SlideShare a Scribd company logo
RDS infrastructure is the Gateway to network-Take it seriously.
Suman B. Singh
RDS (Remote Desktop Service) solutions is the most neglected bit in infrastructure design BUT it
will be one of the sensitive component in upcomingcloud trend.
"We just need RDS servers to install and run some business applications and must be accessible
over internet to provide mobility."This is the very common practice that we come across.While
world is adopting cloud then obviously no need to visit physical data centers to perform day to
day activities so accessing servers remotelyis the onlyway to manage infrastructure.
It becomes very important to developsecure RDSenvironment to access anycloud infrastructure
because this is the gateway to complete infrastructure.
Installing and configuring RDS role will allow user to access servers remotely but same time it
opens backdoor to break into cloud infrastructure. Well-known ports like 3389 and easily
traceable and one can use brute force to gain access to network.
A secure RDS solution must be implemented to access servers remotelyto make sure networkis
protected.
Below mentioned steps can be taken as standard practice that can be used to protect
infrastructure.
1. Use multitier infrastructureapproach,Enable NACL
2. Don’t use default RDP. Use random ports to provide access
3. Configure RDS Gateway and Azure application proxy to protect RDS Session Host servers’
identities
4. Use SSL
5. Implement multi-layerofsecurity (MFA/Firewalls/UDR)
6. Disable default users
7. Use App-Locker
Results were surprisingwhen all cloud servers were monitored usingOMS suit.
Figure 1: OMS in action. Showing fake accounts attempted to access the network.
Figure 2: Unauthorized Logon Attempts using 3389
Figure 3: IPs generating attacks
Figure 4: Top Targeted Accounts

More Related Content

PPTX
vArmour - Securing the Modern Data Centre
PDF
CloudSmartz Disaster Recovery [Use Case] | Smarter Transformation
PDF
Distributech_Presentation DTECH_2013
PPT
Proactive Security That Works
DOCX
Windows and linux
PDF
QNAP Netvox IoT solution
PDF
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
PPTX
Midokura Enterprise MidoNet Overview
vArmour - Securing the Modern Data Centre
CloudSmartz Disaster Recovery [Use Case] | Smarter Transformation
Distributech_Presentation DTECH_2013
Proactive Security That Works
Windows and linux
QNAP Netvox IoT solution
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Midokura Enterprise MidoNet Overview

What's hot (14)

PDF
Cisco connect winnipeg 2018 accelerating incident response in organizations...
PPTX
6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il ...
PDF
Hope, fear, and the data center time machine
PPTX
Cisco connect winnipeg 2018 we make it simple
PPTX
MidoNet Differentiation and Overview
PDF
QIoT 您專屬的私有雲平台 - 新知講堂 - 20170421
PPTX
Virtualized Firewall: Is it the panacea to secure distributed enterprises?
PPTX
Microservices on the Edge
PPTX
AFCEA Energy 2013 IT Symposium - Howerton Keynote
PDF
HaltDos DDoS Protection Solution
PDF
What does a cloud-enabled data centre look like?
PPTX
Secure access to applications on Microsoft Azure
PDF
Security Onion: peeling back the layers of your network in minutes
PDF
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
Cisco connect winnipeg 2018 accelerating incident response in organizations...
6° Sessione VMware NSX: la piattaforma di virtualizzazione della rete per il ...
Hope, fear, and the data center time machine
Cisco connect winnipeg 2018 we make it simple
MidoNet Differentiation and Overview
QIoT 您專屬的私有雲平台 - 新知講堂 - 20170421
Virtualized Firewall: Is it the panacea to secure distributed enterprises?
Microservices on the Edge
AFCEA Energy 2013 IT Symposium - Howerton Keynote
HaltDos DDoS Protection Solution
What does a cloud-enabled data centre look like?
Secure access to applications on Microsoft Azure
Security Onion: peeling back the layers of your network in minutes
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
Ad

Similar to Rds infrastructure is the gateway to network (20)

PDF
5 Ways to Keep Your Remote Desktop Secure
PDF
[RDS /Remote Desktop Services] Lesson 1 : Security Risks & Best Practices You...
PPTX
oracle.pptx
PPT
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
PDF
8. 9590 1-pb
PDF
how-to-get-ready-ebook-en
PPTX
Cloud Architect Company in India
PPTX
cloud computing by satwik
PDF
How Can Windows Server 2022 Remote Desktop Benefit Your Company?
PDF
Cloud Architect Company in India
PPTX
edgecomputing-201203071131.pptx
PDF
IRJET- Detection of Distributed Denial-of-Service (DDos) Attack on Software D...
PDF
Evolving the WAN for the Cloud, using SD-WAN & NFV
PDF
Software defined networking
PPTX
Cloud computing
PPTX
Cloud Innovation and Virtualization.pptx
PDF
Unit 1.2 move to cloud computing
PPTX
Introduction to Cloud Computing CA03.pptx
PDF
AWS Security Challenges
PPT
Cloud Computing
5 Ways to Keep Your Remote Desktop Secure
[RDS /Remote Desktop Services] Lesson 1 : Security Risks & Best Practices You...
oracle.pptx
WinConnections Spring, 2011 - How to Securely Connect Remote Desktop Services...
8. 9590 1-pb
how-to-get-ready-ebook-en
Cloud Architect Company in India
cloud computing by satwik
How Can Windows Server 2022 Remote Desktop Benefit Your Company?
Cloud Architect Company in India
edgecomputing-201203071131.pptx
IRJET- Detection of Distributed Denial-of-Service (DDos) Attack on Software D...
Evolving the WAN for the Cloud, using SD-WAN & NFV
Software defined networking
Cloud computing
Cloud Innovation and Virtualization.pptx
Unit 1.2 move to cloud computing
Introduction to Cloud Computing CA03.pptx
AWS Security Challenges
Cloud Computing
Ad

