0% found this document useful (0 votes)
4 views35 pages

Unit IV CC (R-23)

This document discusses the challenges of cloud computing, including economic factors, interoperability, scalability, fault tolerance, energy efficiency, and security. It emphasizes the importance of addressing these challenges for successful cloud adoption and management, particularly focusing on cost savings, vendor lock-in issues, and the need for industry standards. Additionally, it highlights the significance of energy-efficient practices in cloud data centers to reduce operational costs and environmental impact.

Uploaded by

devichikkala32
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views35 pages

Unit IV CC (R-23)

This document discusses the challenges of cloud computing, including economic factors, interoperability, scalability, fault tolerance, energy efficiency, and security. It emphasizes the importance of addressing these challenges for successful cloud adoption and management, particularly focusing on cost savings, vendor lock-in issues, and the need for industry standards. Additionally, it highlights the significance of energy-efficient practices in cloud data centers to reduce operational costs and environmental impact.

Uploaded by

devichikkala32
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

CLOUD COMPUTING UNIT – IV R – 23

Syllabus

Cloud computing challenges: Economics of the cloud, cloud interoperability and standards,
scalability and fault tolerance, energy efficiency in clouds, federated clouds, cloud computing
security, fundamentals of computer security, cloud security architecture, cloud shared
responsibility model, security in cloud deployment models.

Department of CSE Cloud computing challenges Page 2


CLOUD COMPUTING UNIT – IV R – 23

LEARNING MATERIAL
4.0 INTRODUCTION
Cloud computing, while offering unprecedented agility, scalability, and cost efficiency, presents a
corresponding set of complex challenges that must be addressed for successful adoption and
management. Beyond the foundational benefits, organizations must carefully navigate issues
spanning economics, technical interoperability, operational efficiency, and, most critically,
security. This unit introduces the primary hurdles of cloud deployment, focusing on the economic
realities and the necessity of industry standards to ensure seamless integration across diverse
platforms. Furthermore, it establishes a comprehensive framework for understanding and
mitigating cloud security risks, detailing the fundamental concepts of computer security, the
specific architecture required for cloud environments, and the crucial delineation of
responsibilities through the Cloud Shared Responsibility Model. Addressing these challenges,
particularly concerning scalability, fault tolerance, and energy efficiency, is vital for realizing the
full potential of federated and public cloud services.
4.1.1 Economics of the cloud: The main drivers of cloud computing are economy of scale and
simplicity of software delivery and its operation. In fact, the biggest benefit of this phenomenon is
financial: the pay-as-you-go model offered by cloud providers. In particular, cloud computing
allows:
Reducing the capital costs associated to the IT infrastructure
Eliminating
 the depreciation or lifetime costs associated with IT capital assets
Replacing
 software licensing with subscriptions
Cutting
 the maintenance and administrative costs of IT resources

A capita l cost is the cost occurred in purchasing an asset that is useful in the production of goods
or the rendering of services. Capital costs are one-time expenses that are generally paid up front
and that will contribute over the long term to generate profit. The IT infrastructure and the
software are capital assets because enterprises require them to conduct their business. At present it
does not matter whether the principal business of an enterprise is related to IT, because the
business will definitely have an IT department that is used to automate many of the activities that
are per formed within the enterprise: payroll, customer relationship management, enterprise
resource planning, tracking and inventory of products, and others. Hence, IT resources constitute a
capital cost for any kind of enterprise. It is good practice to try to keep capital costs low because
they introduce expenses that will generate profit over time; more than that, since they are
associated with material things they are subject to depreciation over time, which in the end
reduces the profit of the enterprise because such costs are directly subtracted from the enterprise
revenues. In the case of IT capital costs, the depreciation costs are represented by the loss of value
of the hardware over time and the aging of software products that need to be replaced because
new features are required.
Before cloud computing diffused within the enterprise, the budget spent on IT infrastructure
and software constituted a significant expense for medium-sized and large enterprises. Many
enterprises own a small or medium-sized datacenter that introduces several operational costs in
terms of maintenance, electricity, and cooling. Additional operational costs are occurred in
maintaining an IT department and an IT support center. Moreover, other costs are triggered by the
purchase of potentially expensive software. With cloud computing these costs are significantly
reduced or simply disappear according to its penetration. One of the advantages introduced by the
cloud computing model is that it shifts the capital costs previously allocated to the purchase of
hardware and software into operational costs inducted by renting the infrastructure and paying
subscriptions for the use of software. These costs can be better controlled according to the
business needs and prosperity of the enterprise. Cloud computing also introduces reductions in

Department of CSE Cloud computing challenges Page 3


CLOUD COMPUTING UNIT – IV R – 23

administrative and maintenance costs. That is, there is no or limited need for having
administrative staff take care of the management of the cloud infrastructure. At the same time, the
cost of IT support staff is also reduced. When it comes to depreciation costs, they simply
disappear for the enterprise, since in a scenario where all the IT needs are served by the cloud
there are no IT capital assets that depreciate over time.
The amount of cost savings that cloud computing can introduce within an enterprise is related
to the specific scenario in which cloud services are used and how they contribute to generate a
profit for the enterprise. In the case of a small startup, it is possible to completely leverage the
cloud for many aspects, such as:
• IT infrastructure
• Software development
• CRM and ERP
In this case it is possible to completely eliminate capital costs because there are no initial IT
assets. The situation is completely different in the case of enterprises that already have a consider
able amount of IT assets. In this case, cloud computing, especially IaaS-based solutions, can help
manage unplanned capital costs that are generated by the needs of the enterprise in the short term.
In this case, by leveraging cloud computing, these costs can be turned into operational costs that
last as long as there is a need for them. For example, IT infrastructure leasing helps more
efficiently manage peak loads without inducing capital expenses. As soon as the increased load
does not justify the use of additional resources, these can be released and the costs associated with
them disappear. This is the most adopted model of cloud computing because many enterprises
already have IT facilities. Another option is to make a slow transition toward cloud-based
solutions while the capital IT assets get depreciated and need to be replaced. Between these two
cases there is a wide variety of scenarios in which cloud computing could be of help in generating
profits for enterprises.
Another important aspect is the elimination of some indirect costs that are generated by IT
assets, such as software licensing and support and carbon footprint emissions. With cloud
computing, an enterprise uses software applications on a subscription basis, and there is no need
for any licensing fee because the software providing the service remains the property of the
provider. Leveraging IaaS solutions allows room for datacenter consolidation that in the end could
result in a smaller carbon footprint. In some countries such as Australia, the carbon footprint
emissions are taxable, so by reducing or completely eliminating such emissions, enterprises can
pay less tax.
In terms of the pricing models introduced by cloud computing, we can distinguish three
different strategies that are adopted by the providers:
Tiered pricing: In this model, cloud services are offered in several tiers, each of which
 offers a fixed computing specification and SLA at a specific price per unit of time. This
model is used by Amazon for pricing the EC2 service, which makes available different
server configurations in terms of computing capacity (CPU type and speed, memory) that
have different costs per hour.
Per-unit pricing: This model is more suitable to cases where the principal source of
 revenue for the cloud provider is determined in terms of units of specific services, such as
data transfer and memory allocation. In this scenario customers can configure their
systems more efficiently according to the application needs. This model is used, for
example, by Go Grid, which makes customers pay according to RAM/hour units for the
servers deployed in the Go Grid cloud.
Subscription-based pricing: This is the model used mostly by SaaS providers in which
 users pay a periodic subscription fee for use of the software or the specific component
services that are integrated in their applications. All of these costs are based on a pay-as-

Department of CSE Cloud computing challenges Page 4


CLOUD COMPUTING UNIT – IV R – 23

you-go model, which constitutes a more flexible solution for supporting the delivery on
demand of IT services. This is what actually makes possible the conversion of IT capital
costs into operational costs, since the cost of buying hardware turns into a cost for leasing
it and the cost generated by the purchase of software turns into a subscription fee paid for
using it.
4.1.2 Cloud interoperability and standards:
Cloud computing is a service-based model for delivering IT infrastructure and applications like
utilities such as power, water, and electricity. To fully realize this goal, introducing standards and
allowing interoperability between solutions offered by different vendors are objectives of funda
mental importance. Vendor lock-in constitutes one of the major strategic barriers against the seam
less adoption of cloud computing at all stages. In particular there is major fear on the part of
enterprises in which IT constitutes the significant part of their revenues. Vendor lock-in can
prevent a customer from switching to another competitor’s solution, or when this is possible, it
happens at considerable conversion cost and requires significant amounts of time. This can occur
either because the customer wants to find a more suitable solution for customer needs or because
the vendor is no longer able to provide the required service. The presence of standards that are
actually implemented and adopted in the cloud computing community could give room for
interoperability and then lessen the risks resulting from vendor lock-in.
The current state of standards and interoperability in cloud computing resembles the early Internet
era, when there was no common agreement on the protocols and technologies used and each
organization had its own network. Yet the first steps toward a standardization process have been
made, and a few organizations, such as the Cloud Computing Interoperability Forum (CCIF) the
Open Cloud Consortium, and the DMTF Cloud Standards Incubator, are leading the path. Another
interesting initiative is the Open Cloud Manifesto, which embodies the point of view of various
stakeholders on the benefits of open standards in the field. The standardization efforts are mostly
concerned with the lower level of the cloud computing architecture, which is the most popular and
developed. In particular, in the IaaS market, the use of a proprietary virtual machine format
constitutes the major reasons for the vendor lock-in, and efforts to provide virtual machine image
compatibility between IaaS vendors can possibly improve the level of interoperability among
them. The Open Virtualization Format (OVF) is an attempt to provide a common format for
storing the information and metadata describing a virtual machine image. Even though the OVF
provides a full specification for packaging and distributing virtual machine images in completely
platform-independent fashion, it is supported by few vendors that use it to import static virtual
machine images. The challenge is providing standards for supporting the migration of running
instances, thus allowing the real ability of switching from one infrastructure vendor to another in a
completely transparent manner. Another direction in which standards try to move is devising
general reference architecture for cloud computing systems and providing a standard interface
through which one can interact with them. At the moment the compatibility between different
solutions is quite restricted, and the lack of a common set of APIs make the interaction with
cloud-based solutions vendor specific. In the IaaS market, Amazon Web Services plays a leading
role, and other IaaS solutions, mostly open source, provide AWS-compatible APIs, thus
constituting themselves as valid alternatives. Even in this case, there is no consistent trend in
devising some common APIs for interfacing with IaaS (and, in general, XaaS), and this constitutes
one of the areas in which a considerable improvement can be made in the future.
4.1.3 Scalability and fault tolerance:
The ability to scale on demand constitutes one of the most attractive features of cloud computing.
Clouds allow scaling beyond the limits of the existing in-house IT resources, whether they are
infrastructure (compute and storage) or applications services. To implement such a capability, the
cloud middleware has to be designed with the principle of scalability along different dimensions
in mind for example, performance, size, and load. The cloud middleware manages a huge number

Department of CSE Cloud computing challenges Page 5


CLOUD COMPUTING UNIT – IV R – 23

of resource and users, which rely on the cloud to obtain the horsepower that they cannot obtain
within the premises without bearing considerable administrative and maintenance costs. These
costs are a reality for whomever develops, manages, and maintains the cloud middleware and
offers the service to customers. In this scenario, the ability to tolerate failure becomes
fundamental, sometimes even more important than providing an extremely efficient and optimized
system. Hence, the challenge in this case is designing highly scalable and fault-tolerant systems
that are easy to manage and at the same time provide competitive performance.
4.1.4 Energy efficiency in clouds
Modern datacenters that operate under the cloud computing model are hosting a variety of
applications ranging from those that run for a few seconds (e.g., serving requests of Web
applications such as ecommerce and social network portals) to those that run for longer periods of
time (e.g., simulations or large dataset processing) on shared hardware platforms. The need to
manage multiple applications in a datacenter creates the challenge of on-demand resource
provisioning and allocation in response to time-varying workloads. Normally, datacenter
resources are statically allocated to applications based on peak load characteristics in order to
maintain isolation and provide performance guarantees. Until recently, high performance has been
the sole concern in datacenter deployments, and this demand has been fulfilled without paying
much attention to energy consumption. According to the McKinsey report on “Revolutionizing
Data Center Energy Efficiency”, a typical datacenter consumes as much energy as 25,000
households. Energy costs of powering a typical data center doubles every five years. Because
energy costs are increasing while availability dwindles, there is a need to shift focus from
optimizing datacenter resource management for pure performance alone to optimizing for energy
efficiency while maintaining high service-level performance.

Fig. 4.1 A Green cloud computing Scenario

Datacenters are not only expensive to maintain, they are also unfriendly to the environment.
Carbon emissions due to datacenters worldwide are now more than the emissions of both

Department of CSE Cloud computing challenges Page 6


CLOUD COMPUTING UNIT – IV R – 23

Argentina and the Netherlands. High energy costs and huge carbon footprints are incurred due to
the massive amount of electricity needed to power and cool the numerous servers hosted in these
datacenters. Cloud service providers need to adopt measures to ensure that their profit margins are
not dramatically reduced due to high energy costs. According to Amazon’s estimate, the energy
related costs of its datacenters amount to 42% of the total budget, which includes both direct
power consumption and the cooling infrastructure amortized over a 15-year period. As a result,
companies such as Google, Microsoft, and Yahoo! are building large datacenters in barren desert
land surrounding the Columbia River in the United States to exploit cheap hydroelectric power.
There is also increasing pressure from governments worldwide to reduce carbon footprints, which
have a significant impact on climate change. To address these concerns, leading IT vendors have
recently formed a global consortium, called The Green Grid, to promote energy efficiency for
datacenters and minimize their impact on the environment. Pike Research forecasts that datacenter
energy expenditures worldwide will reduce from $23.3 billion in 2010 to $16.0 billion in 2020, as
well as causing a 28% reduction in greenhouse gas (GHG) emissions from 2010 levels as a result
of the adoption of the cloud computing model for delivering IT services.
Lowering the energy usage of datacenters is a challenging and complex issue because
computing applications and data are growing so quickly that larger servers and disks are needed to
process them fast enough within the required time period. Green cloud computing is envisioned to
achieve not only efficient processing and utilization of computing infrastructure but also minimize
energy consumption. This is essential for ensuring that the future growth of cloud computing is
sustainable. Cloud computing, with increasingly pervasive front-end client devices such as
iPhones interacting with back-end datacenters, will cause an enormous escalation in energy usage.
To address this problem, datacenter resources need to be managed in an energy-efficient manner
to drive green cloud computing. In particular, cloud resources need to be allocated not only to
satisfy QoS requirements specified by users via service-level agreements (SLAs) but also to
reduce energy usage. This can be achieved by applying market-based utility models to accept user
requests that can be fulfilled to enhance revenue along with energy-efficient utilization of cloud
infrastructure.
[Link] Energy-efficient and green cloud computing architecture
A high-level architecture for supporting energy-efficient resource allocation in a green cloud
computing infrastructure is shown in Fig. 4.2. It consists of four main components:
• Consumers/brokers. Cloud consumers or their brokers submit service requests from
anywhere in the world to the cloud. It is important to note that there can be a difference
between cloud consumers and users of deployed services. For instance, a consumer can be
a company deploying a Web application, which presents varying workloads according to
the number of “users” accessing it.
 Green Resource Allocator. Acts as the interface between the cloud infrastructure and
consumers. It requires the interaction of the following components to support energy-
efficient resource management:
o Green Negotiator. Negotiates with the consumers/brokers to finalize the SLAs with
specified prices and penalties (for violations of SLAs) between the cloud provider
and the consumer, depending on the consumer’s QoS requirements and energy-
saving schemes. In Web applications, for instance, the QoS metric can be 95% of
requests being served in less than 3 seconds.
o Service Analyzer. Interprets and analyzes the service requirements of a submitted
request before deciding whether to accept or reject it. Hence, it needs the latest
load and energy information from VM Manager and Energy Monitor, respectively.
o Consumer Profiler. Gathers specific characteristics of consumers so that important
consumers can be granted special privileges and prioritized over other consumers.

Department of CSE Cloud computing challenges Page 7


CLOUD COMPUTING UNIT – IV R – 23

o Pricing. Decides how service requests are charged to manage the supply and
demand of computing resources and facilitate prioritizing service allocations
effectively.
o Energy Monitor. Observes and determines which physical machines to power on or
off.
o Service Scheduler. Assigns requests to VMs and determines resource entitlements
for allocated VMs. It also decides when VMs are to be added or removed to meet
demand.
o VM Manager. Keeps track of the availability of VMs and their resource
entitlements. It is also in charge of migrating VMs across physical machines.
o Accounting. Maintains the actual usage of resources by requests to compute usage
costs. Historical usage information can also be used to improve service allocation
decisions.

Fig. 4.2 Green cloud computing infrastructure


 VMs. Multiple VMs can be dynamically started and stopped on a single physical machine
to meet accepted requests, hence providing maximum flexibility to configure various
partitions of resources on the same physical machine to different specific requirements of
service requests. Multiple VMs can also run concurrently applications based on different
operating system environments on a single physical machine. In addition, by dynamically
migrating VMs across physical machines, workloads can be consolidated and unused
resources can be put on a low power state, turned off, or configured to operate at low
performance levels (e.g., using Dynamic Voltage and Frequency Scaling, or DVFS) to
save energy.
 Physical machines. The underlying physical computing servers provide hardware
infrastructure for creating virtualized resources to meet service demands.

Department of CSE Cloud computing challenges Page 8


CLOUD COMPUTING UNIT – IV R – 23

4.2 Federated clouds


This section address the problem from the administrative and organizational points of view Cloud
computing strongly implies the presence of financial agreements between parties, since services
are available on demand on a pay-per-use basis. Nonetheless, the concepts characterizing cloud
federation and the Inter Cloud are applicable, with some limitations, to building aggregations of
clouds that belong to different administrative domains
Cloud bus Toolkit Components and Technologies
Technology Description
Aneka Middleware for cloud applications development and deployment.
Middleware for scheduling distributed applications across
Broker
heterogeneous systems based on the bag-of-tasks model.
Workflow management Middleware for the execution, composition, management, and
system monitoring of workflows across heterogeneous systems.
Market Maker/Meta A matchmaker that matches the user’s requirements with service
Broker providers’ capabilities within the context of a marketplace.
A framework for the federation of independent computing
InterCloud
clouds.
Middleware that leverages storage clouds for intelligently
MetaCDN delivering users’ content based on their QoS and budget
preferences.
Energy-efficient Ongoing research on developing techniques and technologies for
computing addressing scalability and energy efficiency.

4.2.1 Characterization and definition


The terms cloud federation and InterCloud, often used interchangeably, convey the general
mean ing of an aggregation of cloud computing providers that have separate administrative
domains. It is important to clarify what these two terms mean and how they apply to cloud
computing.
The term federation implies the creation of an organization that supersedes the decisional and
administrative power of the single entities and that acts as a whole.8 Within a cloud computing
con text, the word federation does not have such a strong connotation but implies that there are
agreements between the various cloud providers, allowing them to leverage each other’s services
in a privileged manner. A definition of the term cloud federation was given by Reuven Cohen,
founder and CTO of Enomaly Inc.
Cloud federation manages consistency and access controls when two or more independent geo
graphically distinct Clouds share either authentication, files, computing resources, command and
control or access to storage resources.
This definition is broad enough to include all the different expressions of cloud services aggregations
that are governed by agreements between cloud providers, rather than composed by the user.
InterCloud is a term that is often used interchangeably to express the concept of Cloud federation. It
was introduced by Cisco for expressing a composition of clouds that are interconnected by

Department of CSE Cloud computing challenges Page 9


CLOUD COMPUTING UNIT – IV R – 23

means of open standards to provide a universal environment that leverages cloud computing
services. By mimicking the Internet term, often referred as the “network of networks,” InterCloud
represents a “Cloud of Clouds” and therefore expresses the same concept of federating together
clouds that belong to different administrative organizations. Whereas this is in many cases accept
able, some practitioners and experts like Ellen Rubin, founder and VP of Products at CloudSwitch
prefer to give different connotations to the two terms:
The primary difference between the InterCloud and federation is that the InterCloud is based
on future standards and open interfaces, while federation uses a vendor version of the control
plane. With the InterCloud vision, all Clouds will have a common understanding of how
applications should be deployed. Eventually workloads submitted to a Cloud will include
enough of a definition (resources, security, service level, geo-location, etc.) that the Cloud is
able to process the request and deploy the application. This will create the true utility model,
where all the require ments are met by the definition and the application can execute “as is”
in any Cloud with the resources to support it.
Therefore, the term InterCloud refers mostly to a global vision in which interoperability among
different cloud providers is governed by standards, thus creating an open platform where
applications can shift workloads and freely compose services from different sources. On the other
hand, the concept of a cloud federation is more general and includes ad hoc aggregations between
cloud providers on the basis of private agreements and proprietary interfaces.
4.2.2 Cloud federation stack:
Creating a cloud federation involves research and development at different levels: conceptual,
logical and operational, and infrastructural. Fig. 4.3 provides a comprehensive view of the
challenges faced in designing and implementing an organizational structure that coordinates
together cloud services that belong to different administrative domains and makes them operate
within a context of a single unified service middleware.

Fig.4.3 challenges at federation levels


Each cloud federation level presents different challenges and operates at a different layer of the IT
stack. It then requires the use of different approaches and technologies. Taken together, the
solutions to the challenges faced at each of these levels constitute a reference model for a cloud
federation.

Department of CSE Cloud computing challenges Page 10


CLOUD COMPUTING UNIT – IV R – 23

Conceptual level: The conceptual level addresses the challenges in presenting a cloud federation
as a favorable solution with respect to the use of services leased by single cloud providers. In this
level it is important to clearly identify the advantages for either service providers or service
consumers in joining a federation and to delineate the new opportunities that a federated
environment creates with respect to the single-provider solution. Elements of concern at this level
are:
 Motivations for cloud providers to join a federation
 Motivations for service consumers to leverage a federation
 Advantages for providers in leasing their services to other providers
 Obligations of providers once they have joined the federation
 Trust agreements between providers
 Transparency versus consumers
Among these aspects, the most relevant are the motivations of both service providers and
consumers in joining a federation. From the perspective of cloud service providers, being part of
federation is favorable if it helps increase their revenue and if it provides new opportunities to
increase their business. Moreover, the option of joining a federation can also be considered
convenient if it helps sustain the QoS ensured to customers in periods of peak load, which put
extreme demand on the infrastructure of the single provider. More precisely, it is possible to
identify functional and nonfunctional requirements that cloud service providers have behind these
motivations. The functional requirements include:
Supplying low-latency access to customers, regardless of their location. It is very unlikely
 that single cloud providers have a capillary distribution of their datacenters. Therefore,
services that require low latency might provide poor performance because of unfortunate
geo-location. Within this scenario the federation might help the single providers deliver
the same service and meet the expected QoS.
 Handling bursts in demand. Even though cloud computing gives the illusion of infinite
capacity and continuous availability, service providers rely on a finite IT infrastructure that
eventually will be fully utilized. A natural solution to this problem is increasing the
infrastructure by adding more capacity. For example, to keep up with the increasing
demand for storage and computation, Google has increased its number of servers from
8,000 to more than 450,000 in five years and moved from four server farms to more than
60 datacenters; Facebook has recently doubled its datacenter capacity. Such huge
provisions are affordable for large IT companies that can make appropriate forecasts about
increasing demand. Irregular demand can be better addressed by renting capacity from
other providers, since not every cloud provider is in the position of being an IT giant.
Cloud federation facilitates such activity by providing a context within which the lease of
resources or services is encouraged.
 Scaling existing applications and services beyond the capabilities of the owned
infrastructure. The need for additional capacity can also originate from the growth in scale
of existing applications that are temporarily hosted and do not constitute a vital part of the
service provider core business. Again, the opportunities for leasing additional services
from a federated provider can constitute a potential advantage for a cloud federation.
 Make revenue from unused capacity. To provide the illusion of continuous availability and
infinite capacity, cloud service providers generally own large computing systems, which
Department of CSE Cloud computing challenges Page 11
CLOUD COMPUTING UNIT – IV R – 23

