Cloud Infrastructure supplemental rule pack

Prev Next

The Cloud Infrastructure rule pack is focused on uncovering potentially anomalous activity in the cloud infrastructure hosted in Amazon Web Service (AWS) environments.

Rules in the Cloud Infrastructure rule pack

The rules that comprise the Cloud Infrastructure rule pack include:

Elastic cloud

Elastic cloud (EC2) is the primary AWS service that provides the ability to create computing capacity in the cloud. Helix Enterprise provides fourteen rules associated with this service that detect:

  • AMI’s shared / made public

  • Volumes attached/detached

  • Use of broad ranges added to ingress/egress ACLs

  • Console output requests via API

  • EBS volume snapshots shared / made public

  • Encrypted windows password retrieval

  • Instance monitoring disabled

  • Non-encrypted EBS volume creation

  • Several instances created/started

  • Instance terminated

  • VPC customer gateway created

These rules can be used to detect a number of activities in EC2 that, when unauthorized, could result in a compromise of confidentiality, integrity, or availability of cloud services.

Identity and access management

Identity and Access Management (IAM) allows AWS users to control access to services and resources for users. Helix Enterprise provides 16 rules associated with this service that detect the following:

  • Adding users to groups

  • User password changes

  • Creation/deletion of access keys

  • Creation/deletion of policies

  • MFA device management

  • Manual actions completed without MFA

  • Upload of new server and signing certificates

  • Use of the root account by non-service accounts

  • Policy changes to CloudTrail logging

  • Changes to the account password policy

  • Updates to Login Profiles

These rules can be used to detect activity that could result in unauthorized access to AWS resources.

CloudTrail

CloudTrail is a web service that records AWS API calls and provides logging related to the time, location, and user associated with the API call. The CloudTrail service is ultimately responsible for all of the logging used by Helix Enterprise, but Helix Enterprise also includes five rules specific to CloudTrail management. These rules detect the creation and deletion of trails, the creation and removal of logging alarms, and the stopping of logging services. These rules can be used to detect activity that might decrease the visibility needed to perform a security investigation.

Key management service

Key Management Service (KMS) is a centralized service that allows for the creation and management of encryption keys used to encrypt data and control access. KMS is integrated with multiple other Amazon services including EBS, S3, and RDS. Helix Enterprise provides four rules associated with this service that detect the creation of keys, enabling/disabling of keys, key policy changes, and key grant management changes. These rules can be used to detect activity related to key management that could result in unauthorized access to data.

OpsWorks

OpsWorks is an application management service that eases the deployment and maintenance of applications. Helix Enterprise provides rules associated with this service that detect permissions modifications, the creation/starting/deletion/stopping/rebooting of instances, and the unassignment of instances or volumes. These rules can be used to detected unauthorized access and activity related to OpsWorks managed applications.

Relational database service

Relational Database Service (RDS) provides relational databases in the cloud. Helix Enterprise provides three rules associated with this service that detect ACL management, the deletion of DB instances, and overly broad ingress rules being applied to security groups. These rules can be used to detect unauthorized interaction with RDS databases that could result in a loss of data availability or unauthorized data access.

Redshift

Redshift provides cost-effective scalable data warehousing in the cloud. Helix Enterprise provides three rules associated with this service that detect security group management, deletion of storage clusters, and the disabling of logging. These rules can be used to detect unauthorized interaction with storage services that could result in a loss of data availability or unauthorized data access.

Route53

Route 53 provides cloud-based DNS services. Helix Enterprise provides six rules associated with this service that detect hosted zone management, hosted zone association, domain registrations, domain transfers, domain lock management, and changes in resource record sets. These rules can be used to determine if an unauthorized user is attempting to manage cloud based DNS infrastructure.

Simple queue service

Simple Queue Service (SQS) provides managed message queuing services. Helix Enterprise provides one rule associated with this service that detects the addition of permissions to specific principals, which allow for sharing access to a queue.