The Cloud Infrastructure rule pack is focused on uncovering potentially anomalous activity in the cloud infrastructure hosted in Amazon Web Service (AWS) environments.
Rules in the Cloud Infrastructure rule pack
The rules that comprise the Cloud Infrastructure rule pack include:
Elastic cloud
Elastic cloud (EC2) is the primary AWS service that provides the ability to create computing capacity in the cloud. Helix Enterprise provides fourteen rules associated with this service that detect:
AMI’s shared / made public
Volumes attached/detached
Use of broad ranges added to ingress/egress ACLs
Console output requests via API
EBS volume snapshots shared / made public
Encrypted windows password retrieval
Instance monitoring disabled
Non-encrypted EBS volume creation
Several instances created/started
Instance terminated
VPC customer gateway created
These rules can be used to detect a number of activities in EC2 that, when unauthorized, could result in a compromise of confidentiality, integrity, or availability of cloud services.
Identity and access management
Identity and Access Management (IAM) allows AWS users to control access to services and resources for users. Helix Enterprise provides 16 rules associated with this service that detect the following:
Adding users to groups
User password changes
Creation/deletion of access keys
Creation/deletion of policies
MFA device management
Manual actions completed without MFA
Upload of new server and signing certificates
Use of the root account by non-service accounts
Policy changes to CloudTrail logging
Changes to the account password policy
Updates to Login Profiles
These rules can be used to detect activity that could result in unauthorized access to AWS resources.
CloudTrail
CloudTrail is a web service that records AWS API calls and provides logging related to the time, location, and user associated with the API call. The CloudTrail service is ultimately responsible for all of the logging used by Helix Enterprise, but Helix Enterprise also includes five rules specific to CloudTrail management. These rules detect the creation and deletion of trails, the creation and removal of logging alarms, and the stopping of logging services. These rules can be used to detect activity that might decrease the visibility needed to perform a security investigation.
Key management service
Key Management Service (KMS) is a centralized service that allows for the creation and management of encryption keys used to encrypt data and control access. KMS is integrated with multiple other Amazon services including EBS, S3, and RDS. Helix Enterprise provides four rules associated with this service that detect the creation of keys, enabling/disabling of keys, key policy changes, and key grant management changes. These rules can be used to detect activity related to key management that could result in unauthorized access to data.
OpsWorks
OpsWorks is an application management service that eases the deployment and maintenance of applications. Helix Enterprise provides rules associated with this service that detect permissions modifications, the creation/starting/deletion/stopping/rebooting of instances, and the unassignment of instances or volumes. These rules can be used to detected unauthorized access and activity related to OpsWorks managed applications.
Relational database service
Relational Database Service (RDS) provides relational databases in the cloud. Helix Enterprise provides three rules associated with this service that detect ACL management, the deletion of DB instances, and overly broad ingress rules being applied to security groups. These rules can be used to detect unauthorized interaction with RDS databases that could result in a loss of data availability or unauthorized data access.
Redshift
Redshift provides cost-effective scalable data warehousing in the cloud. Helix Enterprise provides three rules associated with this service that detect security group management, deletion of storage clusters, and the disabling of logging. These rules can be used to detect unauthorized interaction with storage services that could result in a loss of data availability or unauthorized data access.
Route53
Route 53 provides cloud-based DNS services. Helix Enterprise provides six rules associated with this service that detect hosted zone management, hosted zone association, domain registrations, domain transfers, domain lock management, and changes in resource record sets. These rules can be used to determine if an unauthorized user is attempting to manage cloud based DNS infrastructure.
Simple queue service
Simple Queue Service (SQS) provides managed message queuing services. Helix Enterprise provides one rule associated with this service that detects the addition of permissions to specific principals, which allow for sharing access to a queue.