Network SecurityUnit 89 min read
Cloud & IoT Security: Threats, Protocols & Defense
Unit 8 of Network Security explores the security challenges, protocols, and best practices for protecting cloud computing environments and Internet of Things (IoT) devices, including encryption, authentication, and attack mitigation strategies used by companies like Ncell and Daraz.
TAKEAWAYS:
- Cloud security relies on shared responsibility models where providers secure infrastructure while users manage data and applications.
- IoT devices are vulnerable to DDoS attacks, weak authentication, and firmware exploits, requiring hardware-level protections.
- Zero Trust Architecture (ZTA) and microsegmentation are key to securing cloud environments against lateral movement.
- IoT security frameworks (e.g., NIST IR 8259) mandate device authentication, encryption, and patch management.
- Real-world examples show how Ncell’s IoT SIM cards use eSIM authentication to prevent SIM swapping, while Daraz’s cloud servers rely on AWS KMS for order data encryption.
- Exam questions often test attack scenarios (e.g., Mirai botnet), protocol weaknesses (e.g., MQTT’s lack of built-in security), and mitigation techniques (e.g., blockchain for IoT integrity).
1. Cloud Security Fundamentals
Cloud security is built on three core principles:
- Confidentiality: Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- Integrity: Hash functions (SHA-256) and digital signatures prevent tampering.
- Availability: DDoS protection (AWS Shield) and multi-region redundancy ensure uptime.
Shared Responsibility Model
Cloud providers (AWS, Google Cloud, NTC’s cloud services) secure the infrastructure (hypervisors, physical servers), while users (e.g., Daraz, banks) manage:
- Data encryption keys
- Identity and access management (IAM)
- Application security (e.g., SQL injection prevention)
Real-world example: Nepal Rastra Bank (NRB) stores customer transaction data on AWS GovCloud, where NRB controls encryption keys (via AWS KMS) while AWS secures the underlying servers. If a hacker breaches AWS’s network, they still cannot decrypt NRB’s data without the keys.
2. IoT Security Challenges
IoT devices (e.g., smart meters, industrial sensors, Pathao’s delivery trackers) are prime targets due to:
- Weak default credentials (e.g., "admin:admin" in many routers).
- Lack of firmware updates (e.g., old NTC CCTV cameras running unpatched software).
- Limited processing power (cannot run full TLS stacks).
Common IoT Attacks
| Attack Type | Example | Mitigation Strategy |
|---|---|---|
| DDoS | Mirai botnet (2016) | Rate limiting, IoT-specific firewalls |
| Man-in-the-Middle | Unencrypted MQTT traffic | TLS/DTLS for IoT protocols |
| Firmware Exploits | Vulnerable smart locks | Secure boot, code signing |
| Data Leakage | Unauthorized API access | OAuth 2.0, API gateways |
Worked Example: Ncell’s IoT SIM Security Ncell’s eSIM-based IoT authentication prevents SIM swapping by:
- Storing credentials in a secure element (hardware chip).
- Using OMA-DM (Open Mobile Alliance Device Management) for remote updates.
- Enforcing mutual TLS (mTLS) for device authentication.
sequenceDiagram
participant IoTDevice as IoT Device (e.g., Smart Meter)
participant eSIM as eSIM Module
participant NcellNetwork as Ncell Core Network
participant AppServer as Application Server
IoTDevice->>eSIM: Boot with embedded credentials
eSIM->>NcellNetwork: mTLS Handshake (Device Cert + Network CA)
NcellNetwork-->>AppServer: Authenticate device
AppServer->>IoTDevice: Encrypted commands (AES-128)3. Securing Cloud Data
Encryption Techniques
| Layer | Protocol/Standard | Use Case | Example in Nepal |
|---|---|---|---|
| Data at Rest | AES-256 (CBC/GCM) | Storing customer records | Ncell’s subscriber data |
| Data in Transit | TLS 1.3 | Secure API calls | Daraz’s payment gateway |
| Key Management | AWS KMS / HashiCorp Vault | Rotating encryption keys | Nepal Rastra Bank’s ledger |
Worked Example: Daraz’s Order Data Protection Daraz uses:
- Field-level encryption (e.g., credit card numbers encrypted separately from order IDs).
- AWS KMS for key rotation every 90 days.
- HSM (Hardware Security Module) for master key storage.
