An Initiative Strategy for Increasing the Security of Cloud Services and Platforms: Microsoft’s Secure Future Initiative (SCIFI 2017)
“Satya Nadella, Rajesh Jha, Scott Guthrie, and I have put significant thought into how we should respond to the increasingly more sophisticated threats,” explains Charlie Bell, head of Microsoft security, in an internal memo distributed today. “To this end, we have committed to three specific engineering advances we are taking on our journey of continually improving the built-in security of our products and platforms. These advances comprise what we’re calling the Secure Future Initiative. Collectively, they improve security for customers both in the near term and against threats we know will increase over the horizon.”
The push for security won’t be limited to software development at Microsoft. “As a company, we are committed to building an AI-based cyber shield that will protect customers and countries around the world,” explains Brad Smith, Microsoft vice chair and president, in a blog post today. Artificial intelligence is a game change. While threat actors seek to hide their threats like a needle in a vast haystack of data, AI increasingly makes it possible to find the right needle even in a sea of needles. And coupled with a global network of datacenters, we are determined to use AI to detect threats at a speed that is as fast as the interest itself.”
Microsoft now plans to use automation and AI during software development to improve the security of its cloud services, cut the time it takes to fix cloud vulnerabilities, enable better security settings out of the box, and harden its infrastructure to protect against encryption keys falling into the wrong hands.
Bell said that they plan to cut the time it takes to mitigate cloud vulnerabilities in half. This is possible because we have invested and learned in intelligence-driven tools and processes. Ninety days is the typical industry window for security fixes, so if Microsoft can reliably cut that to 45 days, then that’s a great start to this new security initiative.
“To stay ahead of bad actors, we are moving identity platforms to confidential computing infrastructure that we helped pioneer,” says Bell. Data that governs identities is protected not just at rest and transit but also during computational processes as well. This means that even if an attacker gets through our layered defenses in the course of targeting encryption keys, the key data is designed to be inaccessible within automated systems that do not require human touch.”
Improving security defaults is one of the things that Microsoft is doing. “Over the next year we will enable customers with more secure default settings for Multi-Factor Authentication (MFA) out-of-the-box,” says Smith. This will expand our current default policies to include a range of customer services with focus on where customers need this protection the most.
In September, cybersecurity research firm Wiz disclosed that 38TB of data had accidentally been exposed by Microsoft AI researchers thanks to an Azure feature called SAS tokens. Researchers stated at the time that it was extremely hard to manage and revoked account SAS token. Microsoft did not specifically mention SAS in its security initiative but hopefully it is something the company is looking at as well.
Smith calls on states to protect cloud services against attack under international law, and for greater accountability for nation-states that undermine cloud security. “All states should commit publicly that they will not plant software vulnerabilities in the networks of critical infrastructure providers such as energy, water, food, medical care, or other providers,” says Smith. “They should also commit that they will not permit any persons within their territory or jurisdiction to engage in cybercriminal operations that target critical infrastructure.”



