Private Cloud Security Practices
CyberStore Oasis sites use routine hosting practices intended to maintain a secure and reliable environment. These practices include backups, firewall protections, production-environment segmentation, limited system-administration access, and scheduled patch maintenance.
Environment architecture
CyberStore Oasis sites are hosted in a private cloud of web and database servers running on a VMware-based server cluster. The primary cluster is located in a Tier 1 data center in space assigned to CyberStore Oasis.
Backups
Production servers use Barracuda Backup technology for daily encrypted backups, inline deduplication, offsite vaulting, data recovery, LiveBoot, and instant-replacement options. Full server-restore tests are performed periodically.
Denial-of-service protection
Barracuda Next Generation and CloudGen Firewalls protect CyberStore Oasis sites from denial-of-service and distributed-denial-of-service attacks. The firewalls profile standard traffic patterns, filter attack traffic, and allow legitimate traffic through.
The firewalls provide TCP SYN flood protection, source-address session rate limits, and environmental monitoring for link and target-address conditions. When a monitored remote target does not respond to ICMP probing, the environment can activate alternate routes and uplinks.
Intrusion detection and prevention
Barracuda Next Generation and CloudGen Firewall technology provides intrusion detection and prevention for network threats, vulnerabilities, exploits, and exposures in operating systems, applications, and databases.
The protection includes detection and prevention for:
- SQL injection and arbitrary-code execution.
- Access-control attempts and privilege escalation.
- Cross-site scripting and buffer-overflow attacks.
- Denial-of-service and distributed-denial-of-service attacks.
- Directory traversal, probing, and scanning attempts.
- Backdoors, Trojans, rootkits, viruses, worms, and spyware.
Firewall protection also includes stream segmentation, packet-anomaly protection, TCP split-handshake protection, IP and RPC defragmentation, FTP-evasion protection, and URL and HTML decoding.
Patch maintenance
Microsoft Windows patches are applied monthly to production servers. Supporting devices are patched and updated on a semi-annual or annual schedule based on vendor release cycles. Critical security patches are evaluated, tested, and deployed when relevant to the hosting environment.