Check Point exposes yet more shared responsibility misunderstandings for cloud security

Almost one in five organisations polled by cybersecurity solutions provider Check Point Software say they have been victim to a cloud security incident over the past year, while more than a quarter still believe security is the responsibility of the cloud provider.

These and other worrying findings have appeared in Check Point’s latest study. The 2019 Security Report, of which this is the third instalment and combined data with survey responses from IT professionals and C-level executives, also found more than half (59%) of IT respondents polled did not use mobile threat defences.

The report pulls no punches in regard to its analysis. The first section, titled ‘cloud is your weakest link’, explores how cloud services are vulnerable across three main attack vectors; account hijacking, malware delivery, and data leaks. Citing Dome9 – acquired by Check Point last year – in a study last year which found 91% of organisations were concerned about cloud security, the report notes how exposure and default security settings remain an issue.

“65% of IT professionals still underestimate the damage they can cause,” the report explained. “The obvious concern is that organisations are not taking cloud security seriously enough. The breach of sensitive data held in the cloud is a huge risk for an organisation, and threat actors know it. The rate of cyber attacks against cloud-based targets is growing, and with little sign it will slow down.”

The statistic which causes major concern is the three in 10 respondents who affirmed security was the responsibility primarily of the cloud service provider. This, as the report noted, ‘negates recommendations’ over shared, or mutual responsibility.

This is a viewpoint which persists even though cloud providers have tried to remove some of the burden themselves. In November, Amazon Web Services (AWS) launched Amazon S3 Block Public Access, which aimed to secure at the account level, on individual buckets, as well as future buckets created.

The move was to ensure users handled public buckets and objects ‘as needed while giving tools to make sure [users] don’t make them publicly accessible due to a simple mistake or misunderstanding’, in the words of AWS chief evangelist Jeff Barr at the time. Previously, AWS had revamped its design to include bright orange warning indicators to signify which buckets were public.

“As nearly 20% of organisations have experienced a cloud incident in the past year, it’s clear that criminals are looking to exploit these security gaps,” said Zohar Alon, head of the cloud product line at Check Point. “By reviewing and highlighting these developments in the report, organisations can get a better understanding of the threats they face, and how they prevent them impacting on their business.”

You can read the full report here (email required).

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Check Point reveals cloud and mobile security threats are growing


Clare Hopping

22 Feb, 2019

Criminals are increasingly targeting the cloud and mobile environments of businesses because they’re the least protected infrastructure, Check Point has revealed.

The insights are backed up by evidence in the form of the cyber security company’s 2019 Security Report, with almost a fifth of businesses having experienced a security incident over the last 12 months, including data leaks and breaches and malware.

“The third installment of our 2019 Security Report shows just how vulnerable organizations are to attacks targeting their cloud and mobile estates, because there is a lack of awareness of the threats they face and how to mitigate them,” said Zohar Alon, head of cloud product line at Check Point Software Technologies. “As nearly 20% or organizations have experienced a cloud incident in the past year, it’s clear that criminals are looking to exploit these security gaps.”

The reason so many businesses are being targeted is because 30% feel it’s the responsibility of their cloud provider to protect them against threats and this means they’re not sufficiently protecting their cloud infrastructure. However, it’s widely recommended by cloud providers that this duty to protect a cloud environment is shared between the provider and the customer.

The most prevalent threats in the cloud are misconfiguration of cloud platforms, which was highlighted by 62% of businesses, with unauthorised access to cloud platforms cited as a problem by 55% of IT professionals. Those questioned also said insecure interfaces and APIs were a big problem in their organisation.

Mobile environments are also more at risk because businesses are failing to use mobile defences to protect their infrastructure, whether that’s by implementing malware detection or monitoring the usage of devices for system vulnerabilities.

In fact, less than 10% of IT professionals thought mobile threats presented a significant risk to their business, failing to recognise that malware can very easily propagate between mobile devices on a central network.

“By reviewing and highlighting these developments in the Report, organizations can get a better understanding of the threats they face, and how they prevent them impacting on their business,” Alon said.

Google introduces hybrid cloud platform for flexible environments


Clare Hopping

22 Feb, 2019

Google has launched itself into the hybrid cloud arena, launching Google Cloud Service Platform to help businesses take advantage of a mixed on-premise and cloud services at once.

CSP is built upon Google Kubernetes Engine (GKE) and integrates GKE On-Prem, which allows all of Google’s services to be pushed through to datacentres if a business doesn’t want to (or their sensitive data doesn’t allow for it to) operate solely on the cloud.

It will especially be useful for highly-regulated businesses that need to keep ownership of their data, but also companies that need to run legacy applications in their own datacentre, rather than in the cloud.

Alongside the ability to run applications in the cloud or on-premise, CSP also introduces other services that will help developers, security professionals and the IT team operate more efficiently.

For example, CSP Config Management enables the IT department to create multi-cluster policies out of the box to make sure that every cluster has the correct access controls and resource quotes set up. Security teams can monitor usage of the CSP environment, monitoring any changes and alerting them to anything suspicious.

