. Just because the wine is available for the sipping because it's outside the old bottles, doesn't mean it's right to open our mouth and gulp...without compensating those who made that wine.
Monday, May 24, 2010
Friday, February 5, 2010
The Game Within the On-Line Game
Online gaming is a relatively new industry, and one with phenomenal growth over the last 15 years. The release of Call of Duty: Modern Warfare 2 late last year generated a stunning $550M in sales revenue in the first week alone, and overall the series has generated over $3B in sales for Activision, the publisher:
http://www.csmonitor.com/Innovation/Horizons/2009/1127/call-of-duty-series-sales-top-3-billion-activision-says
There is a fly in the ointment, however. As has been true forever, the larger the business, the larger the attraction for the criminal element. What's unique here is the nature of the crime, given that the essential product is that most intangible of assets, software.
There are two fundamental modes of online game play today: standalone mode, and multi-player mode. The latter can be more refined into two general categories, small group play and massively multi-player gaming.
Standalone commercial gaming software has suffered since it's inception from the problem of illicit copies in which the license protection has been "hacked". Simply put, someone has taken a version, analyzed the code internals, and modified the binary level code to disable or otherwise spoof the license checking code. The result: a "free" copy of the software, or at least a copy that won't generate any revenue for the publisher. And software being casually clone-able means this free copy can be and is distributable to as many people willing to pay for it (if required) and use it (illegally, of course).
The result of this common crime is a general axiom in the gaming industry for standalone games, namely that all the sales of significance happen in the first two weeks after release. After that, "cracked" copies are available on the cheap, and the revenue stream ramps down far more rapidly than normal sales dynamics and economics would indicate. As an example, a simple web search for "Call of Duty Modern Warfare 2 download" will quickly find cracked versions of this product available for little to no direct cost.
Massively multi-player on-line role playing gaming (MMORPG) vendors had a solution to this problem...or so they thought. The very nature of MMORPG games required participation in a single unified "world" (virtual reality), implemented as a single world by a server (or server farm) operated by the game publisher. The client software operating on the gamer's computer communicates with the servers to participate in the single world with all the other gamers participating at the moment. The business model is based on ongoing subscription revenue for the privilege of continued participation in the virtual world enabled by the publisher's servers, rather than the licensed sale of a single copy of the game.
Not to be stopped, the criminal element went to work on this model as well. Careful analysis of the code within and the networking traffic to and from the client software on the gamer's personal computer enables these server applications to be "reverse engineered", meaning new software is developed from scratch the performs the same functions as the original publisher's gaming server software. Obviously this isn't cheap nor simple, but given the literally millions of players involved in these types of games, and the ability to operate "parallel worlds" with lower subscription costs, the economic returns of the criminal effort become quite attractive.
For those of us who believe that we have rights to our owned intellectual property and deserve to be compensated for it's usage, there is hope. The technologies to fight back are available today. I'm not referring to simple copy protection schemes that are relatively trivial for competent code hackers to analyze and disable. I am referring to technologies that approach military grade anti-tamper facilities, used to protect US military software assets ("critical program information").
Given the stakes in the gaming industry today, the industry would be remiss to not take advantage of such technologies. The days of accepting only two weeks of revenue for a game that takes years and many millions of dollars to develop, and the days of organized crime stealing massively from the game publishers, can and should be over. To not take advantage of these technologies would be a business management crime of a different sort.
Needless to say, Arxan Technologies is here to help turn the tables on the criminals. We vend these technologies, with easy to use tools to define and insert such protection networks into executable software ("binary code"). Here at Arxan, nothing gives us more joy than a famous "cracker" getting flamed on the the download bulletin boards for long delays in providing a functioning crack for a "new" release after three months...then six months...then twelve months. At which point, the war is won, because that version is now "old" and the process starts over with a new version from the publisher, with yet stronger, more robust and unique guard protections.
It's time to stop intellectual property theft, it's time to stop software business operations theft, it's time to stop piracy of software in general. Call Arxan and let us show you how.
http://www.csmonitor.com/Innovation/Horizons/2009/1127/call-of-duty-series-sales-top-3-billion-activision-says
There is a fly in the ointment, however. As has been true forever, the larger the business, the larger the attraction for the criminal element. What's unique here is the nature of the crime, given that the essential product is that most intangible of assets, software.
