How to Secure Privileged Session Access to Cloud-based VMs; Hint: Don’t Expose SSH/RDP to the Internet

Webinar Registration

BlueKeep and DejaBlue shined a spotlight on this issue because cloud-based VMs are the most convenient targets for these exploits. And the number of VMs in the cloud is exploding. 

But how should administrators access those VMs without creating major risks? The course of least resistance is to just put those VMs out there and enable SSH/RDP access from the Internet. But that is dangerous. 

The “blue” exploits are a great proof of that claim. BlueKeep and DejaBlue permit attackers to break into systems via RDP and gain root level access without any credentials. And two-factor authentication is no protection. With “blue”attacks the game is over before RDP even thinks about checking your password let alone 2FA.

Now of course you can patch (hopefully already) against those attacks but they prove that remote administration protocols are not appropriate for direct exposure to the Internet. And researchers agree there will be more such exploits. Moreover, patches don’t exist when you are targeted with a zero-day attack.

In this webinar, we will look at several different ways to more safely provide admins with SSH/RDP access to VMs in the cloud. Here are a few of the techniques we’ll consider:

  • Dedicated connections like Express Route in Azure
  • Site-to-Site VPNs
  • Remote access VPNs hosted in the cloud
  • IP Security Policies
  • Source network restrictions
  • Terminal Services Gateway
  • Privileged Session Management solutions designed for the cloud

Some of these techniques are circuitous and rely on your existing, on-prem remote admin access infrastructure. The techniques are more or less stronger in relation to each other and have different prerequisites. We will compare and contrast them all. And I’m interested in hearing how you have tackled this issue. Send me your thoughts beforehand and during the webinar and I’ll work them in.

We’ve got a great sponsor for this real-training-for-free™ session – BeyondTrust’s Tal Guest will show you how their privilege management technology allows you to lockdown RDP/SSH and layer additional security controls on top of it, all while still allowing remote access. He will also demo how to disable RDP all together and only use BeyondTrust for internal and remote access in an environment.

Please join us for this real training for free event.

First Name:  
Last Name:  
Work Email:  
Phone:
Organization:
Country:  
State:
Zip/Postal Code:
Company size:
I'd like to schedule a personalized demo with a BeyondTrust rep for:
Industry:
 

Your information will be shared with the sponsor.

By clicking "Submit", you're agreeing to our Privacy Policy and consenting to be contacted by us and the sponsor.

 

 

Additional Resources