- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 259字
- 2021-06-30 19:15:51
Incident response in the cloud
When we speak about cloud computing, we are talking about a shared responsibility (4) between the cloud provider and the company that is contracting the service. The level of responsibility will vary according to the service model, as shown in the following diagram:

For Software as a Service (SaaS), most of the responsibility is on the Cloud Provider; in fact, the customer's responsibility is basically to keep his or her infrastructure on premises protected (including the endpoint that is accessing the cloud resource). For Infrastructure as a Service (IaaS), most of the responsibility lies on the customer's side, including vulnerability and patch management.
Understanding the responsibilities is important in order to understand the data gathering boundaries for incident response purposes. In an IaaS environment, you have full control of the virtual machine and have complete access to all logs provided by the operating system. The only missing information in this model is the underlying network infrastructure and hypervisor logs. Each cloud provider (5) will have its own policy regarding data gathering for incident response purposes, so make sure that you review the cloud provider policy before requesting any data.
For the SaaS model, the vast majority of the information relevant to an incident response is in possession of the cloud provider. If suspicious activities are identified in a SaaS service, you should contact the cloud provider directly, or open an incident via a portal (6). Make sure that you review your SLA to better understand the rules of engagement in an incident response scenario.
- Learn Helm
- 循序漸進(jìn)學(xué)Docker
- 混沌工程:復(fù)雜系統(tǒng)韌性實(shí)現(xiàn)之道
- Windows Vista融會(huì)貫通
- 混沌工程實(shí)戰(zhàn):手把手教你實(shí)現(xiàn)系統(tǒng)穩(wěn)定性
- 異質(zhì)結(jié)原理與器件
- 奔跑吧 Linux內(nèi)核(入門篇)
- Windows 8實(shí)戰(zhàn)從入門到精通(超值版)
- Windows 10從新手到高手
- 完美應(yīng)用Ubuntu(第2版)
- Linux內(nèi)核修煉之道
- 電腦辦公(Windows10+Office2016)從新手到高手
- Microsoft DirectAccess Best Practices and Troubleshooting
- 數(shù)字系統(tǒng)設(shè)計(jì)與VHDL
- 蘋果派