generate costs in terms of maintenance and power consumption despite their real use. Energy
efficient computing solutions can help reduce costs and the impact of IT on the
environment. A different opportunity is given by the cloud federation, whereby providers
can lease their services to other providers for a limited period of time and thus make
revenue, even without direct customers.
The motivations for joining a cloud federation also include nonfunctional requirements. The most
relevant are the following:
 Meeting compulsory regulations about the location of data. Geo-location might become an
in issue that limits a provider’s capability to serve consumers. In this particular scenario it
is not lack of capacity on the provider side that is the reason for leveraging the federation
but, instead, the opportunity for identifying a provider that is in a position to deliver the
service to the customer because of the location of its datacenter. Geo-location of data
becomes an important matter when cloud services deal with confidential data that require
specific levels of secrecy. Different countries have different regulations with respect to, for
instance, the level of access to confidential data that government institutions may have.
 Containing transient spikes in operational costs. Operational costs can experience
temporary spikes when there is a sudden change in electrical power due to natural
disasters. This situation makes it inconvenient to fully exploit a given datacenter and
provides an opportunity for leveraging federation resources to deliver services a cheaper
price.
 Disaster recovery. Natural disasters happen, and if datacenters are co-located a disaster can
put an entire datacenter or more out of service for an undefined period of time. In this
scenario agreements between providers to handle disaster conditions are more likely to be
settled in a federated context than in a competitive market.
For all these cases, cloud federation helps provide not only conceptual solutions but also practical
means to realize these goals.
Cloud federation is an overlay that mostly benefits cloud service providers and that is supposed to be
transparent to service consumers. Besides the indirect benefits to end users, there are indeed some
potential direct benefits originating specifically from the concept of federation. Indirect benefits
are mostly related to the QoS perceived by the end users. Real QoS is possible by enforcing
admission control, which ensures that if a request is accepted, it will be served in compliance with
the QoS profile defined in the SLA signed with the customer. Currently, the major cloud service
providers engage QoS agreements that are mostly based on availability rather than other quality
factors. For instance, in an IaaS scenario the published hardware features of a VM instance might
not mirror its real performance. Since there is no SLA enforcement of such features, the provider
will always try to serve requests, even when risking delivery of poor performance. In a federated
scenario, requests may be served by leveraging other providers, thus ensuring that the expected
performance profile is met. Therefore, as indirect benefit for users, cloud federation can help
increase the overall QoS the user experiences when requesting a service. Direct benefits instead
constitute something that is an advantage to end users, and they are perceivable because of the
existence of federated clouds.
Cloud providers that offer different services can support each other since they are not competitors. A
good example can be taken from the cooperation between the airline and accommodation market
segments. Airline companies provide you with selected options for accommodation to be

Department of CSE Cloud computing challenges Page 12


CLOUD COMPUTING UNIT – IV R – 23

paired with a flight booking. This is generally the result of an agreement between the hotel and air
line companies that might support each other, thus providing better service to the customer. Since
companies operating in the two sectors are not competing with each other, they can both gain
advantage if they provide customers with a complete solution. It is possible to replicate this type
of collaboration in a federated cloud computing environment. For instance, providers that reside in
different market segments (IaaS, PaaS, SaaS) might advertise each other to provide better service
to the user. Enterprises that have legacy systems will be primarily looking at IaaS solutions to
deploy and scale their systems. IaaS vendors can complement their offerings with advantageous
access to some PaaS services by selecting those that might be complementary, of interest to the
user, and offered by federated providers.
In the future, Amazon AWS might provide discounted access to AppEngine or simply provide a
better interaction with the services exposed by Google in terms of data transfer, network
connection, and bandwidth. How does this help the customer? The same company that is already
hosting its Web application on Amazon EC2 might in the future want to integrate new features
and develop them with a scalable technology. Due to performance advantages gained in
leveraging AppEngine from an EC2 deployment, this could be the solution of choice. This is more
likely to be possible within the context of a cloud federation. Moreover, federated clouds can
provide better service to users, even when they reside in the same market segment but provide
different services. For instance, in an IaaS scenario a specific provider might not be able to serve
VM templates for host ing a specific operating system, but it can suggest or point the customer to
another provider that’s able to supply that capability. This scenario is applicable if the two
providers have mutual agreements that are facilitated by belonging to a federation.
Being part of a federation also implies providers’ obligations to avoid parasitic behaviors. For
instance, each provider is expected to be an active member of the federation by contributing its
resources. This makes an organization such as the federation dependable and increases the trust
that each provider puts in it. Obligations, such as always making available a fraction of resources
and services to the federation, might be considered disadvantages, but they may also constitute
potential benefits. For instance, large companies such as Google are charged for energy usage
according to the peak requests rather than detailed actual usage over a month. This means that if
in one month a datacenter reaches 90% of peak capacity and on average works at 60%, it will pay
power bills for the cost of operating at 90% capacity for the entire month. This has led companies
to put a lot of effort into optimizing the utilization of datacenters. A cloud federation might be an
alternative to frenetic optimization, since it might make internal resources available for usage by
other member of the federation. The revenue obtained from leasing these resources is an
opportunity to compensate the energy costs for peak request.
All these aspects provide a rationale for the existence of federated clouds. Obstacles at the
conceptual level are the implications for security and trust. For instance, in a federated context a
provider might offload a portion of the service consumers’ requests to another provider with
which it has agreements. This is done transparently to the user, who might not desire such
behavior. These are challenges that have to be properly addressed in order to make the concept of
cloud federation a viable way to efficiently exploit cloud computing as a technology.
4.3 Fundamentals of Computer Security:
In today's world, the Internet has become an essential and indispensable part of people's daily
lives, much like water and electricity. The advancement of telecommunication technologies, such

Department of CSE Cloud computing challenges Page 13


CLOUD COMPUTING UNIT – IV R – 23

as 5G, 6G, and beyond, and the ubiquity of WiFi have revolutionized the Internet, making it
widely accessible and thus facilitating the widespread adoption of cloud technologies. As a result,
cloud applications such as social media, e-commerce, gaming, and multimedia platforms have
experienced a significant surge in popularity among the general public. The average user now
spends over two hours per day on social media, and a staggering 87% of online shoppers rely on
social media for their purchasing decisions.
4.3.1 Cloud Computer Security Computers, mobile phones, and other electronic devices play a
crucial role in both personal and professional aspects, becoming vital tools for modern businesses.
While the users are spending significant time over the Internet, ensuring the protection of data is a
paramount concern and objective posed by hackers or cyber criminals for all modern businesses
and organizations. The highest priority is placed on enhancing computer. Computer security is the
protection of computer systems and safety (Computer security) measures to safeguard valuable
and sensitive information from the risks of data residing on-premises or remotely and also
securing the hardware. The standard definition of information from harm, theft, and unauthorized
use. Overall, computer security deals with protection computer security described by NIST says
that,
"Prevention of damage to, protection of, and restoration of computers, electronic
communications systems, electronic communications services, wire communication, and
electronic communication, including information contained therein, to ensure its
availability, integrity, authentication, confidentiality, and non repudiation."
The rapid growth in online application usage has led to an increase in cyber threats. For instance.
Reports indicate that cybercriminals generate around $3 billion in annual revenue by exploiting
vulnerabilities in social platforms. Cyber security is a sub domain of computer security that
enables the protection of data, services, and applications over the network. Consequently, there is
a pressing need for robust cyber security measures to protect end-user data, privacy, and secure
transactions in cloud-hosted social media, e-commerce, and other applications.
4.3.2 Categories of Computer Security
Computer security mechanisms are categorized into various types based on the protection
provided to software, hardware, data, or networks in computer systems. Here, we describe the
fundamental computer security categories. The categories are shown in Fig. 4.4.
Application Security: It involves implementing security software, hardware techniques, and
best practices to protect applications and the associated data from unauthorized access or
intrusions. The main objective is to ensure the integrity and confidentiality of accessing
applications. The several sub-domains of Application security (AppSec) include web
application security, Application Programming Interface (API) security, and Cloud-Native
application security. The Open Web Application Security Project (OWASP) has identified and
highlighted the top 10 cloud-native security risks. These risks encompass insecure cloud
configurations, injection flaws at the application layer, inadequate authentication and
authorization, and various other vulnerabilities and risks that need attention and mitigation.

Department of CSE Cloud computing challenges Page 14


CLOUD COMPUTING UNIT – IV R – 23

Fig. 4.4 Categories of Computer Security


Network Security: Network security, also referred to as cyber security, is a critical element of
computer security that involves safeguarding data, systems, and services from unauthorized
access or cyber thefts across networks. It plays a vital role in ensuring the integrity and
protection of digital assets in the interconnected world. The sub domains include physical
(protecting the data and network through unauthorized entities), technical, and administrative
network security. Some of the common examples of network security threats are Phishing,
Denial of Service (DoS) attacks, Malware, and Ransom ware. A cloud network security
solution is the domain of network security that is vital for ensuring the protection of
applications, data, and resources in cloud environments. It plays a crucial role in securing the
traffic between an organization's cloud deployments and its on-premises data center and
intranet.
Information Security: Information security involves mitigating risks associated with
unauthorized access, use, disclosure, destruction, modification, and disruption of information
within systems. It encompasses the protection of various types of data, including personal
information, financial in-formation, and sensitive and confidential data of organizations,
whether stored in physical or digital form. The information security principles follow three
objectives: CIA (Confidentiality, Integrity, and Availability). It also includes non-repudiation
(preserves data integrity in transit), Authenticity (trusted sources), and Accountability (User
access control). A few examples of applications of information security would be protecting
personal data on social media profiles, mobile phone data, email data, and the replication of
biometrics. Information security spans in to several research domains such as cryptography,
cyber forensics, and online social media data protection. Cloud security is also a sub-domain of
information security that focuses on building and hosting secure applications in cloud
environments and securely consuming third-party cloud applications.
Endpoint Security: Endpoint security refers to the collection of measures implemented to safe
guard end-user devices such as mobile devices, laptops, systems, and loT devices from
potential hackers attempting to gain unauthorized access to the user network. This includes
utilizing antivirus software to detect and remove malicious trojans and spyware present on user
devices. Additionally, endpoint tect users from falling victim to cyber attacks and criminals.
Cloud vendors often incorporate endpoint Security encompasses the establishment of
comprehensive security policies and procedures to pro-security as an integral part of their

Department of CSE Cloud computing challenges Page 15


CLOUD COMPUTING UNIT – IV R – 23

solutions, ensuring secure access to cloud infrastructure, services, and applications.