Recently uploaded (20)

PPTX
mahatma gandhi bus terminal in india Case Study.pptx
PDF
UNIT 1 Introduction fnfbbfhfhfbdhdbdto Java.pptx.pdf
PPT
unit 1 ppt.ppthhhhhhhhhhhhhhhhhhhhhhhhhh
PPTX
Wisp Textiles: Where Comfort Meets Everyday Style
PDF
Integrated-2D-and-3D-Animation-Bridging-Dimensions-for-Impactful-Storytelling...
PDF
The Advantages of Working With a Design-Build Studio
PPTX
AC-Unit1.pptx CRYPTOGRAPHIC NNNNFOR ALL
PDF
Urban Design Final Project-Context
PPTX
AD Bungalow Case studies Sem 2.pptxvwewev
PPTX
Fundamental Principles of Visual Graphic Design.pptx
PDF
Benefits_of_Cast_Aluminium_Doors_Presentation.pdf
PPTX
Implications Existing phase plan and its feasibility.pptx
DOCX
actividad 20% informatica microsoft project
PDF
Emailing DDDX-MBCaEiB.pdf DDD_Europe_2022_Intro_to_Context_Mapping_pdf-165590...
PDF
Facade & Landscape Lighting Techniques and Trends.pptx.pdf
PDF
Key Trends in Website Development 2025 | B3AITS - Bow & 3 Arrows IT Solutions
DOCX
The story of the first moon landing.docx
PPTX
Tenders & Contracts Works _ Services Afzal.pptx
PPT
pump pump is a mechanism that is used to transfer a liquid from one place to ...
PPTX
YV PROFILE PROJECTS PROFILE PRES. DESIGN
mahatma gandhi bus terminal in india Case Study.pptx
UNIT 1 Introduction fnfbbfhfhfbdhdbdto Java.pptx.pdf
unit 1 ppt.ppthhhhhhhhhhhhhhhhhhhhhhhhhh
Wisp Textiles: Where Comfort Meets Everyday Style
Integrated-2D-and-3D-Animation-Bridging-Dimensions-for-Impactful-Storytelling...
The Advantages of Working With a Design-Build Studio
AC-Unit1.pptx CRYPTOGRAPHIC NNNNFOR ALL
Urban Design Final Project-Context
AD Bungalow Case studies Sem 2.pptxvwewev
Fundamental Principles of Visual Graphic Design.pptx
Benefits_of_Cast_Aluminium_Doors_Presentation.pdf
Implications Existing phase plan and its feasibility.pptx
actividad 20% informatica microsoft project
Emailing DDDX-MBCaEiB.pdf DDD_Europe_2022_Intro_to_Context_Mapping_pdf-165590...
Facade & Landscape Lighting Techniques and Trends.pptx.pdf
Key Trends in Website Development 2025 | B3AITS - Bow & 3 Arrows IT Solutions
The story of the first moon landing.docx
Tenders & Contracts Works _ Services Afzal.pptx
pump pump is a mechanism that is used to transfer a liquid from one place to ...
YV PROFILE PROJECTS PROFILE PRES. DESIGN

Rds infrastructure is the gateway to network

  • 1. RDS infrastructure is the Gateway to network-Take it seriously. Suman B. Singh RDS (Remote Desktop Service) solutions is the most neglected bit in infrastructure design BUT it will be one of the sensitive component in upcomingcloud trend. "We just need RDS servers to install and run some business applications and must be accessible over internet to provide mobility."This is the very common practice that we come across.While world is adopting cloud then obviously no need to visit physical data centers to perform day to day activities so accessing servers remotelyis the onlyway to manage infrastructure. It becomes very important to developsecure RDSenvironment to access anycloud infrastructure because this is the gateway to complete infrastructure. Installing and configuring RDS role will allow user to access servers remotely but same time it opens backdoor to break into cloud infrastructure. Well-known ports like 3389 and easily traceable and one can use brute force to gain access to network. A secure RDS solution must be implemented to access servers remotelyto make sure networkis protected. Below mentioned steps can be taken as standard practice that can be used to protect infrastructure. 1. Use multitier infrastructureapproach,Enable NACL 2. Don’t use default RDP. Use random ports to provide access 3. Configure RDS Gateway and Azure application proxy to protect RDS Session Host servers’ identities 4. Use SSL 5. Implement multi-layerofsecurity (MFA/Firewalls/UDR) 6. Disable default users 7. Use App-Locker Results were surprisingwhen all cloud servers were monitored usingOMS suit.
  • 2. Figure 1: OMS in action. Showing fake accounts attempted to access the network. Figure 2: Unauthorized Logon Attempts using 3389
  • 3. Figure 3: IPs generating attacks Figure 4: Top Targeted Accounts