Cloud ComputingUnit 810 min read
Cloud Security: Threats, Controls, Encryption & Compliance
Unit 8 of Cloud Computing explores the critical security challenges in cloud environments, including data protection, access control, encryption techniques, compliance frameworks (ISO 27001, GDPR), and real-world attack scenarios like DDoS and insider threats. Students learn how cloud providers and users mitigate risks
Core Concepts: Why Cloud Security is Different
Cloud security is not just an extension of traditional IT security—it is a shared responsibility model where both the cloud provider (e.g., AWS, Azure) and the customer (e.g., eSewa, Daraz) must collaborate to protect data, applications, and infrastructure. Unlike on-premises systems, cloud environments introduce multi-tenancy, dynamic scaling, and third-party dependencies, which create unique attack surfaces.
1. Shared Responsibility Model
The cloud provider secures the physical infrastructure (data centers, hardware), while the customer secures data, applications, and access management. For example:
- AWS: Secures the hypervisor, network, and physical servers.
- Customer (e.g., Ncell): Secures customer data, IAM policies, and application code.
stateDiagram-v2
[*] --> Responsibility:CloudProvider
Responsibility:CloudProvider --> PhysicalInfrastructure:Secures
Responsibility:CloudProvider --> Network:Secures
Responsibility:CloudProvider --> Hypervisor:Secures
[*] --> Responsibility:Customer
Responsibility:Customer --> Data:Secures
Responsibility:Customer --> Applications:Secures
Responsibility:Customer --> IAM:Manages2. Common Cloud Security Threats
Cloud environments face threats that exploit their scalability, connectivity, and shared resources. Key threats include:
| Threat | Description | Example in Nepal |
|---|---|---|
| Data Breaches | Unauthorized access to sensitive data (e.g., customer records). | A Daraz vendor’s database exposed due to weak IAM policies. |
| DDoS Attacks | Overwhelming traffic to disrupt services. | NTC’s website crash during peak hours due to a DDoS attack. |
| Insider Threats | Malicious or negligent employees/contractors. | An eSewa employee leaking customer transaction data. |
| Misconfigured Storage | Open S3 buckets or unencrypted databases. | A Kathmandu-based startup’s AWS S3 bucket left public, exposing user data. |
| Account Hijacking | Stolen credentials used to access cloud resources. | A hacker using stolen credentials to deploy crypto-mining malware on a cloud VM. |
Worked Example: DDoS Attack on NTC
- Scenario: During a major festival, NTC’s website experiences a sudden traffic spike.
- Attack Vector: A botnet floods NTC’s cloud-hosted DNS with fake requests.
- Mitigation:
- Use AWS Shield (DDoS protection service).
- Implement rate limiting on API endpoints.
- Deploy Cloudflare as a CDN to absorb traffic spikes.
3. Security Controls in Cloud Environments
Cloud security relies on preventive, detective, and corrective controls:
A. Preventive Controls
Encryption:
- At Rest: Data encrypted when stored (e.g., AWS KMS, Azure Disk Encryption).
- In Transit: TLS/SSL for data moving between client and server.
- Example: Khalti uses TLS 1.3 for all transactions to prevent MITM attacks.
Access Control:
- IAM (Identity and Access Management): Role-based access (e.g., AWS IAM roles for Pathao drivers vs. admins).
- Multi-Factor Authentication (MFA): Required for all admin access (e.g., NEPSE’s trading platform).
sequenceDiagram
User->>Cloud: Requests Access
Cloud-->>User: MFA Prompt (SMS/OTP)
User->>Cloud: Submits MFA Code
Cloud->>User: Grants Access (if valid)B. Detective Controls
- Logging and Monitoring:
- AWS CloudTrail: Tracks API calls (e.g., who deleted a critical VM).
- SIEM Tools: Splunk or Azure Sentinel for anomaly detection.
- Example: Ncell uses SIEM to detect unusual login attempts from new geolocations.
C. Corrective Controls
- Incident Response:
- Isolation: Quarantine compromised VMs.
- Forensics: Use tools like AWS Detective to trace attack origins.
- Example: After a breach, Daraz isolates affected servers and rolls back to a clean snapshot.
