Information Security of Data Centers

Information Security of Data Centers
This is how the monitoring center located in Moscow, NORD-2 Data Center, looks.

You have read more than once about the measures taken to ensure Information Security (IS). Any self-respecting IT specialist can easily name 5-10 IS rules. Cloud4Y, however, offers to talk about the information security of data centers.

In ensuring the information security of the data center, the most 'protected' objects are:

  • information resources (data);
  • processes of collecting, processing, storing, and transmitting information;
  • system users and support staff;
  • the information infrastructure, including technical and software tools for processing, transmitting, and displaying information, as well as information exchange channels, information protection systems, and facilities.

The area of responsibility of the data center depends on the model of services provided (IaaS/PaaS/SaaS). See the picture below for how this looks:

Information Security of Data Centers
The scope of the data center's security policy depending on the model of services provided

A crucial part of developing an information security policy is building a model of threats and violators. What can pose a threat to the data center?

  1. Adverse events of natural, technogenic, and social nature
  2. Terrorists, criminal elements, etc.
  3. Dependence on suppliers, vendors, partners, clients
  4. Failures, malfunctions, destruction, damage to software and hardware
  5. Data center employees implementing IS threats using the legally granted rights and powers (internal IS violators)
  6. Data center employees implementing IS threats beyond their legally granted rights and powers, as well as individuals not related to the data center staff attempting unauthorized access and unauthorized actions (external IS violators)
  7. Non-compliance with the requirements of supervisory and regulatory bodies, current legislation

Risk analysis — identifying potential threats and assessing the scale of the consequences of their realization — will help to correctly select priority tasks that data center information security specialists should address and plan budgets for the purchase of technical and software tools.

Security is a continuous process that includes the stages of planning, implementation and operation, monitoring, analysis, and improvement of the information security system. To create information security management systems, the so-called "Deming cycle».

An important part of security policies is the distribution of roles and responsibilities among staff for their implementation. Policies should be regularly reviewed in light of changes in legislation, new threats, and emerging protective measures. And of course, requirements for information security should be communicated to the staff and training should be conducted.

Organizational measures

Some experts are skeptical about "paper" security, considering practical skills to counter hacking attempts as paramount. Real-world experience in ensuring information security in banks suggests otherwise. Information security specialists may have excellent expertise in identifying and mitigating risks, but if the staff at the data center does not follow their instructions, everything will be in vain.

Security typically does not generate revenue but only minimizes risks. Therefore, it is often viewed as something obstructive and secondary. And when security specialists start to protest (which they have every right to do), conflicts often arise with staff and operational unit managers.

The existence of industry standards and regulatory requirements helps security professionals assert their positions in negotiations with management, while approved information security policies, provisions, and regulations allow them to enforce compliance from staff regarding the outlined requirements, laying the groundwork for implementing often unpopular decisions.

Protection of premises

When a data center provides colocation services, physical security and access control to client equipment become paramount. Enclosures (fenced-off areas of the hall) monitored by the client and restricted access for data center staff are utilized for this purpose.

In government data centers with physical security, things were quite good at the end of the last century. There was a pass regime, access control to premises, even without computers and video cameras, and fire suppression systems that would automatically release freon in case of fire in the machine room.

Today, physical security is ensured even better. Access control and management systems (ACMS) have become intelligent, and biometric methods of restricting access are being implemented.

Fire suppression systems have become safer for personnel and equipment, including systems for inhibiting, isolating, cooling, and hypoxic exposure to the fire zone. Alongside mandatory fire protection systems, data centers often use aspirating smoke detection systems for early fire detection.

To protect data centers from external threats—fires, explosions, building collapses, flooding, and corrosive gases—security rooms and safes have been used to protect server equipment from almost all external damaging factors.

The weak link is the human.

Smart video surveillance systems, volumetric tracking sensors (acoustic, infrared, ultrasonic, microwave), and ACMS have reduced risks, but they haven't solved all problems. These tools won't help, for instance, when authorized individuals in the data center carrying the right tools inadvertently cause an issue. And, as is often the case, an accidental snag can bring maximum trouble.

The operation of a data center can be affected by unauthorized use of its resources by personnel, such as illegal mining. In these cases, Data Center Infrastructure Management (DCIM) systems can help.

Personnel also need protection, as humans are often called the most vulnerable link in the protection system. Targeted attacks by professional criminals most often begin with the use of social engineering methods. Often, the most secure systems fail or are compromised after someone clicks/downloads/does something somewhere. Such risks can be minimized by training personnel and implementing best practices in information security.

Protection of Engineering Infrastructure

Traditional threats to data center operations include power outages and cooling system failures. These threats have become familiar and methods to combat them have been developed.

A new trend is the widespread implementation of 'smart' equipment integrated into a network: managed UPS systems, intelligent cooling and ventilation systems, various controllers, and sensors connected to monitoring systems. When modeling data center threats, one should not forget the possibility of an attack on the infrastructure network (and possibly on the associated IT network of the data center). The situation is complicated by the fact that some equipment (such as chillers) may be located outside the data center, for instance, on the roof of a rented building.

