1
Public Cloud Data Center: Blind Spot for Security, Safe Haven for Cyberattackers P u b lic IT c l o u d s e r v i c e s g r o w i n g 5 x I T i n d u s t r y a s a w h o l e 155 million workloads will move to public cloud data centers Blind & Blinder The public cloud data center is even more of a blind spot than the traditional data center. Today most organizations lack the ability to detect an active attacker at work on the on-premise or private cloud network. Targeted attackers can gain access to the network and then work for months without fear of being discovered. Insiders are also hard to spot. Detecting attacker activity is even more rare in the public cloud Risks Stolen data (data breach) in the public cloud Manipulation of data in the cloud Launching point for DDoS attacks on other sites Defacement of company website Distributed Denial of Service (DDoS) attacks Ransomware attack on cloud data center Ransomware attack launched from cloud on on-prem or private data center Attacks using cloud servers as the entry point for on-prem or private cloud networks Egress point for an attack Attack affecting the availability of IaaS 1 2 3 4 5 6 7 8 9 10 IaaS is the fastest growing portion of the WW public cloud services market Ingress Egress Blind Spots Ingress Reconnaissance Egress Cloud infrastructure can act as an entry point for an attacker to gain access to an on-prem data center or network Undetected reconnaissance within the cloud data center Lateral Movement Undetected lateral movement within cloud data center New route for command & control (C&C) or data exfiltration LIGHTCYBER.COM (844) 560-7976

The Blind Spot in the Public Cloud Data Center

Embed Size (px)

Citation preview

Page 1: The Blind Spot in the Public Cloud Data Center

Public Cloud Data Center:Blind Spot for Security, Safe Haven

for Cyberattackers

Public IT cloud servic

es gr

owin

g 5x

IT in

dust

ry a

s a

who

le

155 millionworkloads will move to

public cloud data centers

Blind& Blinder

The public cloud data center is even more of a blind spot than the traditional data center. Today most organizations lack the ability to detect an active attacker at work on the on-premise or private cloud network. Targeted attackers can gain access to the network and then work for months without fear of being discovered. Insiders are also hard to spot. Detecting attacker activity is even more rare in the public cloud

RisksStolen data (data breach) in the public cloud

Manipulation of data in the cloud

Launching point for DDoS attacks on other sites

Defacement of company website

Distributed Denial of Service (DDoS) attacks

Ransomware attack on cloud data center

Ransomware attack launched from cloud on on-prem or private data center

Attacks using cloud servers as the entry point for on-prem or private cloud networks

Egress point for an attack

Attack affecting the availability of IaaS

1

2

3

4

5

6

7

8

9

10

IaaS is the fastest growing

portion of the WW public cloud

services market

Ingress

Egress

Blind SpotsIngress Reconnaissance

Egress

Cloud infrastructure can act as an entry point for an attacker to gain access to an on-prem data center or network

Undetected reconnaissance within the cloud data center

Lateral MovementUndetected lateral movement within cloud data center

New route for command & control (C&C) or data exfiltration

LIGHTCYBER.COM • (844) 560-7976