Experts Reveal Google Cloud Platform’s Blind Spot for Data Exfiltration Attacks

March 06, 2023Rabbi LakshmananCloud Computing / Data Security

Google cloud platform

Malicious attackers can leverage “poor” forensic visibility into Google Cloud Platform (GCP) to exfiltrate sensitive data, new research reveals.

“Unfortunately, GCP does not provide the necessary level of visibility into storage logs to enable effective forensic investigations, leaving organizations unaware of potential data exfiltration attacks.” Mitiga, a cloud incident response firm, said in a report.

This attack is based on the assumption that the attacker has control over the target organization’s identity and access management (IAM) entities through methods such as social engineering and has access to the GCP environment.

The crux of the problem is that GCP’s storage access logs do not provide adequate transparency regarding potential file access and read events, instead grouping them all together as a single “object get” activity.

“The same event is used for different types of access, such as reading files, downloading files, and copying files to external servers. [and] It’s reading the file’s metadata,” said Mitiga researcher Veronica Marinov.

This lack of distinction is primarily due to the lack of a way to distinguish between malicious and legitimate user activity, allowing attackers to collect sensitive data without being detected.

data exfiltration attack

In a hypothetical attack, an attacker could use Google’s command line interface (gsutil) to transfer valuable data from the victim’s organization’s storage bucket to an external storage bucket within the attacker’s organization.

Discover the latest malware evasion tactics and defense strategies

Ready to demystify the 9 most dangerous misconceptions about file-based attacks? Join our upcoming webinar and become a hero in the fight against patient zero infections and zero-day security events!

reserve a seat

Since then, Google has provided mitigation recommendations ranging from Virtual Private Cloud (VPC) Service Controls to restricting cloud resource requests using organization limit headers.

This disclosure was made when Sysdig discovered a sophisticated attack campaign called SCARLETEEL. It targets containerized environments to perform its own data and software theft.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *