1 option
Empirical Cloud Security : Practical Intelligence to Evaluate Risks and Attacks / Aditya K. Sood.
- Format:
- Book
- Author/Creator:
- Sood, Aditya K., author.
- Language:
- English
- Subjects (All):
- Computer security.
- Computer networks--Security measures.
- Computer networks.
- Physical Description:
- 1 online resource (491 pages)
- Edition:
- Second edition.
- Place of Publication:
- Dulles, VA : Mercury Learning and Information LLC, [2023]
- Summary:
- The book discusses the security and privacy issues detected during penetration testing, security assessments, configuration reviews, malware analysis, and independent research of the cloud infrastructure and Software-as-a-Service (SaaS) applications. The book highlights hands-on technical approaches on how to detect the security issues based on the intelligence gathered from the real world case studies and also discusses the recommendations to fix the security issues effectively. This book is not about general theoretical discussion rather emphasis is laid on the cloud security concepts and how to assess and fix them practically.
- Contents:
- Cover
- Half-Title
- Title
- Copyright
- Contents
- Preface
- About the Author
- Chapter 1: Cloud Architecture and Security Fundamentals
- Understanding Cloud Virtualization
- Cloud Computing Models
- Comparing Virtualization and Cloud Computing
- Containerization in the Cloud
- Components of Containerized Applications
- Serverless Computing in the Cloud
- Components of Serverless Applications
- The Characteristics of VMs, Containers, and Serverless Computing
- Cloud Native Architecture, Applications, and Microservices
- Embedding Security into Cloud Native Applications
- Securing Cloud Native Applications
- Cloud Native Application Protection Platform (CNAPP)
- Understanding Zero Trust Architecture
- Edge Computing Paradigm
- Embedding Security in the DevOps Model
- Understanding Cloud Security Pillars
- Cloud Security Testing and Assessment Methodologies
- References
- Chapter 2: Iam for Authentication and Authorization: Security Assessment
- Understanding Identity and Access Management Policies
- IAM Policy Types and Elements
- IAM Policy Variables and Identifiers
- Managed and Inline Policy Characterization
- IAM Users, Groups, and Roles
- Trust Relationships and Cross-Account Access
- IAM Access Policy Examples
- IAM Access Permission Policy
- IAM Resource-Based Policy
- Role Trust Policy
- Identity and Resource Policies: Security Misconfigurations
- Confused Deputy Problems
- Over-Permissive Role Trust Policy
- Guessable Identifiers in Role Trust Policy
- Privilege Escalation via an Unrestricted IAM Resource
- Insecure Policies for Serverless Functions
- Unrestricted Access to Serverless Functions
- Serverless Functions with Administrative Privileges
- Serverless Function Untrusted Cross-Account Access
- Unrestricted Access to the VPC Endpoints.
- Insecure Configuration in Passing IAM Roles to Services
- Uploading Unencrypted Objects to Storage Buckets Without Ownership
- Misconfigured Origin Access Identity for CDN Distribution
- Authentication and Authorization Controls Review
- Multi Factor Authentication (MFA)
- User Credential Rotation
- Password Policy Configuration
- Administrative or Root Privileges
- SSH Access Keys for Cloud Instances
- Unused Accounts, Credentials, and Resources
- API Gateway Client-Side Certificates for Authenticity
- Key Management Service (KMS) Customer Master Keys
- Users Authentication from Approved IP Addresses and Locations
- Recommendations
- Automation Scripts for Security Testing
- MFA Check (mfa_check.sh)
- IAM Users Administrator Privileges Analysis (iam_users_admin_root_privileges. sh)
- IAM Users SSH Keys Analysis (iam_users_ssh_keys_check.sh)
- Chapter 3: Cloud Infrastructure: Network Security Assessment
- Network Security: Threats and Flaws
- Why Perform a Network Security Assessment?
- Understanding Security Groups and Network Access Control Lists
- Understanding VPC Peering
- Security Misconfigurations in SGs and NACLs
- Unrestricted Egress Traffic via SGs Outbound Rules
- Unrestricted Egress Traffic via NACLs Outbound Rules
- Insecure NACL Rule Ordering
- Over-Permissive Ingress Rules
- Cloud Network Infrastructure: Practical Security Issues
- Insecure Configuration of Virtual Private Clouds
- Public IP Assignment for Cloud Instances in Subnets
- Over-Permissive Routing Table Entries
- Lateral Movement via VPC Peering
- Insecure Bastion Hosts Implementation
- Outbound Connectivity to the Internet
- Missing Malware Protection and File Integrity Monitoring (FIM)
- Password-Based Authentication for the Bastion SSH Service
- Insecure Cloud VPN Configuration.
- Insecure and Obsolete SSL/TLS Encryption Support for OpenVPN
- Unrestricted VPN Web Client and Administrator Interface
- Exposed Remote Management SSH Service on VPN Host
- IPSec and Internet Key Exchange (IKE) Assessment
- Reviewing Deployment Schemes for Load Balancers
- Application Load Balancer Listener Security
- Network Load Balancer Listener Security
- Insecure Implementation of Network Security Resiliency Services
- Universal WAF not Configured
- Non-Integration of WAF with a Cloud API Gateway
- Non-Integration of WAF with CDN
- Missing DDoS Protection with Critical Cloud Services
- Exposed Cloud Network Services: Case Studies
- AWS Credential Leakage via Directory Indexing
- OpenSSH Service Leaking OS Information
- OpenSSH Service Authentication Type Enumeration
- OpenSSH Service with Weak Encryption Ciphers
- RDP Services with Insecure TLS Configurations
- Portmapper Service Abuse for Reflective DDoS Attacks
- Information Disclosure via NTP Service
- Leaked REST API Interfaces via Unsecured Software
- Unauthorized Operations via Unsecured Cloud Data Flow Server
- Information Disclosure via Container Monitoring Software Interfaces
- Credential Leakage via Unrestricted Automation Server Interfaces
- Data Disclosure via Search Cluster Visualization Interfaces
- Insecure DNS Servers Prone to Multiple Attacks
- Exposed Docker Container Registry HTTP API Interface
- Unsecured Web Servers Exposing API Endpoints
- Exposed Riak Web Interfaces without Authentication
- Exposed Node Exporter Software Discloses Information
- Unsecured Container Management Web Interfaces
- Insecure ERP Deployments in the Public Cloud
- Information Leakage via Exposed Cluster Web UI
- Unsecured Reverse Proxy Web Interfaces
- Chapter 4: Database and Storage Services: Security Assessment.
- Database Cloud Deployments
- Deploying Databases as Cloud Services
- Databases Running on Virtual Machines
- Containerized Databases
- Cloud Databases
- Cloud Databases: Practical Security Issues
- Verifying Authentication State of Cloud Database
- Database Point-in Time Recovery Backups Not Enabled
- Database Active Backups and Snapshots Not Encrypted
- Database Updates Not Configured
- Database Backup Retention Time Period Not Set
- Database Delete Protection Not Configured
- Cloud Storage Services
- Cloud Storage Services: Practical Security Issues
- Security Posture Check for Storage Buckets
- Unencrypted Storage Volumes, Snapshots, and Filesystems
- Unrestricted Access to Backup Snapshots
- Automating Attack Testing Against Cloud Databases and Storage Services
- Unsecured Databases and Storage Service Deployments: Case Studies
- Publicly Exposed Storage Buckets
- Unsecured Redis Instances with Passwordless Access
- Penetrating the Exposed MySQL RDS Instances
- Data Destruction via Unsecured Memcached Interfaces
- Privilege Access Verification of Exposed CouchDB Interfaces
- Keyspace Access and Dumping Credentials for Exposed Cassandra Interfaces
- Data Exfiltration via Search Queries on Exposed Elasticsearch Interface
- Dropping Databases on Unsecured MongoDB Instances
- Exploiting Unpatched Vulnerabilities in Database Instances: Case Studies
- Privilege Escalation and Remote Command Execution in CouchDB
- Reverse Shell via Remote Code Execution on Elasticsearch/Kibana
- Remote Code Execution via JMX/RMI in Cassandra
- Chapter 5: Design and Analysis of Cryptography Controls: Security Assessment
- Understanding Data Security in the Cloud
- Cryptographic Techniques for Data Security
- Data Protection Using Server-Side Encryption (SSE)
- Client-Side Data Encryption Using SDKs.
- Data Protection Using Transport Layer Encryption
- Cryptographic Code: Application Development and Operations
- Crypto Secret Storage and Management
- Data Security: Cryptographic Verification and Assessment
- Machine Image Encryption Test
- File System Encryption Test
- Storage Volumes and Snapshots Encryption Test
- Storage Buckets Encryption Test
- Storage Buckets Transport Encryption Policy Test
- TLS Support for Data Migration Endpoints Test
- Encryption for Cloud Clusters
- Node-to-Node Encryption for Cloud Clusters
- Encryption for Cloud Streaming Services
- Encryption for Cloud Notification Services
- Encryption for Cloud Queue Services
- Envelope Encryption for Container Orchestration Software Secrets
- Cryptographic Library Verification and Vulnerability Assessment
- TLS Certificate Assessment of Cloud Endpoints
- TLS Security Check of Cloud Endpoints
- Hard-Coded Secrets in the Cloud Infrastructure
- Hard-Coded AES Encryption Key in the Lambda Function
- Hard-Coded Credentials in a Docker Container Image
- Hard-Coded Jenkins Credentials in a CloudFormation Template
- Cryptographic Secret Storage in the Cloud
- Recommendations for Applied Cryptography Practice
- Chapter 6: Cloud Applications: Secure Code Review
- Why Perform a Secure Code Review?
- Introduction to Security Frameworks
- Application Code Security: Case Studies
- Insecure Logging
- Exceptions Not Logged for Analysis
- Data Leaks From Logs Storing Sensitive Information
- Insecure File Operations and Handling
- File Uploading with Insecure Bucket Permissions
- Insecure File Downloading from Storage Buckets
- File Uploading to Storage Buckets Without Server-side Encryption
- File Uploading to Storage Buckets Without Client-Side Encryption
- Insecure Input Validations and Code Injections
- Server-Side Request Forgery.
- Function Event Data Injections.
- Notes:
- Includes index.
- Includes bibliographical references and index.
- Description based on print version record.
- ISBN:
- 9781501517990
- 1501517996
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.