Skip to Content

User identity management problems account for most cloud security breaches

December 19, 2018 by
User identity management problems account for most cloud security breaches
Kleber Leal by Zamak Portal
The first concern that comes to people's minds when discussing cloud security is the fear of cybercriminal attacks. After all, who would pose a greater risk to user identity than those who dedicate themselves full-time to discovering new ways to bypass security controls, gain illegal access, steal information, or abuse resources? Yes, cybercrime represents a significant threat to any environment that must be constantly combated. In terms of security controls, the cloud provides a range of technological options that can protect even environments requiring the highest level of cybersecurity. The big issue is that we continue to overlook an essential factor in information security: how the human factor has made life easier for cybercriminals. The numbers are alarming. A study based on Netskope's customers — a cloud cybersecurity provider — pointed out that 71.5% of breaches occurring in Amazon Web Services (AWS) involve Identity and Access Management (IAM). In other words, most are the result of credential theft (login and password) from users of this service, showing that the extreme end of security (people) remains the bottleneck in the context of cyberattacks. According to Paolo Passeri, Director of Cyber Intelligence at Netskope, hackers obtain credentials through a combination of attacks, ranging from sophisticated phishing attacks to using passwords stuck on post-its on coworkers' screens. For the expert, users have no control over password creation to ensure they are secure (mixing different types of characters) nor to guarantee their reliability criteria. "People prefer to use easy-to-remember numeric sequences." Another problem is that cloud providers, including not only AWS but also its main competitors, do not share the responsibility for access to applications. "They could reinforce their policies and force their users to follow certain rules. There are some tools that can check access to see if administrators follow security recommendations," he explains. "Even using multi-factor authentication, such as tokens, is a way to minimize credential leakage." But cloud-using companies must also be more critical when using the cloud. "They cannot forget about security. Working from anywhere on any device is great, but there are risks that companies face, such as the security of the network they use or even the device itself," Passeri recalls. This is because attackers want to reach the cloud to gain access to corporate networks and start carrying out other attacks, or even use the cloud infrastructure (paid for by the victim) to generate cryptocurrencies, for example, or to host malware. While Netskope's research indicates that many of these incidents were considered critical, we need to understand that most could have been easily avoided using a combination of the protection features provided by AWS itself, along with user education/awareness and, especially, the administrators of IaaS or PaaS services. In any case, education remains at the top of the security pyramid, above firewalls, antivirus, etc., according to the Netskope expert. "Technology can help block human errors, but it is not enough. Companies need to have security policies," Passeri concludes. Source: Ip News  

Frequently asked questions

Why is identity management the biggest risk in cloud security?

A Netskope study based on its own customers found that 71.5% of breaches occurring in Amazon Web Services (AWS) involve Identity and Access Management (IAM). This means most incidents stem from stolen login credentials rather than flaws in the cloud infrastructure itself.

How do cybercriminals steal cloud user credentials?

According to Paolo Passeri, Director of Cyber Intelligence at Netskope, hackers combine tactics ranging from sophisticated phishing attacks to using passwords written on post-its stuck to coworkers' screens. This is worsened by users lacking control over creating secure passwords, often preferring easy-to-remember numeric sequences instead.

What helps reduce credential leakage in the cloud?

Using multi-factor authentication (MFA), such as tokens, is one way to minimize credential leakage. According to the Netskope expert, educating users and IaaS/PaaS administrators remains at the top of the security pyramid, above firewalls and antivirus, since technology alone is not enough without clear security policies.

User identity management problems account for most cloud security breaches
Kleber Leal by Zamak Portal December 19, 2018
Share this post
Tags
Archive