Cloud ComputingUnit 511 min read
Cloud Security: Threats, Controls, and Compliance
Unit 5 of Cloud Computing explores cloud security fundamentals, including threats, vulnerabilities, encryption, identity management, compliance frameworks, and real-world security breaches in cloud environments like eSewa or Ncell.
TAKEAWAYS
- Cloud security threats (e.g., data breaches, DDoS, insider threats) exploit shared responsibility models between cloud providers and users.
- Encryption (symmetric/asymmetric) and access controls (IAM, RBAC) are core defenses against unauthorized access.
- Compliance frameworks (ISO 27001, GDPR, HIPAA) ensure legal and regulatory adherence in cloud deployments.
- Zero Trust Architecture and multi-factor authentication (MFA) mitigate risks in hybrid/multi-cloud environments.
- Real-world examples (e.g., eSewa’s 2021 breach, Ncell’s SIM swapping attacks) show how cloud security failures impact users.
- Disaster recovery (DR) and backup strategies (e.g., 3-2-1 rule) are critical for cloud resilience.
1. Introduction to Cloud Security
Cloud security refers to the protection of data, applications, and infrastructure in cloud environments from threats, unauthorized access, and breaches. Unlike traditional IT, cloud security operates under a shared responsibility model, where:
- Cloud Provider secures the infrastructure (physical hardware, networking, hypervisors).
- Customer secures data, applications, and user access.
Why is Cloud Security Unique?
Cloud computing introduces new attack surfaces:
- Shared multi-tenancy: Vulnerabilities in one tenant can affect others.
- Dynamic scaling: Rapid provisioning/deprovisioning can leave gaps.
- Data residency laws: Regulations like GDPR require data to stay in specific regions.
2. Common Cloud Security Threats
Cloud environments face unique threats due to their distributed nature. Below are the most critical ones:
sequenceDiagram
participant User
participant eSewaAPI
participant Hacker
User->>eSewaAPI: Login (Weak Credentials)
Hacker->>eSewaAPI: Brute Force Attack
eSewaAPI-->>Hacker: Access Granted (2021 Breach)
note right of Hacker: 2.5M records leaked
User->>eSewaAPI: Enable MFA (Post-Breach Fix)eSewa’s 2021 credential theft sequence (real-world attack flow)A. Data Breaches and Leakage
- Cause: Weak encryption, misconfigured storage (e.g., S3 buckets left public).
- Example: In 2021, eSewa exposed 2.5 million user records due to an unsecured database.
- Mitigation:
- Encryption at rest (AES-256 for databases).
- Tokenization (replace sensitive data with tokens).
- Regular audits (e.g., AWS Config, Azure Security Center).
B. Denial-of-Service (DoS/DDoS) Attacks
- Cause: Exploiting cloud scalability (e.g., overwhelming APIs).
- Example: Ncell’s 2020 outage was partly due to a DDoS attack on its cloud-based VoIP services.
- Mitigation:
- Rate limiting (e.g., AWS WAF).
- Anycast routing (distribute traffic across regions).
- CDN protection (Cloudflare, Akamai).
C. Insider Threats
- Cause: Malicious employees or compromised credentials.
- Example: A Daraz employee leaked customer data in 2019 after gaining unauthorized access.
- Mitigation:
- Role-Based Access Control (RBAC).
- Behavioral Analytics (e.g., Microsoft Defender for Cloud Apps).
- Least Privilege Principle.
D. Account Hijacking and Credential Theft
- Cause: Weak passwords, phishing, or SIM swapping (e.g., Ncell users losing accounts).
- Mitigation:
- Multi-Factor Authentication (MFA).
- Password managers (e.g., 1Password, Bitwarden).
- Hardware tokens (YubiKey).
E. Insecure APIs and Misconfigurations
- Cause: Poorly secured APIs or default cloud settings.
- Example: Khalti’s API breach in 2022 allowed fraudsters to bypass authentication.
- Mitigation:
- API gateways (e.g., Kong, Apigee).
- Automated configuration checks (e.g., AWS Trusted Advisor).
3. Cloud Security Controls and Best Practices
To counter these threats, organizations use technical, administrative, and physical controls.
A. Encryption
Cloud data must be encrypted in transit (TLS/SSL) and at rest (AES, RSA).
stateDiagram-v2
[*] --> DataAtRest: AES-256 Encryption
DataAtRest --> DataInTransit: TLS 1.3
DataInTransit --> [*]Real-World Example:
- Nepal Rastra Bank (NRB) requires all banks using cloud services to encrypt customer transaction data under PAS 2019.
B. Identity and Access Management (IAM)
- Principle of Least Privilege: Users get only the access they need.
- Role-Based Access Control (RBAC): Assign permissions based on job roles.
- Example:
- A Daraz warehouse manager should not access customer billing data.
C. Network Security
- Firewalls and Segmentation: Isolate cloud workloads (e.g., AWS Security Groups).
- VPNs and Zero Trust: Assume breach; verify every request.
- Example:
- Pathao drivers use VPNs to securely connect to the backend while on the road.
