Forum for Science, Industry and Business

Sponsored by:     3M 
Search our Site:

 

Cloud computing: gaps in the “cloud” - Massive security flaws at Amazon Web Services discovered

24.10.2011
RUB researchers present hack at the ACM Cloud Computing Security Workshop in Chicago

Researchers from Ruhr-University Bochum have found a massive security gap at Amazon Cloud Services. Using different methods of attack (signature wrapping and cross site scripting) they tested the system which was deemed “safe”.

“Based on our research results, Amazon confirmed the security gaps and closed them immediately”, said Prof. Dr. Jörg Schwenk, chair for network and data security at the RUB. Amazon Web Services (AWS) offers its customers cloud computing services and hosts, among others, services like Twitter, Second Life and 4Square.

Cloud computing could be the major computing paradigm of tomorrow. The idea of processing and storing software and data in a cheap external infrastructure is becoming increasingly popular. The fact that these services are by no means as secure as promised is now demonstrated by the research results of Prof. Schwenk and his staff.

Concentrated computing power

The “Cloud” is a collection of many virtual servers with concentrated computing power. Outsourcing to cloud computing has many advantages for professional users: they can rent storage and server capacity short term on demand. The service is invoiced, for example, according to the usage period, and the customer saves the cost of purchasing his own software and hardware. Up to now, the discussion about cloud computing has above all been dominated by the inability to comply with legal requirements. “Real” attacks were, however, less in the public eye.

Search for weak points

“A major challenge for cloud providers is ensuring the absolute security of the data entrusted to them, which should only be accessible by the clients themselves,” said Prof. Schwenk, who set out with his staff to seek weak points. They have found what they were looking for: Juraj Somorovsky, Mario Heiderich and Meiko Jensen tested the security concept of the cloud provider Amazon Web Services.

XML signature wrapping attacks

“Using different kinds of XML signature wrapping attacks, we succeeded in completely taking over the administrative rights of cloud customers”, said Juraj Somorovsky. “This allowed us to create new instances in the victim’s cloud, add or delete images.” The researchers suspect that many cloud offers are susceptible to signature wrapping attacks, since the relevant web service standards make performance and security incompatible. “We are working on a high-performance solution, however, that no longer has any of the known security gaps”, said Prof. Dr. Jörg Schwenk.

Cross site scripting attacks

In addition, the researchers found gaps in the AWS interface and in the Amazon shop which were ideally suited for smuggling in executable script code - what are termed cross-site scripting attacks. With alarming consequences: “We had free access to all customer data, including authentication data, tokens, and even plain text passwords” said Mario Heiderich. The researcher see the common login as a complex potential danger: “It's a chain reaction. A security gap in the complex Amazon shop always also directly causes a gap in the Amazon cloud.”

Private Clouds also vulnerable

In contrast to public belief, Private Clouds are also vulnerable to the aforementioned attacks: Eucalyptus, an open source project widely used to implement Cloud solutions within companies, did expose the same weaknesses. “A rough classification of cloud technologies cannot replace a thorough security investigation”, states Prof. Schwenk.

Security gaps closed

“Critical services and infrastructures are making increasing use of cloud computing”, explained Juraj Somorovsky. According to industry estimates, the turnover of European cloud services is set to more than double in the next four years – from around 68 billion Euros in 2010 to about 148 billion in 2014. “Therefore it is essential that we recognise the security gaps in cloud computing and avoid them on a permanent basis.” Industry took immediate action: “On our advice, Amazon and Eucalyptus confirmed the security gaps and closed them immediately”.

Further information

Prof. Dr. Jörg Schwenk, Faculty of Electrical Engineering and Information Sciences at the RUB, Chair for Network and Data Security, Tel. +49 234 32 26692

joerg.schwenk@rub.de

Editor: Jens Wylkop

Dr. Josef König | idw
Further information:
http://www.ruhr-uni-bochum.de/

More articles from Information Technology:

nachricht NIST-led team develops tiny low-energy device to rapidly reroute light in computer chips
15.11.2019 | National Institute of Standards and Technology (NIST)

nachricht Fraunhofer Radio Technology becomes part of the worldwide Telecom Infra Project (TIP)
14.11.2019 | Fraunhofer-Institut für Angewandte Informationstechnik FIT

All articles from Information Technology >>>

The most recent press releases about innovation >>>

Die letzten 5 Focus-News des innovations-reports im Überblick:

Im Focus: Machine learning microscope adapts lighting to improve diagnosis

Prototype microscope teaches itself the best illumination settings for diagnosing malaria

Engineers at Duke University have developed a microscope that adapts its lighting angles, colors and patterns while teaching itself the optimal...

Im Focus: Small particles, big effects: How graphene nanoparticles improve the resolution of microscopes

Conventional light microscopes cannot distinguish structures when they are separated by a distance smaller than, roughly, the wavelength of light. Superresolution microscopy, developed since the 1980s, lifts this limitation, using fluorescent moieties. Scientists at the Max Planck Institute for Polymer Research have now discovered that graphene nano-molecules can be used to improve this microscopy technique. These graphene nano-molecules offer a number of substantial advantages over the materials previously used, making superresolution microscopy even more versatile.

Microscopy is an important investigation method, in physics, biology, medicine, and many other sciences. However, it has one disadvantage: its resolution is...

Im Focus: Atoms don't like jumping rope

Nanooptical traps are a promising building block for quantum technologies. Austrian and German scientists have now removed an important obstacle to their practical use. They were able to show that a special form of mechanical vibration heats trapped particles in a very short time and knocks them out of the trap.

By controlling individual atoms, quantum properties can be investigated and made usable for technological applications. For about ten years, physicists have...

Im Focus: Images from NJIT's big bear solar observatory peel away layers of a stellar mystery

An international team of scientists, including three researchers from New Jersey Institute of Technology (NJIT), has shed new light on one of the central mysteries of solar physics: how energy from the Sun is transferred to the star's upper atmosphere, heating it to 1 million degrees Fahrenheit and higher in some regions, temperatures that are vastly hotter than the Sun's surface.

With new images from NJIT's Big Bear Solar Observatory (BBSO), the researchers have revealed in groundbreaking, granular detail what appears to be a likely...

Im Focus: New opportunities in additive manufacturing presented

Fraunhofer IFAM Dresden demonstrates manufacturing of copper components

The Fraunhofer Institute for Manufacturing Technology and Advanced Materials IFAM in Dresden has succeeded in using Selective Electron Beam Melting (SEBM) to...

All Focus news of the innovation-report >>>

Anzeige

Anzeige

VideoLinks
Industry & Economy
Event News

First International Conference on Agrophotovoltaics in August 2020

15.11.2019 | Event News

Laser Symposium on Electromobility in Aachen: trends for the mobility revolution

15.11.2019 | Event News

High entropy alloys for hot turbines and tireless metal-forming presses

05.11.2019 | Event News

 
Latest News

Scientists first to develop rapid cell division in marine sponges

21.11.2019 | Life Sciences

First detection of gamma-ray burst afterglow in very-high-energy gamma light

21.11.2019 | Physics and Astronomy

Research team discovers three supermassive black holes at the core of one galaxy

21.11.2019 | Physics and Astronomy

VideoLinks
Science & Research
Overview of more VideoLinks >>>