Palo Alto Networks’ Unit 42 threat hunting team discovered two critical Amazon Web Services (AWS) cloud misconfigurations in a customer’s environment in less than a week that, if exploited by hackers, would have led to a data breach that cost the customers tens of millions of dollars.

“Being good researchers we thought, OK, maybe this is just an isolated incident,” said Matt Chiodi, chief security officer of public cloud at Palo Alto Networks. “We went out and did a reconnaissance operation using GitHub, and we mined that public data. And we found thousands upon thousands of other accounts that were susceptible to the same type of identity misconfigurations. So we know this isn’t just an isolated problem. This is a widespread problem in the cloud.”

Palo Alto Networks threat researchers discuss this problem of identity and access management (IAM) in the cloud in the Unit 42 Cloud Threat Report, released today. The Unit 42 team produces these reports twice a year. But they usually don’t do red team exercises to simulate an attack on a customer’s cloud environment because Unit 42 is a research organization.

“But in this case, we were particularly interested because this customer’s environment was so massively scaled. This customer is a major SAS provider,” Chiodi said. “What we found during that red team exercise where essentially we attacked their environment, we discovered two critical AWS misconfigurations — these are customer misconfigurations, that they injected in their own environment mistakenly — specific to identity that could have led to a multi-million-dollar data breach. That is why it is so important, and why we pretty much have done an entire report on this one issue.”

It’s important to note that malicious actors did not exploit these IAM misconfigurations, and Palo Alto Networks helped the customer remediate the issues.

Unit 42’s Red Team Exercise

However, GitHub data emphasizes the severity of these misconfigurations. It, combined with other sources, “revealed more than 175,000 EC2 snapshots, hundreds of S3 buckets, and many RDS snapshots and KMS keys,” the report said. “Make no mistake: if attackers had discovered what Unit 42 researchers found, they would have assuredly taken steps to ‘own’ these cloud accounts."

During the red team exercise, Unit 42 researchers exploited the misconfigured IAM role trust policy “AssumeRole” and gained access to sensitive resources. This could result in a slew of different attacks against an organization including denial-of-service (DoS), ransomware, and advanced persistent threats (APT).

Researchers also moved laterally with non-administrator access by exploiting a misconfigured IAM role related to flow-log management. They then escalated their privileges to gain administrative access to the entire cloud environment. This allowed them to do things like create new Amazon Elastic Compute Cloud (EC2) and Relational Database Service (RDS) instances and modify user and policy permissions. Attackers could exploit this misconfiguration to steal sensitive data, wipe out infrastructure, or lockdown an operation with ransomware.

“So there’s multiple different ways that an attacker can abuse this type of misconfigured access,” Chiodi said.

Misconfigurations Plague Businesses

Previous Unit 42 research found 65% of cloud security incidents were due to simple misconfigurations. Additionally, IBM X Force’s annual threat report published in February found that of the more than 8.5 billion records breached in 2019, that 7 million of those were due to misconfigured cloud servers and other improperly configured systems.

The National Security Agency (NSA) says misconfiguration of resources remains the most prevalent cloud vulnerability.

Cloud misconfigurations continue to plague businesses, and they present an especially high risk to companies because if a breach occurs due to a misconfiguration, it’s the company’s — not the cloud provider’s — fault.

Providers like AWS and Microsoft Azure are responsible for protecting their public cloud infrastructure and implementing logical controls to separate customer data. The customer, however, is responsible for configuring application-level security controls and for protecting its workloads running on cloud servers.

IAM Best Practices

Misconfigurations remain so prevalent because “most organizations have scaled their cloud presence faster than they’ve scaled their security capabilities,” Chiodi said. “And the only way that organizations are going to be able to get ahead of that is by automating.”

In fact, Unit 42 provides IAM governance best practices in the report, and these include automating several security tasks to limit user privileges. “The sheer scale of the cloud no longer lends itself to doing security work manually,” Chiodi said.

While the report recommends 10 steps that enterprises can take to improve IAM governance, “the No. 1 thing organizations really need to focus on is granting least-privilege access,” he added. This means only granting the least amount of permissions needed for a job, so if a user or resource is compromised, the blast radius is reduced to only those few things the entity was permitted to do. The report recommends automating this task.

“This is where we strongly encourage enterprises to really be focused on being proactive and that’s what we mean by auto-remediating excessive privileges,” Chiodi said. “Look for those accounts that have too many permissions and then automatically take those permissions away. Don’t make it a manual process.”