AWS Vulnerability: Unveiling the Unique Challenges of Cloud Cybersecurity – Or Aspir, Mitiga
Or Aspir, head of research for Mitiga, explains how a vulnerability found in Amazon Web Services (AWS) environments is the latest example of what makes cybersecurity in the cloud so fundamentally different.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with, or Asper, who's head of research for miga, and we're talking about some new attack vectors that they've discovered affecting the Amazon Web Services Cloud.
And we're also gonna talk about the overall state of cloud security in general, or welcome to the show. Uh, thank you. I'm glad to be here.
Alright, So you guys have found a, a mechanism that the bad guys have figured out how to manipulate in a way that kind of exposes some data in ways that are probably not good for us all. Why don't you walk us through a little bit about what is it you guys have found and how big an issue is this? Okay, so I have to say that we didn't see any attackers that use it yet.
However, what we found out is that we always search in our company ways and attackers can abuse features and services on the cloud. So one of them that will, that we'll publish is about the S s M agent and the whole system system management, uh, service in a w s. So what we actually found is that if for some reason you have a compromised machine, an institute in a w s and the attacker, I don't know, they got a zero day, one day, some SS s h key, and then they have some high permissions, uh, on your, uh, machines, then what, um, the attacker will do, it's not only including cloud, it's not not only in cloud, it's on in all the whole, uh, endpoint security is that they would try, the attackers try to maybe upload their Trojan, uh, gain persistency on the environment, um, make the, the actions as legit.
So we found a new, uh, a new way the attacker, if the SS SS M agent, which is a part of the whole system of, uh, system manager at a W Ss is already installed on the endpoint, they don't need to, the attackers don't need to upload their own Trojan, which may look very suspicious to EDS and avs and such. They can just run couple of comments and make this agent to communicate with the attacker a W Ss account. So now the whole, the whole infrastructure of the S ss m uh, can be abused for, uh, for Trojan communication and action.
So think about an, an attacker that, uh, is in your machine. Then there are couple of comments. Then the, the agent will communicate with a malicious a w s account, and then the comments will come through the a s malicious account.
And, uh, it's because, uh, it's, uh, the binary is signed by Amazon because the connection will look like, will look like the IP which connected, which the agent connect to are a W Ss owned ips, the Amazon ips. And nobody would think about making this agent malicious. May a lot of EDRs and, uh, investigators, forensics investigators and such want, will really, uh, detect it as something malicious and probably will put it in some kind of an allow list in their EDRs and such.
So we show that this technique can be, uh, it's, it's real, it's a real threat and people need to know about it. So if the attackers and I, we believe that in the future because it's very, uh, easy attack, attackers will use that. So need to be prepared in the endpoint security part.
Uh, so that's about it in the, in the short, in short list. So what is your sense of the overall state of cloud security these days? I mean, some folks are kind of thinking it's more secure than it is, and other folks would say, Hey, if you can imagine something, it probably means the cyber criminals are already figured out how to do it.
So what's real here? I mean, are they really using fairly sophisticated attack vectors or are they kind of just going for low hanging fruit at the moment? Uh, so this is a good questions.
Uh, so in my, in my experience, what I'm seeing, the attackers are not sophisticated as they can be. Uh, most of them compromise a machine, then using the machine, they will try to jump to the cloud. Uh, from that point, maybe they will try to run some minor or maybe creating more resources or trade data from, from other, uh, data resources in the cloud.
Uh, but they don't, they, they, um, they're still doing stuff in the easy mode as I call it. They, they don't use like a complex APIs to disguise their, their action. The persistent mechanisms are still, uh, they're still very simple.
Like, uh, if you want to have some identity, just create a, IM user in a w s for example, and not try to do something like adding code to a s function. Uh, so I believe, but it, it'll be changing the future. The tech will be much, much smarter.
They will disguise their, their actions. They will stay for a long time in your a w and in your cloud environments. And as we see more and more companies are going to the cloud, there is a big knowledge gap regarding to security and how to do things, uh, in, in the, the, the best security way.
Uh, so we need to be, uh, to, to be, uh, one step ahead of the attackers. Uh, so this is, this is about it. Is cloud security fundamentally different than on premises security?
I feel like a lot of organizations tried to lift and shift their security approaches into the cloud and only to discover that this is a completely different environment. Uh, I agree. I agree.
The, because the, in the cloud environment, you have the shared responsibility, which means that some of the, the things will be, uh, on the cloud provider part and some of the things you need to be, uh, to take care of. Uh, let's, let's take for example, the part which you don't have in the, in, uh, in a lot of services in your cloud, the ability to install something as you're doing in the endpoints, and then you will have all the information coming from, from this product. You don't have have it on.
