Приходите на вебинар Faceter «Как контролировать бизнес через умное видеонаблюдение» 2 июля в 11.00. Регистрация

Cloud storage and the fear of being hacked. 6 possible system threats

03.04.2021 Денис Артемьев video-surveillance-industry

Cloud storage and the fear of being hacked. 6 possible system threats

Penn State University experts have shown empirically that the lion’s share of human fears never come true. The study results have shown that 91.4% of pessimistic predictions did not come true among the experiment participants. Accordingly, we can conclude that the probability with which fears come true is 8.6%.

Despite its apparent vulnerability, video surveillance cloud storage is a reliable way of data storage. Let’s talk about the TOP-6 most popular fears and threats in this area, as well as data protection methods.

What is cloud storage of a video archive?

The online storage model where data is sent to numerous distributed in the operator’s network servers is cloud-based.

Cloud data storage used in video surveillance is simple, convenient and economical. Today, cloud-based remote access and control technology is the leading and most advanced one.

What you need to create a security system with cloud storage:

  • IP video equipment or an ordinary smartphone with Internet access;
  • an agreement with a provider;
  • choice of a tariff plan. For example, if you choose the “Basic” tariff from Faceter, you will get the cloud for free (up to 24 hours of storage in SD quality).

IMPORTANT: the cloud storage service automatically updates the system (without user intervention), taking cybersecurity care. Also, the provider bears the entire burden of legal responsibility for the safety and nondisclosure of data.

What are the concerns of users? Real statistics

33% of the global business community representatives and 26% of Russian companies are concerned about possible cyberattacks on cloud storage.

Research conducted by Kaspersky Lab among IT specialists from 29 countries (including 772 people from the Russian Federation) confirmed that the human factor causes 90% of data leaks from the cloud, and the provider causes only 11% of incidents.

Six possible threats and recommendations for protection

To properly balance the benefits against the threats and distinguish between the reality and the ephemerality of possible hazards, let’s conduct a comprehensive analysis.

Privacy issues

Attack aimReasonsControl measures
Capture / steal dataPurposeful actionLeast privilege principle
ViewHuman factorMonitoring logging
PublicationTechnical vulnerabilityThe reliable rapid response mechanism
DeletingLack of security measuresAdditional data encryption

Invalid client settings

According to analyst Neil MacDonald (Vice President, Fellow and Distinguished Analyst at Gartner Research), almost all successful cyberattacks on cloud services are carried out with the easy submission of incorrect client settings.

Attack aimReasonsControl measures
Capture / steal dataInvalid configuration parametersA detailed description of the infrastructure life cycle in instructions and logs
ViewInadequate controlProactive service management
PublicationInsufficient protection of backups

 

Additional data encryption
DeletingOpen network space connected to the network 
Observation  

Lack of security strategy. Lack of security architecture

Attack aimReasonsControl measures
Capture / steal dataLack of benchmarks and strategiesImplementation of security architecture according to the objectives
ViewLack of documentationProviding continuous visibility of the actual state of security
PublicationLack of balance between innovation and controlConstant system update
Observation  
Deleting  

Insufficient identification procedures, separation of rights and access control

Attack aimReasonsControl measures
Capture / steal dataInsufficient data protectionUsing temporary credentials instead of long-term keys
ViewLack of automatic rotation of keys, passwords and certificatesPeriodic key change
PublicationLack of regularity of automatic rotationRemoving unused keys
ObservationLack of secure access control systems.Setting up multi-factor authentication
DeletingAvoiding strong passwordsRegular key rotation
Obtaining control and management privilegesOpt-out of multi-factor authentication 
Virus injection  

Accounts hacking and stealing 

Attack aimReasonsControl measures
Capture / steal dataInsufficient protection of control and access dataMaking backups
ViewLack of in-depth protection of the client cabinetIntroduce a reliable method of users authentication
PublicationAvoid logging activity monitoring

 

Separation of administrative functions
ObservationLack of protection against phishing and exploitation of stolen informationRestriction of IP addresses for access
DeletingTarget attack 
Obtaining control and management privileges  
Virus injection  
Accounts selling  

Internal threats

Attack aimReasonsControl measures
Capture / steal dataInsufficient data protectionImplementation of a strict identity and access policy
ViewThe human factor, including pressure, threats, coercionLimiting privileges
Publication Prophylaxis
Observation Staff training
Deleting Creating a safe work environment
Obtaining control and management privileges Keeping journals
Virus injection  

 

Are the fears worth attention?

As you can see from the tables, there are many protection measures for each type of threat.

In an interview with “Izvestia”, Evgeny Kaspersky said that modern hackers could carry out previously “tough” attacks even for state security agencies. At the same time, the level of protection of the cloud space is also constantly evolving. Therefore, hacking a cloud, despite its apparent insecurity, is a complex undertaking.

