Techniques for remediating deleted data cybersecurity risks
A system and method for remediating exposed deleted client data in a cloud computing virtualization is presented. The method includes accessing a disk of a virtualization in a computing environment, the disk including deleted data; recovering at least a file from the deleted data; detecting client data on the at least a file, wherein the client data is untied to any functionality provided by the virtualization; and permanently deleting the detected client data from the disk.
1 . A method for remediating exposed deleted client data in a cloud computing virtualization, comprising:
accessing a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;
analyzing the one or more blocks at a low level, wherein the low level bypasses a file system;
reconstructing a file based on the analyzed one or more blocks;
detecting data in the file unutilized by the virtualization;
determining the data is client data in response to the detected data is unutilized; and
permanently deleting the client data from the disk.
2 . The method of claim 1 , wherein permanently deleting the client data further comprises:
detecting a storage block among the one or more blocks containing thereon at least a portion of the client data; and
overwriting the detected storage block.
3 . The method of claim 1 , further comprising:
generating a representation of the client data;
generating a representation of the virtualization; and
storing the representation of the client data and the representation of the virtualization in a security database, wherein the security database includes a representation of the computing environment.
4 . The method of claim 1 , further comprising:
detecting a storage block among the one or more blocks containing thereon at least a portion of the detected client data;
detecting an encryption key associated with the storage block; and
deleting the encryption key prior to permanently deleting the client data from the disk.
5 . The method of claim 1 , further comprising:
shredding the file.
6 . The method of claim 1 , further comprising:
detecting a software image based on which the virtualization is deployed;
generating a new software image based on the virtualization after the client data is permanently deleted; and
replacing the software image with the new software image.
7 . The method of claim 1 , further comprising:
detecting a code object based on which the virtualization is deployed;
generating a new code object based on the virtualization after the client data is permanently deleted; and
replacing the code object with the new code object.
8 . The method of claim 7 , further comprising:
instantiating a new virtualization based on the new code object.
9 . The method of claim 1 , further comprising:
identifying a file header in the analyzed one or more blocks, wherein reconstructing the file is further based on the identified file header.
10 . The method of claim 1 , further comprising:
identifying, on the disk, block storage including deleted files; and
generating an inspectable disk based only on the identified block storage.
11 . A non-transitory computer-readable medium storing a set of instructions for remediating exposed deleted client data in a cloud computing virtualization, the set of instructions comprising:
one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:
access a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;
analyze the one or more blocks at a low level, wherein the low level bypasses a file system;
reconstruct a file based on the analyzed one or more blocks;
detect data in the file unutilized by the virtualization;
determine the data is client data in response to the detected data is unutilized; and
permanently delete the client data from the disk.
12 . A system for remediating exposed deleted client data in a cloud computing virtualization comprising:
a processing circuitry;
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
access a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;
analyze the one or more blocks at a low level, wherein the low level bypasses a file system;
reconstruct a file based on the analyzed one or more blocks;
detect data in the file unutilized by the virtualization;
determine the data is client data in response to the detected data is unutilized; and
permanently delete the client data from the disk.
13 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for permanently deleting the client data, further configure the system to:
detect a storage block among the one or more blocks containing thereon at least a portion of the client data; and
overwrite the detected storage block.
14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
generate a representation of the client data;
generate a representation of the virtualization; and
store the representation of the client data and the representation of the virtualization in a security database, wherein the security database includes a representation of the computing environment.
15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a storage block among the one or more blocks containing thereon at least a portion of the detected client data;
detect an encryption key associated with the storage block; and
delete the encryption key prior to permanently deleting the client data from the disk.
16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
shred the file.
17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a software image based on which the virtualization is deployed;
generate a new software image based on the virtualization after the client data is permanently deleted; and
replace the software image with the new software image.
18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a code object based on which the virtualization is deployed;
generate a new code object based on the virtualization after the client data is permanently deleted; and
replace the code object with the new code object.
19 . The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
instantiate a new virtualization based on the new code object.