Researchers from Ruhr-University Bochum have found a massive security gap at Amazon Cloud Services. Using different methods of attack (signature wrapping and cross site scripting) they tested the system which was deemed “safe”.
“Based on our research results, Amazon confirmed the security gaps and closed them immediately”, said Prof. Dr. Jörg Schwenk, chair for network and data security at the RUB. Amazon Web Services (AWS) offers its customers cloud computing services and hosts, among others, services like Twitter, Second Life and 4Square.
Cloud computing could be the major computing paradigm of tomorrow. The idea of processing and storing software and data in a cheap external infrastructure is becoming increasingly popular. The fact that these services are by no means as secure as promised is now demonstrated by the research results of Prof. Schwenk and his staff.
Concentrated computing power
The “Cloud” is a collection of many virtual servers with concentrated computing power. Outsourcing to cloud computing has many advantages for professional users: they can rent storage and server capacity short term on demand. The service is invoiced, for example, according to the usage period, and the customer saves the cost of purchasing his own software and hardware. Up to now, the discussion about cloud computing has above all been dominated by the inability to comply with legal requirements. “Real” attacks were, however, less in the public eye.
Search for weak points
“A major challenge for cloud providers is ensuring the absolute security of the data entrusted to them, which should only be accessible by the clients themselves,” said Prof. Schwenk, who set out with his staff to seek weak points. They have found what they were looking for: Juraj Somorovsky, Mario Heiderich and Meiko Jensen tested the security concept of the cloud provider Amazon Web Services.
XML signature wrapping attacks
“Using different kinds of XML signature wrapping attacks, we succeeded in completely taking over the administrative rights of cloud customers”, said Juraj Somorovsky. “This allowed us to create new instances in the victim’s cloud, add or delete images.” The researchers suspect that many cloud offers are susceptible to signature wrapping attacks, since the relevant web service standards make performance and security incompatible. “We are working on a high-performance solution, however, that no longer has any of the known security gaps”, said Prof. Dr. Jörg Schwenk.
Cross site scripting attacks
In addition, the researchers found gaps in the AWS interface and in the Amazon shop which were ideally suited for smuggling in executable script code - what are termed cross-site scripting attacks. With alarming consequences: “We had free access to all customer data, including authentication data, tokens, and even plain text passwords” said Mario Heiderich. The researcher see the common login as a complex potential danger: “It's a chain reaction. A security gap in the complex Amazon shop always also directly causes a gap in the Amazon cloud.”
Private Clouds also vulnerable
In contrast to public belief, Private Clouds are also vulnerable to the aforementioned attacks: Eucalyptus, an open source project widely used to implement Cloud solutions within companies, did expose the same weaknesses. “A rough classification of cloud technologies cannot replace a thorough security investigation”, states Prof. Schwenk.
Security gaps closed
“Critical services and infrastructures are making increasing use of cloud computing”, explained Juraj Somorovsky. According to industry estimates, the turnover of European cloud services is set to more than double in the next four years – from around 68 billion Euros in 2010 to about 148 billion in 2014. “Therefore it is essential that we recognise the security gaps in cloud computing and avoid them on a permanent basis.” Industry took immediate action: “On our advice, Amazon and Eucalyptus confirmed the security gaps and closed them immediately”.
Further informationProf. Dr. Jörg Schwenk, Faculty of Electrical Engineering and Information Sciences at the RUB, Chair for Network and Data Security, Tel. +49 234 32 26692
Editor: Jens Wylkop
Dr. Josef König | idw
New technology enables 5-D imaging in live animals, humans
16.01.2017 | University of Southern California
Fraunhofer FIT announces CloudTeams collaborative software development platform – join it for free
10.01.2017 | Fraunhofer-Institut für Angewandte Informationstechnik FIT
Researchers from the University of Hamburg in Germany, in collaboration with colleagues from the University of Aarhus in Denmark, have synthesized a new superconducting material by growing a few layers of an antiferromagnetic transition-metal chalcogenide on a bismuth-based topological insulator, both being non-superconducting materials.
While superconductivity and magnetism are generally believed to be mutually exclusive, surprisingly, in this new material, superconducting correlations...
Laser-driving of semimetals allows creating novel quasiparticle states within condensed matter systems and switching between different states on ultrafast time scales
Studying properties of fundamental particles in condensed matter systems is a promising approach to quantum field theory. Quasiparticles offer the opportunity...
Among the general public, solar thermal energy is currently associated with dark blue, rectangular collectors on building roofs. Technologies are needed for aesthetically high quality architecture which offer the architect more room for manoeuvre when it comes to low- and plus-energy buildings. With the “ArKol” project, researchers at Fraunhofer ISE together with partners are currently developing two façade collectors for solar thermal energy generation, which permit a high degree of design flexibility: a strip collector for opaque façade sections and a solar thermal blind for transparent sections. The current state of the two developments will be presented at the BAU 2017 trade fair.
As part of the “ArKol – development of architecturally highly integrated façade collectors with heat pipes” project, Fraunhofer ISE together with its partners...
At TU Wien, an alternative for resource intensive formwork for the construction of concrete domes was developed. It is now used in a test dome for the Austrian Federal Railways Infrastructure (ÖBB Infrastruktur).
Concrete shells are efficient structures, but not very resource efficient. The formwork for the construction of concrete domes alone requires a high amount of...
Many pathogens use certain sugar compounds from their host to help conceal themselves against the immune system. Scientists at the University of Bonn have now, in cooperation with researchers at the University of York in the United Kingdom, analyzed the dynamics of a bacterial molecule that is involved in this process. They demonstrate that the protein grabs onto the sugar molecule with a Pac Man-like chewing motion and holds it until it can be used. Their results could help design therapeutics that could make the protein poorer at grabbing and holding and hence compromise the pathogen in the host. The study has now been published in “Biophysical Journal”.
The cells of the mouth, nose and intestinal mucosa produce large quantities of a chemical called sialic acid. Many bacteria possess a special transport system...
10.01.2017 | Event News
09.01.2017 | Event News
05.01.2017 | Event News
17.01.2017 | Earth Sciences
17.01.2017 | Materials Sciences
17.01.2017 | Architecture and Construction