Information Age: News, analysis & insight for IT & business leaders

Three in ten virtual machines on AWS are insecure

22 June 2011  

Scientists find that 30% of virtual servers hosted on Amazon Web Services are improperly configured, exposing them to attack

A team of German scientists has found that around 30% of virtual machines hosted on Amazon Web Services are vulnerable to attack because they have been improperly configured by the user.

Researchers from Darmstadt Research Center for Advanced Security at Fraunhofer SIT university studied the Amazon Machine Images (AMI) of 1,100 hosted machines, and found that three in ten are exposed, "allowing attackers to manipulate or compromise web services or virtual infrastructures".

"Even though AWS provide their customers with very detailed security recommendations on their web pages," the researchers found, "at least one third of the machines under consideration have flawed configurations."

The scientists found that they could steal critical information including passwords and private keys that "could be used to control the [user's] entire virtual infrastructure in AWS or to create a virtual infrastructure worth several thousands of dollars per day at the expenses of the [user]."

"The problem clearly lies in the customers’ unawareness and not in Amazon Web Services," commented research lead Professor Ahmad-Reza Sadeghi. "We believe that customers of other cloud providers endanger themselves and other cloud users similarly by ignoring or underestimating security recommendations."

The team said it had informed Amazon of the issue, and it had responded by publishing guidance for customers on how to manage their private keys.


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

Read article

1Z0-040 Oracle Database 10G New Features for Administrators Practice Exam

Oracle 9i administrators can certify on Oracle 10G by passing this exam. The ExamForce 1Z0-040 Oracle Database 10G New Features for Administrators practice exam provides their unique triple testing mode to instantly set a baseline of your knowledge and focus your study where you need it most.

More
Advertisement
div class="banner">