Network SecurityUnit 89 min read

Cloud & IoT Security: Threats, Protocols & Defense

Unit 8 of Network Security explores the security challenges, protocols, and best practices for protecting cloud computing environments and Internet of Things (IoT) devices, including encryption, authentication, and attack mitigation strategies used by companies like Ncell and Daraz.

TAKEAWAYS:

  • Cloud security relies on shared responsibility models where providers secure infrastructure while users manage data and applications.
  • IoT devices are vulnerable to DDoS attacks, weak authentication, and firmware exploits, requiring hardware-level protections.
  • Zero Trust Architecture (ZTA) and microsegmentation are key to securing cloud environments against lateral movement.
  • IoT security frameworks (e.g., NIST IR 8259) mandate device authentication, encryption, and patch management.
  • Real-world examples show how Ncell’s IoT SIM cards use eSIM authentication to prevent SIM swapping, while Daraz’s cloud servers rely on AWS KMS for order data encryption.
  • Exam questions often test attack scenarios (e.g., Mirai botnet), protocol weaknesses (e.g., MQTT’s lack of built-in security), and mitigation techniques (e.g., blockchain for IoT integrity).

1. Cloud Security Fundamentals

Cloud security is built on three core principles:

  1. Confidentiality: Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  2. Integrity: Hash functions (SHA-256) and digital signatures prevent tampering.
  3. Availability: DDoS protection (AWS Shield) and multi-region redundancy ensure uptime.

Shared Responsibility Model

Cloud providers (AWS, Google Cloud, NTC’s cloud services) secure the infrastructure (hypervisors, physical servers), while users (e.g., Daraz, banks) manage:

  • Data encryption keys
  • Identity and access management (IAM)
  • Application security (e.g., SQL injection prevention)
Cloud Provider(Infrastructure)Customer (Data/Apps)
Shared Responsibility Model: AWS/NTC vs. User Responsibilities (e.g., Daraz banks)

Real-world example: Nepal Rastra Bank (NRB) stores customer transaction data on AWS GovCloud, where NRB controls encryption keys (via AWS KMS) while AWS secures the underlying servers. If a hacker breaches AWS’s network, they still cannot decrypt NRB’s data without the keys.


2. IoT Security Challenges

IoT devices (e.g., smart meters, industrial sensors, Pathao’s delivery trackers) are prime targets due to:

  • Weak default credentials (e.g., "admin:admin" in many routers).
  • Lack of firmware updates (e.g., old NTC CCTV cameras running unpatched software).
  • Limited processing power (cannot run full TLS stacks).
MQTTDTLSExploit (Default Creds)IoT DeviceGatewayCloud ServerAttacker
IoT attack surface (Mirai-style DDoS path)

Common IoT Attacks

Attack Type Example Mitigation Strategy
DDoS Mirai botnet (2016) Rate limiting, IoT-specific firewalls
Man-in-the-Middle Unencrypted MQTT traffic TLS/DTLS for IoT protocols
Firmware Exploits Vulnerable smart locks Secure boot, code signing
Data Leakage Unauthorized API access OAuth 2.0, API gateways

Worked Example: Ncell’s IoT SIM Security Ncell’s eSIM-based IoT authentication prevents SIM swapping by:

  1. Storing credentials in a secure element (hardware chip).
  2. Using OMA-DM (Open Mobile Alliance Device Management) for remote updates.
  3. Enforcing mutual TLS (mTLS) for device authentication.
sequenceDiagram
    participant IoTDevice as IoT Device (e.g., Smart Meter)
    participant eSIM as eSIM Module
    participant NcellNetwork as Ncell Core Network
    participant AppServer as Application Server

    IoTDevice->>eSIM: Boot with embedded credentials
    eSIM->>NcellNetwork: mTLS Handshake (Device Cert + Network CA)
    NcellNetwork-->>AppServer: Authenticate device
    AppServer->>IoTDevice: Encrypted commands (AES-128)

3. Securing Cloud Data

Encryption Techniques

Layer Protocol/Standard Use Case Example in Nepal
Data at Rest AES-256 (CBC/GCM) Storing customer records Ncell’s subscriber data
Data in Transit TLS 1.3 Secure API calls Daraz’s payment gateway
Key Management AWS KMS / HashiCorp Vault Rotating encryption keys Nepal Rastra Bank’s ledger

Worked Example: Daraz’s Order Data Protection Daraz uses:

  1. Field-level encryption (e.g., credit card numbers encrypted separately from order IDs).
  2. AWS KMS for key rotation every 90 days.
  3. HSM (Hardware Security Module) for master key storage.
08162431order_id16 bitscustomer_id16 bitscard_last416 bitsamount16 bits
Daraz’s field-level encryption (AWS KMS-managed keys)

4. IoT Security Frameworks

NIST IR 8259: IoT Device Security Guidelines

  1. Device Identity: Unique identifiers (UDID) + digital certificates.
  2. Authentication: Mutual TLS (mTLS) or OAuth 2.0.
  3. Firmware Updates: Over-the-air (OTA) with integrity checks (SHA-256).
  4. Network Security: VLAN segmentation for IoT traffic.