4.3.3 Vulnerabilities, Threats, and Risks
In the field of cyber security, the terms vulnerability, risk, and threat are commonly used to
describe organization to potential threats. To illustrate, leaving your car unlocked in a public
parking lot is a important concepts. In simpler terms, Vulnerability is a weakness or gap in
security that exposes an vulnerability. The Threat refers to a malicious activity or action that
takes advantage of vulnerability. Using the car example, a carjacker exploiting the unlocked
door represents a threat. Risk refers to the potential for loss or harm resulting from a threat
exploiting vulnerability. In the car scenario, the risk is the potential loss of the valuable car and
its contents. We will have a closer look at these terms in the context of computer security.
Vulnerability: Vulnerability is simply a flaw, bug, misconfiguration, or weakness in
applications, databases, networks, or infrastructure that exposes your data and assets to threats.
Microsoft outlines that 80 percent of ransom ware attacks can be traced to common
configuration errors in software and devices. One example would be the WannaCry attack in
2017, the vulnerability in the Windows systems was exploited by a group of ransom ware
attackers. The goal of the attack was to demand ransom in return for the files. The
organizations would realistically have thousands and millions of vulnerabilities, and managing,
mitigating, and patching them with limited workforce is very challenging. The preliminary and
most peculiar vulnerabilities are identified and patched, and the remaining will be vulnerable to
threats. Generally, the vulnerabilities are classified into two types: Technical vulnerabilities,
which are bugs in the code and errors in the software systems. The other category is human
vulnerabilities, which are caused by employees falling into phishing or other common attacks.

Threat: Normally, a threat could exploit the vulnerability, and that can affect the
confidentiality, integrity, and availability of the software systems and data. Generally, the
threat is when an adversary or attacker has the opportunity or ability to bring harm to the
systems or applications, assets, or workforce. Some common examples are malware,
ransomware, and phishing attacks. In simplicity, threats are categorized as intentional threats,
unintentional threats, and natural threats. The intention-al threats are basically proposed attacks
by the hacker; some examples are malware, ransomware, phishing, malicious code, and
wrongfully accessing user login credentials. However, unintentional threats are often caused by
human errors. For example, an employee could forget to update their firewall or antivirus
software. The natural threats are caused due to nature (earthquakes, floods) and are
unpredictable but damage your assets.

Risks: Risk is the probability of a negative or harmful event occurring, which can lead to the
loss of an asset due to exposure to threats and potential damage from a cyber attack. The risk
of losing intellectual property and sensitive information has been increasing recently.
Organizations cannot avoid or eliminate the risks, but management strategies should be well-
planned to tolerate the occurrence of them. Generally, cyber risk is a function of threats
leveraging system vulnerabilities to conduct cyber attacks and steal or cause damage to assets.
Risk can be derived as:
Risk=Threat x Vulnerability

Department of CSE Cloud computing challenges Page 16


CLOUD COMPUTING UNIT – IV R – 23

Risk management should be a key component in the cyber security measures of an organization. It
includes the potential or probability of harmful events or attacks, as well as their assessment of
occurrence and damage of assets that could be caused to the organization. Generally, cyber
risks are classified into two types: Internal and external risks. The internal risks are mostly by
internal (insider) threats due to human error or employees with malicious intent. External risks
are from out-side organizations, basically cyber attacks and distributed denial of service
(DDoS) attacks.
4.3.4 Concepts of Computer Security
Cryptography is a procedure or technique involved in protecting and securing information and
communications through the use of codes so that unintended recipients should not use and
process it. It involves the use of mathematical concepts and a set of rule-based calculations
known as algorithms to convert the messages into other forms so that intruders could not use,
disrupt, or modify the information. Some of the common uses of cryptographic applications are
computer passwords, secure web browsing, digital currencies, and crypto currencies. The
primary features of cryptography are as follows:
1. Confidentiality: The information (data) should be accessible to the intended users and
should be hidden from unintended users. This enables the protection of the data during
transmission, while using and storing.
2. Integrity: The information (data) should not be altered or modified during transmission from
sender to receiver. This involves protecting the data from unauthorized modification or
alteration.
3. Non-repudiation: Ensuring that a party cannot deny having sent or received a message or a
trans-action. This enables protection against replay attacks and message tampering.
4. Authentication: Ensuring the sender and receiver are confirmed or trusted. This enables
protection against identity fraud.
4.3.5 Confidentiality: It is a fundamental computer security principle that ensures sensitive
information is only accessible to authorized individuals, protecting it from unauthorized
disclosure. It is achieved through methods like access control (authentication and authorization)
and encryption. Confidentiality is a core part of the CIA Triad, which also includes integrity and
availability.
Key aspects of confidentiality
Unauthorized access prevention: The primary goal is to prevent unauthorized individuals from
viewing, accessing, or misusing confidential data.
Data protection: It is vital for safeguarding sensitive information, such as personal data,
intellectual property, and proprietary business information.
Implementation:
Access Control: This involves verifying a user's identity (authentication) and then determining their
permissions (authorization).
Encryption: This scrambles data, making it unreadable without the correct decryption key, which is
only available to authorized users.
Consequences of failure: Breaches of confidentiality, especially those involving personal
information, are considered severe violations.

Department of CSE Cloud computing challenges Page 17


CLOUD COMPUTING UNIT – IV R – 23

Examples: Confidentiality is breached through poor security practices like sharing passwords or
using default passwords, which can grant unauthorized access.
4.3.6 Integrity in computer security is the fundamental principle of ensuring that data is accurate,
complete, and trustworthy by protecting it from unauthorized modification or deletion. It is one of
the three core components of the CIA triad (Confidentiality, Integrity, and Availability), and is
maintained through technical controls like hashing, digital signatures, and access controls, as well
as process-based methods like backups and version control.
Key aspects of integrity
Accuracy and completeness: Ensures data is precise and has not been corrupted or altered in any
way, either intentionally or accidentally.
Trustworthiness: Guarantees that data is reliable throughout its entire lifecycle, from creation to
storage to transmission.
Protection from unauthorized changes: Prevents both unauthorized users and authorized users
from making improper or unauthorized modifications to data or programs.
Detection of changes: Implies that any changes made to data should be detectable. For example,
using message authentication codes or hashing can detect if a message has been tampered with
during transmission.
Methods for ensuring integrity
Hashing and checksums: Cryptographic hashing functions create a unique "fingerprint" for a
block of data. If the data is altered, the hash will change, making tampering easily detectable.
Digital signatures: Use cryptography to verify the sender's identity and the integrity of the
message, ensuring it has not been altered since it was signed.
Access controls: Limiting who can access and modify specific data helps prevent unauthorized
changes.
Backups and version control: Regular backups and version control systems allow for the
restoration of data to a known, trusted state if integrity is compromised.
Encryption: While primarily for confidentiality, encryption can also enhance integrity by making
it more difficult for an attacker to intercept and alter data in transit.
4.3.7 Non repudiation: Non-repudiation is a fundamental computer security principle that
ensures a party in a digital transaction cannot deny the authenticity of their actions, such as
sending a message or signing a document. It provides proof of origin and integrity, which means
the sender cannot deny sending the data, and the recipient cannot deny receiving it, creating
accountability and trust in digital communications. Achieving non-repudiation typically involves
using cryptographic techniques like digital signatures, timestamps, and audit trails.
Proof of Origin: Verifies the source of a message or transaction, linking it to a specific entity.
Proof of Integrity: Ensures the data has not been altered since it was sent.
Proof of Receipt: Confirms that the intended recipient actually received the message.
Key components
Digital Signatures: A private key is used to create a signature for a message, and the
corresponding public key is used to verify its authenticity, proving the sender's identity and
ensuring the message hasn't been tampered with.
Time stamping: A time-stamping service is used to prove that a message was sent at a specific

Department of CSE Cloud computing challenges Page 18


CLOUD COMPUTING UNIT – IV R – 23

time, which is crucial for establishing a timeline of events.


Audit Trails: Systems keep logs of who did what and when. This creates an auditable record that
can be used to investigate events and hold parties accountable.
4.3.8 Authentication
Authentication is the computer security process of verifying a user's or system's identity to ensure
only authorized individuals can access resources. It is the first line of defense and relies on
verifying credentials such as passwords (something you know), security tokens or mobile phones
(something you have), or biometrics like fingerprints and facial recognition.
When a user attempts to access a system, they provide credentials (e.g., username and password).
The system compares these provided credentials against a stored database of verified
information. If the credentials match, the user is authenticated and granted access.
Methods of authentication
Something you know: This is the most common type and includes passwords, PINs, and
passphrases.
Something you have: This requires possession of a physical object, such as a smart card, security
token, or a mobile phone that receives a one-time password (OTP).
Something you are: This uses unique biological characteristics for verification, including
fingerprints, facial recognition, retina scans, or voice recognition.
Multi-factor authentication (MFA): This is a security method that requires two or more
different factors of authentication to verify a user's identity.
4.4.1 IaaS Security
The laas layer comprises the underlying system infrastructure (cloud resources), including
physical servers (compute, storage, and network), racks, cooling systems, and other essential data
center components. Within this layer, the cloud service provider offers security services, which
involve safe-guarding the system infrastructure (servers, storage, disks, and network devices)
through the use of surveillance systems. Additionally, comprehensive disaster recovery plans are
implemented to mitigate the risks associated with natural disasters.
The core middleware, which comprises cloud hosting platforms, incorporates hypervisor
technologies to facilitate the creation and management of a virtual pool of compute resources
(machines), storage, and network services. At the hypervisor level, security features are
implemented to ensure the protection of virtual machines. This is achieved through isolation,
machine instruction security via ISA, and safeguarding VM data.
Furthermore, the core middleware offers security functionalities for computing services. For in-
stance, access to virtual machines is managed through SSH and RDP, utilizing PKI and password-
based authentication methods. Network security is also enforced by defining inbound and
outbound traffic rules (security groups) and establishing a shield for private networks using virtual
private cloud (VPC) and network address translation (NAT) rules.
To secure object storage, the core middleware employs Identity and Access Management (IAM) to
control public access to the stored objects in buckets, enabling administrators to grant or revoke
access as needed. Similarly, security measures for block storage include disk encryption and
authentication mechanisms to protect sensitive data. Further, the core middleware is tasked with
ensuring the provision of secure and up-to-date operating system images that are free from

Department of CSE Cloud computing challenges Page 19


CLOUD COMPUTING UNIT – IV R – 23

vulnerabilities and unknown threats.


At the organizational level, security measures are implemented to manage services and user
access. This is achieved through Authentication, Authorization, and Accounting (AAA) using
IAM policies. These policies enable the establishment of access permissions across user accounts,
ensuring might of service usage.
4.4.2. PaaS Security
The CSP's core responsibility is to oversee and manage networks, servers, operating systems, and
storage services. In contrast, PaaS users retain control over their code, workflows, configurations,
and application hosting in specific situations. PaaS security primarily focuses on safeguarding
application code, including securing code artifacts such as repositories and container images. This
involves maintaining strict control over development workflows, securing sensitive data, and
ensuring comprehensive monitoring, logging, and auditability throughout the entire development
lifecycle. Addition-ally, PaaS CSPs offer data encryption capabilities for both data at rest and in
transit. However, PaaS users should exercise caution when transmitting data through API
integrations, particularly when data passes through REST APIs utilizing HTTPS for
communication transport.
4.4.3. SaaS Security
SaaS security is primarily focused on safeguarding private and enterprise data, as well as services
and applications delivered through subscription-based cloud platforms. Take Gmail, for instance,
which serves as a prime example of a SaaS application. In this context, end-users bear the
responsibility of securely managing their login credentials for Gmail. Given the sheer volume of
usernames and passwords to remember, many web browsers offer convenient solutions for storing
these credentials in the form of cookies. However, it is crucial for end-users to exercise caution
when storing sensitive information within browser cookies.
Cloud Service Providers (CSPs) play a pivotal role in ensuring the security of user data and
sensitive information within SaaS applications. They are tasked with establishing robust security
measures to prevent unauthorized access and data breaches. Moreover, CSPs should implement
well-defined security protocols to mitigate the risk of Distributed Denial of Service (DDoS)
attacks in web applications. One effective strategy for enhancing web application security is the
deployment of Web Application Firewalls (WAFs), which offer a robust defense against a wide
range of cyber threats.
4.5 Cloud Shared Responsibility Model
A shared responsibility model is a cloud security framework that outlines the security
responsibilities of both the cloud provider and the user. It encompasses various aspects such as
infrastructure, hardware, data identities, workloads, network settings, and more, assigning specific
accountabilities to each party to ensure accountability for security. Essentially, it describes the
roles and responsibilities of both the cloud service provider and the customer in maintaining the
security of the cloud environment.
In today's landscape, the shared responsibility model has become crucial as organizations
increasingly migrates its applications, data storage, and development platforms from on-premise
to public cloud environments. In traditional on premise setups, customers (these are the service

Department of CSE Cloud computing challenges Page 20


CLOUD COMPUTING UNIT – IV R – 23

providers to their clients, who become prospective customers to the cloud provider after migration
to the cloud) bear the responsibility for securing infrastructure, networks, and applications.
However, transitioning to a public cloud service provider introduces the challenge of defining
accountability in securing the cloud environment. This raises the question of who is responsible
for securing what within the shared responsibility framework.
4.5.1 Shared Responsibility Across Cloud Service Models:
The shared responsibility model aims to define the division of security responsibilities between
users and cloud service providers (CSPs) across various cloud service models, including laaS,
Paas, and SaaS. It establishes clear guidelines for each party's role in ensuring security at different
layers of the cloud service stack. By outlining these responsibilities, the model helps ensurea
comprehensive and collaborative approach to security in the cloud environment.

Fig. 4.5 Cloud Service Model Management Complexities.


Fig. 4.5 depicts the complexity of cloud model management. In the on-premise model, users have
the responsibility of managing their infrastructure, applications, and data storage. However, in the
laas model, the cloud service provider (CSP) lakes on the responsibility of managing the
infrastructure up to the virtualization layer, while the user manages the operating system, API and
middleware, runtime (platform), and application layers. In the Saas model, the CSP manages all
the layers, and the user's role primarily involves working with data and utilizing the application.
Similar to the cloud management model, the shared responsibility model provides the security
considerations by the user and CSP as described in Table 4.1. It describes the security elements
taken care of at all the layers of laaS, PaaS, and Saas of cloud environments. It clearly says that
each of the security elements is owned and managed by an individual party, either the user or
CSP. There also exists divided responsibility, which is marked as both (user + CSP) in Table 4.1.

Department of CSE Cloud computing challenges Page 21


CLOUD COMPUTING UNIT – IV R – 23

Table 4.1. Shared Responsibility Model of Cloud Security

laaS: The CSP is responsible for security measures at the physical environment (data center)
infrastructure, providing network-level security (virtual routers, switches, software-defined
networks), and hypervisor-level security for virtualization stack (managing virtual machines on
virtual hosts, providing security and privacy). Further, the CSP is responsible for security for data
storage and migration, providing security and privacy measures for redundancy and backup of the
data storage and physical storage drives. The User is responsible for security measures at most of
the layers in the laas layer, for example, maintaining the OS level security, Identity management,
and configuring the access management rules, security groups for network flows, maintaining
code level security, endpoint security at API and middleware level, and application data security.
The CSP and User responsibilities persist together at network security. CSP manages network
security at the hardware level, and users need to define a security group (inbound and outbound
rules) to access the VMs and other cloud workloads.
Paas: It provides a hosted runtime environment to develop the applications seamlessly by the
developers, and there is no need to focus on infrastructure management. Similarly, the security
measures divide across the user (developers) and CSP .The CSP is responsible for providing
security at the plat- form level, middleware, network and servers (with OS-level security).
However, the user is responsible for providing security measures for application code, data, and
APIs. However, shared responsibility is there in identity and access control management to access
the data, services, and APIs.
SaaS: Almost all the security elements are taken care of by the CSP; however, the data access
management and secure access of the application are the responsibility of the end user. Public
cloud providers have established a shared responsibility model that outlines the security

Department of CSE Cloud computing challenges Page 22


CLOUD COMPUTING UNIT – IV R – 23

responsibilities for the services they offer to customers. This model clearly defines the security
tasks handled by both the user and the cloud service provider (CSP). Below are the architectures
of the shared responsibility models provided by three major public service providers: Amazon
Web Services (AWS), Google Compute Engine, and Microsoft Azure Services.

4.6 SECURITY IN CLOUD DEPLOYMENT MODELS:


Cloud deployments are classified into three main categories: Private, public, and hybrid. The
cloud security model carries distinct implications depending on the chosen deployment model.
The following subsections provide an overview of the security challenges, architectures,
advantages, and disadvantages associated with each cloud deployment model's security
considerations.
4.6.1 Public Clouds
Security considerations in public cloud environments are primarily focused on adopting the NIST
cyber security framework to implement core functionalities. As the cloud infrastructure is shared
among multiple users, security, identity management, and compliance are crucial aspects in
designing secure systems. Public cloud service providers clearly define the responsibilities of both
end users and the cloud service provider (CSP) in terms of security and compliance. As already
discussed, popular public cloud vendors have established a shared responsibility model, which
outlines the specific responsibilities at each service layer (laaS, PaaS, and SaaS) for maintaining
security. In public cloud environments, security services provided by vendors are typically
categorized into the following:
Infrastructure Security: This category includes the security features mainly focused on compute,
storage, and network infrastructure security. For example, virtual machine security includes
configuring the keys, network security groups, and firewall rules. For storage, the security features
include access methods and data encryption mechanisms.
Network Security: It involves securing the network connections, secure segmentation, creating
VPNs, protecting from DDoS attacks, access of the users over firewall, and monitoring the
network traffic for potential security threats and breaches.
Application Security: It includes the toolset for securing web applications running over CSP.
Some examples of such tools include Web Application Firewalls, vulnerability scanning, runtime
self protection and code vulnerability protection.
Endpoint Security: CSPs provide solutions to secure the endpoint of applications or services using
antivirus, anti-malware, and firewall protection. These tools help to protect from threats at the
endpoint level.
Identity and Access Management: |AM provides security features from authentication, access, and
accounting, which eventually acts as a kind of single sign-on to use cloud services by providing
multifactor authentications and indeed federation to ensure authorized access to services.
Storage Security: Storage security settings in CSP environments take care of data at rest and in
transit. For example, access control and encryption mechanisms are used to secure data at rest,
and CORS features provide secure access of the data in transit over the web.
Risks and Compliance: CSPs offer comprehensive tools, frameworks, and audit services to help
cloud users to meet regulatory requirements and industry standards, for example, PCI DSS or
HIPAA.

Department of CSE Cloud computing challenges Page 23


CLOUD COMPUTING UNIT – IV R – 23

Considering the above security service list, NIST cybersecurity framework, and shared
responsibility model, in the following subsections, we discuss the overview of security services of
popular cloud service providers AWS, Azure Cloud, and Google Cloud Services.
4.6.2 Private Clouds
Private clouds are specialized environments dedicated to a single tenant or organization. They
operate within the organization's firewall rules and network configurations, ensuring a high level
of security. The primary advantage of private clouds lies in their ability to keep sensitive business
data under the direct control and security of the organization. In private cloud setups, the shared
responsibility model places the onus on the organization (both cloud service provider and user) to
protect and secure all aspects of the cloud environment, including compute resources, storage,
network infrastructure, applications, and compliance measures.
Private clouds offer several advantages over public clouds, particularly when it comes to security.
For instance, sensitive data and applications can be hosted on-premises within the organization's
data center. This provides greater visibility and control over security measures and access control
since the private cloud operates behind the customer's own firewall. Additionally, enterprises are
not solely dependent on the industry and regulatory compliance standards provided by Cloud
Service Providers (CSPs). This allows organizations to maintain a higher level of control and
ensure compliance with their specific security requirements.
1. Private Cloud Security Risks: Even though it has many advantages over public clouds, some
of the cloud risks associated to private cloud are:
Overall Security: Enterprises or organizations must embrace technologies and tools to safeguard
their data and applications within the cloud environment. To illustrate, security measures should
be implemented at various levels, including:
Infrastructure Level Security: This entails protecting compute resources, such as ensuring
hypervisor-level security for virtual machines (VMs), securing the operating system (OS), and
implementing physical host-level security.
Storage Level Security: Safeguarding data at the storage level involves implementing security
measures for both block and object storage. This helps ensure the integrity and confidentiality of
stored data.
Platform Level Security: Organizations need to focus on code and data-level security within the
cloud platform. This includes employing secure coding practices, data encryption, and access
control mechanisms to prevent unauthorized access and data breaches.
Identity and Access Management: Implementing robust identity and access management (IAM)
solutions is essential to manage user authentication, authorization, and access control within the
cloud environment. This ensures that only authorized individuals can access resources and helps
prevents unauthorized activities.
By managing security across all these levels of the cloud infrastructure, enterprises should
mitigate risks and threats effectively. It is crucial for organizations to configure and manage
security measures diligently to safeguard their sensitive data and applications within the cloud
environment.
Physical Security: Numerous organizations may face challenges in ensuring physical security for
their data centers, such as installing surveillance cameras, fire protection systems, and robust
access control mechanisms. This lack of physical security measures can expose organizations to

Department of CSE Cloud computing challenges Page 24


CLOUD COMPUTING UNIT – IV R – 23

vulnerabilities, threats, and potential data loss. In contrast, public clouds typically offer redundant
data centers with built-in backup and recovery mechanisms, which enhance data protection and
minimize the risk of data loss.
Insider Threats: Privileged users or employees with access to the private cloud infrastructure may
pose a security risk. Misuse, intentional or accidental data breaches, or unauthorized access by
insiders can compromise sensitive information.
Data Loss or Leakage: Data stored in a private cloud can still be at risk of loss or leakage. This
can occur due to hardware failures, natural disasters, human error, or inadequate backup and
disaster recovery mechanisms.
Inadequate Access Controls: Weak access control mechanisms or mis-configuration of access
policies can result in unauthorized access to private cloud resources. Insufficient privilege
management and weak authentication methods may also lead to security breaches.
Malware and External Attacks: Private clouds can still be vulnerable to external threats, such as
malware infections, distributed denial-of-service (DDoS) attacks, or targeted attacks aimed at
exploiting vulnerabilities in the cloud infrastructure or applications.
Lack of Patch Management: Failure to apply timely security patches and updates to the private
cloud's underlying infrastructure, virtualization software, or applications can leave vulnerabilities
unaddressed and increase the risk of exploitation.
Compliance and Regulatory Issues: Private clouds that handle sensitive data may face challenges
in meeting industry-specific compliance requirements. Failure to adhere to regulations may result
in legal consequences and damage the organization's reputation.
Data Segregation and Multi-Tenancy: In certain cases, private clouds may be configured to
support multiple tenants or business units within an organization. If proper data segregation
measures are not implemented, there is a risk of unauthorized access to sensitive data across
different tenants or business units.
Lack of Visibility and Monitoring: Insufficient monitoring and logging of private cloud activities
can make it challenging to detect and respond to security incidents in a timely manner. This can
result in prolonged exposure to potential threats and delayed incident response.
Third-Party Dependencies: Private clouds may rely on third-party vendors for hardware,
software, or managed services. In such cases, organizations should carefully assess the security
measures and reliability of these vendors to mitigate any associated risks.
2. Securing the Private Clouds
Securing a private cloud requires ongoing attention to effectively manage the environment and
mitigate evolving risks and threats. Here are some essential suggestions and best practices to
follow in order to ensure the security of private clouds:
Choose the Right Platform and Provider: The initial step toward achieving an updated and
secure private cloud is selecting the appropriate cloud management software that aligns with your
requirements. Numerous providers, including VMWare, OpenStack, Redhat, Azure Stack, and
AWS Outposts, offer software solutions, each with its own advantages and challenges. When
making a decision, it is essential to consider key considerations such as the software's track
record, reputation, security services offered at each layer, and certifications in data security and
compliance. By evaluating these factors, organizations can make an informed choice and
prioritize a secure and reliable private cloud environment.

