Cloud Computing and VirtualizationUnit 915 min read
Cloud Security: Threats, Controls, Compliance & Real-World Cases
Unit 9 of Cloud Computing and Virtualization explores cloud-specific security threats (DDoS, data leaks, insider attacks), defense mechanisms (encryption, IAM, zero trust), compliance frameworks (ISO 27001, GDPR), and real-world breaches like the 2022 Ncell data leak. Learn how companies like eSewa and banks secure tra
Cloud Security Fundamentals: Why Cloud is Different
Cloud security is not just "IT security in the cloud." The shared responsibility model (see figure below) means you control some risks while the cloud provider controls others. For example:
- Your responsibility: Configuring IAM roles, encrypting data at rest, patching VMs.
- Provider’s responsibility: Physical security of data centers, hypervisor hardening, network isolation.
stateDiagram-v2
[*] --> Shared: "Customer"
Shared --> Customer: "Data, Config, Apps, OS, Middleware"
Shared --> Provider: "Runtime, Hypervisor, Network, Physical"
Provider --> [*]
note right of Shared
Shared Responsibility Model
(AWS/Azure/GCP example)
end noteReal-world example: When eSewa migrated its payment gateway to AWS, it retained control over API keys and customer data encryption (its responsibility) while relying on AWS’s DDoS protection (provider’s responsibility). The 2021 eSewa breach occurred because customer-side credentials were leaked—not AWS’s fault.
1. Cloud-Specific Threats: What’s Unique to Cloud?
Cloud introduces new attack surfaces that don’t exist in on-premises systems. Here are the top 3 threats with real-world examples:
A. Data Breaches & Leakage
How it happens:
- Misconfigured storage buckets (e.g., S3 buckets with public permissions).
- Weak encryption keys (e.g., using default keys or storing them in plaintext).
- Insider threats (e.g., employees accessing data they shouldn’t).
Example:
- Ncell (2022): A misconfigured database exposed 10 million customer records (names, phone numbers, SIM details). The attacker exploited default credentials left unchanged by Ncell’s IT team.
- Daraz (2021): A third-party vendor’s unencrypted database was hacked, leaking user payment details during checkout.
Visual: How a misconfigured S3 bucket becomes a breach
Prevention:
- Encryption: Use AWS KMS or Azure Key Vault for key management.
- Access Control: Apply least privilege (e.g., IAM roles with minimal permissions).
- Audit Logs: Enable AWS CloudTrail or Azure Monitor to detect unauthorized access.
B. Distributed Denial-of-Service (DDoS) Attacks
How it works: Attackers flood cloud services (e.g., APIs, databases) with traffic to crash them. Cloud providers are primary targets because they host high-traffic services.
Example:
- Nepal’s NTC (2020): During COVID-19, hackers launched a DDoS attack on NTC’s website, disrupting internet services for hours. The attack used botnets (zombie devices) to overwhelm NTC’s servers.
- Google (2017): A 2.54 Tbps DDoS attack (largest ever recorded) targeted Google’s infrastructure. The attackers exploited misconfigured DNS servers.
Visual: DDoS Attack Flow
graph LR
A["Attacker"] -->|"Botnet"| B["Zombie Devices<br/>(Infects IoT, PCs)"]
B -->|"Flood Traffic"| C["Cloud Service<br/>(e.g., NTC Website)"]
C -->|"Overload"| D["Service Crash<br/>(Downtime for users)"]Prevention:
- Cloud Provider Tools:
- AWS Shield (free tier protects against most attacks).
- Azure DDoS Protection (auto-scales to absorb attacks).
- Rate Limiting: Use API Gateway to throttle requests.
- Anycast Routing: Distribute traffic across multiple data centers (used by Cloudflare).
C. Insider Threats & Account Hijacking
How it happens:
- Credential theft (phishing, keyloggers).
- Privilege escalation (e.g., an admin granting themselves excessive permissions).
- Malicious insiders (e.g., employees selling data).
Example:
- WhatsApp (2019): Hackers used NSO Group’s Pegasus spyware to hijack accounts of journalists and activists. The attack exploited zero-day vulnerabilities in WhatsApp’s cloud messaging service.
- Khalti (2020): An internal employee leaked merchant API keys, allowing attackers to siphon NPR 50 million from business accounts.
Prevention:
- Multi-Factor Authentication (MFA): Enforce TOTP or hardware keys (e.g., YubiKey).
- Just-In-Time (JIT) Access: Grant permissions temporarily (e.g., AWS IAM Access Analyzer).
- Behavioral Analytics: Use Microsoft Defender for Cloud to detect anomalous logins.
