Bringing Cybersecurity to the Data Center
Summary
Data centers are the heart of many enterprises, providing scalable, reliable access to the information and applications that define the organization. Specifically, perimeter threat prevention technologies tend to be heavily focused on detecting an initial compromise or infection (e.g. exploits and malware). Instead of exploits or malware, attackers are far more likely to search for clever ways to use their newly-gained position of trust to access or damage data center assets. Compromising administrator accounts, implanting backdoors, setting up hidden tunnels and RATs are all standard operating procedure for an ongoing persistent attack. For example hidden command-and-control traffic, network reconnaissance, lateral movement, the compromise of user and admin credentials can all precede an intrusion into the data center.