CMP424 Cloud Computing and Virtualization

Cloud Computing and VirtualizationUnit 915 min read

Cloud Security: Threats, Controls, Compliance & Real-World Cases

Unit 9 of Cloud Computing and Virtualization explores cloud-specific security threats (DDoS, data leaks, insider attacks), defense mechanisms (encryption, IAM, zero trust), compliance frameworks (ISO 27001, GDPR), and real-world breaches like the 2022 Ncell data leak. Learn how companies like eSewa and banks secure tra

Cloud Security Fundamentals: Why Cloud is Different

Cloud security is not just "IT security in the cloud." The shared responsibility model (see figure below) means you control some risks while the cloud provider controls others. For example:

  • Your responsibility: Configuring IAM roles, encrypting data at rest, patching VMs.
  • Provider’s responsibility: Physical security of data centers, hypervisor hardening, network isolation.
stateDiagram-v2
    [*] --> Shared: "Customer"
    Shared --> Customer: "Data, Config, Apps, OS, Middleware"
    Shared --> Provider: "Runtime, Hypervisor, Network, Physical"
    Provider --> [*]
    note right of Shared
        Shared Responsibility Model
        (AWS/Azure/GCP example)
    end note

Real-world example: When eSewa migrated its payment gateway to AWS, it retained control over API keys and customer data encryption (its responsibility) while relying on AWS’s DDoS protection (provider’s responsibility). The 2021 eSewa breach occurred because customer-side credentials were leaked—not AWS’s fault.


1. Cloud-Specific Threats: What’s Unique to Cloud?

Cloud introduces new attack surfaces that don’t exist in on-premises systems. Here are the top 3 threats with real-world examples:

A. Data Breaches & Leakage

How it happens:

  • Misconfigured storage buckets (e.g., S3 buckets with public permissions).
  • Weak encryption keys (e.g., using default keys or storing them in plaintext).
  • Insider threats (e.g., employees accessing data they shouldn’t).

Example:

  • Ncell (2022): A misconfigured database exposed 10 million customer records (names, phone numbers, SIM details). The attacker exploited default credentials left unchanged by Ncell’s IT team.
  • Daraz (2021): A third-party vendor’s unencrypted database was hacked, leaking user payment details during checkout.

Visual: How a misconfigured S3 bucket becomes a breach

Uploads 'confidential.pdf' (Public ACL)Finds via Google searchDownloads 'confidential.pdf'UserAttackerS3Bucket
Misconfigured S3 bucket breach flow (no authentication required)

Prevention:

  • Encryption: Use AWS KMS or Azure Key Vault for key management.
  • Access Control: Apply least privilege (e.g., IAM roles with minimal permissions).
  • Audit Logs: Enable AWS CloudTrail or Azure Monitor to detect unauthorized access.

B. Distributed Denial-of-Service (DDoS) Attacks

How it works: Attackers flood cloud services (e.g., APIs, databases) with traffic to crash them. Cloud providers are primary targets because they host high-traffic services.

Example:

  • Nepal’s NTC (2020): During COVID-19, hackers launched a DDoS attack on NTC’s website, disrupting internet services for hours. The attack used botnets (zombie devices) to overwhelm NTC’s servers.
  • Google (2017): A 2.54 Tbps DDoS attack (largest ever recorded) targeted Google’s infrastructure. The attackers exploited misconfigured DNS servers.

Visual: DDoS Attack Flow

graph LR
    A["Attacker"] -->|"Botnet"| B["Zombie Devices<br/>(Infects IoT, PCs)"]
    B -->|"Flood Traffic"| C["Cloud Service<br/>(e.g., NTC Website)"]
    C -->|"Overload"| D["Service Crash<br/>(Downtime for users)"]

Prevention:

  • Cloud Provider Tools:
    • AWS Shield (free tier protects against most attacks).
    • Azure DDoS Protection (auto-scales to absorb attacks).
  • Rate Limiting: Use API Gateway to throttle requests.
  • Anycast Routing: Distribute traffic across multiple data centers (used by Cloudflare).

C. Insider Threats & Account Hijacking

How it happens:

  • Credential theft (phishing, keyloggers).
  • Privilege escalation (e.g., an admin granting themselves excessive permissions).
  • Malicious insiders (e.g., employees selling data).
Privilege EscalationUnauthorized AccessIAM MisconfigurationAdminMalicious InsiderCloud ProviderCustomer Data
Insider threat attack path in cloud environments

Example:

  • WhatsApp (2019): Hackers used NSO Group’s Pegasus spyware to hijack accounts of journalists and activists. The attack exploited zero-day vulnerabilities in WhatsApp’s cloud messaging service.
  • Khalti (2020): An internal employee leaked merchant API keys, allowing attackers to siphon NPR 50 million from business accounts.