Comparison: IoT Protocols

Protocol Security Features Weaknesses Used By
MQTT TLS/DTLS support No built-in auth Pathao’s delivery IoT
CoAP DTLS, OSCORE (object security) Limited payload size Smart home devices
AMQP SASL, TLS Complex setup NTC’s SCADA systems

5. Cloud Threat Mitigation

Zero Trust Architecture (ZTA)

  • Principle: "Never trust, always verify."
  • Components:
    • Microsegmentation: Isolate cloud workloads (e.g., Daraz’s payment service in a separate VPC).
    • Continuous Authentication: Risk-based access (e.g., Khalti’s 2FA + behavioral analytics).
    • Least Privilege: IAM roles with minimal permissions.
stateDiagram-v2
    [*] --> UserAccessRequest
    UserAccessRequest --> VerifyIdentity: MFA + Device Check
    VerifyIdentity --> AssessRisk: Behavioral AI
    AssessRisk --> GrantAccess: Temporary Token
    GrantAccess --> MonitorActivity: Log & Alert
    MonitorActivity --> [*]

Real-world example: Nepal Stock Exchange (NEPSE) uses ZTA to secure trading terminals:

  • Traders authenticate via biometrics + hardware tokens.
  • API calls are signed with JWT tokens valid for 5 minutes.

6. IoT-Specific Defenses

Hardware-Based Security

Technique How It Works Example
Secure Boot Verifies firmware before execution Raspberry Pi 4 IoT devices
Trusted Platform Module (TPM) Stores cryptographic keys in hardware Industrial IoT gateways
Physical Unclonable Functions (PUF) Unique device fingerprinting Ncell’s anti-cloning SIMs

Blockchain for IoT Integrity

  • Use Case: Tamper-proof logs for medical devices (e.g., patient monitors).
  • How It Works:
    1. IoT device records data in a private blockchain (Hyperledger Fabric).
    2. Smart contracts validate sensor readings.
    3. Hospitals audit data without trusting a central server.
sequenceDiagram
    participant PatientMonitor as IoT Device
    participant Blockchain as Private Ledger
    participant Hospital as Auditor

    PatientMonitor->>Blockchain: Submit reading (ECG data + timestamp)
    Blockchain->>Blockchain: Validate via smart contract
    Hospital->>Blockchain: Query data (immutable audit trail)

7. Exam Tip: How This Unit Is Tested

  1. Scenario-Based Questions (30%):

    • "A Daraz server is under a DDoS attack. Explain how AWS Shield + IoT-specific rate limiting would mitigate this."
    • Key Points to Include:
      • AWS Shield’s always-on DDoS protection.
      • IoT traffic filtering (e.g., blocking spoofed source IPs).
      • Multi-region failover for availability.
  2. Protocol Analysis (25%):

    • "Compare MQTT and CoAP security. Which would you use for Pathao’s delivery tracking, and why?"
    • Must Cover:
      • MQTT’s QoS levels vs. CoAP’s lightweight DTLS.
      • Pathao’s need for low latency (CoAP) + device authentication (mTLS).
  3. Attack Mitigation (20%):

    • "Design a defense against the Mirai botnet for NTC’s IoT-enabled traffic lights."
    • Expected Answer:
      • Network-level: Deploy Cisco Umbrella to block C&C servers.
      • Device-level: Enforce secure boot + TPM for firmware integrity.
      • Monitoring: Use SIEM tools (e.g., Splunk) to detect unusual traffic.
  4. Short Definitions (15%):

    • Zero Trust: "A model where no entity (user/device) is trusted by default; verification is required for every access request."
    • IoT Botnet: "A network of compromised IoT devices (e.g., cameras, routers) used to launch DDoS attacks (e.g., Mirai)."
  5. Real-World Applications (10%):

    • "How does Khalti secure its cloud-based payment system?"
    • Must Mention:
      • Tokenization (never stores raw card numbers).
      • PCI-DSS compliance (quarterly audits).
      • Multi-factor authentication (OTP + biometrics).

Final Visual Summary

Based on the TU BIT syllabus for Network Security, unit 8.

Discussion

Loading…