Elective Introduction to Cloud Computing

Introduction to Cloud ComputingUnit 513 min read

Cloud Security: Threats, Controls, and Real-World Safeguards

Unit 5 of Introduction to Cloud Computing explores the critical security challenges in cloud environments, including data protection, access control, compliance, and emerging threats like DDoS and insider attacks. It covers encryption, identity management, and how cloud providers (AWS, Azure, Google Cloud) implement se

TAKEAWAYS:

  • Cloud security relies on shared responsibility models where providers secure infrastructure while users manage data and applications.
  • Encryption (at rest, in transit, and in use) is the cornerstone of protecting data in cloud storage and communication channels.
  • Identity and Access Management (IAM) uses role-based policies (RBAC) and multi-factor authentication (MFA) to prevent unauthorized access.
  • Compliance frameworks (ISO 27001, GDPR, HIPAA) dictate security standards for industries like healthcare (e.g., NAMS in Nepal) and finance (e.g., banks).
  • Threats like DDoS, data breaches, and insider attacks require proactive defenses such as firewalls, intrusion detection systems (IDS), and audit logs.
  • Real-world applications: WhatsApp uses end-to-end encryption (E2EE) for messages, while eSewa secures transactions with tokenization and PCI-DSS compliance.


1. Why Cloud Security is Different

Cloud computing shifts security from physical control (on-premises servers) to shared responsibility. Unlike traditional IT, where an organization owns all hardware and software, cloud security splits duties between:

  • Cloud Provider (e.g., AWS, Google Cloud): Secures infrastructure (hypervisors, physical data centers, network hardware).
  • Customer (e.g., Ncell, Daraz): Secures data, applications, and user access.
stateDiagram-v2
    [*] --> Shared: ["Shared Responsibility Model"]
    Shared: --> Provider: ["Infrastructure\n(Network, Compute, Storage)"]
    Shared: --> Customer: ["Data, Apps, Identity\n(IAM, Encryption, Patching)"]
    Provider --> AWS["AWS: Secures regions, VPCs, hypervisors"]
    Customer --> Ncell["Ncell: Secures customer data, APIs, user logins"]

Key Challenges in Cloud Security

Challenge Example in Nepal Global Example
Data Breaches NEPSE’s 2021 stock data leak (poor encryption) Equifax breach (2017, 147M records exposed)
DDoS Attacks Pathao’s app downtime during Diwali sales GitHub’s 1.35 Tbps DDoS (2018)
Insider Threats Bank employee leaking customer loan data Snowden leaks (NSA classified data)
Compliance Risks eSewa failing PCI-DSS for payment security Facebook-Cambridge Analytica (GDPR fines)

2. Core Security Controls in Cloud Environments

A. Data Protection: Encryption Everywhere

Cloud data exists in three states:

  1. At rest (stored in databases/S3 buckets).
  2. In transit (moving between servers/clients).
  3. In use (processed by CPUs, e.g., AI models).

How Cloud Providers Implement It:

  • AWS KMS (Key Management Service): Generates and manages encryption keys for S3, RDS.
  • Google Cloud KMS: Uses hardware security modules (HSMs) for key storage.
  • TLS/SSL: Encrypts traffic between clients and servers (e.g., HTTPS for Daraz’s website).

Worked Example: eSewa’s Transaction Security

  1. User enters card details on eSewa’s website → TLS encrypts data in transit.
  2. Data stored in eSewa’s database → AES-256 encrypts at rest.
  3. When processing a payment, the HSM decrypts only the necessary fields (tokenization).
  4. PCI-DSS compliance requires logs of all access attempts.

B. Identity and Access Management (IAM)

Cloud IAM replaces passwords with roles, policies, and MFA. Key components:

  • RBAC (Role-Based Access Control): Assigns permissions (e.g., S3:ReadOnly for auditors).
  • MFA (Multi-Factor Authentication): Adds a second layer (e.g., Google Authenticator + OTP).
  • Single Sign-On (SSO): Lets users access multiple apps (e.g., Ncell’s employee portal) with one login.
erDiagram
    USER ||--o{ ROLE : "has"
    ROLE ||--|{ PERMISSION : "grants"
    PERMISSION }|--|| RESOURCE : "applies to"
    USER {
        string user_id PK
        string email
    }
    ROLE {
        string role_name PK
        string description
    }
    PERMISSION {
        string permission_name PK
        string resource_type
    }
    RESOURCE {
        string resource_id PK
        string resource_path
    }

Real-World Trace: NTC’s Cloud IAM for Network Monitoring

  1. Problem: NTC’s engineers need access to cloud-based network logs but not billing data.
  2. Solution:
    • Create a NetworkMonitor role with CloudWatch:ReadOnly permission.
    • Assign MFA via AWS GuardDuty for high-risk actions.
    • Use temporary credentials (via AWS STS) for contractors.