And compared to the degree of protection of video materials on local devices (recorders and external devices), the cloud is the safest way to store data. At least in favour of the cloud is the fact that it is impossible to exert a negative physical effect on the server as on a video recorder (steal, break, destroy).

Results

Users are concerned about the integrity and reliability of external cloud platforms. However, the video archive’s cloud storage is protected on maximum from the influence of unauthorized persons and the users themselves. An additional plus is the automatic update of security systems and the absence of legal responsibility for information storage and confidentiality.

Денис Артемьев

Денис Артемьев

Специалист в области видеонаблюдения, видеоаналитики, облачных систем хранения данных. Консультант по вопросам интеграции систем и средств видеонаблюдения в различные сферы бизнеса. Опыт работы в отрасли более 10 лет.
video-surveillance-industry
Published: 03.04.2021

интересное от Faceter

Silhouette Recognition: 3 Reasons for Implementing the System in the Moscow Region
Silhouette Recognition: 3 Reasons for Implementing the System in the Moscow Region
Have you heard about silhouette recognition? This is a new high-tech capability of intelligent video surveillance. Human silhouette recognition and face recogni...
Read more
08.06.2022
The level of responsibility of buildings and structures and video surveillance
The level of responsibility of buildings and structures and video surveillance
Let's analyze the relationship between the concept of "the level of responsibility of buildings and structures" and the need for video surveillance. Let's talk...
Read more
07.06.2022
Video surveillance of animals in the zoo: 6 reasons + live broadcasts
Video surveillance of animals in the zoo: 6 reasons + live broadcasts
A video surveillance camera for animals in a zoo and at home can be essential and useful. Video surveillance of animals helps to look after them properly.
Read more
07.06.2022
Watch out! 7 unexpected places with hidden video surveillance
Watch out! 7 unexpected places with hidden video surveillance
You have no idea where hidden wireless mini video surveillance is waiting for you. We will tell you about the TOP-7 places where there might be a recording came...
Read more
03.06.2022
Video surveillance at a construction site + crane video surveillance
Video surveillance at a construction site + crane video surveillance
Construction site video surveillance and crane surveillance are two trendy areas in the construction industry. Don't miss out on the unique opportunities offere...
Read more
03.06.2022
How to display the camera image on a monitor? 4 ways + Faceter
How to display the camera image on a monitor? 4 ways + Faceter
The most common problem for users is how to display the camera picture on a monitor. We will tell you how to set up video surveillance via the Internet and othe...
Read more
03.06.2022
Election surveillance cameras. 98% coverage at 50,000 polling stations.
Election surveillance cameras. 98% coverage at 50,000 polling stations.
Election security cameras (polling station cameras) are the reality of our times. Businesses, ordinary citizens, and government agencies need video surveillance...
Read more
01.06.2022
Video surveillance repair. Common problems and 5 sources of breakdown
Video surveillance repair. Common problems and 5 sources of breakdown
Are you worried that it will cost a lot of money to repair video surveillance? Yes, video surveillance repair can cost the earth. There are options without inve...
Read more
01.06.2022
Poor image of a video camera: 5 reasons and 12 solutions
Poor image of a video camera: 5 reasons and 12 solutions
There is no such thing as a bad digital camera picture without a reason. Here's how to find the cause, what to do and how to fix the problem. Read this article...
Read more
01.06.2022
6 situations in life when a video camera is simply necessary
6 situations in life when a video camera is simply necessary
Is video surveillance a necessity for your home? Let's talk about 6 situations in life when a video surveillance system can provide security and peace of mind.
Read more
27.05.2022
Voltage drop and quality of video surveillance: 3 countermeasures
Voltage drop and quality of video surveillance: 3 countermeasures
From this article, you will learn how to determine the voltage drop on the resistance. After reading this you will be able to correct the voltage drop in the mo...
Read more
27.05.2022
Cameras for computer vision: review and selection criteria
Cameras for computer vision: review and selection criteria
Let's find out in detail what cameras for computer vision are. We will talk about why digital CCTV cameras are much better than analog cameras.
Read more
27.05.2022
What is the computer vision technology? 2 tasks and self-study
What is the computer vision technology? 2 tasks and self-study
Computer vision technologies are everywhere. We tend to participate in endless scans without noticing it. Install a video surveillance system with computer visi...
Read more
24.05.2022
Video surveillance and the Internet speed: 6 options for reducing consumption
Video surveillance and the Internet speed: 6 options for reducing consumption
Can the speed of the Internet decrease when the video surveillance system is working? From this article, you will learn the answer and what speed of the Interne...
Read more
24.05.2022
Video recording of road accidents in the stream of vehicles. The solution for everyone.
Video recording of road accidents in the stream of vehicles. The solution for everyone.
Video recording of road accidents in the stream, recognition of license numbers, and information transfer to the traffic police operator are the facts of life o...
Read more
24.05.2022