Under CISA pressure collaboration, Microsoft makes cloud security logs available for free
(2023/07/20)
- Reference: 1689856214
- News link: https://www.theregister.co.uk/2023/07/20/under_cisa_spressures_collaboration_microsoft/
- Source link:
Microsoft announced on Wednesday it would provide all customers free access to cloud security logs – a service usually reserved for premium clients – within weeks of a reveal that government officials' cloud-based emails were targets of an alleged China-based hack.
Microsoft [1]wrote on its blog it was expanding the service's access beginning in September 2023 to "increase the secure-by-default baseline" of its cloud platforms "in response to the increasing frequency and evolution of nation-state cyber threats."
Subscribers to the standard version of Microsoft Purview Audit will also have their default retention period extended from 90 to 180 days.
[2]
The cloud Goliath theorized that, while logs don’t prevent attacks, they are useful in digital forensics and incident responding. They provide insight into legitimate versus abnormal user behavior.
[3]Linux has nearly half of the desktop OS Linux market
[4]Someone just blew over $190k on a 4GB first-gen iPhone
[5]Unidentified object on Australian beach may be part of Indian rocket launcher
[6]Tesla board members to return $735M in compensation settlement
[7]Mint 21.2 is desktop Linux without the faff
The move is the result of close coordination with commercial and government customers, as well as the Cybersecurity and Infrastructure Security Agency (CISA), said Microsoft. It added that CISA called for more accountability from industry regarding cyber security.
CISA director Jen Easterly called the decision "a step in the right direction."
[8]
[9]
In a [10]blog post on the CISA website praising the decision, the org's executive assistant director for cyber security Eric Goldstein cited the recent Microsoft Exchange Online [11]breach.
According to Goldstein, the affected agency used logging data to detect the breach on Microsoft's cloud-based email services and take action to limit the damage. He said charging for logging data was "a recipe for inadequate visibility into investigating cyber security incidents."
[12]
The attack – which Microsoft has called espionage-focused and attributed to a China-based threat actor it tracks as Storm-O558 – was found by the Federal Civilian Executive Brach (FCEB) agency. Among the reported victims are US commerce secretary Gina Raimondo and other State and Commerce Department officials. The threat actors had access to accounts for around a month before being detected on June 16, 2023.
Redmond [13]said it had determined the actor was forging Azure Active Directory (AD) tokens using an acquired Microsoft account (MSA) consumer signing key, which was made possible by a validation error in Microsoft code. The use of an incorrect key allowed Microsoft's crack team of boffins to track all access requests from the threat actor.
On Friday, Microsoft admitted it still didn't know how the hackers gained access to the signing key needed to access accounts, and said the investigation was "ongoing."
[14]
It also revealed that it had seen Storm-0558 transition to other techniques – indicating the gang's ability to use signing keys has been disrupted by cyber security measures. ®
Get our [15]Tech Resources
[1] https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2023/07/18/linux_desktop_debate/
[4] https://www.theregister.com/2023/07/18/first_gen_iphone_auction/
[5] https://www.theregister.com/2023/07/18/unidentified_object_on_australian_beach/
[6] https://www.theregister.com/2023/07/18/tesla_excess_compensation/
[7] https://www.theregister.com/2023/07/19/mint_212/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.cisa.gov/news-events/news/when-tech-vendors-make-important-logging-info-available-free-everyone-wins
[11] https://www.theregister.com/2023/07/13/microsoft_alleges_china_behind_espionagefocused/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Microsoft [1]wrote on its blog it was expanding the service's access beginning in September 2023 to "increase the secure-by-default baseline" of its cloud platforms "in response to the increasing frequency and evolution of nation-state cyber threats."
Subscribers to the standard version of Microsoft Purview Audit will also have their default retention period extended from 90 to 180 days.
[2]
The cloud Goliath theorized that, while logs don’t prevent attacks, they are useful in digital forensics and incident responding. They provide insight into legitimate versus abnormal user behavior.
[3]Linux has nearly half of the desktop OS Linux market
[4]Someone just blew over $190k on a 4GB first-gen iPhone
[5]Unidentified object on Australian beach may be part of Indian rocket launcher
[6]Tesla board members to return $735M in compensation settlement
[7]Mint 21.2 is desktop Linux without the faff
The move is the result of close coordination with commercial and government customers, as well as the Cybersecurity and Infrastructure Security Agency (CISA), said Microsoft. It added that CISA called for more accountability from industry regarding cyber security.
CISA director Jen Easterly called the decision "a step in the right direction."
[8]
[9]
In a [10]blog post on the CISA website praising the decision, the org's executive assistant director for cyber security Eric Goldstein cited the recent Microsoft Exchange Online [11]breach.
According to Goldstein, the affected agency used logging data to detect the breach on Microsoft's cloud-based email services and take action to limit the damage. He said charging for logging data was "a recipe for inadequate visibility into investigating cyber security incidents."
[12]
The attack – which Microsoft has called espionage-focused and attributed to a China-based threat actor it tracks as Storm-O558 – was found by the Federal Civilian Executive Brach (FCEB) agency. Among the reported victims are US commerce secretary Gina Raimondo and other State and Commerce Department officials. The threat actors had access to accounts for around a month before being detected on June 16, 2023.
Redmond [13]said it had determined the actor was forging Azure Active Directory (AD) tokens using an acquired Microsoft account (MSA) consumer signing key, which was made possible by a validation error in Microsoft code. The use of an incorrect key allowed Microsoft's crack team of boffins to track all access requests from the threat actor.
On Friday, Microsoft admitted it still didn't know how the hackers gained access to the signing key needed to access accounts, and said the investigation was "ongoing."
[14]
It also revealed that it had seen Storm-0558 transition to other techniques – indicating the gang's ability to use signing keys has been disrupted by cyber security measures. ®
Get our [15]Tech Resources
[1] https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2023/07/18/linux_desktop_debate/
[4] https://www.theregister.com/2023/07/18/first_gen_iphone_auction/
[5] https://www.theregister.com/2023/07/18/unidentified_object_on_australian_beach/
[6] https://www.theregister.com/2023/07/18/tesla_excess_compensation/
[7] https://www.theregister.com/2023/07/19/mint_212/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.cisa.gov/news-events/news/when-tech-vendors-make-important-logging-info-available-free-everyone-wins
[11] https://www.theregister.com/2023/07/13/microsoft_alleges_china_behind_espionagefocused/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLlaJ7GGH111dap-7RBo7wAAA9I&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
"a step in the right direction"
A small step for Borkzilla, a giant leap for cloud network administrators.
And it took a breach to make that available. The fact that retaining cloud log ability had been considered acceptable by a provider is not really surprising. The fact that potential customers found that acceptable is just the demonstration that it is not technical people that wanted The Cloud TM to happen, it was the CEO's nephews and the bragging rights that it erroneously conferred.
Any admin worth the name would have seen the paltry amount of tools at his disposition, compared to what he had available with his on-prem servers, and scoffed at the idea that he should hand over his data to a server he barely had any control over.
Except nobody asked the admin's opinion in the mad dash to be the coolest cloud kid on the block.
Well, at least now some semblance of sanity is emerging from the morass.