Wednesday, December 19, 2018

Need for CISOs and Solution Architects to Build Threat Modelling in Evolving Cloud Applications


By Tejas Sheth, Cloud Security Architect, Trend Micro

“What is my security responsibility in the cloud when I am using IaaS, PaaS and/or Serverless application?” This is one of the most common questions we get asked by companies that are considering moving to the cloud and/or modernize their application with micro service architecture. This is because, today the application uses multiple services from single/multiple cloud service provider and each service in cloud has different shared security responsibility.

Shared security responsibility in the cloud environment change based on application architecture and type of cloud services it integrates to.

Generally speaking, the cloud service provider, such as AWS or Azure, takes care of the infrastructure and security of the cloud. The customer, on the other hand, is responsible for securing everything in the cloud.

This shared responsibility model gives businesses the ownership and control of their data, applications, and operating system, just like in the on-premise environment. But not all cloud services provide same type of controls on operating system platform. It means that companies that are using PaaS, and containerized application have different security responsibility than companies using pure IaaS and/or Serverless applications.

The companies may find themselves confronted by different security challenges as they move through different stages of cloud adoption. Therefore, it is important for CISOs and solution architects to create threat modelling for the evolving application architecture in the cloud.

The three stages of cloud adoption and application evolution include:

Stage one: Threat vector in monolithic applications in the cloud

For the longest time ever, the monolithic architecture had been the default application development pattern. Its single codebase approach brings about ease of development, deployment, and testing. On top of that, developers are familiar with the architecture.

Application code in the cloud isn’t just written by the company. As with all modern web applications, developers use third party - mostly open-source – components, typically including web frameworks and libraries. These third-party components have security vulnerabilities of their own.

Security for monolithic applications revolves around authentication, authorization, and encryption. As a result, by using vulnerability-laden third-party components, hackers can launch attacks at the security processes, thereby rendering them invalid, compromising the security for the whole architecture.

Stage two: Threat vector in containerized applications and PaaS

When the cloud journey evolves, applications start to become loosely coupled and stateless in nature. Applications also begin to integrate with other cloud services like object storage, caching services, and NoSQL databases. From these evolutions sprang the micro services architecture, where modules become small, individual application entities in containers, and they communicate over RESTful API. The APIs add another layer that needs to be secured with run-time application self-protection.

While developers follow the Agile methodology and release new application updates every day, DevOps team uses containers to achieve continuous integration and continuous delivery (CI/CD). This process can hinder security team’s visibility, as many moving components are used by developers and/or the DevOps team inside containers.

If companies don’t have visibility into the threats, they can’t apply security controls to the system. Since containerized micro service applications remove visibility for the teams who follow traditional security methods, it’s important to integrate security into the DevOps process.

Stage three: Threat vector in serverless applications

In the serverless model, companies who own the systems don’t have to purchase or rent servers or virtual machines to run the code. Serverless architecture is heavily dependent on third-party services. The best-known vendor host currently is AWS Lambda and Azure/GCP Functions.

The shared responsibility model in serverless application becomes more complex from a security compliance standpoint. The threat vector is different in a serverless application, from monolithic or micro service application architecture. This requires the company think about security from an application design perspective.

In order to access other cloud services, serverless function needs to be configured with identity roles and the permission, be provided by the cloud provider. Such infrastructure privilege access to function code can become a new threat vector if access to function trigger (external APIs) is not hardened.

Serverless functions on different cloud platforms are configured differently. For Example, While AWS Lambda and GCP functions provides serverless functions with basic library and default language support, Azure’s function requires different configuration for each language version and libraries from KUDU shell access. These variations can change the threat vector for different cloud service providers.

Such new type of security risk is causing new type of attack e.g. Denial of wallet and attacks on application code and library. Securing serverless application requires protection run-time application self-protection (RASP) and another API security configuration.

