Skip to main content

The Flavor of Clouds: Are Some Cloud Platforms More Attractive to Attackers?

Significant financial loss and sensitive data exposure continue to be a significant risk for entities that host systems in the cloud. Identifying if attackers prefer attacking systems hosted in one cloud provider over another could assist architects and engineers in selecting a provider.

Honeypots were deployed to Amazon Web Services (AWS), Azure, and Google Cloud Platform, incorporating a Social Engineering lure to measure human interaction and bot interactions to determine if attackers preferred one cloud provider over another. The data analysis did not identify human interactions, leaving only bot interactions for further examination. Hosting providers that hosted the bots were identified by enriching the data during analysis.

The results showed that the SSH server hosted in AWS experienced significantly fewer attacks, and far fewer attacks originated from AWS. Determining causation from this metric alone was not possible. AWS is likely employing undocumented mitigation strategies, attackers may prefer other clouds over AWS, or resources are allocated based on the number of usernames used in the attacks against SSH.

The data also showed that a very low percentage of bots attacked all three cloud providers overlapped with one another, indicating that bot herders are configuring attack infrastructure to focus on particular clouds rather than directing bots to crawl the internet mindlessly. Bots were tailored to the environments they attacked based on analysis of how they interacted with the web servers. Defenders, engineers, and architects should not deviate from required and selected security frameworks regardless of attacker preferences that may be identified.

SANS_Flavor_Clouds_Are_Some_Cloud_Platforms_More_Attractive_Attackers (PDF, 0.48MB)

17 Feb 2025
ByJames Smith
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Identifying Security Vulnerabilities in Kubernetes Environments

Research Paper

This research aims to develop a practical methodology for identifying security misconfigurations in Kubernetes environments, across both Infrastructure-as-Code (IaC) and live cluster states.

  • 14 May 2026
  • Patrick Trecek

Marketing or Added Value? The Truth About Purpose-Built Detection and Response for Containers

Research Paper

With the rise of Cloud Detection and Response (CDR), this paper dives deeper into the added value and gaps of these solutions compared to the traditional pillar, Endpoint Detection and Response (EDR).

  • 5 Dec 2025
  • Jeffrey Everling

ZTA Unpacked: The Critical Technical Components of Zero Trust Architecture

Research Paper

This paper demystifies the technical foundation of Zero Trust Architecture (ZTA) and outlines the key technologies that drive modern, mature implementations. 

  • 15 Aug 2025
  • Greg Scheidel

Navigating the Challenges of Securing Hybrid Environments

Research Paper

This paper explores ways to bring clarity and control back to your hybrid security strategy—with practical guidance on Zero Trust, unified monitoring, and the evolving role of AI in modern defense.

  • 24 Jul 2025
  • Matt Bromiley

Securing Azure with PIM: A Just-in-Time Access Study

Research Paper

This study assesses Azure Privileged Identity Management (PIM) and its Just-in-Time access model within a controlled Azure environment, simulating enterprise scenarios across Azure Subscription Roles.

  • 11 Jul 2025
  • Dustin Bourgois

Resiliency and Business Continuity in the Cloud Era

Research Paper

In this white paper, Dave Shackleford unpacks today’s evolving cloud threat landscape.

  • 21 May 2025
  • Dave Shackleford

Out-of-Band Defense: Securing VPNs from Password-Spray Attacks with Cloud Automation

Research Paper

This research examines an out-of-band solution to detect and block password-spray attacks on Remote Access VPN services, addressing vulnerabilities like Cisco’s CVE-2024-20481 amid rising threats post-COVID-19.

  • 12 May 2025
  • SANS Institute

Securing the Future with Microsoft Defender for Cloud: Best Practices and Insights

Research Paper

In this paper, you’ll learn how to enhance your cloud security posture through actionable insights and use cases involving Microsoft Defender for Cloud.

  • 26 Mar 2025
  • Dave Shackleford

Detecting Azure Hybrid Machine Attack Paths with Graph Theory

Research Paper

This research extends the data collected by the security tool BloodHound to uncover hidden connections between on-premises devices and their cloud identities within an Azure environment.

  • 7 Jan 2025
  • Shawn Woods

The Cost of Container Runtime Security

Research Paper

Containerization has fundamentally changed how applications are developed, deployed, and managed....

  • 5 Dec 2024
  • Luke Stigdon

Never Trust, Always Verify: Analysis of Zero Trust Best Practices for Conditional Access

Research Paper

This study examines the effectiveness of Microsoft Entra's Conditional Access policies in thwarting...

  • 26 Sep 2024
  • Glenn Andal

Memory Safety and Beyond: Unveiling the Missing Piece in Golang

Research Paper

This study examines Go's default HTTP implementation while undergoing certain Denial of Service...

  • 2 Aug 2024
  • Anu Mathew

Active Directory: Tactical Containment to Curb Domain Dominance

Research Paper

More than two decades after Microsoft released Active Directory, the identity platform remains in...

  • 22 Apr 2024
  • Chris Tierney

Evaluating Detection Time Delta in Amazon GuardDuty

Research Paper

Understanding the effectiveness of security solutions like Amazon GuardDuty is essential for...

  • 30 Nov 2023
  • Ayo Ajiboye

Apples to Oranges: Understanding the Changing Attack Surface for Applications Migrated from Self- Hosted to SaaS

Research Paper

Why would you defend two instances of the same application differently? Self-hosted applications...

  • 15 Sep 2023
  • Eddie Black

Kubernetes: Stealing Service Account Tokens to Obtain Cluster-Admin

Research Paper

Kubernetes security is a complex subject that relies on well-designed Role-Based Access Control...

  • 14 Jun 2023
  • Cory Helco

Is Your Cloud Environment Secure? How Do You Know?

Research Paper

The adoption and utilization of cloud environments continue to proliferate for businesses of all...

  • 8 Dec 2022
  • Kiel Vaughn

Enterprise Observable Security: A Holistic Approach Using Azure

Research Paper

The information security industry has been plagued with many technical and social challenges that...

  • 5 Oct 2022
  • Jose Maria Polanco Canul

2021 Ransomware Case Study: Identifying High Priority Security Controls for Public Institutions

Research Paper

Three quarters through 2021 and malicious cyber actors appear to be taking full advantage of the...

  • 1 Dec 2021
  • Anthony Luna

Decreasing Attacker Dwell Time in Azure Active Directory

Research Paper

As companies continue to embrace the cloud, attackers also have shifted their attack methods to...

  • 21 Jul 2021
  • Mark Morowczynski