D. Compliance and Governance
Cloud providers must adhere to industry standards:
| Framework | Purpose | Example Use Case |
|---|---|---|
| ISO 27001 | Information security management | Banks (NMB, Global IME) |
| GDPR | EU data protection | Nepali companies handling EU data |
| HIPAA | Healthcare data security | Online clinics (e.g., SehatSathi) |
| PCI DSS | Payment card security | eSewa, Khalti |
E. Disaster Recovery (DR) and Backups
- 3-2-1 Rule: 3 copies, 2 media types, 1 offsite.
- Example:
- NTC’s cloud-based billing system uses automated backups to recover from outages.
4. Real-World Applications of Cloud Security
Case Study 1: eSewa’s Security Breach (2021)
- Threat: Unauthorized access to user databases due to weak encryption.
- Impact: 2.5 million records exposed (names, phone numbers, transaction history).
- Lesson: Always use end-to-end encryption and regular penetration testing.
Case Study 2: Ncell’s SIM Swapping Attacks
- Threat: Hackers tricked Ncell support into transferring SIMs to their devices.
- Impact: Users lost access to banking apps (e.g., NMB, Standard Chartered).
- Solution: Biometric authentication + hardware tokens for high-risk transactions.
Case Study 3: Daraz’s Supply Chain Security
- Threat: Fake sellers on the platform stealing payment data.
- Solution:
- Blockchain for order verification.
- AI-based fraud detection (e.g., detecting duplicate orders).
5. Cloud Security Tools and Services
| Tool/Service | Provider | Use Case |
|---|---|---|
| AWS GuardDuty | Amazon Web Services | Detects malicious activity in AWS |
| Azure Sentinel | Microsoft Azure | SIEM (Security Information & Event Mgmt) |
| Cloudflare | Cloudflare | DDoS protection for websites |
| HashiCorp Vault | HashiCorp | Secrets management (API keys, DB passwords) |
| Prisma Cloud | Palo Alto Networks | Cloud-native security posture management |
6. Exam Tip: How to Score Full Marks
Understand the Shared Responsibility Model:
- Provider secures infrastructure (e.g., hypervisors, physical servers).
- Customer secures data, apps, and user access.
- Example: If Nepal Stock Exchange (NEPSE) uses AWS, AWS secures the EC2 instances, but NEPSE must secure trading data.
Compare Threats with Mitigations:
- Threat: DDoS → Mitigation: Cloudflare, rate limiting.
- Threat: Data leakage → Mitigation: Encryption, tokenization.
Know Compliance Frameworks:
- GDPR = EU data protection.
- ISO 27001 = General security standard.
- PCI DSS = Payment security.
Real-World Scenarios:
- eSewa breach → Weak encryption → Solution: Enforce TLS 1.3 + MFA.
- Ncell SIM swap → Social engineering → Solution: Hardware tokens.
Diagrams in Exams:
- Draw shared responsibility models.
- Show encryption flows (AES at rest, TLS in transit).
- Sketch IAM role assignments (e.g., "Admin," "Viewer," "Developer").
7. Worked Example: Securing a Cloud-Based Bank (e.g., NMB)
Scenario: NMB wants to migrate its loan processing system to AWS.
Step 1: Identify Threats
| Threat | Risk Level | Mitigation |
|---|---|---|
| Data breach | High | AES-256 encryption + tokenization |
| DDoS on API | Medium | AWS Shield + Cloudflare |
| Insider fraud | High | RBAC + behavioral analytics |
| Compliance violations | Critical | ISO 27001 certification |
Step 2: Apply Security Controls
sequenceDiagram
Customer->>AWS: Request Loan Data (TLS 1.3)
AWS->>Customer: Verify MFA (SMS + Biometric)
Customer->>AWS: Submit Loan (Encrypted Payload)
AWS->>Database: Store (AES-256)
Database->>AWS: Return Approval (Tokenized)Step 3: Compliance Check
- GDPR: Ensure customer data stays in EU-compliant regions (e.g., AWS Frankfurt).
- PAS 2019 (NRB): Mandatory audit logs for all transactions.
8. Common Mistakes to Avoid
- Ignoring the shared responsibility model → Assume provider secures everything.
- Using default cloud settings → Always enable MFA and encryption.
- Neglecting third-party risks → Vendors (e.g., eSewa’s payment gateway) can be weak links.
- Overlooking compliance → Fines for GDPR violations can be 4% of global revenue.
9. Summary Table: Cloud Security Best Practices
| Category | Best Practice | Example |
|---|---|---|
| Data Protection | Encrypt at rest + in transit | AWS KMS + TLS 1.3 |
| Access Control | RBAC + MFA | Azure AD Conditional Access |
| Network Security | Firewalls + Zero Trust | AWS Security Groups + Cloudflare |
| Compliance | ISO 27001, GDPR, PCI DSS | NMB’s ISO 27001 certification |
| Disaster Recovery | 3-2-1 backup rule | NTC’s automated cloud backups |
10. Final Checklist for TU/PU Exams
✅ Can you draw the shared responsibility model? ✅ Do you know 3 cloud security threats and their mitigations? ✅ Can you explain encryption in transit vs. at rest? ✅ Are you familiar with GDPR, ISO 27001, and PCI DSS? ✅ Can you describe a real-world breach (e.g., eSewa, Ncell) and its lessons?
Based on the TU BIT syllabus for Cloud Computing, unit 5.
Discussion
Loading…