Cloud computing security problems exist!

Source: Internet
Author: User
Tags ssh access

 

As an optimistic person, I used to think that the security of cloud computing is only a small probability event. In most cases, no one is very interested in attacking you, but last weekend, one thing happened, and I completely changed this idea. I started an instance on linode FOR THE yunengine internal test, but on the 7th, this instance was suddenly closed by linode because "TOS violation-SSH Brute Force", that is to say, someone else cracked my root password and used this machine to continue sending SSH access, to crack other machines, I sent 47523 packets to 262286 hosts in about four hours, in addition, I do not know who changed the password of the host running WordPress (that is, "Everyone is cloud"). In general, the danger of "outside" exists, to avoid being attacked again, I got a 14-bit long password on the new instance, hoping to avoid further attacks. In addition, linode provides a host security document. You can refer to the following summary:

    1. Maintain system and software updates
    2. Disable unused services
    3. Lock SSH
    4. Restrict access by root and system users
    5. Use a firewall to block excessive traffic
    6. Use denyhosts and fail2ban to prevent password-based attacks
    7. Encrypt Sensitive data

 

Finally, although cloud computing security issues do exist, the simplicity of cloud computing in architecture and Management will make it "promising" in terms of security ", especially when we are very concerned and paying attention to it.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.