Google Cloud Security Command Center’s newest service puts cryptomining malware in its crosshairs.
In what the No. 3 cloud giant calls a first from a major cloud provider, Google Cloud’s new Virtual Machine Threat Detection (VMTD), available in public preview via Security Command Center, provides agentless memory scanning to detect threats such as cryptomining malware inside virtual machines (VMs) running in Google Cloud.
This becomes increasingly important as CrowdStrike and other security vendors say cryptomining attacks are on the rise. Atlas VPN calls them the most common web threats. And the latest Google Cybersecurity Action Team Threat Horizons Report found 86% of compromised cloud instances were used to perform cryptocurrency mining.
“VMTD is one of the ways we protect our Google Cloud Platform customers against growing attacks like coin mining, data exfiltration, and ransomware,” Google Cloud Product Manager Timothy Peacock wrote in a blog post.
Agentless threat detection
Instead of deploying a software agent inside of a VM, the new VMTD service uses the hypervisor to gather telemetry and detect threats. “Not running an agent inside of their instance means less performance impact, lowered operational burden for agent deployment and management, and exposing less attack surface to potential adversaries,” Peacock wrote.
Also in the blog post, he outlined other steps Google Cloud takes to safeguard customer trust with the new threat inspection service. First, the VMTD public preview is an opt-in service — it’s not mandatory — for Security Command Center premium customers.
Plus, Google Cloud never processes memory in VMTD from its Confidential Computing nodes, Peacock added.
Google Cloud beefs up enterprise security
VMTD follows several recent additions to Google Cloud’s security arsenal as the No. 3 cloud provider beefs up its enterprise products and services.
Last month it acquired security orchestration, automation, and response (SOAR) vendor Siemplify to bring that capability in-house. Google Cloud plans to integrate Siemplify into its security analytics platform Chronicle to “help enterprises modernize and automate their security operations,” Google Cloud Security VP and GM Sunil Potti wrote in a blog post.
The cloud provider also rolled out extended detection and response (XDR) partnerships with CrowdStrike, Palo Alto Networks, and Cybereason at its annual customer event, building on earlier partnerships with all three security vendors.
And late last year Google released Cloud IDS, a network-based threat detection based on Palo Alto Networks’ technology.
Comments