Ebb and Flow: Network Flow Logging as a Staple of Public Cloud Visibility or a Waning Imperative?
The basic tenets of information security remain relatively unchanged even while specific examples of security-related tools, processes, and procedures may shift in popularity over time. Deciding what to prioritize and recommend as a security professional can be challenging, but the most straightforward cases are those justified by the quantitative reduction of risk. In this search for quantitative risk reduction, it is worthwhile for security professionals to consider that the methods used to fulfill basic security needs in one environment may not provide the same benefit in another. The 2019 version of the Cloud Security Alliance's Top Threats to Cloud Computing document warns of critical security issues facing public cloud consumers (Cloud Security Alliance, 2019, p.40). The CSA also acknowledges their work concentrates less on some of the more traditional security threats like 'vulnerabilities and malware', while calling for further research (Cloud Security Alliance, 2019, p.40). This whitepaper inhabits the category of additional research and also occupies a space parallel, but perhaps not identical to classical security views. This research assumes a slightly-less-traditional approach by not taking the value of flow logging, or its costs in the cloud, for granted. It further asserts that given limited resources, there may be more directly valuable logging sources available. This paper establishes a quantitative methodology for judging the effectiveness of flow and non-flow logging as applied in a public cloud environment. It exercises this methodology by simulating top cloud computing threats and examining the capabilities of each.
39580 (PDF, 3.30MB)
18 May 2020Related Content
Identifying Security Vulnerabilities in Kubernetes Environments
Research PaperThis research aims to develop a practical methodology for identifying security misconfigurations in Kubernetes environments, across both Infrastructure-as-Code (IaC) and live cluster states.
- 14 May 2026
- Patrick Trecek
Marketing or Added Value? The Truth About Purpose-Built Detection and Response for Containers
Research PaperWith the rise of Cloud Detection and Response (CDR), this paper dives deeper into the added value and gaps of these solutions compared to the traditional pillar, Endpoint Detection and Response (EDR).
- 5 Dec 2025
- Jeffrey Everling
Securing Azure with PIM: A Just-in-Time Access Study
Research PaperThis study assesses Azure Privileged Identity Management (PIM) and its Just-in-Time access model within a controlled Azure environment, simulating enterprise scenarios across Azure Subscription Roles.
- 11 Jul 2025
- Dustin Bourgois
Out-of-Band Defense: Securing VPNs from Password-Spray Attacks with Cloud Automation
Research PaperThis research examines an out-of-band solution to detect and block password-spray attacks on Remote Access VPN services, addressing vulnerabilities like Cisco’s CVE-2024-20481 amid rising threats post-COVID-19.
- 12 May 2025
- SANS Institute
The Flavor of Clouds: Are Some Cloud Platforms More Attractive to Attackers?
Research PaperSignificant financial loss and sensitive data exposure continue to be a significant risk for entities that host systems in the cloud.
- 17 Feb 2025
- James Smith
Detecting Azure Hybrid Machine Attack Paths with Graph Theory
Research PaperThis research extends the data collected by the security tool BloodHound to uncover hidden connections between on-premises devices and their cloud identities within an Azure environment.
- 7 Jan 2025
- Shawn Woods
The Cost of Container Runtime Security
Research PaperContainerization has fundamentally changed how applications are developed, deployed, and managed....
- 5 Dec 2024
- Luke Stigdon
Never Trust, Always Verify: Analysis of Zero Trust Best Practices for Conditional Access
Research PaperThis study examines the effectiveness of Microsoft Entra's Conditional Access policies in thwarting...
- 26 Sep 2024
- Glenn Andal
Memory Safety and Beyond: Unveiling the Missing Piece in Golang
Research PaperThis study examines Go's default HTTP implementation while undergoing certain Denial of Service...
- 2 Aug 2024
- Anu Mathew
Active Directory: Tactical Containment to Curb Domain Dominance
Research PaperMore than two decades after Microsoft released Active Directory, the identity platform remains in...
- 22 Apr 2024
- Chris Tierney
Evaluating Detection Time Delta in Amazon GuardDuty
Research PaperUnderstanding the effectiveness of security solutions like Amazon GuardDuty is essential for...
- 30 Nov 2023
- Ayo Ajiboye
Apples to Oranges: Understanding the Changing Attack Surface for Applications Migrated from Self- Hosted to SaaS
Research PaperWhy would you defend two instances of the same application differently? Self-hosted applications...
- 15 Sep 2023
- Eddie Black
Kubernetes: Stealing Service Account Tokens to Obtain Cluster-Admin
Research PaperKubernetes security is a complex subject that relies on well-designed Role-Based Access Control...
- 14 Jun 2023
- Cory Helco
Is Your Cloud Environment Secure? How Do You Know?
Research PaperThe adoption and utilization of cloud environments continue to proliferate for businesses of all...
- 8 Dec 2022
- Kiel Vaughn
Enterprise Observable Security: A Holistic Approach Using Azure
Research PaperThe information security industry has been plagued with many technical and social challenges that...
- 5 Oct 2022
- Jose Maria Polanco Canul
2021 Ransomware Case Study: Identifying High Priority Security Controls for Public Institutions
Research PaperThree quarters through 2021 and malicious cyber actors appear to be taking full advantage of the...
- 1 Dec 2021
- Anthony Luna
Decreasing Attacker Dwell Time in Azure Active Directory
Research PaperAs companies continue to embrace the cloud, attackers also have shifted their attack methods to...
- 21 Jul 2021
- Mark Morowczynski
Detecting and Preventing the Top AWS Database Security Risks
Research PaperEngineers regularly perform risky actions while deploying and operating databases on cloud services...
- 9 Dec 2020
- Gavin Grisamore
Prescriptive Model for Software Supply Chain Assurance in Private Cloud Environments
Research PaperAs companies embrace Continuous Integration/Continuous Deployment (CI/CD) environments, automated...
- 14 Oct 2020
- Robert Wood
Shall We Play a Game?: Analyzing the Security of Cloud Gaming Services
Research PaperThe adoption of cloud gaming services is quickly growing. Like many services that are eager to go to...
- 7 Oct 2020
- Adam Knepprath
