Cloud ComputingUnit 511 min read

Cloud Security: Threats, Controls, and Compliance

Unit 5 of Cloud Computing explores cloud security fundamentals, including threats, vulnerabilities, encryption, identity management, compliance frameworks, and real-world security breaches in cloud environments like eSewa or Ncell.

TAKEAWAYS

  • Cloud security threats (e.g., data breaches, DDoS, insider threats) exploit shared responsibility models between cloud providers and users.
  • Encryption (symmetric/asymmetric) and access controls (IAM, RBAC) are core defenses against unauthorized access.
  • Compliance frameworks (ISO 27001, GDPR, HIPAA) ensure legal and regulatory adherence in cloud deployments.
  • Zero Trust Architecture and multi-factor authentication (MFA) mitigate risks in hybrid/multi-cloud environments.
  • Real-world examples (e.g., eSewa’s 2021 breach, Ncell’s SIM swapping attacks) show how cloud security failures impact users.
  • Disaster recovery (DR) and backup strategies (e.g., 3-2-1 rule) are critical for cloud resilience.

1. Introduction to Cloud Security

Cloud security refers to the protection of data, applications, and infrastructure in cloud environments from threats, unauthorized access, and breaches. Unlike traditional IT, cloud security operates under a shared responsibility model, where:

  • Cloud Provider secures the infrastructure (physical hardware, networking, hypervisors).
  • Customer secures data, applications, and user access.
Cloud Provider(Infrastructure)Hypervisors, Physical SecurityCustomer (Data/Applications)Encryption, IAM, App SecurityShared Responsibility ModelCompliance, Audits
Shared responsibility model in AWS/GCP/Azure (e.g., NMB’s cloud banking uses this)

Why is Cloud Security Unique?

Cloud computing introduces new attack surfaces:

  • Shared multi-tenancy: Vulnerabilities in one tenant can affect others.
  • Dynamic scaling: Rapid provisioning/deprovisioning can leave gaps.
  • Data residency laws: Regulations like GDPR require data to stay in specific regions.

2. Common Cloud Security Threats

Cloud environments face unique threats due to their distributed nature. Below are the most critical ones:

Brute Force (2021)SIM SwappingAPI MisconfigeSewaNcellDarazHacker
Top 3 Nepali cloud breach vectors (2020–2023)
sequenceDiagram
    participant User
    participant eSewaAPI
    participant Hacker
    User->>eSewaAPI: Login (Weak Credentials)
    Hacker->>eSewaAPI: Brute Force Attack
    eSewaAPI-->>Hacker: Access Granted (2021 Breach)
    note right of Hacker: 2.5M records leaked
    User->>eSewaAPI: Enable MFA (Post-Breach Fix)
eSewa’s 2021 credential theft sequence (real-world attack flow)

A. Data Breaches and Leakage

  • Cause: Weak encryption, misconfigured storage (e.g., S3 buckets left public).
  • Example: In 2021, eSewa exposed 2.5 million user records due to an unsecured database.
  • Mitigation:
    • Encryption at rest (AES-256 for databases).
    • Tokenization (replace sensitive data with tokens).
    • Regular audits (e.g., AWS Config, Azure Security Center).

B. Denial-of-Service (DoS/DDoS) Attacks

  • Cause: Exploiting cloud scalability (e.g., overwhelming APIs).
  • Example: Ncell’s 2020 outage was partly due to a DDoS attack on its cloud-based VoIP services.
  • Mitigation:
    • Rate limiting (e.g., AWS WAF).
    • Anycast routing (distribute traffic across regions).
    • CDN protection (Cloudflare, Akamai).

C. Insider Threats

  • Cause: Malicious employees or compromised credentials.
  • Example: A Daraz employee leaked customer data in 2019 after gaining unauthorized access.
  • Mitigation:
    • Role-Based Access Control (RBAC).
    • Behavioral Analytics (e.g., Microsoft Defender for Cloud Apps).
    • Least Privilege Principle.

D. Account Hijacking and Credential Theft

  • Cause: Weak passwords, phishing, or SIM swapping (e.g., Ncell users losing accounts).
  • Mitigation:
    • Multi-Factor Authentication (MFA).
    • Password managers (e.g., 1Password, Bitwarden).
    • Hardware tokens (YubiKey).

E. Insecure APIs and Misconfigurations

  • Cause: Poorly secured APIs or default cloud settings.
  • Example: Khalti’s API breach in 2022 allowed fraudsters to bypass authentication.
  • Mitigation:
    • API gateways (e.g., Kong, Apigee).
    • Automated configuration checks (e.g., AWS Trusted Advisor).

3. Cloud Security Controls and Best Practices

To counter these threats, organizations use technical, administrative, and physical controls.

A. Encryption

Cloud data must be encrypted in transit (TLS/SSL) and at rest (AES, RSA).

stateDiagram-v2
    [*] --> DataAtRest: AES-256 Encryption
    DataAtRest --> DataInTransit: TLS 1.3
    DataInTransit --> [*]

Real-World Example:

  • Nepal Rastra Bank (NRB) requires all banks using cloud services to encrypt customer transaction data under PAS 2019.

B. Identity and Access Management (IAM)

  • Principle of Least Privilege: Users get only the access they need.
  • Role-Based Access Control (RBAC): Assign permissions based on job roles.
  • Example:
    • A Daraz warehouse manager should not access customer billing data.

C. Network Security

  • Firewalls and Segmentation: Isolate cloud workloads (e.g., AWS Security Groups).
  • VPNs and Zero Trust: Assume breach; verify every request.
  • Example:
    • Pathao drivers use VPNs to securely connect to the backend while on the road.

