Security Best Practices
Lock down your Cassandra cluster - Authentication, Encryption, Hardening!
📖 The Story: Jake's $2M Data Breach
Jake deployed Cassandra to production with DEFAULT SETTINGS. No password, no encryption, port 9042 open to the internet. Three weeks later: 50 million customer records stolen, $2M fine from regulators, company reputation destroyed. All because he skipped security.
😱 What Went Wrong
Jake's "Setup":
The Attack:
- 🌐 Discovery: Shodan scan found open port 9042
- 🔓 Access: Connected with cqlsh (no password!)
- 📊 Enumeration: DESCRIBE KEYSPACES found customer data
- 💾 Exfiltration: Exported 50M records over 3 days
- 💰 Ransom: $500K Bitcoin demand
- 📰 Public: Media reported the breach
- ⚖️ Fine: $2M GDPR violation
The Damage:
- 💰 Direct Cost: $2M regulatory fine
- 💸 Response Cost: $500K incident response
- 📉 Stock Price: 40% drop
- 😡 Customers: 60% churn rate
- 💼 Jake: Fired, career damaged
✅ What Should Have Been Done
Proper Security Setup (30 minutes of work!):
Cost of Security:
- ⏱️ Time: 30 minutes to configure
- 💰 Money: $0 (free!)
- 🛡️ Protection: Priceless
- 😊 Sleep: Peaceful nights
30 minutes of security = Avoided $3M disaster! 🎉
🛡️ Defense in Depth - Security Layers
Multiple layers of protection!
Layer 1: Network
- Firewall rules
- VPC/Private networks
- IP whitelisting
- Port restrictions
- VPN access only
First line of defense!
Layer 2: Authentication
- PasswordAuthenticator
- Strong passwords
- Change defaults
- Rotate credentials
- LDAP integration
Who are you?
Layer 3: Authorization
- CassandraAuthorizer
- Role-based access
- Least privilege
- Table-level permissions
- Audit trails
What can you do?
Layer 4: Encryption
- Client-to-node SSL
- Node-to-node SSL
- Encryption at rest
- TLS 1.2+
- Strong ciphers
Protect data in transit!
Layer 5: Hardening
- Disable JMX remote
- Remove defaults
- Minimal services
- OS hardening
- Security patches
Reduce attack surface!
Layer 6: Monitoring
- Audit logging
- Failed login tracking
- Suspicious queries
- Alert on anomalies
- SIEM integration
Detect attacks!
🔐 Authentication Setup
Require login - NO anonymous access!
Enable PasswordAuthenticator
Switch from AllowAll to Password-based
Change Default Superuser Password
CRITICAL: Default is cassandra/cassandra!
Create Application Users
Never use superuser in applications!
Password Best Practices
- 🔒 Minimum 12 characters
- 🔤 Mix: Upper, lower, numbers, symbols
- ❌ No dictionary words
- 🔄 Rotate every 90 days
- 🚫 Never commit to git!
- 🗝️ Use password manager
- 🎯 Different per environment
🔒 Encryption - Protect Data in Transit
SSL/TLS for client and inter-node!
Why Encrypt?
Without Encryption
Anyone on the network can see your data!
Generate SSL Certificates
Enable Client-to-Node Encryption
Encrypt traffic between apps and Cassandra
Enable Node-to-Node Encryption
Encrypt traffic between Cassandra nodes
Now Encrypted!
Attacker runs Wireshark again:
🌐 Network Security
Lock down network access!
INSECURE
SECURE
Firewall Rules (iptables)
Port Reference
| Port | Purpose | Access |
|---|---|---|
| 9042 | CQL native transport | App servers only |
| 7000 | Inter-node communication | Cassandra nodes only |
| 7001 | Inter-node SSL | Cassandra nodes only |
| 7199 | JMX monitoring | Localhost only (or monitoring subnet) |
| 9160 | Thrift (deprecated) | DISABLE if not using |
⚔️ System Hardening
Reduce attack surface!