The only things that almost you, uh, that you have are the logs that are provided by the cloud provider itself. So if for some reason there is a visibility gap gap in those logs, so you'll have the, the visibility gap too. So because of that, you really depend, you really depend on the cloud providers to provide you, uh, the forensics information that you need.
And you cannot like install something and it'll give you the forensic information that the cloud doesn't bring you. Um, but, and, and yet again, um, you need to know how to use, well the services that are provided by you regarding to logs, regarding to, uh, configuration that you can see the assets that you have on the cloud. Uh, I think the easy part is that everything is used by an A p I.
So if you know which, which APIs are exposed to you and what you can use, uh, you can create a solution 1, 1, 1 product solution for that in order to see discovery of assets and, and more. We hear a lot about the shared security model and shared responsibility in the cloud. Is that feasible for most organizations?
It seems like, uh, you know, the cloud guys are saying that they'll secure the infrastructure, but you're responsible for everything else, but nobody quite knows exactly what everything else is. Uh, yeah, yeah. Um, um, sorry.
Uh, okay. So, uh, the shared responsibility, it's, it can be helpful. For example, they, they promise you that the physical servers are, uh, in a, in a secure saving, secure place and nobody can reach them, uh, un authorized access, which is very, very good.
Um, but yet again, you are very dependent on them regarding to, for example, forensics information. So if they don't provide you those, those information in incidents, or if there is a malicious actor in your environment, you have a problem. I can say that I think one of the problems in, uh, in this aspect is that if you want to see, for example, data access, data access logs, uh, it, it isn't it, it doesn't, uh, it isn't free.
So you need to pay, uh, more and even a lot of money in order to gain great visibility on your environment. We going into data access, data flow that comes and goes from your resources, uh, which is very important in cases of expiration and more. Um, but I, I, I believe that we are, the, the cloud is, is a, is a production ready.
So I, I believe that in the future we'll see more and more cloud providers, uh, um, provides you more information about the security aspects and, uh, uh, give you more visibility on your environment. Um, so I'm very optimistic about the shared responsibility on the cloud. Mm-hmm.
Are any of the clouds more secure than others, or are they all kind equally insecure in different kinds of ways? Um, so every cloud has its pros and cons regarding to security. Um, I can say that in, in, in a w s I feel, um, more, more, um, it's easy to read the logs of the, of the A W Ss, for example, CloudTrail.
Then, uh, can, can we, can we maybe, uh, uh, redo the, redo this question? Sure. No.
Okay. No worries. Yeah.
So, uh, I, so I'm quoting, um, I, I'm, I feel that if I will say what exactly I, I, I think maybe, uh, it can be, uh, problematic for me. But, uh, so returning back to the, to the, uh, interview. So, um, so every cloud has its pros and cons regarding to security.
Um, we can see in a w Ss, for example, that you have, uh, great logs to, to provide provided by you in CloudTrail, uh, but uh, in, uh, Azure for example, you can see a lot of security solutions that can help you, uh, have, uh, great, uh, d oh, sorry. Let, let's do it again. Uh, so sorry.
So we got it to, to the security that is better than, no, sorry, sorry. Uh, Mike, I just got, uh, my head got, uh, you know, How about, how about I asked the question again and we just start from there. Let's go.
Yeah, yeah, yeah, yeah. Alright, let's do that. Alright.
From your perspective, are any of the cloud services more secure than the other ones, or are they all somewhat insecure in different ways and we just have to figure out how to navigate each one? Uh, so I think the problem is the knowledge that you have on those clouds providers, you need to know for each cloud provider, what are the pros and cons regarding to security and where are the weaknesses or the misconfigurations that you can have that will make you tough, very, very hard to detect if something, uh, is malicious. Um, you need to understand very well the logs that are provided by you.
Um, I feel, uh, because I'm, I am, uh, I feel more comfortable in a w s I can tell you that in a w s there are great visibility regarding to management activity in CloudTrail. Uh, but, um, but I feel that it's, it's not, there isn't like first place for the, for the best cloud cloud provider, which brings you the security you need to have great knowledge if you are starting to work with, if your company's starting to work with a specific cloud provider, you need to have a great knowledge about the, the security and the visibility gaps and what the solution provided by, by other third parties and the cloud providers regarding into security. Uh, so I don't think there is a, like a, a cloud provider, which is the worst or the best.