There are two fundamental modes of online game play today: standalone mode, and multi-player mode. The latter can be more refined into two general categories, small group play and massively multi-player gaming.
Standalone commercial gaming software has suffered since it's inception from the problem of illicit copies in which the license protection has been "hacked". Simply put, someone has taken a version, analyzed the code internals, and modified the binary level code to disable or otherwise spoof the license checking code. The result: a "free" copy of the software, or at least a copy that won't generate any revenue for the publisher. And software being casually clone-able means this free copy can be and is distributable to as many people willing to pay for it (if required) and use it (illegally, of course).
The result of this common crime is a general axiom in the gaming industry for standalone games, namely that all the sales of significance happen in the first two weeks after release. After that, "cracked" copies are available on the cheap, and the revenue stream ramps down far more rapidly than normal sales dynamics and economics would indicate. As an example, a simple web search for "Call of Duty Modern Warfare 2 download" will quickly find cracked versions of this product available for little to no direct cost.
Massively multi-player on-line role playing gaming (MMORPG) vendors had a solution to this problem...or so they thought. The very nature of MMORPG games required participation in a single unified "world" (virtual reality), implemented as a single world by a server (or server farm) operated by the game publisher. The client software operating on the gamer's computer communicates with the servers to participate in the single world with all the other gamers participating at the moment. The business model is based on ongoing subscription revenue for the privilege of continued participation in the virtual world enabled by the publisher's servers, rather than the licensed sale of a single copy of the game.
Not to be stopped, the criminal element went to work on this model as well. Careful analysis of the code within and the networking traffic to and from the client software on the gamer's personal computer enables these server applications to be "reverse engineered", meaning new software is developed from scratch the performs the same functions as the original publisher's gaming server software. Obviously this isn't cheap nor simple, but given the literally millions of players involved in these types of games, and the ability to operate "parallel worlds" with lower subscription costs, the economic returns of the criminal effort become quite attractive.
For those of us who believe that we have rights to our owned intellectual property and deserve to be compensated for it's usage, there is hope. The technologies to fight back are available today. I'm not referring to simple copy protection schemes that are relatively trivial for competent code hackers to analyze and disable. I am referring to technologies that approach military grade anti-tamper facilities, used to protect US military software assets ("critical program information").
Given the stakes in the gaming industry today, the industry would be remiss to not take advantage of such technologies. The days of accepting only two weeks of revenue for a game that takes years and many millions of dollars to develop, and the days of organized crime stealing massively from the game publishers, can and should be over. To not take advantage of these technologies would be a business management crime of a different sort.
Needless to say, Arxan Technologies is here to help turn the tables on the criminals. We vend these technologies, with easy to use tools to define and insert such protection networks into executable software ("binary code"). Here at Arxan, nothing gives us more joy than a famous "cracker" getting flamed on the the download bulletin boards for long delays in providing a functioning crack for a "new" release after three months...then six months...then twelve months. At which point, the war is won, because that version is now "old" and the process starts over with a new version from the publisher, with yet stronger, more robust and unique guard protections.
It's time to stop intellectual property theft, it's time to stop software business operations theft, it's time to stop piracy of software in general. Call Arxan and let us show you how.
Thursday, January 21, 2010
Commercial Cyber Warfare
Today Sec. of State Clinton went after China for their network censorship:
http://www.cbsnews.com/stories/2010/01/21/ap/tech/main6123918.shtml
However, as I see it, the issue of real significance here isn't China's censorship. The news reports of "attacks" on Google and other "unnamed" companies is the action of real significance. I'm not referring to illegal access to mail accounts. I'm referring to the explicit theft of intellectual property in the form of source code:
http://www.wired.com/threatlevel/2010/01/google-hack-attack/
In China, the coupling between government and leading companies in different industries is extremely strong. It can be hard to distinguish where a company stops and the government begins when it comes to such industry players as Baidu, HuaWei, and China Telecom.
It is reasonable to suspect and to investigate the potential that aggressive theft of source code from US companies is an activity that is being actively supported, and potentially even led, by the Chinese government. It appears that at the very least, the Chinese government tolerates such operations and private industry reuse of this stolen software.