1. Disable Remote JMX
2. Remove/Disable Default Accounts
3. Disable Thrift (if not using)
4. OS-Level Hardening
5. Limit cassandra User Privileges
📊 Security Monitoring & Audit Logging
Detect and respond to attacks!
Enable Audit Logging
Monitor Failed Logins
Monitor Suspicious Queries
Set Up Alerts
Create alerts for:
- 🚨 More than 5 failed logins from same IP
- 🚨 DROP/ALTER statements from non-admin users
- 🚨 Access from unexpected IP addresses
- 🚨 Large data exports (millions of rows)
- 🚨 Access during off-hours
- 🚨 JMX connections (if should be disabled)
✅ Complete Security Checklist
Production readiness checklist!
Authentication
- ☐ PasswordAuthenticator enabled
- ☐ Default cassandra password changed
- ☐ Application users created
- ☐ Strong passwords (12+ chars)
- ☐ Password rotation policy
- ☐ LDAP/AD integration (if applicable)
Authorization
- ☐ CassandraAuthorizer enabled
- ☐ Least privilege roles
- ☐ Table-level permissions
- ☐ No applications use superuser
- ☐ Regular permission audits
- ☐ Default cassandra role disabled
Encryption
- ☐ Client-to-node SSL enabled
- ☐ Node-to-node SSL enabled
- ☐ TLS 1.2+ only
- ☐ Strong cipher suites
- ☐ Certificate rotation plan
- ☐ Encryption at rest (if required)
Network
- ☐ Firewall rules configured
- ☐ Private network/VPC
- ☐ No internet exposure
- ☐ Port 9042 restricted
- ☐ JMX localhost only
- ☐ SSH from jump host only
Hardening
- ☐ JMX remote disabled
- ☐ Thrift disabled
- ☐ File permissions set
- ☐ Run as non-root
- ☐ OS security patches
- ☐ Unnecessary services disabled
Monitoring
- ☐ Audit logging enabled
- ☐ Failed login alerts
- ☐ Suspicious query detection
- ☐ SIEM integration
- ☐ Regular log review
- ☐ Incident response plan
Pre-Production Security Verification
Before going to production, verify:
🎉 Your Cassandra Cluster is Now SECURE!
You've learned comprehensive Cassandra security!
🎓 What You Accomplished:
- 🔐 Authentication: Password required, strong passwords
- 👮 Authorization: Role-based access, least privilege
- 🔒 Encryption: SSL/TLS for client and inter-node
- 🌐 Network: Firewall rules, private network
- ⚔️ Hardening: JMX disabled, OS hardened
- 📊 Monitoring: Audit logs, alert on attacks
💡 Key Takeaways:
- Security is NOT optional - One breach = millions in fines
- Defense in depth - Multiple layers catch what one misses
- Default is insecure - ALWAYS configure before production
- 30 minutes of setup - Can save $2M+ in damages
- Monitor everything - Detect attacks before damage
- Least privilege - Only grant what's needed
📋 Quick Security Setup (30 Minutes):
🚨 Red Flags to Watch:
- ❌ "We'll add security later" → NO! Add it NOW!
- ❌ "It's only dev environment" → Dev gets hacked too!
- ❌ "No one knows about it" → Security by obscurity fails!
- ❌ "Too complicated" → 30 minutes vs $2M fine!
- ❌ "Performance impact" → Negligible vs data breach!
✅ Security Verification Commands:
🏆 Production Security Score
Calculate your score (out of 100):
- 🔐 Authentication enabled: +20 points
- 👮 Authorization enabled: +20 points
- 🔒 Client encryption: +15 points
- 🔒 Node-to-node encryption: +10 points
- 🌐 Firewall configured: +15 points
- ⚔️ System hardened: +10 points
- 📊 Audit logging: +10 points
Your target: 100/100 before production! ✅
80-100: Excellent! Production-ready 🎉
60-79: Good, but add more layers ⚠️
40-59: Vulnerable, fix critical gaps ❌
0-39: DANGER! Do not go to production! 💥
🛡️ Remember Jake's $2M breach - Don't be Jake!
30 minutes of security = Years of peace! 🎯
📱 Responsive Ad 📱