4. IoT Security Frameworks
NIST IR 8259: IoT Device Security Guidelines
- Device Identity: Unique identifiers (UDID) + digital certificates.
- Authentication: Mutual TLS (mTLS) or OAuth 2.0.
- Firmware Updates: Over-the-air (OTA) with integrity checks (SHA-256).
- Network Security: VLAN segmentation for IoT traffic.
Comparison: IoT Protocols
| Protocol | Security Features | Weaknesses | Used By |
|---|---|---|---|
| MQTT | TLS/DTLS support | No built-in auth | Pathao’s delivery IoT |
| CoAP | DTLS, OSCORE (object security) | Limited payload size | Smart home devices |
| AMQP | SASL, TLS | Complex setup | NTC’s SCADA systems |
5. Cloud Threat Mitigation
Zero Trust Architecture (ZTA)
- Principle: "Never trust, always verify."
- Components:
- Microsegmentation: Isolate cloud workloads (e.g., Daraz’s payment service in a separate VPC).
- Continuous Authentication: Risk-based access (e.g., Khalti’s 2FA + behavioral analytics).
- Least Privilege: IAM roles with minimal permissions.
stateDiagram-v2
[*] --> UserAccessRequest
UserAccessRequest --> VerifyIdentity: MFA + Device Check
VerifyIdentity --> AssessRisk: Behavioral AI
AssessRisk --> GrantAccess: Temporary Token
GrantAccess --> MonitorActivity: Log & Alert
MonitorActivity --> [*]Real-world example: Nepal Stock Exchange (NEPSE) uses ZTA to secure trading terminals:
- Traders authenticate via biometrics + hardware tokens.
- API calls are signed with JWT tokens valid for 5 minutes.
6. IoT-Specific Defenses
Hardware-Based Security
| Technique | How It Works | Example |
|---|---|---|
| Secure Boot | Verifies firmware before execution | Raspberry Pi 4 IoT devices |
| Trusted Platform Module (TPM) | Stores cryptographic keys in hardware | Industrial IoT gateways |
| Physical Unclonable Functions (PUF) | Unique device fingerprinting | Ncell’s anti-cloning SIMs |
Blockchain for IoT Integrity
- Use Case: Tamper-proof logs for medical devices (e.g., patient monitors).
- How It Works:
- IoT device records data in a private blockchain (Hyperledger Fabric).
- Smart contracts validate sensor readings.
- Hospitals audit data without trusting a central server.
sequenceDiagram
participant PatientMonitor as IoT Device
participant Blockchain as Private Ledger
participant Hospital as Auditor
PatientMonitor->>Blockchain: Submit reading (ECG data + timestamp)
Blockchain->>Blockchain: Validate via smart contract
Hospital->>Blockchain: Query data (immutable audit trail)7. Exam Tip: How This Unit Is Tested
Scenario-Based Questions (30%):
- "A Daraz server is under a DDoS attack. Explain how AWS Shield + IoT-specific rate limiting would mitigate this."
- Key Points to Include:
- AWS Shield’s always-on DDoS protection.
- IoT traffic filtering (e.g., blocking spoofed source IPs).
- Multi-region failover for availability.
Protocol Analysis (25%):
- "Compare MQTT and CoAP security. Which would you use for Pathao’s delivery tracking, and why?"
- Must Cover:
- MQTT’s QoS levels vs. CoAP’s lightweight DTLS.
- Pathao’s need for low latency (CoAP) + device authentication (mTLS).
Attack Mitigation (20%):
- "Design a defense against the Mirai botnet for NTC’s IoT-enabled traffic lights."
- Expected Answer:
- Network-level: Deploy Cisco Umbrella to block C&C servers.
- Device-level: Enforce secure boot + TPM for firmware integrity.
- Monitoring: Use SIEM tools (e.g., Splunk) to detect unusual traffic.
Short Definitions (15%):
- Zero Trust: "A model where no entity (user/device) is trusted by default; verification is required for every access request."
- IoT Botnet: "A network of compromised IoT devices (e.g., cameras, routers) used to launch DDoS attacks (e.g., Mirai)."
Real-World Applications (10%):
- "How does Khalti secure its cloud-based payment system?"
- Must Mention:
- Tokenization (never stores raw card numbers).
- PCI-DSS compliance (quarterly audits).
- Multi-factor authentication (OTP + biometrics).
Final Visual Summary
Based on the TU BIT syllabus for Network Security, unit 8.
Discussion
Loading…