In an age when information and intellectual property is the coin of the realm, does government sanctioned intellectual property theft constitute not just a crime, but verges on an act of war?
These kinds of acts should be investigated deeply by the government. Regardless of ultimate responsibility, we need a strong, overt response from the US government. The message must be clear and backed by strong actions that this kind of attack will not be tolerated and will be prosecuted.
A specific US response needs to include a product watch program to monitor for the use of stolen software, followed by vigorous prosecution of such illegal usage of stolen technology through available legal, diplomatic and trade channels. Reused source code will have significant bodies of unique identifiable binary code in the products utilizing the technology. This is an area where private industry has far too little power to fight back effectively, though it could play a key role in the monitoring program.
I acknowledge the private industry accountability for failing to prevent such theft. We in the software industry can and must make deeper investments in our security systems around our core property of value, our source code. DLP technologies, encryption technologies, strong multi-factor authentication for source access, and other solutions are available.
China's censorship is an important issue. That some group from China is actively stealing US company technology out from under our nose is an extremely important issue as well, and needs equal attention and even more governmental action.
At Arxan, we provide technologies to help protect software intellectual property through protection of the binary code with what we call "guards". We provide this technology in both military/classified forms to the DoD and DoD contractors, and in commercial form to commercial customers. However, to protect the source code of software from theft through systemic security holes, different measures are needed. Stronger source code security measures need to be deployed by private industry. The US government must speak out and lead in efforts to identify and prosecute those responsible and those who attempt to take advantage of such theft.
http://www.cbsnews.com/stories/2010/01/21/ap/tech/main6123918.shtml
However, as I see it, the issue of real significance here isn't China's censorship. The news reports of "attacks" on Google and other "unnamed" companies is the action of real significance. I'm not referring to illegal access to mail accounts. I'm referring to the explicit theft of intellectual property in the form of source code:
http://www.wired.com/threatlevel/2010/01/google-hack-attack/
In China, the coupling between government and leading companies in different industries is extremely strong. It can be hard to distinguish where a company stops and the government begins when it comes to such industry players as Baidu, HuaWei, and China Telecom.
It is reasonable to suspect and to investigate the potential that aggressive theft of source code from US companies is an activity that is being actively supported, and potentially even led, by the Chinese government. It appears that at the very least, the Chinese government tolerates such operations and private industry reuse of this stolen software.
In an age when information and intellectual property is the coin of the realm, does government sanctioned intellectual property theft constitute not just a crime, but verges on an act of war?
These kinds of acts should be investigated deeply by the government. Regardless of ultimate responsibility, we need a strong, overt response from the US government. The message must be clear and backed by strong actions that this kind of attack will not be tolerated and will be prosecuted.
A specific US response needs to include a product watch program to monitor for the use of stolen software, followed by vigorous prosecution of such illegal usage of stolen technology through available legal, diplomatic and trade channels. Reused source code will have significant bodies of unique identifiable binary code in the products utilizing the technology. This is an area where private industry has far too little power to fight back effectively, though it could play a key role in the monitoring program.
I acknowledge the private industry accountability for failing to prevent such theft. We in the software industry can and must make deeper investments in our security systems around our core property of value, our source code. DLP technologies, encryption technologies, strong multi-factor authentication for source access, and other solutions are available.
China's censorship is an important issue. That some group from China is actively stealing US company technology out from under our nose is an extremely important issue as well, and needs equal attention and even more governmental action.
At Arxan, we provide technologies to help protect software intellectual property through protection of the binary code with what we call "guards". We provide this technology in both military/classified forms to the DoD and DoD contractors, and in commercial form to commercial customers. However, to protect the source code of software from theft through systemic security holes, different measures are needed. Stronger source code security measures need to be deployed by private industry. The US government must speak out and lead in efforts to identify and prosecute those responsible and those who attempt to take advantage of such theft.
Monday, January 11, 2010
Secure Software Marketplaces
The news today of a trojan'd application for Android phones (http://www.sophos.com/blogs/gc/g/2010/01/11/banking-malware-android-marketplace) is a fascinating and potentially extremely significant, if not altogether expected development in the smart phone wars.