Prevention:

  • Multi-Factor Authentication (MFA): Enforce TOTP or hardware keys (e.g., YubiKey).
  • Just-In-Time (JIT) Access: Grant permissions temporarily (e.g., AWS IAM Access Analyzer).
  • Behavioral Analytics: Use Microsoft Defender for Cloud to detect anomalous logins.

2. Cloud Security Controls: How to Defend

Cloud security relies on layers of defense. Below is a comparison table of key controls:

Control What It Does Example Tools Best For
Identity & Access Mgmt (IAM) Controls who/what can access cloud resources AWS IAM, Azure AD, Okta Preventing unauthorized access
Encryption Protects data at rest/in transit AWS KMS, TLS 1.3, Azure Disk Encryption Confidentiality (e.g., bank records)
Network Security Isolates resources, filters traffic AWS Security Groups, Azure NSGs, Firewalls DDoS protection, segmenting VPCs
Zero Trust Architecture "Never trust, always verify" model BeyondTrust, Google BeyondCorp High-security environments (govt, healthcare)
Data Loss Prevention (DLP) Blocks sensitive data leaks Microsoft Purview, Symantec DLP Compliance (GDPR, HIPAA)
Key Management Securely stores and rotates encryption keys AWS CloudHSM, HashiCorp Vault Enterprise-grade encryption

A. Identity & Access Management (IAM)

Core Principle: Least Privilege (give users only the permissions they need). Example:

  • eSewa’s IAM Policy:
    • Payment processors can only access /payments API.
    • Customer support can only read /user-profile (no write access).
    • Admins get temporary elevated access via AWS IAM Roles.

Visual: IAM Policy Structure (AWS Example)

Effect: Allow/DenyAction: [s3:GetObject]Resource: [arn:aws:s3:::esewa-bucket/*]PolicyGroupUser
AWS IAM Policy Hierarchy (User → Group → Policy)

Common Mistakes:

  • Using root account for daily tasks (❌).
  • Assigning * permissions to users (❌).
  • Not rotating keys (❌).

B. Encryption: At Rest vs. In Transit

Type What It Protects Example Tools Real-World Use Case
At Rest Data stored on disks/databases AWS EBS Encryption, Azure SQL TDE Nepal Rastra Bank encrypts customer transaction logs.
In Transit Data moving between systems TLS 1.3, IPsec, SSH Khalti uses TLS to secure payment gateways.
Key Management Protects encryption keys AWS KMS, HashiCorp Vault Google Cloud uses HSMs for Gmail encryption.

Worked Example: Encrypting a Database in AWS

  1. Enable encryption at rest for the RDS instance.
  2. Use AWS KMS to generate a customer-managed key (CMK).
  3. Rotate keys every 90 days (automated via AWS Key Rotation).
  4. Enable TLS 1.3 for all database connections.

Visual: Encryption Layers in a Cloud App

graph LR
    A["User"] -->|"HTTPS (TLS)"| B["Load Balancer"]
    B -->|"Internal TLS"| C["App Server"]
    C -->|"Encrypted DB Connection"| D["RDS Database<br/>(Encrypted at rest)"]
    D -->|"KMS"| E["Key Management Service"]
        Data is encrypted:
        - In transit (TLS)
        - At rest (AES-256)
        - Keys protected by KMS
    end note

C. Zero Trust: "Never Trust, Always Verify"

Why Zero Trust? Traditional security assumes everything inside the network is safe. Zero Trust assumes breach and verifies every request.

Example:

  • Google BeyondCorp: Employees access apps without VPNs. Every request is authenticated via identity tokens.
  • Nepal’s NTC: Uses Zero Trust to secure its core routing infrastructure, preventing insider attacks.

Visual: Zero Trust Architecture

sequenceDiagram
    participant User
    participant IdentityProvider
    participant App
    participant Resource
    User->>IdentityProvider: "Authenticate\n(MFA, Biometrics)"
    IdentityProvider-->>User: "JWT Token"
    User->>App: "Request Resource\n(Attaches JWT)"
    App->>IdentityProvider: "Validate Token"
    alt Valid
        IdentityProvider-->>App: "Allow"
        App->>Resource: "Grant Access"
    else Invalid
        IdentityProvider-->>App: "Deny"
    end

Key Components:

  1. Identity Verification: MFA, biometrics, certificates.
  2. Device Trust: Check if the device is compliant (e.g., has antivirus).
  3. Micro-Segmentation: Isolate resources (e.g., AWS VPC).

3. Compliance & Standards: What You Must Know

Cloud providers must meet industry standards. Here are the top 3 frameworks for Nepalese students:

Framework What It Covers Who Needs It? Example in Nepal
ISO 27001 Information Security Management System (ISMS) Banks, healthcare, government Nepal Rastra Bank (NRB) compliance
GDPR Data protection (EU standard) Companies handling EU citizen data Daraz (stores EU customer data)
PCI DSS Payment Card Industry security E-commerce, fintech eSewa, Khalti

Worked Example: GDPR Compliance for a Nepalese App

  1. Data Minimization: Only collect phone number + email (no SSN).
  2. User Consent: Show a clear privacy policy (like Pathao’s).
  3. Right to Erasure: Allow users to delete their data (e.g., via API call).
  4. Data Localization: Store EU user data in AWS Frankfurt (not Nepal).

Visual: GDPR Compliance Checklist

mindmap
  root((GDPR Compliance))
    Lawful Basis
      Consent
      Contract
      Legal Obligation
    Data Subject Rights
      Access
      Rectification
      Erasure
      Data Portability
    Data Protection Impact Assessment (DPIA)
    Data Breach Notification
    International Data Transfers

4. Real-World Case Study: The Ncell Data Leak (2022)

What Happened?

  • Attack Vector: Misconfigured MongoDB database (no authentication).
  • Impact: 10 million records exposed (names, phone numbers, SIM details).
  • Root Cause:
    • Default credentials were not changed.
    • No encryption at rest.
    • No IAM least privilege (anyone could access the DB).
2022-03-15Database exposedvia public S3 bucket2022-03-16Attacker findsbucket via Google sear2022-03-17Ncell confirmsbreach (10M records)2022-04-01Regulatory finesissued (NTA)
Ncell breach timeline with mitigation delays

How Ncell Fixed It:

  1. Patched the database (enabled authentication).
  2. Encrypted all customer data (AES-256).
  3. Implemented AWS GuardDuty to detect future breaches.
  4. Trained employees on secure coding (OWASP Top 10).

Lesson:

  • Default settings = Security holes.
  • Assume breach (Zero Trust mindset).
  • Automate security (e.g., AWS Config for compliance checks).

In the Real World

  1. eSewa & Khalti (Nepal)

    • Use Case: Tokenization (replacing card numbers with tokens).
    • How It Works: When you pay via eSewa, your card details are never stored. Instead, a one-time token is generated and used for the transaction.
    • Security Benefit: Even if the database is breached, card numbers are useless.
  2. Nepal Rastra Bank (NRB)

    • Use Case: Multi-Factor Authentication (MFA) for online banking.
    • How It Works: After entering a password, users must enter an OTP sent via SMS (or use a hardware token).
    • Why It Matters: Prevents credential stuffing attacks (where hackers use leaked passwords).
  3. Daraz (Nepal’s Amazon)

    • Use Case: DDoS Protection during Black Friday sales.
    • How It Works: Uses Cloudflare to absorb attack traffic and AWS Shield to auto-scale defenses.
    • Real Impact: In 2021, Daraz withstood a 500 Gbps DDoS attack without downtime.
  4. NTC & Ncell (Telecom Security)

    • Use Case: Network Segmentation to isolate core routing.
    • How It Works: NTC uses AWS VPC to separate customer data from billing systems.
    • Why It’s Critical: Prevents a breach in one system from spreading to others.

Exam Tip

What Examiners Look For

  1. Definitions & Concepts (30%)

    • Know the difference between shared responsibility model, IAM, and Zero Trust.
    • Example question: "Explain how AWS and Azure divide security responsibilities. Give one real-world example where a company was breached due to misconfigured IAM."
  2. Scenario-Based Questions (40%)

    • You’ll be given a real-world scenario (e.g., "A bank’s cloud database is leaking customer data"). You must:
      • Identify the threat (e.g., misconfigured S3 bucket).
      • Suggest 3 fixes (e.g., enable encryption, revoke public access, enable CloudTrail).
    • Example: "Pathao’s app is under a DDoS attack. How would you mitigate it using AWS services?" Answer:
      • Use AWS Shield Advanced for DDoS protection.
      • Deploy CloudFront to distribute traffic.
      • Enable AWS WAF to block malicious requests.
  3. Comparison Tables (20%)

    • Expect questions like: "Compare encryption at rest vs. in transit. Which one is used by Khalti, and why?"
    • Always draw a diagram (e.g., the encryption layers figure above).
  4. Case Study Analysis (10%)

    • You may be asked to analyze a breach (e.g., Ncell 2022) and explain:
      • How it happened (misconfigured DB).
      • How to prevent it (IAM, encryption, auditing).

How to Score Full Marks

✅ Use real-world examples (e.g., eSewa, Ncell, Daraz). ✅ Draw diagrams for complex topics (e.g., Zero Trust flow, encryption layers). ✅ Link theory to Nepalese context (e.g., "NRB follows ISO 27001 because..."). ✅ For numerical questions (e.g., calculating encryption overhead), show step-by-step math.


Final Checklist Before the Exam

  • Can I explain the shared responsibility model with an example?
  • Do I know 3 cloud-specific threats and their fixes?
  • Can I draw a Zero Trust architecture diagram?
  • Do I understand GDPR vs. PCI DSS with a Nepalese use case?
  • Can I analyze a real breach (e.g., Ncell) and suggest fixes?

Based on the PU BE Computer (PU) syllabus for Cloud Computing and Virtualization (CMP424), unit 9.

Discussion

Loading…