{"id":25361,"date":"2019-04-11T11:14:21","date_gmt":"2019-04-11T10:14:21","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=25361"},"modified":"2019-04-11T11:16:53","modified_gmt":"2019-04-11T10:16:53","slug":"altron-karabina-expert-on-how-to-prevent-cloud-application-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/04\/11\/altron-karabina-expert-on-how-to-prevent-cloud-application-attacks\/","title":{"rendered":"Altron Karabina expert on how to prevent cloud application attacks"},"content":{"rendered":"<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><b><span style=\"font-family: 'Arial',sans-serif;color: black\">Sebastiaan Rothman, Senior Consultant Applications and Infrastructure at Altron Karabina, looks at what organisations can do to prevent cloud application attacks.<\/span><\/b><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-25364 size-large\" src=\"https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/04\/Sebastiaan-Rothman-848x1024.jpg\" alt=\"\" width=\"848\" height=\"1024\" srcset=\"https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/04\/Sebastiaan-Rothman-848x1024.jpg 848w, https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/04\/Sebastiaan-Rothman-248x300.jpg 248w, https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/04\/Sebastiaan-Rothman-768x928.jpg 768w, https:\/\/www.intelligentcio.com\/africa\/wp-content\/uploads\/sites\/5\/2019\/04\/Sebastiaan-Rothman.jpg 1365w\" sizes=\"auto, (max-width: 848px) 100vw, 848px\" \/><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Broadly speaking, cloud-based applications typically consist of one or more of the following platforms:<\/span> w<span style=\"font-family: 'Arial',sans-serif;color: black\">eb and mobile application services; <\/span>s<span style=\"font-family: 'Arial',sans-serif;color: black\">torage; and <\/span>d<span style=\"font-family: 'Arial',sans-serif;color: black\">atabases.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Each of these platforms have their own unique challenges when it comes to security, with varying degrees of complexity.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><b><span style=\"font-family: 'Arial',sans-serif;color: black\">Web and mobile application services<\/span><\/b><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Securing applications services in Azure has as much to do with process and policy as it does with technology. Strong authentication, preferably multi-factor authentication, provides the first line of defence against potential data breaches.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">After authentication, granular role-based access control ensures that authenticated users only have access to the resources they have been explicitly granted access to.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Secret, certificate and key protection goes a long way in ensuring that this information isn\u2019t written into code and locking down incoming requests to applications from specific IP addresses further reduce the potential attack surface of an application. These goals can be achieved by leveraging tools such as Azure Key Vault and properly designed networking.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">It is highly recommended to install a Web Application Firewall (WAF) in the environment to provide intelligent monitoring, filtering and protection of web and mobile applications hosted in Azure.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><b><span style=\"font-family: 'Arial',sans-serif;color: black\">Storage<\/span><\/b><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Having secure access to storage resources is extremely important for obvious reasons, but ultimately this is where your information is stored, and as such extra care needs to be taken when configuring access to storage.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Configuring and using stored access signatures is preferred over the use of storage account keys. <\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Role-based Access Control (RBAC) should always be used to configure for access by natural persons or named processes outside of application access.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Client-side encryption for high value data, and Storage Service Encryption for data at rest must be configured and used as a minimum to secure data.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><b><span style=\"font-family: 'Arial',sans-serif;color: black\">Databases<\/span><\/b><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Several mechanisms and best practice exist for securing databases, specifically SQL, in Azure. As with both application and storage security, the first line of defence for databases comes in the form of efficient identity management. The use of Azure Active Directory authentication over SQL authentication is recommended, allowing for common security practice such as password rotation to happen without disruption to services.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Further technical configurations such as a limited scope of network access, and the use of Transparent Data Encryption (TDE) on databases further secures information and reduces the risk of any unauthorised access.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Securing services in Azure, like any infrastructure or hosted application, requires diligent planning from the beginning to ensure risk is mitigated as much as possible. Even though the cloud provider makes all these tools and features available to help secure your environment, the onus is still on you to make sure they are correctly and effectively configured.<\/span><\/p>\n<p style=\"margin: 0cm 0cm 8.0pt 0cm\"><span style=\"font-family: 'Arial',sans-serif;color: black\">Relying on the cloud provider to keep your information safe is a foolish mistake, and one you will pay for dearly.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sebastiaan Rothman, Senior Consultant Applications and Infrastructure at Altron Karabina, looks at what organisations can do to prevent cloud application attacks. Broadly speaking, cloud-based applications typically consist of one or more of the following platforms: web and mobile application services; storage; and databases. Each of these platforms have their own unique challenges when it comes [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":25362,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,134,182,843,5,136,399],"tags":[8989,620,8996,8992,8991,8994,8993,8988,8985,236,8995,8997,8998,1524,8990,1525],"class_list":["post-25361","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-blog","category-cloud","category-editors-choice","category-enterprise-security","category-industry-expert","category-more-news","tag-altron-karabina","tag-azure","tag-azure-active-directory","tag-azure-key-vault","tag-databases","tag-rbac","tag-role-based-access-controll","tag-sebastiaan-rothman","tag-sql","tag-storage","tag-storage-service-encryption","tag-tde","tag-transparent-data-encryption","tag-waf","tag-web-and-mobile-application-services","tag-web-application-firewall"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/25361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=25361"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/25361\/revisions"}],"predecessor-version":[{"id":25365,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/25361\/revisions\/25365"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/25362"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=25361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=25361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=25361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}