Source-linked AI summary

Survey on Security Issues in Cloud Computing and Associated Mitigation Techniques

Rohit Bhadauria, Sugata Sanyal

arXiv:1204.0764v2cs.CR

TL;DR

Cloud computing creates security and privacy challenges because data and services are distributed across remote, shared, and virtualized infrastructure. This survey analyzes these threats, secure-cloud characteristics, and mitigation techniques, concluding that security requires controls addressing data protection, auditing, provider practices, and service availability.

  • Problem

    Distributed cloud infrastructure, remote data centers, shared resources, and increasing deployment create unresolved security and privacy risks for users and organizations.

  • Method

    The paper surveys cloud security threats, secure-infrastructure characteristics, and proposed ways to address challenges across cloud environments.

  • Results

    The survey identifies threats involving data security, data lineage, service availability, application attacks, denial of service, and provider-related failures.

  • Takeaways & Limitations

    Cloud security requires attention to confidentiality and integrity, regular auditing, service-level compliance, and minimizing provider human errors.

  • Takeaways & Limitations

    Application-level threats can adapt to fixed security checks, making closed task-specific systems slower than open-ended systems.

Abstract

from arXiv · show

Cloud Computing holds the potential to eliminate the requirements for setting up of high-cost computing infrastructure for IT-based solutions and services that the industry uses. It promises to provide a flexible IT architecture, accessible through internet for lightweight portable devices. This would allow multi-fold increase in the capacity or capabilities of the existing and new software. In a cloud computing environment, the entire data reside over a set of networked resources, enabling the data to be accessed through virtual machines. Since these data-centers may lie in any corner of the world beyond the reach and control of users, there are multifarious security and privacy challenges that need to be understood and taken care of. Also, one can never deny the possibility of a server breakdown that has been witnessed, rather quite often in the recent times. There are various issues that need to be dealt with respect to security and privacy in a cloud computing scenario. This extensive survey paper aims to elaborate and analyze the numerous unresolved issues threatening the cloud computing adoption and diffusion affecting the various stake-holders linked to it.

1. INTRODUCTION

Cloud computing offers on-demand access to shared, scalable resources without requiring users to own infrastructure. Its adoption is driven by cost reductions, global accessibility, and flexibility.

  • Its adoption promises reduced hardware and maintenance costs, global accessibility, and flexible IT capabilities.
  • Cloud computing provides shared resources that can be rapidly provisioned and released with minimal management effort.
  • Users can access computing services worldwide without owning the underlying infrastructure.
  • Cloud computing supports scalability, multi-tenancy, dynamic resource allocation, and continuous performance monitoring.

2. CLOUD TAXONOMY, CHARACTERISTICS AND BENEFITS

Cloud computing is organized through service and deployment models built on virtualization and related web technologies. These models provide flexible, pay-per-use access while creating security and governance requirements.

  • Service models: IaaS provides infrastructure, PaaS provides application-hosting platforms, and SaaS provides complete applications on demand.
  • Service models: SaaS hosts applications online under a pay-per-use model, reducing local installation and software-maintenance requirements.
  • Service models: IaaS resources are virtualized, scalable, and shared, requiring governance to control virtual-machine creation and usage.
  • Deployment models: Clouds may be public, private, community, or hybrid, depending on ownership, management, and sharing arrangements.
  • Mobile cloud computing: Mobile cloud computing extends cloud services to mobile technologies but depends on evolving network access and mobile-device adoption.
  • Enabling technologies: Virtualization, service-oriented architecture, APIs, and mash-ups support cloud services and resource consolidation.
  • Security context: Cloud adoption also introduces security and privacy concerns because inexpensive distributed resources can facilitate attacks on confidential information.
  • Security context: Recommended protections include encryption and restricting service-provider access so providers can manage data without viewing its contents.

3. OBSTACLES AND OPPORTUNITIES FOR CLOUD COMPUTING

Cloud computing remains constrained by architectural vulnerabilities, security threats, performance variability, portability barriers, and dependence on reliable networks. These obstacles are especially pronounced in shared public and mobile-cloud environments.

  • Security and privacy: Cloud architecture contains loopholes that expose organizations to diverse security and privacy threats.
  • Security and privacy: Public clouds intensify security risks because users share virtual machines, monitors, middleware, and multi-tenant infrastructure.
  • Security and privacy: Mash-ups combine multiple web components, creating diverse security challenges and opportunities for eavesdropping.
  • Performance and latency: Virtual machines share CPUs and memory more effectively than network and disk I/O, producing uneven performance across instances.
  • Performance and latency: Latency increases through encryption, congestion, packet loss, windowing, and data movement across clouds.
  • Portability and interoperability: Lock-in can prevent migration because applications, data formats, programming languages, APIs, and infrastructure may depend on a provider.
  • Portability and interoperability: Open architectures, standard syntax, provider-independent components, and data portability are proposed to reduce migration barriers.
  • Portability and interoperability: Interoperability becomes necessary when organizations use multiple cloud platforms for different applications or integrated tasks.

4. DATA STORAGE AND SECURITY IN THE CLOUD

Cloud storage introduces risks of data modification, loss, leakage, remanence, and weak traceability across virtualized and shared environments. The paper discusses encryption, redundancy, trust, provenance, and lineage as responses to these risks.

  • Storage risks: Cloud storage has experienced data modification or loss from security breaches and human error despite provider safety claims.
  • Protection mechanisms: Traditional mechanisms may be unsuitable for virtualized cloud storage, motivating encryption, homomorphic verification, and trust-based methods.
  • Data protection: Data-in-transit protection requires current encryption and protocols that provide both confidentiality and integrity.
  • Data protection: Data-at-rest management is more constrained in SaaS and PaaS because data may be commingled and application vulnerabilities can bypass tagging.
  • Auditing and provenance: Data lineage and provenance are difficult in virtualized clouds because non-linear data flows complicate integrity auditing and computational verification.
  • Storage risks: Data remanence creates more severe security concerns in public clouds than in private-cloud offerings.
  • Reported incidents: Reported breaches and service disruptions illustrate that cloud platforms remain vulnerable to exposure and availability failures.
  • Storage risks: Redundant copies and explicit SLA provisions are recommended to address data loss caused by human or system errors.

5. THREATS TO SECURITY IN CLOUD COMPUTING

Cloud security requires more than classifying threats by service-delivery model. The paper emphasizes a holistic approach centered on multi-tenancy and isolation.

  • Multi-tenancy and isolation are chief security concerns in cloud environments.Addressing them is intended to give customers greater assurance than simply asking them to trust the cloud.
  • Existing surveys classify cloud threats according to service-delivery models.
  • A comprehensive cloud-security survey must consider multiple aspects beyond service-delivery models.

5.1 Basic Security

Basic cloud security spans SaaS threats and multiple protection layers. The section discusses injection, scripting, interception, and the need for security across access, privacy, network, physical, and application layers.

  • Web 2.0 security has become increasingly important as its user community expands.
  • SaaS and Web 2.0 environments face SQL injection, XSS, and man-in-the-middle attacks.SQL injection can expose databases, XSS injects malicious scripts into web content, and MITM attacks intercept conversations to inject information or learn transferred data.
  • XSS particularly affects dynamic websites because their content and services are generated dynamically.The passage distinguishes stored and reflected XSS as methods of injecting malicious code into pages displayed to users.
  • Cloud protection requires security for server access, internet access, databases, data privacy, programs, and multiple infrastructure layers.The listed layers include network, physical, and application security.

5.2 Network Level Security

Network-level cloud security differs between public and private environments and must address access control, data protection, routing, interception, address reuse, and prefix hijacking. Public-cloud exposure increases the risk of leakage and cross-customer access.

  • Public clouds are more vulnerable than private clouds and require confidentiality, integrity, access controls, and stronger encryption measures.Migrating resources to the internet can increase exposure to leakage or breaches, while outdated cloud policies may permit cross-customer data access.
  • Network-level threats include DNS attacks, sniffing, reused IP addresses, DoS, and DDoS attacks.
  • DNSSEC can reduce DNS threats, but malicious rerouting may still create security problems between senders and receivers.
  • Reused IP addresses can expose a previous user’s data because DNS caches may retain stale address information.A delay between DNS changes and cache clearing can allow another user to access data associated with the earlier address.
  • Prefix hijacking can redirect traffic to unintended destinations, causing data leakage.The attack involves incorrect IP announcements by an autonomous system using the BGP model.

5.3 Application Level Security

Application-level security must address impersonation, adaptive threats, virtualization risks, and service-disruption attacks. The section presents stronger security checks, adaptive platforms, monitoring, and intrusion-detection cooperation as responses.

  • Attackers may imitate trusted users and corrupt data without being noticed.
  • Closed, task-oriented security systems can be slower than open-ended systems against dynamic and adaptable application threats.
  • Hypervisors control guest systems, so compromise can affect guest operating systems and data across shared physical infrastructure.A malicious guest may attack the host, while hypervisor control can expose data passing through guest systems.
  • Monitoring guest virtual machines and communication among infrastructure components supports cloud protection against hypervisor attacks.
  • DoS attacks flood service providers with requests, making services unavailable and increasing bandwidth consumption and congestion.Intrusion detection systems can cooperate across clouds by exchanging information and alerting the wider system.
  • Cookie forgery can impersonate authorized users, while cleanup or cookie-data encryption can reduce this risk.

5.3.4 Hidden Field Manipulation

The section surveys application and network attacks affecting cloud services, including hidden-field manipulation, debug-option exposure, DDoS, CAPTCHA breaking, and brute-force attacks, alongside proposed mitigations.

  • Hidden Field Manipulation: Hidden fields can be modified by attackers, causing severe security violations.
  • Hidden Field Manipulation: Leaving website debug options enabled can provide hackers back-end access to alter the site.
  • DDoS Attacks: DDoS attacks use compromised networks to flood servers, making services unavailable to authorized users.
  • DDoS Attacks: Proposed DDoS defenses include swarm-based logic, virtual-machine intrusion detection, and SNORT-like monitoring.
  • CAPTCHA Breaking: CAPTCHAs deter automated abuse, but audio and speech-to-text systems have enabled attackers to bypass them.
  • Brute-Force Attacks: Challenge-response protocols slow dictionary and brute-force attacks by requiring time-consuming response computation.

5.3.9 Google Hacking

The section presents Google hacking and related application-security concerns, emphasizing provider controls, standard web protections, isolation, authentication, backup, and policy maintenance.

  • Google Hacking: Google hacking uses search engines to locate sensitive information and security loopholes that can support attacks.
  • Service Models: Application security should be assessed across IaaS, PaaS, and SaaS because application-level attacks can cause system downtime.
  • Security Controls: Standard web-security measures are recommended, while custom authorization and authentication schemes require proper testing before deployment.
  • Security Controls: Continuous Data Protection backups can support data recovery after a sudden attack.
  • IaaS Security: IaaS assessments include securing virtual network infrastructure, identity and access management, and multifactor authentication.
  • PaaS Security: PaaS providers should isolate applications so one customer cannot access another customer's data.
  • Provider Security: Cloud providers should regularly review and update security policies and ensure that revised policies are implemented.
  • Service Models: Because SaaS security controls remain with the provider, the same security concerns apply to SaaS environments.

6. SECURITY ISSUES IN THE CLOUD DEPLOYMENT MODELS

Cloud deployment models have distinct security responsibilities and risks: public clouds raise concerns about control, multi-tenancy, third parties, and insiders, while private and hybrid clouds retain virtualization and organizational risks.

  • Deployment Models: Public, private, and hybrid deployments each have advantages and limitations requiring model-specific security strategies.
  • Public Cloud: Public clouds place infrastructure security with the provider while multiple customers share the platform.
  • Public Cloud: Public-cloud data requires confidentiality, integrity, and availability throughout its lifecycle despite limited control over provider practices.
  • Public Cloud: Multi-tenant public infrastructure creates risks of data leakage between customers, requiring careful provider investigation.
  • Public Cloud: Third-party cloud vendors require service-level agreements and contingency plans addressing system breakdowns.
  • Public Cloud: Security requirements and penalties should be specified in SLAs, including encryption requirements for data sent over the internet.
  • Public Cloud: Cloud adoption expands the insider circle to provider staff and subcontractors, motivating client-provider access-control policies.
  • Private Cloud: Private-cloud virtualization requires analysis of hypervisor risks, guest-to-guest communication, host malware, and web-interface vulnerabilities.

7. ENSURING SECURITY AGAINST THE VARIOUS TYPES OF ATTACKS

The section reviews defenses against common cloud attacks and proposes layered monitoring, filtering, authentication, encryption, and a generic framework capable of operating across cloud environments.

  • Attack Mitigation: Existing cloud security schemes address SQL injection, XSS, DoS, DDoS, Google hacking, and forced hacking through validation, filtering, and safer coding practices.
  • Generic Framework: A generic security framework should optimize cost-performance while supporting different cloud environments and predefined or customized policies.
  • Web Security: Multi-layer security and URL filtering are used to block malware and harmful or undesirable web pages.
  • Web Security: The adaptable web-security architecture is described as protecting against new and converging malware threats.
  • Authentication: AWS multifactor authentication requires a six-digit single-use code in addition to username and password.
  • Google Hacking: Google-hacking prevention includes vulnerability scanning and avoiding disclosure of sensitive information to Google.
  • Network Attacks: Monitoring can help control bandwidth-consuming DoS and DDoS attacks, while encryption, key exchange, IPSec, and packet filtering reduce spoofing risks.
  • Comparative Analysis: A comparative analysis of existing security schemes is presented in Table 1.

8. CONCLUSION

Cloud adoption is expanding across organizations, but security threats remain across network and application layers. The paper surveys security concerns in core cloud services and discusses measures to prevent them.

  • 8. CONCLUSION: Organizations are increasingly moving services and applications to cloud platforms, including CRM and automotive content delivery.Examples include Schneider Electric’s Salesforce CRM implementation and Toyota’s collaboration with Microsoft Azure.
  • 8. CONCLUSION: Cloud environments face security threats ranging from the network level to the application level.The paper identifies cloud security as a continuing concern despite the broader transformation brought by cloud computing.
  • 8. CONCLUSION: Protecting cloud data requires attention to confidentiality and integrity when selecting storage services.The paper also emphasizes regular auditing to protect against external threats.
  • 8. CONCLUSION: Cloud service providers must meet service-level agreements and minimize human errors to support smooth functioning.These provider responsibilities are presented alongside broader security controls.
  • 8. CONCLUSION: The paper examines security concerns across the three basic cloud services and discusses solutions intended to prevent them.This frames the survey around both threat analysis and mitigation techniques.
Loading 1204.0764v2…