Dr Anton Chuvakin Blog (Original)

Security writing since the mid-2000s. New posts are mirrored from Anton on Security on Medium.

Cloud Security Monitoring!

Historical Archive Note: This post was originally published on the Gartner Blog Network on January 9, 2012 by Anton Chuvakin.
Original URL: http://blogs.gartner.com/anton-chuvakin/2012/01/09/cloud-security-monitoring/ | Archive.org Snapshot

How exciting is that? You combine 3 non-specific words – cloud, security, monitoring – and you get … what exactly? Let’s find out! This quarter my research focuses on cloud security monitoring and cloud logging.

I will try to define the subject(s) and then provide analysis and recommendations for architecting security monitoring of public cloud environments. Naturally, SaaS, PaaS and IaaS have different visibility constraints and require distinct approaches.

In particular, for IaaS (Infrastructure as a Service), one has near-complete control over the guest OS, which means standard host-based logging, endpoint agents, and SIEM connectors apply directly. For SaaS, one is at the mercy of provider APIs.

Key questions we will address in the upcoming research:

  • What logs and telemetry are realistic to obtain from cloud service providers?
  • How do traditional SIEM tools ingest and correlate ephemeral cloud instances?
  • Where should analysis occur: in the cloud, on-premises, or hybrid?

Stay tuned as we develop the framework and interview both vendors and enterprise early adopters.