Welcome!

Weblogic Authors: Yeshim Deniz, Elizabeth White, Michael Meiner, Michael Bushong, Avi Rosenthal

Related Topics: @CloudExpo

@CloudExpo: Article

Strategies for Securing Enterprise-to-Cloud Communication

IaaS vendors and Enterprise consumers share responsibilities for enabling Cloud Security

The Cloud Security Alliance (CSA) published Version 2.1 of its Guidance for Critical Areas of Focus in Cloud Computing with a significant and comprehensive set of recommendations that enterprises should incorporate within their security best practices if they are to use cloud computing in a meaningful way.

The Guidance provides broad recommendations for operational security concerns including application security, encryption & key management, and identity & access management. In this article, we will consider security implications of REST- and SOAP-based communication between consumers and specifically, Infrastructure as a Service (IaaS) providers.

Cloud Application Security
Cloud application security requires looking at classic application security models and extending these models out to dynamic and multi-tenant architectures. While planning for cloud-based application security, DMZ-resident application security should be used as the starting point. DMZ-based security enforcement models should be extended to incorporate secure enterprise-to-cloud traffic management and operational control.  IaaS cloud providers design their management APIs to accommodate consumers with varying skill sets. Popular IaaS providers (Amazon EC2, Rackspace, Opsource, GoGrid) publish RESTful APIs for keeping a low threshold-of-difficulty to accommodate a broad set of consumers that lack sophisticated SOAP-based communication stacks but can easily consume XML/JSON using RESTful interaction. Amazon EC2, however, also provides a sophisticated WDSL for SOAP-based interaction. Although cloud providers have a greater responsibility of implementing extensive application security provisions while accommodating consumers of varying technical skills, cloud consumers also have to share the burden of risk mitigation by ensuring that their API calls into the cloud providers are secure and clean. The potential for a cascading effect in a shared, multi-tenant environment is high: a single poorly formed SOAP- or REST-based API request can cause a Denial of Service (DoS) attack potentially shutting down access to the cloud management APIs for many.

Implications for Cloud Consumers
Cloud consumers, for example enterprises, usually make outbound calls into an IaaS provider using a REST-based or a SOAP-based API for provisioning and managing server instances. Such standards-based API calls provide significant flexibility and ease for automating cloud resource management. However, this flexibility also opens the door to security risks that should be addressed. Here are a few operational recommendations, expanding on the CSA Guidance for Application Security, that cloud consumers should consider for lowering their risk profile while interacting with an IaaS:

  1. Enable Encryption: Cloud consumer should use SSL (HTTPS) for encrypting data-in-motion. When available, data-at-rest encryption (WS-Security) should also be used for invoking IaaS management services. Enabling content-level encryption for SOAP and REST responses ensures that only authorized consumer can decrypt responses with their private keys and use the API for managing their cloud images.
  2. Check Requests & Responses: Before invoking a REST- or SOAP-based call to an IaaS, consumers should determine whether the invocation is in the correct format and does not contain malware and that the request message integrity has not been compromised. The response from SOAP and REST-XML/JSON calls should also be scanned for malware and possible corruption before consumption by enterprise cloud management applications. Fortunately, structured data such as XML and SOAP provide the ability to check for message hygiene through a variety of ways starting with the simplest check: XSD Schema Validation. A schema, embedded in a WSDL file, provides constraints for message data types, structure, and content (through facets). Enforcing schema validation or simple deep-content validation through regular expression for REST calls ensures that the messages adhere to their required structure. Additional checks must be performed for malware that may be transmitted in a request or response to identify and quarantine infected messages. Such protective actions can prevent malware cascading through an enterprise or its IaaS provider.
  3. Enable Web services: For building a robust and secure framework for interacting with IaaS providers, SOAP-based interaction provides richness over RESTful XML/JSON. With SOAP use, enterprises can leverage their Public Key Infrastructure (PKI) and have full key life-cycle management including the ability to issue, sign, revoke and validate X.509 certificates being used in SOAP calls. By using key-pairs, enterprises have extensive control over authentication, message integrity and privacy while interacting with an IaaS. Using X.509 with GETs in a RESTful interaction is difficult and non-standard (other than for SSL mutual authentication that most IaaS providers do not support).

Implications for Cloud Providers
IaaS vendors usually provide a simple-to-use, web-based UI that enables user to manage cloud-based server images. This web-based interface is great to get up and running quickly, however, for enterprises that deploy numerous images, automated scripting for image management is essential. Most IaaS vendors provide REST, SOAP or Command Line scripting APIs for automating image management functions. Here are a few operational recommendations, expanding on the CSA Guidance for Application Security, that cloud providers should consider for lowering their risk profile:

