Generalized Single Packet Authorization For Cloud Computing Environments

ShmooCon IX - 2013

Presented by: Michael Rash
Date: Saturday February 16, 2013
Time: 12:00 - 12:50
Location: Regency A
Track: Build It!

Cloud Computing environments such as those provided by Amazon and Google can be your passport to powerful computing resources without having to worry about typical provisioning and hardware issues, but if the recent Microsoft RDP vulnerability (CVE-2012-0002) is any guide, security is still a real problem.

This talk will present techniques to generalize Single Packet Authorization (SPA) as implemented by the "fwknop" project to most Cloud Computing environments subject to certain requirements. Cloud providers usually implement their own network ACL capabilities among other security measures to maintain data separation between clients, and yet they also need to allow functional remote access to individual cloud images via ssh or other administrative protocol. This is where fwknop comes in. Although fwknop does not integrate directly with proprietary cloud provider network ACL's, this does not present a problem, and as proof a functioning deployment of fwknop within Amazon's Virtual Private Cloud (VPC) environment will be demonstrated as a protection against the RDP vulnerability. Further, in the case of VPC networks, contrary to the typical Amazon VPC NAT model, such a deployment requires the use of only one EC2 Elastic IP in order for SPA to facilitate access to any internal system.

Michael Rash

Michael Rash holds a Master's Degree in applied mathematics with a concentration in computer security from the University of Maryland, and is author of the book "Linux Firewalls: Attack Detection and Response with iptables, psad, and fwsnort" published by No Starch Press. Michael works professionally as a Security Architect for Enterasys Networks, Inc., and previously worked as a Security Architect for G2, Inc. He is a frequent speaker at computer security conferences, and is the founder of cipherdyne.org, an organization dedicated to open source security technologies. Michael is the lead developer of the psad, fwsnort, and fwknop projects.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats