Showing posts with label Network Security. Show all posts
Showing posts with label Network Security. Show all posts

Monday, 20 December 2021

Log4j software bug: how the internet is responding and how to secure your applications?

 
Log4j, a software used by millions of web servers, was found with a major security flaw last week. Hackers are trying to take advantage of this bug (attacks are termed as Log4shell attacks) as this library is being used extensively over the globe by millions of apps. 

Detected first within the game "Minecraft", this vulnerability was soon brought to light by the media worldwide. 

It is easier for attackers to deceive the Log4j using the malicious code that contains a recursive lookup, resulting in a StackOverflowError and thereby forcing the software to store the log entry in form of a particular text that will terminate the process. Popularly known as a DDOS attack.

Soon, the cybersecurity agencies worldwide have raised alerts over Log4j. CyberSec experts are calling it "one of the worst in years, if not decades".

Companies have advised their customers to update to version 2.17.0 to cope up with the vulnerability. The update is said to be able to fix most of the issues. 

Companies can use a combination of multiple AWS services to help limit their risk/exposure from the Log4j vulnerability. Services like AWS WAF, Amazon Route 53 Resolver DNS Firewall, AWS Network Firewall, Inspector, Guard Duty, Security hub, etc. could prove to be useful when maximizing the security against cyberattacks carried out as a result of exploiting such vulnerabilities.

As an AWS Advanced Consulting Partner and having expertise in security, we at Cloud.in adopt security practices as per AWS standards for all our customers. Considering the AWS environment and offerings there are a lot of services that enhance and improve the security posture of your applications. 

Reach out to us to secure your applications at sales@cloud.in

Monday, 6 May 2019

Now Amazon Neptune Is Accessible In Asia Pacific (Seoul)

Amazon Neptune is a rapid, proven, completely organized graph database service which helps seamlessly to create and execute applications that function with specifically linked datasets. The basic fundamental of Amazon Neptune is a purpose-built, high-performance graph database engine optimized for keeping billions of relationships and querying the graph with milliseconds latency. Amazon Neptune gives assistance to approved graph models Property Graph and W3C's RDF, and their relevant query languages Apache TinkerPop Gremlin and SPARQL, enabling you to simply create queries that productively navigate particularly associated datasets. Amazon Neptune controls graph use cases like recommendation engines, fraud detection, knowledge graphs, drug discovery, and network security. Now Amazon Neptune is accessible in the Asia Pacific (Seoul) region and US East (N. Virginia, Ohio), US West (Oregon), Europe (Ireland, London, Frankfurt), Asia Pacific (Singapore, Sydney, Tokyo, Mumbai, Seoul). To know further about AWS regions and services, refer to the AWS global region table. And to know about Amazon Neptune, refer to product page, developer resources, and documentation

Curious How to Organize, Integrate Your Data, and Build Smart AI Apps? Try Amazon SageMaker!

Imagine this: You have a huge box of Lego bricks (aka your data) that can be used to build something amazing, maybe a castle, a rocket, or e...