  1. Provide standards-based flexibility: From the simplest of RESTful XML/JSON GETs to sophisticated signed SOAP requests with embedded X.509, IaaS providers have to address requirements from users with highly-varied technical skills. For large enterprise customers, IaaS vendors must provide strong authentication capabilities and rich SOAP-based interaction, whereas for smaller companies that may not have technical skill for handling a SOAP stack, simple RESTful interaction is usually preferred. Within simple, RESTful type interaction, there is a glaring lack of standardization on identity token use. Enterprises serious about using IaaS have to consider multi-cloud deployments for higher reliability. Standards-based identity tokens - perhaps OAuth for RESTful APIs and WS-X.509 for SOAP APIs - will provide a common management framework for enterprises to build redundancy through multi-cloud deployments.
  2. Enable comprehensive encryption: IaaS vendors must provide both data-in-motion security via protocols such as SSL and data-at-rest security through standards such as WS-Security for satisfying corporate security requirements. All IaaS vendors provide SSL-based encryption for invoking management APIs, however, content-level encryption for data-at-rest is not implement. IaaS providers such as Amazon EC2 support X.509 certificates for authentication and also provides WS-Signature capabilities for their SOAP-based API. Other IaaS vendors should provide such SOAP-based APIs along with more granular security controls. IaaS vendors should support SOAP APIs and provide granular encryption for XML/SOAP responses as an additional level of encryption control so that only enterprises with strict ownership and control of their private keys can view encrypted information within a XML/SOAP response.
  3. Perform comprehensive API testing: Before releasing a set cloud management calls to consumers, the APIs should be thoroughly tested across all exposed interaction formats, e.g., JSON/XML-REST and SOAP over HTTP(S).  The testing should be comprehensive and should cover four aspects of testing:  functional, performance, interoperability, and security.  Functional testing ensures that the cloud provisioning and management calls behave as expected and that no regression errors have been introduced.  Such functional testing has to cover all message types, identity tokens and security artifacts.  Performance testing can establish concurrency and throughput profiles for the APIs.  Interoperability testing ensures the APIs are consumable by the widest array of application platforms.  Adhering to WS-I Basic Profiles, for example, ensures that service description (WSDL) for the cloud management API can be used by .NET, Java, and LAMP environments with relative ease.  Finally, and perhaps, the most overlooked aspect of testing is a full penetration and security test for the IaaS management API that identifies REST, XML and SOAP-based vulnerabilities before the IaaS is exposed for public consumption. The multiplicative effect of a multi-tenant setting and multiple configuration APIs results is a dramatic expansion of the attack surface area. Identifying and remediating such risks through exhaustive penetration testing should be an essential component of IaaS providers Application Security operational plan.

Conclusions
Cloud application security requires extending risk planning and analysis beyond corporate boundaries. Enterprises that are already comfortable with deploying applications in the DMZ for deep integration with external trading partner have already laid the fo undations for interacting securely with IaaS cloud providers. Such mature enterprises have already figured out how to invoke external APIs via XML/SOAP, manage their identity tokens, encrypt communication and monitor traffic. Utilizing IaaS provider APIs and building a reliable multi-cloud application strategy requires extending their existing application infrastructure for centralized cloud management and control. Cloud providers, public and private, on-premise and off-premise have a higher burden of managing cloud application security than cloud service consumers. Cloud providers are required to balance security with flexibility. Greater security may discourage users with lower technical skills whereas enterprise customers may expect only the highest level of security. Cloud vendors should continue to focus on providing flexibility while extending security options available to users. They should also consider using standards-based identity tokens and work towards a standard management API that enables enterprises to build secure and reliable multi-cloud deployments.

References

  1. Guidance for Critical Areas of Focus in Cloud Computing
  2. Beginner's Guide to OAUTH
  3. Understanding WS-Security
  4. Pillars of SOA Testing

More Stories By Mamoon Yunus

Mamoon Yunus is an industry-honored CEO and visionary in Web Services-based technologies. As the founder of Forum Systems, he pioneered XML Security Gateways & Firewalls and was granted a patent for XML Gateway Appliances. He has spearheaded Forum's direction and strategy for eight generations of award-winning XML Security products. Prior to Forum Systems, Yunus was a Global Systems Engineer for webMethods (NASD: WEBM) where he developed XML-based business integration and architecture plans for Global 2000 companies such as GE, Pepsi, Siemens, and Mass Mutual. He has held various high-level executive positions at Informix (acquired by IBM) and Cambridge Technology Group.

He holds two Graduate Degrees in Engineering from MIT and a BSME from Georgia Institute of Technology. InfoWorld recognized Yunus as one of four "Up and coming CTOs to watch in 2004." He is a sought-after speaker at industry conferences such as RSA, Gartner, Web Services Edge, CSI, Network Interop, and Microsoft TechEd. Yunus has the distinction of showcasing Forum Systems' entrepreneurial leadership as a case study at the MIT Sloan School of Management. He has also been featured on CNBC as Terry Bradshaw's "Pick of the Week."

