UPDATED 13:36 EDT / MARCH 26 2013

NEWS

2013 State of Cloud Security Report from Alert Logic

Alert Logic is in the business of making a better more secure cloud. As the leading provider of Security-as-a-Service solutions they focus on securing all aspects of the application and infrastructure stack. Their latest report on the state of Cloud Security shows a number of interesting trends. One of these is that web applications attacks are the most significant security threat for IT infrastructures. In fact, the findings collectively illustrate that the greatest security threat in enterprise data centers and cloud environments is indeed the web application attack.

“The data confirms what we suspected. Web application attacks continue to be a serious threat across all environments,” said Stephen Coty, director, Security Research with Alert Logic. “These types of threats are easily launched through automated tools and should be a top concern for any organization that is serious about security.”

The six month study took place between April 1 and September 30, 2012. Over one billion security events were observed and Alert Logic verified more than 45,000 security incidents as valid threats. The Alert Logic State of Cloud Security Report – Spring 2013 evaluated three vectors of analysis – incident occurrence, incident frequency and threat diversity – across six security incident categories.

Here are some key findings within the report:

> The cloud is not inherently less safe. Among the six security incident categories examined, Web application attack was the only threat category more prevalent in cloud hosting provider environments than in enterprise environments. The frequency of attacks experienced by enterprise data centers was higher across the board than cloud hosting provider environments. The frequency of reconnaissance attacks was nearly 10 times higher in enterprise environments than observed in cloud environments. Data center environments experienced malware/botnet attacks nearly three times more frequently compared to the cloud.

> Different IT environments face different threats. Attacks in enterprise data centers tend to be more sophisticated and targeted, versus cloud hosting provider environments, which experience more opportunistic threat activity. Nearly half (49 percent) of enterprise environments in the study experienced verified malware/botnet activity, compared to just five percent of cloud hosting provider environments.

> Cloud hosting provider environments typically face a narrower range of threats. The study found that customers using enterprise data center environments experienced an average of 2.5 types of incidents, while those using cloud hosting provider environments experienced an average of 1.8 incident types.

As found in the report, one of the key takeaways was the variety and statistical disparity of threats whether in an enterprise data center or out on a cloud hosting provider. Such findings reinforce not only a flexible security construct, but also a layered approach with particular focus on web application security. Clearly logging, analysis, and response are part of the prescription in this ongoing effort. Have a look at the free download of the Alert Logic State of Cloud Security Report – Spring 2013, available at http://www.alertlogic.com/csr.

 


A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU