CyberSecurity SEE

CISA and NIST Release Guidance for Protecting Cloud Identity Tokens

CISA and NIST Release Guidance for Protecting Cloud Identity Tokens

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have recently finalized guidance aimed at bolstering the security of cloud identity tokens and their assertions. This directive is primarily targeted at federal agencies, cloud service providers, and the organizations that rely on these services. The guidance comes in response to an increasing trend in which adversaries exploit weaknesses in cloud identity management to gain unauthorized access to sensitive data.

Interagency Report 8587, made publicly available on September 15, delves into the specifics of token management pertaining to single sign-on (SSO) systems, identity federation, and application programming interface (API) access. As noted by the agencies, cyber attackers have increasingly focused their efforts on these tokens, using them to navigate internal networks and access crucial information. The report underscores the critical nature of mitigating risks associated with the theft, forgery, and misuse of these tokens.

Although adherence to the new guidelines is voluntary, they establish a framework of best practices that organizations are encouraged to implement. The guidance emphasizes the importance of limiting the duration of access and identity tokens to no more than one hour. Moreover, expired tokens must be automatically rejected by any systems that handle authorization processes and policy enforcement, thereby minimizing opportunities for unauthorized access.

A core aspect of the guidance pertains to key management. It stipulates that signing keys associated with high-impact systems should be rotated every 90 days, while those in less critical environments should undergo similar updates at least annually. Additionally, tokens related to moderate-impact systems or higher should be securely stored in isolated or hardware-backed environments, avoiding persistent storage on servers or other digital resources to reduce vulnerability. Furthermore, high-impact systems are instructed to perform signing operations within isolated execution environments, creating an additional layer of security.

The agencies also emphasize the need for scoped keys, advocating for boundaries that are as narrow as feasible. In a notable security directive, the report insists that any token created outside federally authorized environments must not be permitted to validate or sign tokens within such environments. Another critical requirement is that every token must include an explicit audience field; if an access control mechanism receives a token lacking this attribute, it is instructed to reject it outright. Furthermore, to protect personal data, the guidelines specify that tokens and any embedded user information must remain unrecorded in internal logs.

The implications of this guidance extend to the use of artificial intelligence (AI) in accessing systems, data, and APIs. The report acknowledges that AI agents increasingly rely on signed tokens to perform their functions. However, the scope of the current guidance does not cover the broader risks associated with AI access, indicating that NIST and CISA continue to develop additional guidelines in that area.

The urgency behind this guidance is underscored by two specific incidents that highlight the vulnerabilities associated with token management. In a significant supply chain attack in 2020, adversaries compromised Active Directory Federation Services, allowing them to forge Security Assertion Markup Language (SAML) assertions and bypass multifactor authentication (MFA) protections installed at numerous organizations, including federal bodies. In another notable breach, unauthorized foreign entities exploited a consumer signing key that had been inadvertently exposed, forging tokens that managed to validate unauthorized access within government and enterprise systems—an incident that led to the compromise of over 60,000 emails from a single agency.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, encapsulated the essence of the guidance by highlighting the evolving nature of security in relation to identity. He noted, “Identity is the new perimeter, and the tokens and assertions behind it are attractive targets for sophisticated adversaries.” By establishing these new practices, the guidelines aim to strengthen the overall security of token issuance, thereby ensuring that stolen credentials do not facilitate unauthorized access across federal resources.

The final version of the guidance is not solely a product of government deliberation; nearly 250 public comments contributed to its formulation. Key technology firms, including Google, Microsoft, Okta, Amazon Web Services, Oracle, IBM, HashiCorp, Wiz, and the OpenID Foundation, provided insights and critiques through the Joint Cyber Defense Collaborative, reflecting a broad engagement from various stakeholders in the tech community.

Through these efforts, CISA and NIST aim to reinforce the resilience of cloud identity mechanisms, shielding them against increasingly sophisticated cyber threats.

Source link

Exit mobile version