Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity

    Properly Securing OpenStack Cloud Core Focus at Summit

    Written by

    Sean Michael Kerner
    Published May 13, 2014
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      ATLANTA—At multiple sessions at the OpenStack Summit here, developers and security researchers provided insight and details on properly securing an OpenStack cloud deployment.

      Security is one of the most often cited barriers to cloud adoption, but experts speaking at the summit don’t see it as an obstacle.

      Enterprises really should look at cloud security from the opposite viewpoint, said Bryan Payne, director of security research at Nebula. “Cloud is an interesting opportunity to do really good security work,” Payne said. “The cloud has orchestration tools that allow you to roll out consistent configuration and update your software consistently, as well.”

      In a cloud deployment, there is also known hardware and software, and by having a known base, it is easier for enterprises to take the right steps to secure the cloud infrastructure, Payne said. “When rolling out infrastructure for cloud, enterprises have control of what is in place and that’s a security dream,” he said.

      A typical security function is to look at a system to see what is different from what is expected. As such, the more an organization knows about its systems, the more it can detect any divergence.

      “So if you have an orchestration system and you know what your hardware and software is, then you’ve got a good platform for security,” Payne said.
      To ensure OpenStack cloud platform security, Payne advocates making sure that there is a separation of concerns such that there is a different logical network for outside the cloud versus the internal cloud network.

      Payne also recommends the use of Transport Layer Security (TLS) to be configured for all OpenStack deployments. TLS provides encryption for data in motion across a network.

      In a cloud deployment, beyond just the actual infrastructure that provides compute, there are also guests that run on top of the cloud in virtual machines (VMs).

      One of the potential cloud security risks outlined by Payne is known as a VM breakout. “What a VM breakout means is I can run code in an instance that will exploit something in the virtualization layer that will then let me run code on the host operating system itself,” Payne said.

      In a VM breakout situation, an attacker could potentially get access to other VMs running in a cloud. Payne emphasized that there are steps organizations can take to limit the risk of VM breakouts. Among those steps is the proper use of SELinux, or Security Enhanced Linux, which provides mandatory access control rules for processes and applications on a system.

      “Getting the cloud up and running is step one,” Payne said. “Securing the cloud is step two, and it is often harder than step one.”

      Keystone Identity Service

      One primary control point for security in an OpenStack cloud is the Keystone identity service.

      Organizations should take steps to secure Keystone, Keith Newstadt, cloud services architect at Symantec, explained during a session at the summit.

      As an identity provider, Keystone is likely to be a target for brute-force attacks, he explained, in which criminals attempt to force their way into a system by using automated username and password lists in an attempt to gain access.

      One way to protect Keystone against brute-force attacks is to introduce rate-limiting for user log-ins, Newstadt said. With rate limiting, only a certain number of user log-in requests can come into the system in a given time period.

      Organizations also need to be able to blacklist malicious IP addresses as well as detect and block anomalous patterns and user behaviors, he said.

      “Keystone is the gatekeeper for OpenStack,” Newstadt said. “Credentials are the keys to the kingdom, so protect them.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×