D. Compliance and Governance

Cloud providers must adhere to industry standards:

Framework Purpose Example Use Case
ISO 27001 Information security management Banks (NMB, Global IME)
GDPR EU data protection Nepali companies handling EU data
HIPAA Healthcare data security Online clinics (e.g., SehatSathi)
PCI DSS Payment card security eSewa, Khalti

E. Disaster Recovery (DR) and Backups

  • 3-2-1 Rule: 3 copies, 2 media types, 1 offsite.
  • Example:
    • NTC’s cloud-based billing system uses automated backups to recover from outages.

4. Real-World Applications of Cloud Security

Case Study 1: eSewa’s Security Breach (2021)

  • Threat: Unauthorized access to user databases due to weak encryption.
  • Impact: 2.5 million records exposed (names, phone numbers, transaction history).
  • Lesson: Always use end-to-end encryption and regular penetration testing.
2021 BSBrute-force attackvia weak credentials2021 BS2.5M recordsleaked (public disclos2022 BSMFA enforcedpost-breach
eSewa breach timeline with mitigation steps

Case Study 2: Ncell’s SIM Swapping Attacks

  • Threat: Hackers tricked Ncell support into transferring SIMs to their devices.
  • Impact: Users lost access to banking apps (e.g., NMB, Standard Chartered).
  • Solution: Biometric authentication + hardware tokens for high-risk transactions.

Case Study 3: Daraz’s Supply Chain Security

  • Threat: Fake sellers on the platform stealing payment data.
  • Solution:
    • Blockchain for order verification.
    • AI-based fraud detection (e.g., detecting duplicate orders).

5. Cloud Security Tools and Services

Tool/Service Provider Use Case
AWS GuardDuty Amazon Web Services Detects malicious activity in AWS
Azure Sentinel Microsoft Azure SIEM (Security Information & Event Mgmt)
Cloudflare Cloudflare DDoS protection for websites
HashiCorp Vault HashiCorp Secrets management (API keys, DB passwords)
Prisma Cloud Palo Alto Networks Cloud-native security posture management

6. Exam Tip: How to Score Full Marks

  1. Understand the Shared Responsibility Model:

    • Provider secures infrastructure (e.g., hypervisors, physical servers).
    • Customer secures data, apps, and user access.
    • Example: If Nepal Stock Exchange (NEPSE) uses AWS, AWS secures the EC2 instances, but NEPSE must secure trading data.
  2. Compare Threats with Mitigations:

    • Threat: DDoS → Mitigation: Cloudflare, rate limiting.
    • Threat: Data leakage → Mitigation: Encryption, tokenization.
  3. Know Compliance Frameworks:

    • GDPR = EU data protection.
    • ISO 27001 = General security standard.
    • PCI DSS = Payment security.
  4. Real-World Scenarios:

    • eSewa breach → Weak encryption → Solution: Enforce TLS 1.3 + MFA.
    • Ncell SIM swap → Social engineering → Solution: Hardware tokens.
  5. Diagrams in Exams:

    • Draw shared responsibility models.
    • Show encryption flows (AES at rest, TLS in transit).
    • Sketch IAM role assignments (e.g., "Admin," "Viewer," "Developer").

7. Worked Example: Securing a Cloud-Based Bank (e.g., NMB)

Scenario: NMB wants to migrate its loan processing system to AWS.

Step 1: Identify Threats

Threat Risk Level Mitigation
Data breach High AES-256 encryption + tokenization
DDoS on API Medium AWS Shield + Cloudflare
Insider fraud High RBAC + behavioral analytics
Compliance violations Critical ISO 27001 certification

Step 2: Apply Security Controls

sequenceDiagram
    Customer->>AWS: Request Loan Data (TLS 1.3)
    AWS->>Customer: Verify MFA (SMS + Biometric)
    Customer->>AWS: Submit Loan (Encrypted Payload)
    AWS->>Database: Store (AES-256)
    Database->>AWS: Return Approval (Tokenized)

Step 3: Compliance Check

  • GDPR: Ensure customer data stays in EU-compliant regions (e.g., AWS Frankfurt).
  • PAS 2019 (NRB): Mandatory audit logs for all transactions.

8. Common Mistakes to Avoid

  • Ignoring the shared responsibility model → Assume provider secures everything.
  • Using default cloud settings → Always enable MFA and encryption.
  • Neglecting third-party risks → Vendors (e.g., eSewa’s payment gateway) can be weak links.
  • Overlooking compliance → Fines for GDPR violations can be 4% of global revenue.

9. Summary Table: Cloud Security Best Practices

Category Best Practice Example
Data Protection Encrypt at rest + in transit AWS KMS + TLS 1.3
Access Control RBAC + MFA Azure AD Conditional Access
Network Security Firewalls + Zero Trust AWS Security Groups + Cloudflare
Compliance ISO 27001, GDPR, PCI DSS NMB’s ISO 27001 certification
Disaster Recovery 3-2-1 backup rule NTC’s automated cloud backups

10. Final Checklist for TU/PU Exams

✅ Can you draw the shared responsibility model? ✅ Do you know 3 cloud security threats and their mitigations? ✅ Can you explain encryption in transit vs. at rest? ✅ Are you familiar with GDPR, ISO 27001, and PCI DSS? ✅ Can you describe a real-world breach (e.g., eSewa, Ncell) and its lessons?


Based on the TU BIT syllabus for Cloud Computing, unit 5.

Discussion

Loading…