@ThingsExpo Stories
SYS-CON Events announced today that Calligo, an innovative cloud service provider offering mid-sized companies the highest levels of data privacy and security, has been named "Bronze Sponsor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Calligo offers unparalleled application performance guarantees, commercial flexibility and a personalised support service from its globally located cloud plat...
IoT is at the core or many Digital Transformation initiatives with the goal of re-inventing a company's business model. We all agree that collecting relevant IoT data will result in massive amounts of data needing to be stored. However, with the rapid development of IoT devices and ongoing business model transformation, we are not able to predict the volume and growth of IoT data. And with the lack of IoT history, traditional methods of IT and infrastructure planning based on the past do not app...
With tough new regulations coming to Europe on data privacy in May 2018, Calligo will explain why in reality the effect is global and transforms how you consider critical data. EU GDPR fundamentally rewrites the rules for cloud, Big Data and IoT. In his session at 21st Cloud Expo, Adam Ryan, Vice President and General Manager EMEA at Calligo, will examine the regulations and provide insight on how it affects technology, challenges the established rules and will usher in new levels of diligence...
SYS-CON Events announced today that DXWorldExpo has been named “Global Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Digital Transformation is the key issue driving the global enterprise IT business. Digital Transformation is most prominent among Global 2000 enterprises and government institutions.
SYS-CON Events announced today that Datera, that offers a radically new data management architecture, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Datera is transforming the traditional datacenter model through modern cloud simplicity. The technology industry is at another major inflection point. The rise of mobile, the Internet of Things, data storage and Big...
In his session at @ThingsExpo, Sudarshan Krishnamurthi, a Senior Manager, Business Strategy, at Cisco Systems, discussed how IT and operational technology (OT) work together, as opposed to being in separate siloes as once was traditional. Attendees learned how to fully leverage the power of IoT in their organization by bringing the two sides together and bridging the communication gap. He also looked at what good leadership must entail in order to accomplish this, and how IT managers can be the ...
DX World EXPO, LLC., a Lighthouse Point, Florida-based startup trade show producer and the creator of "DXWorldEXPO® - Digital Transformation Conference & Expo" has announced its executive management team. The team is headed by Levent Selamoglu, who has been named CEO. "Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation," he said in making the announcement.
Everything run by electricity will eventually be connected to the Internet. Get ahead of the Internet of Things revolution and join Akvelon expert and IoT industry leader, Sergey Grebnov, in his session at @ThingsExpo, for an educational dive into the world of managing your home, workplace and all the devices they contain with the power of machine-based AI and intelligent Bot services for a completely streamlined experience.
In the enterprise today, connected IoT devices are everywhere – both inside and outside corporate environments. The need to identify, manage, control and secure a quickly growing web of connections and outside devices is making the already challenging task of security even more important, and onerous. In his session at @ThingsExpo, Rich Boyer, CISO and Chief Architect for Security at NTT i3, discussed new ways of thinking and the approaches needed to address the emerging challenges of security i...
While the focus and objectives of IoT initiatives are many and diverse, they all share a few common attributes, and one of those is the network. Commonly, that network includes the Internet, over which there isn't any real control for performance and availability. Or is there? The current state of the art for Big Data analytics, as applied to network telemetry, offers new opportunities for improving and assuring operational integrity. In his session at @ThingsExpo, Jim Frey, Vice President of S...
"DX encompasses the continuing technology revolution, and is addressing society's most important issues throughout the entire $78 trillion 21st-century global economy," said Roger Strukhoff, Conference Chair. "DX World Expo has organized these issues along 10 tracks with more than 150 of the world's top speakers coming to Istanbul to help change the world."
"We provide IoT solutions. We provide the most compatible solutions for many applications. Our solutions are industry agnostic and also protocol agnostic," explained Richard Han, Head of Sales and Marketing and Engineering at Systena America, in this SYS-CON.tv interview at @ThingsExpo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"We are focused on SAP running in the clouds, to make this super easy because we believe in the tremendous value of those powerful worlds - SAP and the cloud," explained Frank Stienhans, CTO of Ocean9, Inc., in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
"We've been engaging with a lot of customers including Panasonic, we've been involved with Cisco and now we're working with the U.S. government - the Department of Homeland Security," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held June 6-8, 2017, at the Javits Center in New York City, NY.
The financial services market is one of the most data-driven industries in the world, yet it’s bogged down by legacy CPU technologies that simply can’t keep up with the task of querying and visualizing billions of records. In his session at 20th Cloud Expo, Karthik Lalithraj, a Principal Solutions Architect at Kinetica, discussed how the advent of advanced in-database analytics on the GPU makes it possible to run sophisticated data science workloads on the same database that is housing the rich...
Internet of @ThingsExpo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 21st Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devic...
What sort of WebRTC based applications can we expect to see over the next year and beyond? One way to predict development trends is to see what sorts of applications startups are building. In his session at @ThingsExpo, Arin Sime, founder of WebRTC.ventures, discussed the current and likely future trends in WebRTC application development based on real requests for custom applications from real customers, as well as other public sources of information.
"The Striim platform is a full end-to-end streaming integration and analytics platform that is middleware that covers a lot of different use cases," explained Steve Wilkes, Founder and CTO at Striim, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
SYS-CON Events announced today that Massive Networks will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Massive Networks mission is simple. To help your business operate seamlessly with fast, reliable, and secure internet and network solutions. Improve your customer's experience with outstanding connections to your cloud.
"MobiDev is a Ukraine-based software development company. We do mobile development, and we're specialists in that. But we do full stack software development for entrepreneurs, for emerging companies, and for enterprise ventures," explained Alan Winters, U.S. Head of Business Development at MobiDev, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.