Simply put, if the consumer marketplace develops a ground fear of the software available for Android phones, the predictions about Android phone growth may be vastly inflated.
Whether we like it or not (and some don't, preferring a phone browser centric world), ubiquitous phone apps are the "killer app" for smart phones, at least for the moment. This single spot of bad news for Android can quickly become a huge differentiator for Apple with its controlled iTunes store for safe apps for the iPhone. Similarly, it points to an interesting opportunity in the business ecology: who is going to offer a vetted app store for Android phones, with appropriate software security reviews on the in-bound side and guarantees on the outbound side? Without such a market service, I'm suspicious that hackers will quickly ruin the unregulated marketplace for Android apps.
Secure 'droid app store anyone? Anyone?
Simply put, if the consumer marketplace develops a ground fear of the software available for Android phones, the predictions about Android phone growth may be vastly inflated.
Whether we like it or not (and some don't, preferring a phone browser centric world), ubiquitous phone apps are the "killer app" for smart phones, at least for the moment. This single spot of bad news for Android can quickly become a huge differentiator for Apple with its controlled iTunes store for safe apps for the iPhone. Similarly, it points to an interesting opportunity in the business ecology: who is going to offer a vetted app store for Android phones, with appropriate software security reviews on the in-bound side and guarantees on the outbound side? Without such a market service, I'm suspicious that hackers will quickly ruin the unregulated marketplace for Android apps.
Secure 'droid app store anyone? Anyone?
Monday, November 9, 2009
Security in the Cloud
Cloud computing is one of the "big new things" in commercial computing today. The promises of cloud computing are broad and deep: lowered capital costs, lowered operational costs, ease of scale, broad accessibility, high availability, and more.
And then there's security. It's the usual follow-on question after hearing about all the benefits, "yes, great, and...what about security?".
The simple truth is that cloud computing carries with it each and every security risk that already existing in your commercial computing environment, and unfortunately significantly increased risks.
Why is this so? Simply because at the highest levels, there is little structural change in shifting elements of your computing infrastructure from "here" (inside your corporate data center) to "there" (inside an external vendors corporate data center). The same security controls you needed (and in many cases didn't have) are needed in your cloud providors environment (and in many cases they don't have), and the same fundamental attack vectors and risks are present.
As we drill down into the details however, it will become clear that the situation is worse than this, for two fundamental reasons: one is shared infrastructure, the second is a general loss of control. Let's look at each of these.
The foundation of the cost benefit premise of cloud computing rests on the leverage achieved through a shared computing infrastructure, with the cost benefits of scale and higher average utilization. But shared with who? That's risk #1; you don't know who, and you can't control who. "Other companies, other users." Shared at what level? At all levels: shared storage, shared networking, shared routers, shared firewalls, right on down to operating your applications on the same physical hardware being used by other cloud clients (though always in a separate virtual machine instance).
So what's the risk of that? The risk is the ease of access to your data and application software. By definition, an environment where "others" are running their software and maintaining their data in the same physical environment that you are running your software and maintaining your data creates very substantial incremental security risk, because environmental access is the first step in any and every IP and data theft attack. If I'm "in" the general computing environment, and I can run arbitrary application software, I've got a launching pad for attacks on local data and applications.
Another element of shared infrastructure in cloud computing is the extension of the insider risk. Many of your own insiders will still have cloud environment access similar to the access they had when you were running inside your own data center. However, you've now added a whole new class of insiders: the cloud provider employees! And unlike your own insider threats, where you can take active steps to reduce risk, with the cloud provider you have no controls and no influence. Relative to these unknown people, you applications and data might as well be considered "fully available", with all that that implies.
The second general area of risk is in a loss of controls. This loss of control is across the board, starting at the level of physical access; when you operated in your data center, you controlled physical access, and with a cloud provider you don't. Logical access is no different; what people (administrators or otherwise) can access your databases and your applications? You have vague assurances from the cloud provider, but you have no direct control whatsoever.