StackDriver Monitoring offers a single management console for teams to keeps tabs on both environment at once and compatibility with the GCP marketplace offers open-source, and commercial Kubernetes applications with templates to make it faster to deploy applications.

“Built on open APIs, CSP is a less disruptive and more compliant approach than competing hybrid offerings,” Eyal Manor, vice president of Google Cloud said. “CSP gives you the freedom to modernize your applications at your own pace, innovate faster, and improve operational security and governance.

“Now that our customers have started to modernize their applications in their own data centers with CSP, we believe it will be the enterprise application deployment platform of choice for many years to come.”

Cloud Native Computing Foundation Receives Grant from Google Cloud | @DevOpsSUMMIT #DevOps #Kubernetes

VANCOUVER, Canada, Aug. 29, 2018 /PRNewswire/ — Open Source Summit North America – The Cloud Native Computing Foundation® (CNCF®), which sustains and integrates open source technologies like Kubernetes® and Prometheus™, today announced that Google Cloud has begun transferring ownership and management of the Kubernetes project’s cloud resources to CNCF community contributors. Google Cloud will help fund this move with a $9 million grant of Google Cloud Platform credits, divided over three years, to cover the infrastructure costs associated with Kubernetes development and distribution, such as running the continuous integration and continuous delivery (CI/CD) pipelines and providing the container image download repository.

read more

Sponsorship Opportunities at @KubeSUMMIT Silicon Valley | #CloudNative #Serverless #AWS #Docker #Kubernetes #Microservices

As you know, enterprise IT conversation over the past year have often centered upon the open-source Kubernetes container orchestration system. In fact, Kubernetes has emerged as the key technology — and even primary platform — of cloud migrations for a wide variety of organizations. Kubernetes is critical to forward-looking enterprises that continue to push their IT infrastructures toward maximum functionality, scalability, and flexibility. As they do so, IT professionals are also embracing the reality of Serverless architectures, which are critical to developing and operating real-time applications and services. Serverless is particularly important as enterprises of all sizes develop and deploy Internet of Things (IoT) initiatives.

read more

CloudEXPO Introduces Rockstar @KubeSUMMIT Faculty | #CloudNative #Serverless #DataCenter #Monitoring #Containers #DevOps #Docker #Kubernetes

IT professionals are also embracing the reality of Serverless architectures, which are critical to developing and operating real-time applications and services. Serverless is particularly important as enterprises of all sizes develop and deploy Internet of Things (IoT) initiatives.

Serverless and Kubernetes are great examples of continuous, rapid pace of change in enterprise IT. They also raise a number of critical issues and questions about employee training, development processes, and operational metrics.

There’s a real need for serious conversations about Serverless and Kubernetes among the people who are doing this work and managing it.

So we are very pleased today to announce the ServerlessSUMMIT at CloudEXPO.

read more

StackRox to Highlight Kubernetes Security | @KubeSUMMIT @StackRox #CloudNative #Serverless #DevOps #Docker #Kubernetes #Security

StackRox helps enterprises secure their containerized and Kubernetes environments at scale. The StackRox Container Security Platform enables security and DevOps teams to enforce their compliance and security policies across the entire container life cycle, from build to deploy to runtime. StackRox integrates with existing DevOps and security tools, enabling teams to quickly operationalize container and Kubernetes security. StackRox customers span cloud-native startups, Global 2000 enterprises, and government agencies. StackRox is privately held and headquartered in Mountain View, California. To learn more, visit www.stackrox.com and follow us on Facebook, LinkedIn and Twitter.

read more

MapR Amplifies Power of Kubernetes | @KubeSUMMIT @MapR #CloudNative #Serverless #DevOps #Docker #Kubernetes

Implementation of Container Storage Interface (CSI) for Kubernetes delivers persistent storage for compute running in Kubernetes-managed containers. This future-proofs Kubernetes+Storage deployments. Unlike the Kubernetes Flexvol-based volume plugin, storage is no longer tightly coupled or dependent on Kubernetes releases. This creates greater stability because the storage interface is decoupled entirely from critical Kubernetes components allowing separation of privileges as CSI components do not need full privileges of Kubernetes components. With the implementation of Container Storage Interface (CSI), persistent data layer for Kubernetes and other Container Orchestration (CO) tools, such as Mesos and Docker Swarm are now future-proofed.

read more

Persistent Storage for Kubernetes | @KubeSUMMIT @Elastifile #CloudNative #Containers #Serverless #DevOps #Docker #Kubernetes

With container technologies widely recognized as the cloud-era standard for workload scaling and application mobility, organizations are increasingly seeking to support container-based workflows. In particular, the desire to containerize a diverse spectrum of enterprise applications has highlighted the need for reliable, container-friendly, persistent storage. However, to effectively complement today’s cloud-centric container orchestration platforms, persistent storage solutions must blend reliability and scalability with a simple, cloud-native user experience. The introduction of Elastifile’s CSI driver addresses these needs by augmenting containerized workflows with highly-available, scalable NFS file storage delivered via Elastifile Cloud File System…and with no complex, manual storage provisioning required.

read more

Redis Labs further changes licensing terms – to make developers happy and keep big cloud vendors at bay

Open source database provider Redis Labs has announced Redis Source Available License (RSAL), representing a modification of previous licensing terms for its modules and looking towards clarification with the open source and developer communities.