Protection of Communication Channels

If the data center provides services not only in a colocation model, it will need to address cloud protection. According to Check Point, last year, 51% of organizations worldwide faced attacks on cloud structures. DDoS attacks halt business operations, ransomware demands payment, and targeted attacks on banking systems lead to the theft of funds from correspondent accounts.

The threats of external intrusions worry data center information security specialists. Distributed attacks aimed at halting service provision are particularly relevant for data centers, as well as threats of hacking, data theft, or alteration of information contained in virtual infrastructures or storage systems.

Modern systems with features for detecting and neutralizing malicious code, application control, and the capability to incorporate Threat Intelligence proactive protection technology serve to protect the external perimeter of the data center. In some cases, intrusion prevention systems (IPS) are deployed with automatic adjustment of the signature set to fit the parameters of the protected environment.

To protect against DDoS attacks, Russian companies typically use external specialized services that redirect traffic to other nodes and filter it in the cloud. Protection on the operator's side is much more effective than on the client's side, and data centers act as intermediaries in selling these services.

Data centers are also susceptible to internal DDoS attacks: an attacker infiltrates poorly protected servers of a company using colocation to host its equipment, and from there conducts a Denial of Service attack via the internal network on other clients of the data center.

Attention to Virtual Environments

The specifics of the protected object must be considered—utilization of virtualization tools, the dynamic nature of IT infrastructure changes, and interconnected services, where a successful attack on one client may threaten the security of others. For instance, by breaching the frontend Docker while operating in PaaS based on Kubernetes, an attacker can immediately acquire all password information and even access to the orchestration system.

Products provided through a service model have a high degree of automation. To avoid disrupting business, the implemented information protection measures must have a similar level of automation and horizontal scaling. Scaling should be ensured at all levels of information security, including automation of access control and rotation of access keys. The task of scaling functional modules that inspect network traffic stands apart.

For example, filtering network traffic at the application, network, and session levels in data centers with a high degree of virtualization should be performed at the hypervisor network module level (for example, VMware's Distributed Firewall) or by creating service chains (virtual firewalls from Palo Alto Networks).

If there are vulnerabilities at the virtualization level of computing resources, efforts to create a comprehensive information security system at the platform level will be ineffective.

Information Protection Levels in Data Centers

The general approach to protection is to use integrated, multi-layered information security systems, including macrosegmentation at the firewall level (allocating segments for various business functional areas), microsegmentation based on virtual firewalls, or tagging traffic groups (user roles or services) defined by access policies.

The next level involves detecting anomalies within and between segments. Traffic dynamics are analyzed to identify possible malicious activities, such as network scanning, DDoS attack attempts, and data downloading, for instance, by slicing database files and outputting them through sporadically appearing sessions over extended intervals. Data centers handle massive amounts of traffic, so advanced search algorithms must be employed for anomaly detection, without packet inspection. It is crucial to recognize not only indicators of malicious and abnormal behavior but also the operation of malware even in encrypted traffic without decrypting it, as proposed in Cisco's solutions (Stealthwatch).

The final frontier is protecting the endpoints of the local network: servers and virtual machines, for example, through agents installed on the endpoints (virtual machines) that analyze input-output, deletion, copying, and network activities and transmit data to the cloud, where intensive computational analyses are conducted. There, analysis is performed using Big Data algorithms, machine logic trees are built, and anomalies are identified. The algorithms self-learn based on the vast amounts of data supplied by a global network of sensors.

It is also possible to operate without installing agents. Modern information protection tools should be agentless and integrated into operating systems at the hypervisor level.
The mentioned measures significantly reduce information security risks, but they may not be sufficient for data centers that support automation of highly hazardous production processes, such as nuclear power plants.

Regulatory requirements

Depending on the information processed, the physical and virtualized infrastructures of the data center must meet different security requirements as defined by laws and industry standards.

Laws such as the Federal Law "On Personal Data" (152-FZ) and the recently enacted "On the Security of Critical Information Infrastructure of the Russian Federation" (187-FZ) have come into play— the prosecutor's office is already interested in the progress of its implementation. Debates about data centers being classified as subjects of critical information infrastructure are still ongoing, but data centers wishing to provide services to such subjects will likely have to comply with the new regulatory requirements.

Data centers hosting government information systems will face significant challenges. According to the Government Resolution of the Russian Federation dated May 11, 2017, No. 555, issues of information security must be resolved before the GIS is put into commercial operation. Any data center that wishes to host a GIS must comply with the regulators' requirements in advance.

Over the past 30 years, data center security systems have made significant strides: from simple physical protection systems and organizational measures, which are still relevant, to complex intelligent systems increasingly incorporating elements of artificial intelligence. However, the essence of the approach has not changed. The most advanced technologies will not help without organizational measures and staff training, just as paperwork cannot replace software and technical solutions. Data center security cannot be ensured once and for all; it is a constant daily effort to identify priority threats and comprehensively address emerging issues.

What else is useful to read in the blog Cloud4Y

→ Setting up top in GNU/Linux
→ Penetration testers on the front lines of cybersecurity
→ The journey of artificial intelligence from a fantastic idea to a scientific field
→ 4 ways to save on cloud backups
→ Muddy history

Subscribe to our Telegram-channel, so you don't miss our next article! We write no more than twice a week and only when necessary. We also remind you that you can test for free Cloud4Y's cloud solutions.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster