With all the recent attention to the Kneber bot net, I am reminded that we must consider how we would detect bot infections in the cloud. Most bot infections are well-hidden from local security tools and like Kneber only reveal themselves via detection of suspicious network activity. Most cloud providers do not allow tenants to monitor the network. How will cloud tenants detect when their cloud based systems are compromised?
I see three security models for solving this problem:
- Cloud Security Management -- the cloud provider assumes responsibility for detection.
- Self-service Security -- the cloud provider provides tenants with network monitoring and detection capabilities.
- Assume the risk.
Read the rest of the article.