This control issue extends out to more subtle yet extremely significant areas. Take the example of web application security risks. These are the most pernicious security risks in computing today, with SQL injection attacks alone (just one of many types of web application security risks) resulting in the theft of millions of credit card numbers. The most recent attempt to harden web applications is through the deployment of so called web application firewalls. These are networking appliances that monitor networking traffic looking for evidence of a web application attack. These devices require a very high amount of customization in their specific monitoring practices, effectively to "tune" the firewall the specifics of the applications and their operations being protected. Can such a solution be applied in your shift to a cloud computing environment? Generally no, due to the difficulty of assuring the application firewall is both "in the right place" relative to what is now managed as a highly mobile set of applications within the large cloud infrastructure environment, and the need for your application firewall rules to apply to your applications data flow and your applications data flow only.
Control issues cut right through all traditional required practices in commercial computing. Backup? Of course the cloud vendor provides backup! Can you test that it's actually occurring and the data is recoverable? There have already been major examples of commercial cloud providers losing customer data. It's a risk, and it's driven by your loss of control when shifting your computing practices to an external provider, and those risks are exacerbated by the shared infrastructure nature of that environment.
All of this said, cloud computing is here and it's expanding it's footprint dramatically across the commercial computing landscape. Cost saving attracts commercial usage likes light attracts moths. The issues cited here are going to get incrementally addressed over time, as part of high value cloud solutions.
The better news is that some fundamental solution technology exists today. The essence of security protection in a cloud environment is to take advantage of what you do control to implement security mechanisms to the level required by your business. The two critical control points are, simply put, your applications and your data.
Data security solutions have been increasingly developed and deployed over the last ten years, and these solutions generally can be deployed coupled directly into the cloud hosting environment. Any computing solution migration to the cloud must seriously consider the addition of such security technologies.
Application internal security solutions are a relatively new technology area. This kind of technology derives from military grade technology utilized to protect critical military technology assets from reverse engineering and tampering. This technology is now available for and being applied to commercial software.
Application internal security technology puts security functions directly into the application software. These security functions start with obscuring the code flow, the instruction sequencing, and even the unencrypted presence of critical blocks of code, to protect against reverse engineering and through reversing, the identification of critical value components and/or critical points for effective tampering. They extend to dynamic monitoring of code correctness both in terms of actual instruction to dynamic code behaviors. And such security units can, internally within the application, monitor data flows to detect and respond to evidence of web application security attacks.
The tremendous benefit of application internal security technology is the complete independence such technology has from location considerations. An internally secured application carries it's security properties with it, where ever it goes: in your data center, on your employee's laptops and cellphones, or in a external provider's cloud computing environment. Such technology is immune to network topology changes, and protects the application in private and shared infrastructures.
Cloud computing is still in it's infancy, and it's reasonable to say that cloud computing is one of several fundamental change agents that is transforming our information world at a faster rate than ever before. While cloud computing has dramatic benefits and is highly attractive as a computing environment solution, it must be approached extremely cautiously from a security perspective. The shared nature of the cloud and the loss of controls that occur when utilizing the cloud dramatically increase your security risk footprint. The best and most immediately available technologies for dealing with these two factors are the deployment of application internal security technologies and data security technologies.
And then there's security. It's the usual follow-on question after hearing about all the benefits, "yes, great, and...what about security?".
The simple truth is that cloud computing carries with it each and every security risk that already existing in your commercial computing environment, and unfortunately significantly increased risks.
Why is this so? Simply because at the highest levels, there is little structural change in shifting elements of your computing infrastructure from "here" (inside your corporate data center) to "there" (inside an external vendors corporate data center). The same security controls you needed (and in many cases didn't have) are needed in your cloud providors environment (and in many cases they don't have), and the same fundamental attack vectors and risks are present.
As we drill down into the details however, it will become clear that the situation is worse than this, for two fundamental reasons: one is shared infrastructure, the second is a general loss of control. Let's look at each of these.
The foundation of the cost benefit premise of cloud computing rests on the leverage achieved through a shared computing infrastructure, with the cost benefits of scale and higher average utilization. But shared with who? That's risk #1; you don't know who, and you can't control who. "Other companies, other users." Shared at what level? At all levels: shared storage, shared networking, shared routers, shared firewalls, right on down to operating your applications on the same physical hardware being used by other cloud clients (though always in a separate virtual machine instance).
