|By Jason Thompson||
|May 13, 2013 02:30 PM EDT||
From its origin in 1995, SSH, the secure shell data-in-transit protocol, has been used the world over as a method to transfer data between machines, as well as a tool to provide remote administrator access. Some variation of the protocol is packaged free in every version of Unix, Mac OS and Linux. Recently, its use has grown exponentially in Windows operating systems as well. While the exact number of worldwide SSH deployments is unknown, it is estimated that nearly half of all of the World Wide Web uses SSH, making it a virtually mandatory service in the world of network security.
After nearly two decades of use, SSH has succeeded in securing billions of business transactions without any faults of the protocol itself, demonstrating its dependability as a security solution. On the other hand, the evolution of cyber-threat ability requires that organizations take a careful look at how they manage their SSH environments.
New Threats Requires New Thinking
Organizations rely on SSH to securely transmit immense amounts of sensitive data - such as banking information, healthcare records, classified intelligence and other personally identifiable material. Therefore, to attackers and malicious insiders, SSH is a barrier protecting vital corporate data.
However, because this barrier is inherently unbreakable, attackers must pursue alternate routes around the secure shell; to do this, they must focus instead on the mismanagement of SSH keys.
Network administrators establish a trust-based relationship between a user's computer and server by implementing a cryptographic key pair. The connection is established and managed within the corporation's networking system. Unfortunately, many of these systems are outdated and often cannot search for or pinpoint the location of trust-based relationships. Therefore, the search for keys must be done manually. Given a network often houses keys numbering in the hundreds of thousands, it is too easy to lose track of these trust relationships.
This leads to a disheartening conclusion: if an attacker inside or outside the company walls can discover a key, they can essentially imitate any authorized user and gain access to any sensitive data freely.
Improper management of SSH keys presents a prominent vulnerability available for exploitation by attackers looking to gain access to sensitive information.
A study performed recently on some of the largest corporations in the world produced shocking results deriving from the lack of judgment and knowledge of the importance of key management:
- Roughly 10 percent of all SSH user keys offer root access, creating a major compliance and security issue
- Having key-based access grants be essentially permanent leaves the network vulnerable to attack and is in direct violation of SOX, PCI and FISMA requirements for proper termination of access
- Enterprises rarely know what each key is used for, presenting not only a security risk, but also a business continuity risk
- Many SSH keys that grant access to critical servers are no longer usable
- Man-in-the-middle attacks are made simple when organizations share the same SSH host keys across thousands of computers
- Some organizations permit administrators to create or delete SSH user keys at will - without approvals or control - essentially granting unfettered, permanent access to systems and people
- Very few organizations ever rotate SSH user keys, or even remove them when a user leaves or an application is decommissioned
Today, advanced threat vectors are very real and are becoming more commonplace. It is more imperative than ever for organizations without proper SSH key management protocols to restructure their approach to key management, or otherwise face serious consequences.
Organizations must also understand that federal compliance standards such as SOX, NIST, PCI and HIPAA all entail huge fines if they do not exercise the utmost control over access to sensitive network information. With 20,000 servers, a typical number for many large organizations, the cost of manual SSH key management is $40 million over ten years. When the reputation damage caused by a security breach is factored in, organizations have a slew of incentives to repair organizational SSH key management practices.
Key Management Practices Must Change
Fortunately, access control issues in secure shell environments are not a result of any vulnerabilities or flaws in the SSH protocol itself. Rather, the security and compliance risks identified are caused by:
- A reluctance on the part of auditors to flag issues for which they don't have effective answers
- Insufficient resources and time to dig into the issue to gain understanding or develop answers
- Years of lack of clear guidelines or policies relating to SSH key management
- Unintentionally ignoring of the scope and implications of the problem
- A lack of guidelines and good tools early on for solving key management issues
- The focus of the access management field on interactive users without addressing automated access
Why then, has this problem remained in the dark, particularly given the possible consequences? Given its complexity, SSH key management has remained buried in the domain of system administrators. System administrators usually don't control the entire IT environment; instead, they only see the area under their immediate jurisdiction. It must also be taken into account that IT administrators are some of the company's busiest employees, and as such, they may not have had time to recognize and investigate the issue. In addition, because managers and executives are disconnected from the problem, and its underlying consequences, no action is taken and the high risk remains present.
Best Practices for Dealing with SSH Key Mismanagement
The process needed to fix the issue involves several teams within IT operations. The possible liability and compliance risks demand the awareness and buy-in from executive management as well.
Some best practices to get rid of the dangers include:
- Enforcing proper approvals for all key setups
- Discovering all existing users, public and private keys, and mapping trust between machines and users
- Restricting where each key has access and what commands can be executed using the key
- Rotating keys regularly, so that copied keys cease to work and proper termination of access can be ensured
- Monitoring the environment to determine which keys are actually used, and removing keys no longer in use
- Automating key setups and key removals; eliminating manual work and human errors. This step slashes the number of administrators needed for key setups from possibly several hundred to only a few highly trusted administrators
To further reduce risk, proper key management should involve the establishment of internal boundaries within the organization. The organization should strictly control what key-based trust relationships can cross which boundaries, while enforcing iron-clad IP address and "forced command" restrictions for all authorized keys involving trust relationships crossing such boundaries.