2. Cloud Security Controls: How to Defend
Cloud security relies on layers of defense. Below is a comparison table of key controls:
| Control | What It Does | Example Tools | Best For |
|---|---|---|---|
| Identity & Access Mgmt (IAM) | Controls who/what can access cloud resources | AWS IAM, Azure AD, Okta | Preventing unauthorized access |
| Encryption | Protects data at rest/in transit | AWS KMS, TLS 1.3, Azure Disk Encryption | Confidentiality (e.g., bank records) |
| Network Security | Isolates resources, filters traffic | AWS Security Groups, Azure NSGs, Firewalls | DDoS protection, segmenting VPCs |
| Zero Trust Architecture | "Never trust, always verify" model | BeyondTrust, Google BeyondCorp | High-security environments (govt, healthcare) |
| Data Loss Prevention (DLP) | Blocks sensitive data leaks | Microsoft Purview, Symantec DLP | Compliance (GDPR, HIPAA) |
| Key Management | Securely stores and rotates encryption keys | AWS CloudHSM, HashiCorp Vault | Enterprise-grade encryption |
A. Identity & Access Management (IAM)
Core Principle: Least Privilege (give users only the permissions they need). Example:
- eSewa’s IAM Policy:
- Payment processors can only access
/paymentsAPI. - Customer support can only read
/user-profile(no write access). - Admins get temporary elevated access via AWS IAM Roles.
- Payment processors can only access
Visual: IAM Policy Structure (AWS Example)
Common Mistakes:
- Using root account for daily tasks (❌).
- Assigning
*permissions to users (❌). - Not rotating keys (❌).
B. Encryption: At Rest vs. In Transit
| Type | What It Protects | Example Tools | Real-World Use Case |
|---|---|---|---|
| At Rest | Data stored on disks/databases | AWS EBS Encryption, Azure SQL TDE | Nepal Rastra Bank encrypts customer transaction logs. |
| In Transit | Data moving between systems | TLS 1.3, IPsec, SSH | Khalti uses TLS to secure payment gateways. |
| Key Management | Protects encryption keys | AWS KMS, HashiCorp Vault | Google Cloud uses HSMs for Gmail encryption. |
Worked Example: Encrypting a Database in AWS
- Enable encryption at rest for the RDS instance.
- Use AWS KMS to generate a customer-managed key (CMK).
- Rotate keys every 90 days (automated via AWS Key Rotation).
- Enable TLS 1.3 for all database connections.
Visual: Encryption Layers in a Cloud App
graph LR
A["User"] -->|"HTTPS (TLS)"| B["Load Balancer"]
B -->|"Internal TLS"| C["App Server"]
C -->|"Encrypted DB Connection"| D["RDS Database<br/>(Encrypted at rest)"]
D -->|"KMS"| E["Key Management Service"]
Data is encrypted:
- In transit (TLS)
- At rest (AES-256)
- Keys protected by KMS
end noteC. Zero Trust: "Never Trust, Always Verify"
Why Zero Trust? Traditional security assumes everything inside the network is safe. Zero Trust assumes breach and verifies every request.
Example:
- Google BeyondCorp: Employees access apps without VPNs. Every request is authenticated via identity tokens.
- Nepal’s NTC: Uses Zero Trust to secure its core routing infrastructure, preventing insider attacks.
Visual: Zero Trust Architecture
sequenceDiagram
participant User
participant IdentityProvider
participant App
participant Resource
User->>IdentityProvider: "Authenticate\n(MFA, Biometrics)"
IdentityProvider-->>User: "JWT Token"
User->>App: "Request Resource\n(Attaches JWT)"
App->>IdentityProvider: "Validate Token"
alt Valid
IdentityProvider-->>App: "Allow"
App->>Resource: "Grant Access"
else Invalid
IdentityProvider-->>App: "Deny"
endKey Components:
- Identity Verification: MFA, biometrics, certificates.
- Device Trust: Check if the device is compliant (e.g., has antivirus).
- Micro-Segmentation: Isolate resources (e.g., AWS VPC).
3. Compliance & Standards: What You Must Know
Cloud providers must meet industry standards. Here are the top 3 frameworks for Nepalese students:
| Framework | What It Covers | Who Needs It? | Example in Nepal |
|---|---|---|---|
| ISO 27001 | Information Security Management System (ISMS) | Banks, healthcare, government | Nepal Rastra Bank (NRB) compliance |
| GDPR | Data protection (EU standard) | Companies handling EU citizen data | Daraz (stores EU customer data) |
| PCI DSS | Payment Card Industry security | E-commerce, fintech | eSewa, Khalti |
Worked Example: GDPR Compliance for a Nepalese App
- Data Minimization: Only collect phone number + email (no SSN).
- User Consent: Show a clear privacy policy (like Pathao’s).
- Right to Erasure: Allow users to delete their data (e.g., via API call).
- Data Localization: Store EU user data in AWS Frankfurt (not Nepal).
Visual: GDPR Compliance Checklist
mindmap
root((GDPR Compliance))
Lawful Basis
Consent
Contract
Legal Obligation
Data Subject Rights
Access
Rectification
Erasure
Data Portability
Data Protection Impact Assessment (DPIA)
Data Breach Notification
International Data Transfers4. Real-World Case Study: The Ncell Data Leak (2022)
What Happened?
- Attack Vector: Misconfigured MongoDB database (no authentication).
- Impact: 10 million records exposed (names, phone numbers, SIM details).
- Root Cause:
- Default credentials were not changed.
- No encryption at rest.
- No IAM least privilege (anyone could access the DB).
How Ncell Fixed It:
- Patched the database (enabled authentication).
- Encrypted all customer data (AES-256).
- Implemented AWS GuardDuty to detect future breaches.
- Trained employees on secure coding (OWASP Top 10).
Lesson:
- Default settings = Security holes.
- Assume breach (Zero Trust mindset).
- Automate security (e.g., AWS Config for compliance checks).
In the Real World
eSewa & Khalti (Nepal)
- Use Case: Tokenization (replacing card numbers with tokens).
- How It Works: When you pay via eSewa, your card details are never stored. Instead, a one-time token is generated and used for the transaction.
- Security Benefit: Even if the database is breached, card numbers are useless.
Nepal Rastra Bank (NRB)
- Use Case: Multi-Factor Authentication (MFA) for online banking.
- How It Works: After entering a password, users must enter an OTP sent via SMS (or use a hardware token).
- Why It Matters: Prevents credential stuffing attacks (where hackers use leaked passwords).
Daraz (Nepal’s Amazon)
- Use Case: DDoS Protection during Black Friday sales.
- How It Works: Uses Cloudflare to absorb attack traffic and AWS Shield to auto-scale defenses.
- Real Impact: In 2021, Daraz withstood a 500 Gbps DDoS attack without downtime.
NTC & Ncell (Telecom Security)
- Use Case: Network Segmentation to isolate core routing.
- How It Works: NTC uses AWS VPC to separate customer data from billing systems.
- Why It’s Critical: Prevents a breach in one system from spreading to others.
Exam Tip
What Examiners Look For
Definitions & Concepts (30%)
- Know the difference between shared responsibility model, IAM, and Zero Trust.
- Example question: "Explain how AWS and Azure divide security responsibilities. Give one real-world example where a company was breached due to misconfigured IAM."
Scenario-Based Questions (40%)
- You’ll be given a real-world scenario (e.g., "A bank’s cloud database is leaking customer data"). You must:
- Identify the threat (e.g., misconfigured S3 bucket).
- Suggest 3 fixes (e.g., enable encryption, revoke public access, enable CloudTrail).
- Example:
"Pathao’s app is under a DDoS attack. How would you mitigate it using AWS services?"
Answer:
- Use AWS Shield Advanced for DDoS protection.
- Deploy CloudFront to distribute traffic.
- Enable AWS WAF to block malicious requests.
- You’ll be given a real-world scenario (e.g., "A bank’s cloud database is leaking customer data"). You must:
Comparison Tables (20%)
- Expect questions like: "Compare encryption at rest vs. in transit. Which one is used by Khalti, and why?"
- Always draw a diagram (e.g., the encryption layers figure above).
Case Study Analysis (10%)
- You may be asked to analyze a breach (e.g., Ncell 2022) and explain:
- How it happened (misconfigured DB).
- How to prevent it (IAM, encryption, auditing).
- You may be asked to analyze a breach (e.g., Ncell 2022) and explain:
How to Score Full Marks
✅ Use real-world examples (e.g., eSewa, Ncell, Daraz). ✅ Draw diagrams for complex topics (e.g., Zero Trust flow, encryption layers). ✅ Link theory to Nepalese context (e.g., "NRB follows ISO 27001 because..."). ✅ For numerical questions (e.g., calculating encryption overhead), show step-by-step math.
Final Checklist Before the Exam
- Can I explain the shared responsibility model with an example?
- Do I know 3 cloud-specific threats and their fixes?
- Can I draw a Zero Trust architecture diagram?
- Do I understand GDPR vs. PCI DSS with a Nepalese use case?
- Can I analyze a real breach (e.g., Ncell) and suggest fixes?
Based on the PU BE Computer (PU) syllabus for Cloud Computing and Virtualization (CMP424), unit 9.
Discussion
Loading…