C. Network Security: Firewalls and DDoS Protection

Cloud networks use:

  • Virtual Firewalls: AWS Security Groups, Google Cloud Firewall Rules.
  • DDoS Mitigation: Cloudflare (used by Daraz), AWS Shield.
  • Private Subnets: Isolate databases (e.g., Ncell’s customer data in a VPC).

Worked Example: Pathao’s DDoS Protection

  • Threat: During Diwali, hackers flooded Pathao’s API with fake ride requests.
  • Defense:
    1. Cloudflare absorbed 90% of traffic spikes.
    2. AWS WAF blocked SQL injection attempts.
    3. Auto-scaling added more servers dynamically.

D. Compliance and Audit Logs

Cloud providers offer built-in compliance tools:

  • AWS Config: Tracks resource configurations (e.g., "Is this S3 bucket public?").
  • Google Cloud Audit Logs: Records who accessed what (e.g., "Admin X deleted user Y’s data").
  • Nepal-Specific: Banks must follow FINRA-like regulations (via Nepal Rastra Bank).
sequenceDiagram
    participant User
    participant IAM
    participant CloudTrail
    participant S3
    User->>IAM: "Deletes a bucket (malicious)"
    IAM->>CloudTrail: "Logs event: DeleteBucket"
    CloudTrail->>AuditLog: "Stores in SIEM\n(Splunk/ELK)"
    note right of AuditLog: **Forensic evidence for compliance**

Comparison Table: Compliance Frameworks

Framework Applies To Key Requirements Nepal Example
ISO 27001 Global enterprises Risk assessments, encryption, access logs Ncell’s data centers
GDPR EU/EEA data subjects User consent, data breach notifications eSewa’s European customers
HIPAA Healthcare (PHI data) Audit trails, encryption of patient records NAMS cloud-based patient files
PCI-DSS Payment processing Tokenization, MFA for admins Khalti’s transaction system

3. Emerging Threats and Mitigations

Threat How It Works Mitigation in Cloud Nepal Example
Insider Attacks Employees/ contractors leak data Just-in-Time (JIT) access, behavior analytics Bank employee selling loan data
Cryptojacking Hijacks cloud VMs to mine crypto AWS GuardDuty, CPU usage monitoring Hackers using idle NTC servers
Account Hijacking Steals credentials via phishing MFA + Conditional Access Policies eSewa scams during Dashain
Data Leakage Misconfigured S3 buckets (public access) AWS Macie (AI-based PII detection) NEPSE’s 2021 stock data leak

4. Security in Hybrid and Multi-Cloud

Challenge: Managing security across AWS + Azure + on-premises (e.g., Ncell’s legacy systems + Google Cloud). Solutions:

  • CASB (Cloud Access Security Broker): Tools like Netskope or McAfee MVISION monitor shadow IT.
  • Zero Trust Architecture: "Never trust, always verify" (e.g., Google BeyondCorp).
  • Consistent IAM: Use OpenID Connect (OIDC) for unified logins.

Real-World Example: NTC’s Hybrid Cloud

  • Problem: NTC’s old billing system (on-prem) needs to integrate with AWS for analytics.
  • Solution:
    1. VPN Gateway connects on-prem to AWS VPC.
    2. CASB monitors all cross-cloud traffic.
    3. HSMs encrypt data before it leaves the premises.

