Cloud computing security woes

Security experts are blaming cloud computing providers for giving cyber criminals the tools to launch attacks more easily, efficiently and anonymously than ever before.


Speaking at the fourth InfoSecurity Summit in Hong Kong on Tuesday, [April 24, 2012,] SC Leung – a senior consultant at the city-state’s Computer Emergency Response Team said attackers are making the most of the technology.

“They are using it more efficiently for web hosting and they can subscribe to cloud services to get bandwidth on demand,” Leung said.

“They can hack computers thanks to the computing power of Amazon and it’s very hard to trace them. We need to solve this problem with the cloud service providers.”

This isn’t the first time Amazon took heat for helping out the bad guys. Hackers used Amazon's EC2 service who broke into Sony’s Playstation Network last year and accessed data on over 77 million users. They supplied fake information to the cloud computing giant.

Infosecurity practitioners at the event also said they are losing the battle against zero-day threats (security vulnerabilities disclosed before anyone can test and deploy updates), adding that the cyber criminals are better resourced, faster and more agile than themselves.

“It’s a question of how fast organizations can patch versus how fast malware writers can write malware,” said SH Lim, head of information security at the Hong Kong Jockey Club.

“How do we test our apps in just five days? Do we do a self denial-of-service by causing an app to fail because we don’t test a patch before applying it?”

Siu Fai Leung, senior vice president of security services in Asia at Bank of America Merrill Lynch, argued IT teams actually need exposure to plenty of malware to hone their defenses.

“Like humans we can’t survive without any viruses. If you don’t have an incident how can you make sure you’re protected?” he said. “A drill is a drill but when it comes to real life situations you need to put your systems to the test.”

No comments
Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
Salary survey: How much are you worth?; Dedicated outdoor air systems; Energy models and lighting
Fire, life safety in schools; Fire protection codes; Detection, suppression, and notification; 2015 Commissioning Giants; Emergency and standby power in hospitals
HVAC and building envelope: Efficient, effective systems; Designing fire sprinkler systems; Wireless controls in buildings; 2015 Product of the Year winners
Designing positive-energy buildings; Ensuring power quality; Complying with NFPA 110; Minimizing arc flash hazards
Implementing microgrids: Controlling campus power generation; Understanding cogeneration systems; Evaluating UPS system efficiency; Driving data center PUE, efficiency
Optimizing genset sizing; How the Internet of Things affects the data center; Increasing transformer efficiency; Standby vs. emergency power in mission critical facilities
As brand protection manager for Eaton’s Electrical Sector, Tom Grace oversees counterfeit awareness...
Amara Rozgus is chief editor and content manager of Consulting-Specifier Engineer magazine.
IEEE power industry experts bring their combined experience in the electrical power industry...
Michael Heinsdorf, P.E., LEED AP, CDT is an Engineering Specification Writer at ARCOM MasterSpec.