On the Importance of Cloud Access Security Agent CASB

16-022-supersoniccontract

As enterprise IT operations are gradually going to the cloud locally, they begin to look for security access control methods to introduce cloud operations from internal data centers. Cloud Access Security Proxy (CASB) is such a tool. Today, CASB has been introduced for ten years and is a common component of enterprise security infrastructure. But for many people, it is still a mystery to know exactly the function of CASB and why it is different from the next generation firewall.

This article will take you to study CASB and explain its origin and evolution.

The original purpose of CASB is to provide visibility of all cloud services in the enterprise infrastructure. CASB is the first special weapon against "shadow IT" and unauthorized cloud services. CASB is deployed at the network boundary and uses a variety of proxy types to identify each response to or connection from the cloud service, regardless of whether the cloud service is approved.

At the beginning of the creation of CASBs, they were often deployed as physical devices in customer data centers. Now, they can still be deployed, but they are more deployed as cloud services themselves in the "security as a service" (SaaS) model. In both cases, today's CASB uses agents and APIs to identify the largest possible range of cloud services and take action based on the additional functions that the product now has.

Knowing the existence of cloud services is not the same as protecting them (or implementing security control for specific services), so CASB gradually develops and provides more services for the security team. As Gartner said, CASB's "four pillars" have developed - visualization, compliance, data security and threat protection.

These four functional areas are important in the shared responsibility cloud security model, in which cloud providers are responsible for protecting their infrastructure, and cloud customers are responsible for the security of their applications and data.

So, what is the real meaning of the "four pillars"? How are they used to protect the enterprise cloud? The following will be discussed one by one.

 

visualization

CASB can let enterprise leaders know whether the cloud services that all employees insist on using in the network are safe. Although this is necessary and frightening, the current CASB can indeed provide partial detection. CASB can be used to find and monitor the way to and from cloud service traffic. It can also tell the security team which employees are using cloud services and how they get cloud services. When confronted with employees, CASB tools can provide effective help if employees do not admit that their personal behavior has damaged the company's security plan.

Compliance

With the development of CASB, especially when they use APIs instead of agents to improve the visibility of cloud businesses, they can view data transferred from one cloud to another and between internally deployed infrastructure and clouds. In addition to providing the security team with a better understanding of the organization's cloud infrastructure, it can also view the data stored in the cloud and being processed.

Many aspects of compliance depend on understanding where and how data is stored. In addition to external regulations, many organizations have internal rules on how to store and handle specific types of data. CASB allows the security team to clearly understand the status of cloud bound data, so that it can detect and correct the situation of employees storing or migrating data to avoid violating external regulations.

data security

By understanding the status of data on the cloud, CASB can take the next step to protect the data. Through API controls, CASB can view transactions that have never entered the enterprise network (such as transactions between cloud services). CASB can implement a series of rules, such as data encryption or obfuscation, specific requirements for authentication and access control, and other parameters, to ensure that data is stored in a secure manner.

Threat protection

"Access" is a part of CASB. Such products can provide threat protection and strengthen the access and authentication control of cloud data applications. In many cases, CASB can monitor business activities and execute rules by interacting with existing single sign on or "identity as a service tool". One of the advantages of CASB is the ability to integrate with the existing security infrastructure, which distinguishes CASB from other tools.

In general, next-generation firewalls, Web application firewalls, and other security tools are considered complex and unable to maximize their advantages. In contrast, CASB has always been a tool that is easy to configure and deploy, even for inexperienced security teams.