In summary, although security needs vary at different stages of the cloud adoption lifecycle, when it comes to different types of applications, basic principles for security remain the same. Visibility is the key to applying security controls on any threat vector. Integrity monitoring of file system and log analytics can help to provide visibility on threat vectors.

Vulnerability scanning and applying patch and virtual patch are mandatory steps throughout the cloud journey. Intrusion prevention system and intrusion detection system (IPS/IDS), monitoring possible control and command (C&C) connection, and firewall can be used to identify and mitigate threats at the initial phase of the intrusion kill chain.

Eminent Technocrats Converged at NXP India TechConnect to Address Challenges in Automotive and IoT Applications



NXP India, a world leader in secure connectivity solutions for embedded applications organized the TechConnect Industry TechSummit on ‘Next Generation Product Development Challenges and Opportunities in Automotive, IoT and Networking Applications’ at Manayata Tech Park in Bangalore. The event featured panelists from leading organizations, such as HCL, LDRA, NVIDIA and Synopsys, academic institutions, such as IIT-Delhi and startups, such as Orxca Energies, among others.

The summit included two panel discussions - ‘Next Generation Product development’ and ‘Verification and Validation’. While the first discussion focused on challenges and opportunities emerging from Connected Infotainment, Autonomous Vehicles, Industrial IoT, e-bike battery innovations, security for IoT, Networking & Automotive applications and Industry-academia partnerships for training newer generations of students in associated technologies; the second panel plunged into the technical challenges associated with security in verification and validation. Some of India’s most valued dignitaries attended the discussions and debated on various product development challenges that have been exponentially increasing, particularly with shrinking geometries.

The panel discussion also brought out the emphasis on addressing security aspects of the new applications at all levels of Hardware and Software abstraction with the paced emergence of autonomous cars, IoT and 5G wireless connectivity. The discussion further highlighted the increasing need to address specific technical challenges on emerging applications, such as Machine Learning and Artificial Intelligence.

The day-long event witnessed participation from industry experts, such as Magesh Srinivasan, Global Head, Connected Car & AI, HCL; Preeti Ranjan Panda, Head of Department of IT & Engineering, IIT Delhi; Ganesh Shankar, Founder and CEO, FluxGen Technologies; Prajwal Sabnis, Co-Founder, Orxa Energies Pvt. Ltd.; Shinto Joseph, Director, South East Asia Operations, LDRA; Manoharan CP, Director, Systems Engineering & Field Sales Support, Spirent; Anand  Muthaiah, VP Engineering, Tessolve Semiconductors; Puneet Ahuja, Sr. Design Engineering Manager, Cadence; Amit Sharma, Director, Corporate Applications Engineering, Synopsys; Yogesh Mittal, Director, Functional Verification & Emulation, NXP and Amit Agarwal, Senior Engineering Manager, NVIDIA. The panels were moderated by Kumaran Venkatesh, President & Partner, AXLerateNOW and Vijay Chachra, Director of Engineering, NXP Semiconductors.

Speaking of the initiative, Sanjay Gupta, Vice President & India Country Manager, NXP India said, “India has huge technological talent and NXP India has constantly worked towards uniting this talent with related skills and expertise. TechConnect is one such initiative that has helped expand NXP India’s horizons of industry knowledge and synergize with fierce thoughts and minds to emerge as a driver of next generation innovation in the secure connected vehicle, end-to-end security and smart connected solutions.”

Kicking off the discussion, the moderator Kumaran Venkatesh, President & Partner, AXLerateNOW said “The future of Next generation product development would revolve around Artificial intelligence and Machine learning. The challenge for product developers is designing futuristic connected devices with IOT and security in mind.”

Adding to the discussion on challenges faced by Autonomous Vehicles, Gupta said, “Autonomous vehicles need safety-related functionality that can sense and react to hazardous situations. It’s an engineering process as critical as engineering the product itself. Think of all the hazardous contingencies that an autonomous vehicle has to contend with—particularly in an urban environment. This need to anticipate a wide range of possible interactions between the vehicle and its environment is one of the biggest challenges in developing safety for autonomous vehicles. To comply with FS standards, an engineer must anticipate what can go wrong when a product interacts with its environment (including us unpredictable humans), then conceive of a safety-related system and place the system into an appropriate safe state. Add to this, further consideration of whether that safe state will itself result in a hazard.”

Speaking on the note of trends and challenges of the connected cars and AI, Magesh Srinivasan, Global Head- Connected car & AI, HCL says “Today, infotainment is on the brink of major evolution with the next global megatrend being seamless connectivity between smartphones and automobiles. Connectivity to cloud and other types of Internet-based computing that help users improve their driving pattern and vehicle health, by predictive analysis of driving patterns, vehicle health and maintenance, will be the key differentiators eventually. And that’s not it. Manufacturers across the globe have already started adopting intelligent infotainment systems, such as Android Automotive, which enhance safety on the move by providing safe connectivity, navigation and media experience.”

NXP’s TechConnect is a comprehensive platform dedicated to sharing knowledge, tools & best practices, and initiating dialogues on innovation and disruptive technologies, through events, such as the TechTalk, TechSymposium, TechTutorial, and TechSummit. In its essence, TechConnect aims to promote the spirit of innovation and empower employees to connect and learn from industry veterans.

Monday, December 17, 2018

Atos and Indian Government Sign Major HPC Agreement to Support India’s National Supercomputing Mission


Atos, a global leader in digital transformation, today signed a HPC agreement with the C-DAC (Centre for Development of Advanced Computing), an organization within the MeitY (Ministry of Electronics & Information Technology of India), in the presence of the French Minister for External Affairs Jean-Yves Le Drian, and the Secretary of the Minister of Electronics and IT India, Ajay Prakash Sawhney, in New Delhi. This agreement is part of India’s NSM (National Supercomputing Mission).

“We’re delighted to officially become today the technology partner of C-DAC for HPC-related platforms and to participate in India’s prestigious NSM (National Supercomputing Mission) program.  We are honoured that our BullSequana supercomputers, will be empowering Indian academic and R&D institutions across the country to accelerate their research and at the same time support India’s ambition to be a leader in HPC.” said Pierre BarnabĂ©, Chief Operating Officer, Big Data & Security at Atos.

“This new agreement illustrates the strategic relationship and partnership between France and India and will enable India to leapfrog to the league of world-class supercomputing power nations.” said Dr. Herman Darbari, Director General of C-DAC.

This project will see Atos deploy its BullSequana supercomputers, including the recently announced BullSequana XH2000 in various academic and research institutions, making Atos a leading supercomputing provider in India.

JetEscapes Holidays Announces Attractive Packages for Dubai Shopping Festival Starting Rs 28,740 Onwards


Jet Airways’ JetEscapes Holidays today introduced exciting, new all-inclusive Dubai holiday packages for guests planning to travel to Dubai to indulge in retail therapy at the world’s biggest shopping festival - ‘The Dubai Shopping Festival’.

Attractively priced and highly popular, JetEscapes’ Dubai Holidays packages aim to offer an enhanced shopping experience at the annual festival and are inclusive of return Economy air fares, airport transfers, hotel accommodation with breakfast, city tours, travel insurance and the chance to earn 5 JPMiles on every Rs.100 spent. The incredible 6-week sale extravaganza is scheduled from 26th December, 2018 to 2nd February, 2019.

An annual pilgrimage for shoppers’, the Dubai Shopping Festival is replete with fashion shows, fireworks and mega sales, which completely transform the entire city of Dubai. This year, JetEscapes Holidays has announced two nights/ three days and four nights/ five days’ holiday options. The two nights/ three days package starts from Rs 28, 740/-* and four nights/ five days package starts from INR 51, 850/-*respectively. The four attractive holiday packages, ‘Dubai Free & Easy’, ‘Magic Dubai’, ‘Mania Dubai’ and ‘Fascinating Dubai’ have been especially created in response to the needs of travellers keen to experience this special global extravaganza.