While SSH is widely considered the benchmark for data-in-transit security, the current threat landscape requires organizations to rethink how they are managing access to their encrypted networks. The SSH protocol has done a great job in protecting data-in-transit at a tactical level, but an ever-increasing number of threat vectors means effective management of the SSH environment is critical to secure network operations. Best security practices like the ones identified above will position your enterprise to prepare for security threats and new compliance mandates before they occur.
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
Dec. 8, 2016 10:30 AM EST Reads: 7,292
An IoT product’s log files speak volumes about what’s happening with your products in the field, pinpointing current and potential issues, and enabling you to predict failures and save millions of dollars in inventory. But until recently, no one knew how to listen. In his session at @ThingsExpo, Dan Gettens, Chief Research Officer at OnProcess, discussed recent research by Massachusetts Institute of Technology and OnProcess Technology, where MIT created a new, breakthrough analytics model for ...
Dec. 8, 2016 10:30 AM EST Reads: 520
Successful digital transformation requires new organizational competencies and capabilities. Research tells us that the biggest impediment to successful transformation is human; consequently, the biggest enabler is a properly skilled and empowered workforce. In the digital age, new individual and collective competencies are required. In his session at 19th Cloud Expo, Bob Newhouse, CEO and founder of Agilitiv, drew together recent research and lessons learned from emerging and established compa...
Dec. 8, 2016 10:00 AM EST Reads: 978
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Dec. 8, 2016 09:45 AM EST Reads: 1,917
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
Dec. 8, 2016 09:30 AM EST Reads: 590
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Dec. 8, 2016 09:15 AM EST Reads: 928
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
Dec. 8, 2016 08:45 AM EST Reads: 887
Businesses and business units of all sizes can benefit from cloud computing, but many don't want the cost, performance and security concerns of public cloud nor the complexity of building their own private clouds. Today, some cloud vendors are using artificial intelligence (AI) to simplify cloud deployment and management. In his session at 20th Cloud Expo, Ajay Gulati, Co-founder and CEO of ZeroStack, will discuss how AI can simplify cloud operations. He will cover the following topics: why clou...
Dec. 8, 2016 08:30 AM EST Reads: 968
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2017 New York. The 20th Cloud Expo and 7th @ThingsExpo will take place on June 6-8, 2017, at the Javits Center in New York City, NY. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Internet to enable us all to im...
Dec. 8, 2016 08:30 AM EST Reads: 830
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
Dec. 8, 2016 08:15 AM EST Reads: 2,038
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
Dec. 8, 2016 07:00 AM EST Reads: 1,716
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Dec. 8, 2016 06:30 AM EST Reads: 1,140
Internet of @ThingsExpo has announced today that Chris Matthieu has been named tech chair of Internet of @ThingsExpo 2017 New York The 7th Internet of @ThingsExpo will take place on June 6-8, 2017, at the Javits Center in New York City, New York. Chris Matthieu is the co-founder and CTO of Octoblu, a revolutionary real-time IoT platform recently acquired by Citrix. Octoblu connects things, systems, people and clouds to a global mesh network allowing users to automate and control design flo...
Dec. 8, 2016 04:30 AM EST Reads: 748
With 15% of enterprises adopting a hybrid IT strategy, you need to set a plan to integrate hybrid cloud throughout your infrastructure. In his session at 18th Cloud Expo, Steven Dreher, Director of Solutions Architecture at Green House Data, discussed how to plan for shifting resource requirements, overcome challenges, and implement hybrid IT alongside your existing data center assets. Highlights included anticipating workload, cost and resource calculations, integrating services on both sides...
Dec. 8, 2016 04:00 AM EST Reads: 3,807
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Dec. 8, 2016 04:00 AM EST Reads: 1,063
Unless your company can spend a lot of money on new technology, re-engineering your environment and hiring a comprehensive cybersecurity team, you will most likely move to the cloud or seek external service partnerships. In his session at 18th Cloud Expo, Darren Guccione, CEO of Keeper Security, revealed what you need to know when it comes to encryption in the cloud.
Dec. 8, 2016 04:00 AM EST Reads: 4,821
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
Dec. 8, 2016 02:45 AM EST Reads: 1,311
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
Dec. 8, 2016 01:45 AM EST Reads: 1,417
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Dec. 8, 2016 12:30 AM EST Reads: 1,156
The Internet of Things (IoT) promises to simplify and streamline our lives by automating routine tasks that distract us from our goals. This promise is based on the ubiquitous deployment of smart, connected devices that link everything from industrial control systems to automobiles to refrigerators. Unfortunately, comparatively few of the devices currently deployed have been developed with an eye toward security, and as the DDoS attacks of late October 2016 have demonstrated, this oversight can ...
Dec. 8, 2016 12:15 AM EST Reads: 1,390