Regarding to security, What do you think that organizations underestimate about cloud security most? I mean, you, you've seen a lot of mistakes, I'm sure you've seen a lot of attacks. I mean, what is it that kind of you wish people would be more proactive about?
Um, so I, I wish that people will learn about the best practice in security, uh, in the cloud providers. For example, I saw, uh, people that, uh, it and DevOps that uses, uh, high, very high privilege, uh, identities in order to do stuff that can, they can use it with much, much lower permission. Um, the way that they, they authenticate to the cloud, they use some kind of a plan, like a, um, hot coded password instead of using some kind of an SS s o configuration.
Um, so it can be easy for the tech if they know the, if they reveal the actual password, they can just authenticate. Um, so, but I think that the, the really hard part is to do everything in the least privilege mode and, uh, think about if you don't use this service or if you don't need to to connect to this, uh, to this, uh, a p I disable it. So even if, because we believe in GaN and I believe itself, that you will have an attack eventually in your environment, and it doesn't have to be your fault.
It can be supply chain attack. It can be, um, some zero day that was, uh, that was abused on your, uh, compromise system. So the first part that you have to have this privilege, so the, the, the, uh, blast radius will be much, much lower.
And the second part that I believe is that people really don't know what, uh, how much visibility they have on their environment. They don't know, for example, if somebody will steal information from this specific bucket, if I have the right logs, so I can investigate it and detect if something, when they're malicious. So they don't think about, okay, how can I have a great visibility, security visibility on my environment, which logs I need to collect, how I need to configure those, uh, log collectors.
Um, and, and this is bad because when there will be an incident, they will, they won't be prepared, and they, they won't have enough information about what happened that what and what they attack. The, uh, so I think the second problem is not only the configuration, uh, and the permissions, but the actual, uh, logging configuration and, uh, if they have an easy way to, to query those logs. Um, so that, that's what I saw from our, from our costs, from our customers and from other experience from other, other companies that are in the cloud.
Do you think we need a little more adult supervision? And I'm asking the question because so often we let developers provision whatever they want, but they don't have a lot of cybersecurity expertise, maybe even appreciation. So, you know, have we kind of created our own monster here?
Because in the name of expediency we made things easily accessible, but now we pay for it with security issues. So do we need to find a new balance? Um, so in the cloud pro, the cloud providers provides you the ability to isolate stuff, for example, if you know how to isolate the development scope from the production in a really good manner.
So if something is happening on the development side, it won't hurt the production. So you need to know exactly how to, to split those environment in. Uh, so the split of scopes, um, I think, I think you need, even, even with the development process, you need to think about this privilege.
Uh, I, I, I don't think the, it, it's a good, uh, solution to bring the developer the, all the permission that, that he wants. Because if for some reason this developer is getting compromised, the machine getting compromised, then the attack can run using this user. And I don't think always the developer think about the security, security aspect of, uh, of, uh, their work.
So I think the, the DevOps, the IT personnel need to think about, uh, they, they, they think about least privilege in the development side, even if it can and may, uh, make the development process much longer. Um, and again, isolation is very, very important. So what else are you guys working on and why were you looking at this particular vulnerability in the first place?
Um, so we as, uh, my research group is working on finding new ways and, and the popular ways attackers can do malicious actions on your environment, specifically on cloud providers and on SaaS solutions too, like identity providers, GitHub, GitLab, Salesforce, everything. And we try to think to put the black hat on our head and think about what hack, uh, tech can do, uh, with this process and writing detections and more, we found, uh, curious stuff like, because we are thinking as an attacker, we think about, okay, for example, in the ssss m we see that there is an agent which is installed by default on almost all the easy two instances. And think about, okay, so if I can abuse it, if I can make this as system agent connect to an AWS different a w s account, it can run as a rat, as a Trojan.
And, uh, when we found, when we find things like that, we, it's important to share our knowledge with the, with the community. So we write blogs about it. Uh, uh, we are lecturing in, uh, in, uh, conferences, security conferences.
We do meetups. Uh, so it's Spotify us to make like, to, to make the community more secure and more, um, and know about the security and cloud pro providers and SaaS. And, um, so, and yet again, this is what we do in our research group.
We're finding new ways data can abuse stuff, how we can detect those malicious actions, um, and share with the public what we, what we find. All right folks. Well, the bad guys have all day to go figure out new things to do.
And of course, they're only gonna do the things that probably are the easiest, but it's not like they're not looking after all this stuff. So you should too, or thanks for being on the show and sharing your knowledge and insights. Thank you very much, mark.
It was a pleasure to be here. All Right. And, uh, be safe.
All right. And back to you guys in the studio.