4. Encryption in Cloud Security
Encryption is the cornerstone of cloud security, protecting data in transit, at rest, and in use.
| Encryption Type | Use Case | Example in Cloud |
|---|---|---|
| Symmetric Encryption | Fast encryption/decryption for bulk data. | AWS KMS (AES-256) for encrypting EBS volumes. |
| Asymmetric Encryption | Secure key exchange (e.g., TLS handshake). | SSL certificates for secure WhatsApp API calls. |
| Hashing | Integrity verification (e.g., passwords). | Khalti uses SHA-256 to store user passwords (never plaintext). |
Worked Example: Encrypting a Database in Azure
- At Rest: Enable Azure SQL Database Transparent Data Encryption (TDE).
- In Transit: Enforce TLS 1.2+ for all connections.
- Key Management: Use Azure Key Vault to store encryption keys.
5. Compliance and Standards
Cloud providers must adhere to global and local regulations:
| Standard | Scope | Example in Nepal |
|---|---|---|
| ISO 27001 | Information security management. | Ncell’s cloud infrastructure certified for ISO 27001. |
| GDPR | EU data protection (applies to global companies handling EU citizen data). | Daraz must comply with GDPR for European customers. |
| PCI DSS | Payment card security. | eSewa’s cloud payment gateway must pass PCI DSS audits. |
| Nepal’s Data Privacy Act | Protects Nepali citizens’ personal data. | Banks like NMB must encrypt customer data stored in AWS Nepal regions. |
6. Zero Trust Architecture
Traditional perimeter security (firewalls, VPNs) is insufficient for cloud. Zero Trust assumes:
- "Never trust, always verify."
- Micro-segmentation: Divide cloud networks into small zones (e.g., separate VMs for frontend/backend).
- Continuous Authentication: Re-authenticate users/devices periodically.
Real-World Example: Google BeyondCorp
- Eliminates VPNs by requiring device health checks and context-aware access.
- Used by Google Workspace to secure remote employees.
7. Security-as-Code (DevSecOps)
Integrating security into CI/CD pipelines ensures vulnerabilities are caught early:
- Static Code Analysis: Tools like SonarQube scan for vulnerabilities in Pathao’s app code.
- Infrastructure as Code (IaC) Security: AWS CloudFormation templates include security groups and IAM policies.
- Automated Compliance Checks: Terraform + Checkov validate AWS resource configurations.
sequenceDiagram
Developer->>Git: Commits Code
Git->>CI/CD: Triggers Pipeline
CI/CD->>SonarQube: Static Analysis
SonarQube-->>CI/CD: Vulnerability Report
CI/CD->>AWS: Deploys Only if SecureIn the Real World
eSewa’s Payment Security
- Idea Used: Tokenization + PCI DSS Compliance
- How: eSewa replaces card details with tokens (e.g.,
tok_123abc) stored in AWS KMS-encrypted databases. This prevents card data from being exposed even if the database is breached.
Ncell’s 5G Cloud Core Security
- Idea Used: Zero Trust + Micro-Segmentation
- How: Ncell’s cloud-native 5G core uses Kubernetes network policies to isolate control planes (e.g., AMF, SMF) from user planes. Only authenticated devices (via SIM-based MFA) can access services.
Daraz’s Global Supply Chain Tracking
- Idea Used: Blockchain for Supply Chain + AWS IoT
- How: Daraz partners use Hyperledger Fabric (on AWS) to log shipments from vendors to customers. Each step (warehouse → courier → delivery) is cryptographically signed, preventing tampering.
Exam Tip
Shared Responsibility Model: Always draw the AWS/Azure shared responsibility diagram in exams. Memorize:
- Provider: Physical security, hypervisor, networking.
- Customer: Data, IAM, applications.
Encryption Questions: Expect scenario-based questions (e.g., "How would you secure a Khalti database in Azure?").
- Answer with:
- At rest: Azure Disk Encryption.
- In transit: TLS 1.3.
- Key management: Azure Key Vault.
- Answer with:
Compliance Short Answers:
- ISO 27001: Risk assessment + controls.
- GDPR: Right to erasure, data minimization.
- PCI DSS: Never store raw card data; use tokens.
Zero Trust Diagrams: If asked to explain Zero Trust, always include:
- Identity provider (e.g., Okta).
- Micro-segmentation (e.g., Kubernetes namespaces).
- Continuous authentication (e.g., device posture checks).
Threat Mitigation Tables: For threats like DDoS or insider threats, structure answers as:
Threat Mitigation Tool/Service DDoS Rate limiting + CDN Cloudflare + AWS Shield Insider Least privilege + MFA AWS IAM + Duo Security
Based on the TU BITM syllabus for Cloud Computing (IT277), unit 8.
Discussion
Loading…