The company had in August changed its terms to Apache2 modified with Commons Clause with more than one eye on the biggest cloud providers, who were packaging Redis technology into proprietary offerings and pocketing the resulting profits.

This was a move which was followed towards the end of last year by similar companies, such as MongoDB and Confluent. Writing at the time of the latter’s $2.5 billion valuation following a $125m series D funding round in January, as this publication reported, Confluent co-founder Jay Kreps outlined his company’s position.

“The major cloud providers all differ in how they approach open source,” Kreps wrote in a blog post back in December. “Some of these companies partner with the open source companies that offer hosted versions of their system as a service. Others take the open source code, bake it into the cloud offering and put all their own investments into differentiated proprietary offerings.

“The point is not to moralise about this behaviour; these companies are simply following their commercial interests and acting within the bounds of what the license of the software allows,” Kreps added. “But we think the right way to build fundamental infrastructure layers is with open code.”

Hence the need to tighten things up. Yet the problem Redis Labs found was that the previous terms for its modules – the Redis database project itself remains unchanged – were too open to interpretation, or too confusing. Previously, under Apache2 modified with Commons Clause, the rule was that users were not allowed to sell a product or service ‘whose value derives entirely, or substantially, from the functionality of the software.’ But as Redis subsequently noted, how substantial is ‘substantially’ exactly?

The new solution under RSAL is to communicate more clearly that developers can use the software, modify the source code, integrate it with an application, and use, distribute or sell that application. The only restriction is that the application cannot be a database, a caching engine, a stream processing engine, a search engine, an indexing engine, or a machine learning, deep learning, or artificial intelligence-serving engine.

“We are very open to our community,” Ofer Bengal, Redis Labs CEO, told CloudTech. “We got a lot of feedback and responses regarding Commons Clause which made us think there may be a better definition of license for our case.

“When we said [users were] not allowed to sell a product or service… this created concerns with some developers providing services around open source projects, like consulting services and support services,” Bengal added. “In order to get adoption you need to satisfy the needs of developers, and once we heard after we released Commons Clause that some developers weren’t happy – not with the concept but with the way it was presented and copyrighted, the language of the license – that was the point where we thought that we should correct it.

“We hope that once doing that developers would be happier and more receptive to using software under these licenses.”

For some users, however, that ship may have already sailed. In the aftermath of Redis’ original licensing changes, offshoot groups developed, in particular GoodFORM (Free and Open Redis Modules). Led by developers at Debian and Fedora, GoodFORM set out to fork Redis’ code ‘committed to making [it] available under an open source license permanently’ amid fears they were unable to ship Redis’ versions of affected modules to their users.

Bengal’s response to these projects was unequivocal. “With all due respect, they should wake up and smell the coffee,” he said. “They don’t realise that the world has changed and the exact concept of open source is challenging in today’s environment.

“What they have done is just to counter what we have done. They forked the Redis modules that we had at the time, but this means nothing because they have done nothing with it, and I suspect that they cannot do anything with it,” Bengal added. “You must realise that developing a database is a very complex thing, it’s not a small piece of software that someone can develop from his parents’ home garage. There are tons of nuances and complexities, and if you do not devote yourself 24/7 for years to develop a database there is no way you can really contribute to it.”

It has been a busy few days all told for Redis, with the announcement of $60m in a series E funding round being confirmed earlier this week. The round, which was led by new investor Francisco Partners and also featuring existing investors Goldman Sachs Private Capital Investing, Bain Capital Ventures, Viola Ventures and Dell Technologies Capital, is a particularly important one according to Bengal.

“We are now at the stage where we’re seeing that our opportunity is huge,” he said. “The race over market share as the market matures becomes fiercer and fiercer, and in order to have foothold and market share you need to move very quickly and aggressively.

“Compared to our peers, we decided that in order to move faster and accelerate our growth we need to be more aggressive on the sales side, marketing side, and even on the product development side,” Bengal added.

With regards to the cloud behemoths, there may be some light at the end of the tunnel. In a blog post explaining Redis’ latest modules license changes, co-founder and CTO Yiftach Shoolman noted that the company was “seeing some cloud providers think differently about how they can collaborate with open source vendors.” Bengal added that, Amazon Web Services (AWS) aside, ‘the mood is trying to change’, inferring that partnerships between some cloud providers and companies behind open source projects may not be too far away.

You can read the full explanation of Redis Source Available License (RSAL) here.

Read more: Confluent's $2.5 billion valuation may provide affirmation amid open source turbulence

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.