With these tailor-made packages, guests can get a glimpse of the culture, traditions and history of Dubai. Guests choosing the ‘Magic Dubai’, ‘Mania Dubai’ and ‘Fascinating Dubai’ packages will also be able to experience the Dhow Cruise and Desert Safari along with dinner and enjoy a free entrance to the Global Village. Guests opting for ‘Mania Dubai’, in addition to the above, will also get access to the architectural landmark, Dubai Frame which has also been described as "the biggest picture frame on the planet". There are special add-on delights for guests availing ‘Mania Dubai’ and ‘Fascinating Dubai’ packages with Abu Dhabi city tour, visit to Ferrari World and free entrance to Warner Bros Studio included in the packages.

And while in Dubai, guests will also be able to join the live showing of the grand Mughal-E-Azam show from 10th – 12th January, 2019. Mughal-e-Azam – an absolute must watch, is the first large-scale Indian Broadway-style musical which pays a stunning homage to K. Asif’s classic film of the same name. The musical swept the Broadway World Awards and won seven trophies, including Best Play & Best Director in 2017.

Guests travelling for the Dubai Shopping Festival can now enjoy even more convenient flight options from Mumbai and Delhi with Jet Airways. Effective 5th December, 2018, Jet Airways has added a 7th daily non-stop frequency between Mumbai and Dubai. Effective 24th October, 2018, the airline added a 4th daily frequency on the Delhi-Dubai route, giving its guests added convenience of travelling at their chosen time and make the most of their holidays.

Belson Coutinho, Sr. Vice President – Marketing, eCommerce & Innovations, Jet Airways said, “The Dubai Shopping Festival is a shopaholic’s dream. As the world’s largest shopping festival clubbed with top-of-the-line entertainment, the annual showcase gives this Gulf hot spot a whole new platform replete with jovial and vibrant vibes. Tourists including families, will be spoilt for choice with the presence of every major global retail and lifestyle brand at the 23rd Dubai Shopping Festival not only offering unbeatable shopping deals to travellers, but also an exhaustive and equally impressive culinary options from the choicest restaurants. JetEscapes Holidays’ all-inclusive Dubai Shopping Festival packages are designed to offer a unique and memorable holiday experience for the entire family, while taking care of our guests’ every travel need. Providing guests with lasting experiences is one of the core strengths of Jet Airways.”

Shine.com Introduces Face Recognition and Touch ID Capabilities in its Mobile Application


Underlining its focus on leveraging technology as a key differentiator, Shine.com, India’s 2nd largest job portal, has introduced face recognition and touch ID capabilities in its mobile application. The technological milestone marks the first time that any Indian online jobs portal has integrated features designed around hardware-based tech in its mobile app, and emphasizes Shine.com’s commitment to offering users a superior and distinct experience on its platform.

Following the development, when a Shine.com user signs up on or logs into the mobile app for the first time, they are prompted to create a Face/Touch ID for future sessions. One user session on the Shine mobile application lasts for a month, after which users need to log in again. By streamlining the login process through Face/Touch ID, Shine.com has ensured that users can seamlessly log back into the app without any hassle, even if they forget their passwords.

Users can also log into the app any time they receive notifications simply by using their face/touch ID, without having to enter a password or go through other means of authentication. The new features also draw on the in-built security mechanism of the OS platform that the mobile app operates on, to safeguard the user’s information.

Amardeep Vishwakarma, CTO, Shine.com, added, “Shine.com has been an industry frontrunner for the past several years, with an unwavering focus on user-centricity when it comes to its offerings. We were amongst the first online jobs portals in India to have launched their own mobile app. The launch of this first-of-its-kind face and touch-based login features on our mobile app, well before any other player in the domain, further reinforces our commitment to simplifying and adding value to our users’ interactions with our online platform.”

