What is unauthorised cloud-resource abuse?¶
Unauthorised cloud-resource abuse is creation or use of cloud infrastructure outside the account holder's authority or intended purpose. An offender may use compromised access to run mining, host content, relay traffic, store data or support attacks while charges and alerts accrue to the victim account.
Billing ownership identifies who receives the cost, not who created or controlled the resource.
Trace resource creation to an identity path¶
Provider records can connect a virtual machine, container, function, database or network service to the action that created it. Preserve:
- tenant, subscription, project and region;
- resource and image identifiers;
- user, role, service principal or API key;
- authentication session and source device;
- creation, modification and deletion API calls;
- templates, scripts or automation involved; and
- network activity, workload, cost and provider alerts.
One stolen credential or deployment template may create many resources without further human input. Separate the initial human or automated instruction from each resulting instance.
Account for transient resources¶
Offenders may use unfamiliar regions or projects, then delete resources quickly. Providers may also suspend or stop them automatically. Audit, billing and enforcement records can establish that a resource existed even when it is no longer running at examination.
Compare the disputed deployment with normal regions, roles, images and change processes. An unfamiliar resource is not automatically malicious, but the difference can direct attention to a compromised identity or automation route.
Key takeaway
Follow cloud-resource creation from authentication and API action to workload, effect and cost, while keeping subscriber ownership separate from the identity or automation that exercised control.