The rise of Haas and IaaS and their impacts on data security

Michael Angelo Michael Angelo
February 18, 2019 Big Data, Cloud & DevOps

The fun thing about being asked to predict security industry issues and trends is that I get to think about what could affect us, both negatively and positively in the upcoming year. Whether I approach it with the mindset of “How bad can things go if we do this?” or “What issues are we missing that could hurt us?”, there will always be the possibility of having the hindsight realization of “What were we thinking?” when looking back on predictions from the previous year.

I’d like to pay special attention to the prediction that we will finally recognize a fundamental exposure with Hardware as a Service (HaaS), Infrastructure as a Service (IaaS) and Platform as a Service (PaaS). Specifically, the rise of HaaS and IaaS in 2019 will shed light on a central insecurity in PaaS cloud strategy, as the staff controlling cloud environments have access to the information and materials stored and used in the cloud.

We have all seen the NIST security recommendations for Cloud PaaS (encompassing HaaS and IaaS) security. While they are foundationally accurate, they seem to have missed the real issue with PaaS. Phrased differently, they recognize the security requirements as well as the legal requirements. So, what is exactly dangerous about PaaS?

experfy-blog

In the modern age, I truly hope that everyone realizes that anything with a computer and memory needs to be wiped before it is recycled. The good news is that recycling is not a PaaS problem by nature. If we look at cloud implementations of PaaS, some of the most valuable features are auto-migration and dynamic reconfiguration of an environment.

Auto-migration and dynamic reconfiguration do not require a restart, whereas under normal circumstances a program or system would need to be restarted. For these features to work in PaaS, the environment must to be changed while “still active,” which works by pausing, snapshotting the system and modifying it from there. Next, the system needs to be “unpaused” because while the system can be enabled from a pause, it is not a re-initialization.

When paused, everything that is active in memory remains in memory exactly as it was when paused. The active memory may even be flushed out to disk and migrated elsewhere. For those of you following along, you may see the problem by now.

The real issue is that when the snapshot is written to a disk, those controlling the cloud environment have full access to the data and materials being utilized and kept in the cloud, which in turn compromises the privacy of that information. While most may realize this privacy issue with SaaS, they are largely unaware of the issue with PaaS too.

Of particular concern are those depending on virtual machines and the encryption on them to guarantee privacy. Consider the following, you have a virtual machine hosted in the cloud with encrypted stored data. As un-accessed and stored material, the file would be encrypted and protected. When accessing the file and entering a decryption key however, the file and key are now officially in memory.

Overall, while we ask ourselves “What is dangerous about PaaS?” we need to understand that attention needs to be given to protecting the system snapshots from a HaaS and an IaaS perspective. We need to ensure the snapshots are protected so that they can still run, but not be copied or accessed in an unauthorized manner, or be migrated to unauthorized hardware.

Most importantly, we should continue asking, “Who really has access to the virtual machines and snapshots?” Until this happens, PaaS remains a real threat. 

'Originally seen in Information Management

  • Experfy Insights

    Top articles, research, podcasts, webinars and more delivered to you monthly.

  • Michael Angelo

    Tags
    Big Data & Technology
    © 2021, Experfy Inc. All rights reserved.
    Leave a Comment
    Next Post
    New Tech Trends that Are Impacting Healthcare in 2019

    New Tech Trends that Are Impacting Healthcare in 2019

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    More in Big Data, Cloud & DevOps
    Big Data, Cloud & DevOps
    Cognitive Load Of Being On Call: 6 Tips To Address It

    If you’ve ever been on call, you’ve probably experienced the pain of being woken up at 4 a.m., unactionable alerts, alerts going to the wrong team, and other unfortunate events. But, there’s an aspect of being on call that is less talked about, but even more ubiquitous – the cognitive load. “Cognitive load” has perhaps

    5 MINUTES READ Continue Reading »
    Big Data, Cloud & DevOps
    How To Refine 360 Customer View With Next Generation Data Matching

    Knowing your customer in the digital age Want to know more about your customers? About their demographics, personal choices, and preferable buying journey? Who do you think is the best source for such insights? You’re right. The customer. But, in a fast-paced world, it is almost impossible to extract all relevant information about a customer

    4 MINUTES READ Continue Reading »
    Big Data, Cloud & DevOps
    3 Ways Businesses Can Use Cloud Computing To The Fullest

    Cloud computing is the anytime, anywhere delivery of IT services like compute, storage, networking, and application software over the internet to end-users. The underlying physical resources, as well as processes, are masked to the end-user, who accesses only the files and apps they want. Companies (usually) pay for only the cloud computing services they use,

    7 MINUTES READ Continue Reading »

    About Us

    Incubated in Harvard Innovation Lab, Experfy specializes in pipelining and deploying the world's best AI and engineering talent at breakneck speed, with exceptional focus on quality and compliance. Enterprises and governments also leverage our award-winning SaaS platform to build their own customized future of work solutions such as talent clouds.

    Join Us At

    Contact Us

    1700 West Park Drive, Suite 190
    Westborough, MA 01581

    Email: [email protected]

    Toll Free: (844) EXPERFY or
    (844) 397-3739

    © 2025, Experfy Inc. All rights reserved.