So what's the risk of that? The risk is the ease of access to your data and application software. By definition, an environment where "others" are running their software and maintaining their data in the same physical environment that you are running your software and maintaining your data creates very substantial incremental security risk, because environmental access is the first step in any and every IP and data theft attack. If I'm "in" the general computing environment, and I can run arbitrary application software, I've got a launching pad for attacks on local data and applications.
Another element of shared infrastructure in cloud computing is the extension of the insider risk. Many of your own insiders will still have cloud environment access similar to the access they had when you were running inside your own data center. However, you've now added a whole new class of insiders: the cloud provider employees! And unlike your own insider threats, where you can take active steps to reduce risk, with the cloud provider you have no controls and no influence. Relative to these unknown people, you applications and data might as well be considered "fully available", with all that that implies.
The second general area of risk is in a loss of controls. This loss of control is across the board, starting at the level of physical access; when you operated in your data center, you controlled physical access, and with a cloud provider you don't. Logical access is no different; what people (administrators or otherwise) can access your databases and your applications? You have vague assurances from the cloud provider, but you have no direct control whatsoever.
This control issue extends out to more subtle yet extremely significant areas. Take the example of web application security risks. These are the most pernicious security risks in computing today, with SQL injection attacks alone (just one of many types of web application security risks) resulting in the theft of millions of credit card numbers. The most recent attempt to harden web applications is through the deployment of so called web application firewalls. These are networking appliances that monitor networking traffic looking for evidence of a web application attack. These devices require a very high amount of customization in their specific monitoring practices, effectively to "tune" the firewall the specifics of the applications and their operations being protected. Can such a solution be applied in your shift to a cloud computing environment? Generally no, due to the difficulty of assuring the application firewall is both "in the right place" relative to what is now managed as a highly mobile set of applications within the large cloud infrastructure environment, and the need for your application firewall rules to apply to your applications data flow and your applications data flow only.
Control issues cut right through all traditional required practices in commercial computing. Backup? Of course the cloud vendor provides backup! Can you test that it's actually occurring and the data is recoverable? There have already been major examples of commercial cloud providers losing customer data. It's a risk, and it's driven by your loss of control when shifting your computing practices to an external provider, and those risks are exacerbated by the shared infrastructure nature of that environment.
All of this said, cloud computing is here and it's expanding it's footprint dramatically across the commercial computing landscape. Cost saving attracts commercial usage likes light attracts moths. The issues cited here are going to get incrementally addressed over time, as part of high value cloud solutions.
The better news is that some fundamental solution technology exists today. The essence of security protection in a cloud environment is to take advantage of what you do control to implement security mechanisms to the level required by your business. The two critical control points are, simply put, your applications and your data.
Data security solutions have been increasingly developed and deployed over the last ten years, and these solutions generally can be deployed coupled directly into the cloud hosting environment. Any computing solution migration to the cloud must seriously consider the addition of such security technologies.
Application internal security solutions are a relatively new technology area. This kind of technology derives from military grade technology utilized to protect critical military technology assets from reverse engineering and tampering. This technology is now available for and being applied to commercial software.
Application internal security technology puts security functions directly into the application software. These security functions start with obscuring the code flow, the instruction sequencing, and even the unencrypted presence of critical blocks of code, to protect against reverse engineering and through reversing, the identification of critical value components and/or critical points for effective tampering. They extend to dynamic monitoring of code correctness both in terms of actual instruction to dynamic code behaviors. And such security units can, internally within the application, monitor data flows to detect and respond to evidence of web application security attacks.
The tremendous benefit of application internal security technology is the complete independence such technology has from location considerations. An internally secured application carries it's security properties with it, where ever it goes: in your data center, on your employee's laptops and cellphones, or in a external provider's cloud computing environment. Such technology is immune to network topology changes, and protects the application in private and shared infrastructures.
Cloud computing is still in it's infancy, and it's reasonable to say that cloud computing is one of several fundamental change agents that is transforming our information world at a faster rate than ever before. While cloud computing has dramatic benefits and is highly attractive as a computing environment solution, it must be approached extremely cautiously from a security perspective. The shared nature of the cloud and the loss of controls that occur when utilizing the cloud dramatically increase your security risk footprint. The best and most immediately available technologies for dealing with these two factors are the deployment of application internal security technologies and data security technologies.
Subscribe to:
Posts (Atom)
