Loading...

Improve your Azure Network Infrastructure Security with Complementary Services

Improve your Azure Network Infrastructure Security with Complementary Services

Given the rising number of cyber-attacks and data breaches in recent times, security has become paramount. For a while now, it’s been clear that securing only your network’s perimeter is simply not enough. The idea that we can inherently trust systems or users in “internal networks” is a recipe for disaster.  Not to mention, it’s likely that many of your systems and users are not even in an internal network anymore.

 

In this ever-changing world, attackers are constantly finding new ways to exploit vulnerabilities. This is one of the reasons to consider the strategy of defense-in-depth: if there are multiple layers of protection in place and one of them fails, another security mechanism exists to stand in the way of an attack.

 

Besides a multi-layered approach to security, having a Zero Trust mindset is important. We focus on three principles when pursuing Zero Trust practices: verify explicitly, use least privileged access, and assume breach.

ZTNetSecDiagram.jpg

Do you want to segment your cloud resources and protect against malicious traffic flows?

 

Ensuring that the systems and resources are well segmented is foundational in network security. However, resources have legitimate reasons to communicate with one another. How can we detect and prevent threats across the resources that are segmented but need to communicate?

 

With Azure Firewall, you can keep your virtual networks (VNETs) segmented in a hub-and-spoke architecture model. The Azure Firewall is responsible for enforcing rules centrally, allowing or denying traffic that flows to and from resources in VNETs. However, the resources may still need to communicate over the network.

 

For connections that are allowed, Azure Firewall helps you explicitly verify the security of these connections with Threat Intelligence-based filtering and Intrusion Detection and Prevention System (IDPS). Allowed connections should not be blindly trusted: by assuming breach, we can watch out for potential attacks occurring within our networks. Threat Intelligence actively looks for connections to malicious IPs or domains, taking action to block that traffic even if it was allowed in the first place. IDPS offers an extra layer of defense, allowing for rapid detection of attacks by looking for specific patterns, such as byte sequences in network traffic, or known malicious instruction sequences used by malware.

 

Do you want administrators to manage resources securely from any device and any location, while minimizing attack surface?

 

Most of our administrators are no longer in our data centers where they can physically manage systems. The mentality of allowing administrators access to manage resources solely based on their network location does not align with our reality anymore, neither should we expose our systems to the public internet so that administrators can manage them on-the-go.

 

Most common needs for secure administration include strong authentication mechanisms, minimized direct exposure to the internet, and control over how and when administrators access resources. With Azure Bastion, you can keep virtual machines in Azure completely private and still allow administrators to manage them from any device and any location. In this scenario, virtual machines are managed via Azure Portal with Azure Bastion. This method explicitly verifies credentials before each connection, and multi-factor authentication, least privilege access controls and conditional access policies can be configured and enforced to provide multi-layered protection against potential administrative exploitations.

 

Do you want to have resilient resources that are up-and-running, even when under attack?

 

We want to ensure that our services are resilient and available to our users as much as possible. Even if attackers are trying to disrupt the availability of our services, we need the ability to explicitly verify which connections are coming from legitimate users and which ones are malicious.

 

With Azure DDoS Protection Standard, mitigation of distributed denial-of-service (DDoS) attacks are auto-tuned to the capacity of your resources. When an attack is detected, mitigation starts automatically. It identifies which packets are coming from attackers and drops those connections, while legitimate packets are forwarded to your services, minimizing the impact to valid users while an attack is occurring.

 

How do these services work together to improve overall network security?

 

Based on what we explored above, we saw how Azure Bastion and Azure Firewall are essential services to securely manage our resources and catch malicious traffic activity in our networks. Since Azure Bastion and Azure Firewall are services that can have public IP addresses, they may be susceptible to DDoS attacks. With Azure DDoS Protection Standard, we can stand against DDoS attacks that could potentially impact the availability of these crucial security services. Azure DDoS Protection acts as an insurance to keep critical infrastructure running even in the event of an attack.

 

Next Steps

 

 

 

References

Published on:

Learn more
Azure Network Security Blog articles
Azure Network Security Blog articles

Azure Network Security Blog articles

Share post:

Related posts

IPv6 Adoption: Enhancing Azure WAF on Front Door

The transition to IPv6 is a significant step for enterprise corporations, reflecting the evolution of internet technology and the need for a l...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge (Preview): Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Private IP DNAT Support (Preview) and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide

REST API is a cornerstone in the management of resources on Azure, providing a streamlined and efficient approach for executing create, read, ...

1 year ago

Monitoring Azure DDoS Protection Mitigation Triggers

Monitoring Azure DDoS Protection Mitigation Triggers In today’s digital landscape, Distributed Denial of Service (DDoS) attacks pose a signifi...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis

In today's digital age, the security of applications, servers, and networks is paramount. One of the most significant threats to this security...

1 year ago

Independent Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF

Introduction   In the constantly changing world of cybersecurity, both flexibility and effective security are essential for safeguarding ...

1 year ago

Private IP DNAT Support and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Monitoring traffic flows in Azure Firewall using Virtual Network Flow Logs

Azure Firewall is a managed service designed to protect your Azure Virtual Network resources, providing advanced threat protection and advance...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.