“While most apps focus only on improving on the software side of tech, our app is currently the only jobs app which is also keeping pace with changes on the hardware side. The latest version of the Shine.com mobile app is geared for the latest smartphones in the market, the iPhone XS and the iPhone XR, and is leveraging cutting-edge technology to enable a significantly better user experience,” added he.

Shine.com has enabled touch ID-based login on both Android and iOS applications, while the face recognition-based login is currently available exclusively on the Shine.com iOS app on iPhone XS and iPhone XR. The platform plans to soon make the face ID feature available on its Android app as well.

Shradha Sharma of Yourstory, Launches Author Vishwas Mudagal's Book, The Last Avatar

Successful entrepreneur, CEO, angel investor, motivational speaker and author Vishwas Mudagal's latest book, a mythological fiction and sci-fi novel,titled ‘The Last Avatar’, was today launched at Atta Galatta by eminent media personality, Shradha Sharma, Founder, CEO & Chief Editor of Your story, a media technology platform for entrepreneurs. 

Set in the future and written over a fabric of mythology, weaved with threads of science fiction, the Last Avatar is the first installment of a three-part trilogy under Age of Kalki and attempts to demystify the tense geopolitical times that truly surround us today. Launches amidst popular guests and avid book readers, the event included a book reading sessions by the author himself, followed by a tete a tete with the guest for the evening, Shardha Sharma, who has been instrumental in shaping the career of many entrepreneurs and played an encouraging role for emerging starts-ups. 

Speaking on the occasion, author Vishwas Mudagal says, I was always fascinated with the prophecy of Kalki, the last avatar of God who the ancient Hindu Puranas and epics predict would be born to end the age of darkness on earth. I decided to create a true Indian superhero with Kalli, in a way no one had ever thought about before". 

This is the author’s second book, after a very successful debut – Losing my Religion launched in 2014,  which went on to become a sensational bestseller and etched his place as a top author and youth icon. 

Effectively jugging multiple roles, Vishwas Mudagal is also the CEO & Co-Founder of GoodWorkLabs and GoodWorks CoWork, ranked the No1 co working space in Bangalore, and has embraced storytelling as his parallel career to pursue his love and passion for writing.

Spell Bee League Carnival’ Sees Overwhelming Success in Bengaluru


Spell Bee League in association with NRN Aerospace Systems organized “Spell Bee League Carnival”, a spelling fiesta for children on 16th December 2018 at The Kittur Rani Chennamma Stadium (Jayanagar), Bangalore. The daylong event saw over  1000 children from 1st – 10th standard participate in spelling competitions to win a grand prize of gifts worth 1 Lakh rupees. 32 Children were selected for the Quarter Finals which will be held in the coming days.

The event was inaugurated by MLA of Jayanagar, Sowmya Reddy. In her address she said “Competitions and events of this nature need to be organized on a larger scale across Bangalore. These help on enhancing the communication skill of the children. This not only helps them become more competitive but also gives them a break from their study schedule. I wish the event all the very best”

The event had dedicated zones for parents where they had access to a team of experienced mentors who advised them on topics around parenting and career goals of children. Activities by International & National partner brands included mind stimulating tasks for the future troopers.

Speaking on the occasion, Madhu HS, Co-founder, Spell Bee League said “We have received an overwhelming response for the event. We have seen participation of over 1000 children and we have selected 32 among them for the quarter finals that will happen in the coming days. Today we have also announced the launch of #SpellBeeHive, a unique talent community for children of all age group a nd we are very excited about it”

This event is being organized by BizWingz and is presented by NRN Aerospace Systems, Smart Kidz Club, School Travel App, Kydz Adda, Sanrakshan PTE Ltd Singapore, Faith Foundation Trust, PFA Wildlife Hospital, Hoopsters, Bisleri Fonzo and Breathe Entertainment. Bengaluru’s leading radio station, Indigo 91.9 fm is the official radio partner for the event.

Total Pageviews