{"id":45579,"date":"2020-02-13T14:28:22","date_gmt":"2020-02-13T14:28:22","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/02\/13\/six-critical-attack-vectors-to-watch-out-for-in-your-data-centre\/"},"modified":"2020-02-13T14:33:08","modified_gmt":"2020-02-13T14:33:08","slug":"six-critical-attack-vectors-to-watch-out-for-in-your-data-centre","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/02\/13\/six-critical-attack-vectors-to-watch-out-for-in-your-data-centre\/","title":{"rendered":"Six critical attack vectors to watch out for in your data centre"},"content":{"rendered":"\n<p><em>Data centres can be considered a silver-bullet to a successful hack if an attacker gets their hands on the data they contain. Matt Walmsley, EMEA Director, Vectra, highlights the most critical attack vectors that sophisticated attackers tend to use against data centres.  <\/em><\/p>\n\n\n\n<p>Data centres and the wealth of information they contain, represent a tantalising prize for attackers. But unless the attacker gets lucky and finds an Internet-facing vulnerability, directly compromising a data centre takes a significant amount of effort and planning. <\/p>\n\n\n\n<p>As a result, cyberattacks that target data centres tend to be patient, mature operations that emphasise persistence and require flying below the radar of security teams. From our experience, here are the six most critical attack vectors and techniques that sophisticated cyberattackers use against data centres.<\/p>\n\n\n\n<p><strong>Co-opting administrative access <\/strong><\/p>\n\n\n\n<p>Administrators have unparalleled access to the data centre and as a\nresult are natural targets for attackers. Administrative protocols can give\nattackers backdoor access into the data centre without the need to directly\nexploit an application vulnerability. And by using standard admin tools such as\nSSH, Telnet or RDP, attackers can easily blend in with normal admin traffic. <\/p>\n\n\n\n<p><strong>Closing the local authentication loophole <\/strong><\/p>\n\n\n\n<p>In addition to the standard paths utilised by administrators, many data centres rely on local authentication options, that can be used in an emergency, to access the hosts and workloads they need to manage. However, these local authentication options are not logged and the same login credentials are often shared across hosts and workloads for the sake of simplicity. When attackers find the credentials by compromising an administrator, they can silently access the data centre without fear of their activity being logged. <\/p>\n\n\n\n<p><strong>The administrative hardware backdoor<\/strong><\/p>\n\n\n\n<p>Local authentication offers an example of a backdoor that\nadministrators \u2014 and attackers \u2014 can use to gain access to a data centre.\nHowever, there are other examples that take the same approach and extend it\ndeeper into the hardware. <\/p>\n\n\n\n<p>While the data centre is synonymous with virtualisation, the virtualised environments and resources still need to run on physical hardware. Virtual disks are ultimately dependent on physical disks and the physical disks run in physical servers. Physical servers likewise have their own management planes designed for lights-out and out-of-band management. The management planes have their own management protocols, power, processors and memory, which allow admins to mount disks and re-image servers even when the main server is powered off. <\/p>\n\n\n\n<p>These actions are often performed via protocols such as the\nIntelligent Platform Management Interface (IPMI). While many hardware vendors\nhave their own branded versions of IPMI \u2014 such as Dell iDRAC or HPE Integrated\nLights-Out (ILO) \u2014 they are all based on IPMI and perform the same functions. <\/p>\n\n\n\n<p>IPMI and its related protocols have well-documented security weaknesses and are often slow to receive updates and fixes. Additionally, there is currently a worrying 92,400 hosts\u2019 IPMI interfaces exposed to the Internet. The combination of IPMI vulnerabilities and its immense power make it a major attack vector for bad actors that are trying to subvert the security of the data centre.<\/p>\n\n\n\n<p><strong>Advanced attackers aim low <\/strong><\/p>\n\n\n\n<p>Unfortunately, hardware problems in the data centre don\u2019t end with IPMI. Advanced attackers, including nation-states, increasingly target physical servers, routers, switches and even firewalls. At a fundamental level, the attackers use rootkits that sit below the level of the operating system, making them extremely difficult to detect using traditional methods.<\/p>\n\n\n\n<p>These techniques allow attackers to infect the very devices that\nare trusted and charged with protecting the network, and then use those devices\nto launch attacks deeper into the network. <\/p>\n\n\n\n<p><strong>Keeping an eye on data <\/strong><\/p>\n\n\n\n<p>The ultimate goal of most attacks is to steal data. Depending on\ntheir needs and skill level, attackers can use a variety of approaches to\nsmuggle data out of the data centre. The most obvious approach involves moving\ndata in bulk out of the data centre, either directly to the Internet or to an\nintermediate staging area in the campus network. <\/p>\n\n\n\n<p>Subtle attackers may attempt to stay low-and-slow by patiently\nexfiltrating data at rates that are less likely to be noticed or arouse\nsuspicion. Efforts can also be made to obscure data exfiltration in hidden\ntunnels within normally allowed traffic, such as HTTP, HTTPS or DNS traffic.<\/p>\n\n\n\n<p><strong>Blending physical and virtual context <\/strong><\/p>\n\n\n\n<p>Data centres are unique to their own organisations and vary based\non applications and how users interact with them. The most common type of data centre\ntoday is the private enterprise data centre. Attacks against these data centres\nare typically extensions of attacks against the larger enterprise. <\/p>\n\n\n\n<p>For example, attackers may have initially compromised an employee laptop via a phishing email or social engineering. Next, attackers typically look to establish persistence within the network by spreading from the initial victim to other hosts or devices. To control the ongoing attack, attackers will plant backdoors or hidden tunnels to communicate back and forth from inside the network. Over time, attackers will map out the internal network, identify valuable resources and compromise devices and user credentials along the way. <\/p>\n\n\n\n<p>The most coveted stolen asset for an attacker is administrator\ncredentials because they ensure near autonomy inside the victim\u2019s network.\nAdministrator credentials are particularly essential for data centre attacks,\nsince administrators are often the only individuals who can access data en masse.<\/p>\n\n\n\n<p>The key point is that an attack is typically at a mature stage by\nthe time it reaches a private data centre. The hidden command-and-control\ntraffic, the reconnaissance, the lateral movement and the compromise of user\nand admin credentials are all prerequisites that lead up to the intrusion into\nthe data centre.<\/p>\n\n\n\n<p><strong>Conclusion <\/strong><\/p>\n\n\n\n<p>While most data centre security has focused on protecting the\nvirtualised layers of the data centre and micro-segmentation, real-world\nattackers are increasingly subverting the physical infrastructure that the data\ncentre depends on. <\/p>\n\n\n\n<p>The use of advanced attacker detection models that expose hidden attacks against application, data and virtualisation layers in the data centre, as well as the underlying physical infrastructure, will enable security teams to address critical vulnerabilities at every layer of the virtualised data centre, even when attackers use legitimate services and protocols for their illegitimate actions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data centres can be considered a silver-bullet to a successful hack if an attacker gets their hands on the data they contain. Matt Walmsley, EMEA Director, Vectra, highlights the most critical attack vectors that sophisticated attackers tend to use against data centres. Data centres and the wealth of information they contain, represent a tantalising prize [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":45582,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,13],"tags":[],"class_list":["post-45579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-top-stories"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/45579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=45579"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/45579\/revisions"}],"predecessor-version":[{"id":45581,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/45579\/revisions\/45581"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/45582"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=45579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=45579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=45579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}