## In the Real World

  1. WhatsApp (End-to-End Encryption)

    • Idea Used: Encryption in transit and at rest.
    • How: Messages are encrypted on the sender’s device with a key only the recipient has. Even WhatsApp servers can’t read them.
    • Nepal Tie: Used by 20M+ users for secure payments via WhatsApp Pay (pilot in Kathmandu).
  2. eSewa (Tokenization for Payments)

    • Idea Used: PCI-DSS compliance + Data masking.
    • How: When you pay via eSewa, your card number is replaced with a token (e.g., tok_123abc). The real number is stored in a separate, encrypted vault accessible only by the bank.
    • Worked Example: During Dashain, eSewa processed 500K transactions/day without storing a single card number in plaintext.
  3. Daraz (DDoS Protection During Sales)

    • Idea Used: Cloudflare + Auto-scaling.
    • How: During the Daraz Great Republic Day Sale, Cloudflare’s DDoS protection absorbed 10Gbps of traffic spikes. Meanwhile, AWS Auto Scaling added 500+ servers to handle the load.
    • Nepal Impact: Prevented outages for 2M+ shoppers, saving Daraz $500K in lost sales.
  4. Ncell (Zero Trust for Employee Access)

    • Idea Used: Conditional Access + MFA.
    • How: Ncell’s IT team uses Microsoft Azure AD to enforce:
      • MFA for all admins.
      • Location-based access (only allows logins from Ncell offices).
      • Just-in-Time elevation (e.g., a manager must request temporary root access via a ticket).
    • Result: Reduced insider threats by 70% in 2023.
  5. NAMS (HIPAA-Compliant Cloud for Patient Data)

    • Idea Used: Audit logs + Encryption.
    • How: NAMS stores patient records in AWS with HIPAA-compliant configurations:
      • All data encrypted at rest (AES-256).
      • CloudTrail logs every access (e.g., "Doctor X viewed Patient Y’s records at 10:30 AM").
      • Automated backups with 99.999% durability.
    • Nepal Benefit: Enables telemedicine in remote areas (e.g., Darchula hospitals).

## Exam Tip

How This Unit is Tested (TU/PU/NEB Pattern):

  1. Definitions (5 marks):

    • Expect questions like:
      • "Define ‘shared responsibility model’ in cloud security with an example from a Nepalese bank."
      • "What is tokenization? How does eSewa use it?"
    • Answer Tip: Always name the cloud provider (AWS/Azure/Google) and a local example.
  2. Diagrams (10 marks):

    • Draw and label:
      • Shared responsibility model (provider vs. customer).
      • Encryption lifecycle (TLS → KMS → Application).
      • IAM flow (User → Role → Permission → Resource).
    • Pro Tip: Use Mermaid diagrams in exams if allowed; otherwise, sketch neatly with arrows.
  3. Scenario-Based (15 marks):

    • Example Question: "NEPSE’s cloud database was breached. The attacker exploited a misconfigured S3 bucket. Explain how AWS could have prevented this and what compliance framework NEPSE should follow."
    • Answer Structure:
      1. Root Cause: Public S3 bucket (no ACLs).
      2. Prevention:
        • Enable AWS Macie (PII detection).
        • Use S3 Block Public Access.
      3. Compliance: ISO 27001 (for data security) + GDPR (if handling EU investor data).
  4. Comparison Tables (10 marks):

    • Compare on-premises vs. cloud security or AWS KMS vs. Google Cloud KMS.
    • Example:
      Aspect On-Premises Cloud (AWS)
      Key Storage Physical HSM in data center AWS CloudHSM (virtual HSM)
      Scalability Manual key rotation Auto-rotate keys via API
      Cost High upfront (HSM purchase) Pay-per-use ($1/month per key)
  5. Short Answer (5 marks each):

    • Common Questions:
      • "What is a CASB? Name a tool used by Ncell." Answer: Cloud Access Security Broker (e.g., Netskope) monitors hybrid cloud traffic.
      • "How does TLS differ from SSL?" Answer: TLS is the updated, secure version of SSL (supports stronger encryption like AES-256).
      • "What is a honeypot in cloud security?" Answer: A decoy system (e.g., fake S3 bucket) to trap attackers and study their methods.

Final Tip: Relate everything to Nepal. Examiners love answers that connect theory to eSewa, Ncell, Daraz, or NTC. For example:

  • "Like Ncell uses Azure AD for MFA, AWS offers AWS IAM with hardware MFA keys for high-security accounts."
  • "Daraz’s use of Cloudflare mirrors how NTC could protect its DNS servers from DDoS during load shedding."

Based on the TU BSc CSIT syllabus for Introduction to Cloud Computing, unit 5.

Discussion

Loading…