Department of CSE Cloud computing challenges Page 25


CLOUD COMPUTING UNIT – IV R – 23

Implement a Patch Management Strategy: One of the key strategies for enhancing the security of
a private cloud is implementing a robust patch management approach. Patch management
involves regularly updating operating systems (VM images), firmware, and hardware components
to mitigate evolving vulnerabilities, bugs, and necessary fixes. Additionally, it is crucial to
establish regular backup and recovery plans to address any unforeseen issues that may arise
during the patch management process. A comprehensive patch management policy should include
defined timelines for patch deployment, thorough testing procedures, and a well-structured
deployment plan to ensure minimal disruption to the cloud environment. By prioritizing patch
management, organizations can proactively address security vulnerabilities and maintain a secure
private cloud infrastructure.
Educating the Staff: It is essential to ensure that both the IT team and other users of the cloud
environment possess the necessary skill set to access cloud services securely. For instance, when
provisioning VMs, it is crucial to disable default passwords and instead utilize PKIs or enforce the
use of complex passwords. Enterprises should prioritize providing training and guidance to users
on effectively managing and troubleshooting private clouds while maintaining data integrity and
protecting against evolving threats, data breaches, and enforcing strong access control
mechanisms. By equipping users with the necessary knowledge and skills, organizations can
minimize risks, enhance security, and ensure the proper utilization of private cloud resources.
Regular Audits and Update Security Policies: Enterprises should prioritize undergoing third-
party audits and, most importantly, CSA STAR (Cloud Security Alliance Security, Trust &
Assurance Registry) evaluations to demonstrate their ability to defend against threats and risks. It
is crucial for organizations to regularly update their security policies as vulnerabilities and
security threats evolve rapidly in the current era of digitization. By staying proactive and keeping
security policies up to date, enterprises can better protect their assets and maintain a robust
security posture in the face of evolving digital risks.
4.6.3 Hybrid Cloud
The hybrid cloud presents an opportunity to utilize existing on-premise IT infrastructure for
storing sensitive information while seamlessly scaling to public cloud resources as needed, and
releasing them when no longer required. This approach allows organizations to opt for the
advantages of both on-premise and public cloud environments, ensuring efficient allocation of
resources. However, the process of provisioning resources, running applications, and transferring
data to and from other clouds in real-time poses significant security challenges that need to be
addressed.
The Cloud Security Alliance Hybrid Cloud Security Working Group described the four cross-
cloud security capabilities Perimeter, transmission, storage, and management security. The
Perimeter security focused on defining the security of physical and logical boundaries between
on-premises cloud and public cloud environments. Transmission security defines the security
controls for migrating the infrastructure resources (Virtual Machines, Containers), applications,
and data. Storage security ensures the data storage, backup, and restoration of security policies in
hybrid cloud environments.
Finally, management security ensures and incorporates the security considerations for operation
management, permission engagement, identity, and authentication with unified management
across multiple cloud environments. Considering the cross-cloud security capabilities, we describe
the hybrid cloud risks that cannot be avoided or neglected.

Department of CSE Cloud computing challenges Page 26


CLOUD COMPUTING UNIT – IV R – 23

[Link] Hybrid Cloud Security Risks


Hybrid cloud exceptionally provides sealed access to the private and public cloud environments;
however, several security risks cannot be avoided and are discussed below as per the standard
documentation from CSA hybrid cloud security risks and ENISA.
Distributed Denial of Service Attack (DDoS): A prominent consequence of Distributed Denial of
Service (DDoS) attacks is network traffic congestion, which directly affects the performance and
quality of cloud services. This, in turn, can harm the reputation of Cloud Service Providers
(CSPs). In the case of a hybrid cloud environment, it is important to consider that DDoS attacks
can potentially disrupt not only external communications but also internal communications
between different components of the hybrid solution.
Data Breach: Since the user's endpoints and cloud applications are connected over the internet,
this provision results in a higher risk of data leakage due to several factors such as mis-
configurations of settings, unauthorized access, or man-in-the-middle attacks. It is the
responsibility of the organization and CSPs to protect the data in transit by using data loss
prevention mechanisms.
Compliance: Organizations face difficulty maintaining compliance with government frameworks
in a hybrid cloud setup. The movement of data between on-premise and cloud environments
complicates compliance with government regulations. For instance, ensuring data storage aligns
with legal or regulatory requirements based on country and region is ensured by CSPs.
Service Level Agreements (SLAs): SLAs define the service level objectives (SLOs) and quality of
service (QoS) parameters between the users and CSPs. Since, in the context of multiple clouds,
each CSP has its own API, tools, and SLAs, which makes it complex to align the underlying
components for consistency. There should be intelligent brokers to monitor and manage the SLA
violations and regulate them with multiple CSPs and on-premise clouds.
Cloud Skills: The private and public clouds are different platforms and may need separate skills
to manage and control the cloud applications and data. The security configurations and
terminologies of each CSP may be different, for example, AWS, Azure, or Google Cloud. Thus,
unknown skill
sets can lead to mis-configurations or insecure configurations, thus leading to security breaches.
So, the lack of cloud skills and knowledge can lead to direct consequences of security incidents.
Risk Assessment: Conducting risk assessments in the context of a hybrid cloud environment poses
significant challenges, particularly when evaluating multiple cloud environments. It is not feasible
to assess the overall risk of the hybrid cloud infrastructure as a whole, as individual assessments
need to be performed for each cloud provider and the private cloud. This fragmented approach to
risk assessment can potentially introduce security vulnerabilities due to the lack of standardized
tools and mechanisms for assessing the hybrid cloud as a cohesive system.
[Link] Securing the Hybrid Clouds:
Hybrid cloud architecture involves the orchestration between different platforms, allowing work-
loads to move and run across private clouds and public cloud environments. This architecture
provides several advantages of flexibility, scalability, and more options to lease the resources
When the users need to attain peak workloads. However, it imposes the challenges of security.
Such as compliance, data leakage during transit, further visibility, and control. Hybrid cloud
security involves protecting the data, applications, and infrastructure in both private and public

Department of CSE Cloud computing challenges Page 27


CLOUD COMPUTING UNIT – IV R – 23

cloud environments. Key guidelines and principles are proposed:

Department of CSE Cloud computing challenges Page 28


CLOUD COMPUTING UNIT – IV R – 23

1. Create a Unified Access Management Strategy: The perimeter of cloud use is diverse into
different locations of private and public clouds, which imposes challenges of managing the
security settings. Design of unified IAM is essential when data or users seamlessly migrate
between the clouds. The unified access management involves the multi-factor authentication for
privileged accounts, use of automated tools to monitor and enforce security policies, and least
privileges.
2. Automating the Configuration and Validation Across: All Clouds: Misconfigurations are the
major security threats for enterprises; despite using hybrid clouds, the responsibility moves to the
next level. Use of automated tools and cloud security posture management frameworks to ensure
secure configurations across all environments can be beneficial in securing the hybrid clouds.
3. Adopt New Security Standard Approaches: In the software development chain, the security
professionals and developers are integral part of the development eco system to deliver secure
software systems. Using newer approaches, for example, DevSecOps provide a clear vision, goal,
and visibility in designing and developing the applications that run across hybrid clouds. The
DevSecOps provides an opportunity to implement security controls, risk validation, and other
security approaches principles in the development pipeline.
4. Wider Scope to Enhance the Data Security: Enterprises should consider security of the data at
rest by encrypting it. Use of hardware security modules and virtual hardware security modules at
private and public clouds provides greater security to the data when it is stored. Enforcing the
strict security policies in the private cloud users and strong IAM policies can give more control
and visibility to the data.
5. Use Zero Trust Principles: Managing the security configurations, access policies, and controls
is a challenging task in hybrid cloud environments for data and applications. Using novel
architectures that use not only authentication and access control but understanding the context
gives the full visibility to provide access in non-controlled or non-secure environments.

Department of CSE Cloud computing challenges Page 29


CLOUD COMPUTING UNIT – IV R – 23

Assignment-Cum-Tutorial Questions
Part – A: Objective Questions

1. Which of the following is a key benefit of cloud computing economics? [ ]


a) Higher hardware cost
b) Pay-as-you-go pricing
c) Fixed billing
d) Local server dependency

2. Cloud interoperability mainly focuses on [ ]


a) Data encryption
b) Vendor lock-in
c) Application migration between providers
d) Software updates

3. Scalability in the cloud allows [ ]


a) Increasing hardware manually
b) Dynamic resource allocation
c) Reducing cost permanently
d) Fixed performance

4. Fault tolerance in cloud computing ensures []


a) System failure on errors
b) Continuous operation even after failures
c) Manual recovery only
d) Higher energy use

5. Energy efficiency in cloud computing focuses on [ ]


a) Reducing power consumption
b) Increasing cost
c) Using more servers
d) Disabling virtualization

6. Cloud interoperability issue is related to [ ]


a) Security
b) Data portability
c) Backup process
d) Virtualization only

7. Which layer of cloud architecture handles security? [ ]


a) Application layer
b) Infrastructure layer
c) Security layer across all
d) Storage only

8. Energy efficiency in clouds can be improved by [ ]


a) Running idle VMs
b) Data center cooling optimization
c) Using more servers
d) Keeping high CPU utilization always

Department of CSE Cloud computing challenges Page 30


CLOUD COMPUTING UNIT – IV R – 23

9. Federated clouds combine [ ]


a) Access is limited to wired LAN
b) Services are available over the network using standard mechanisms
c) Access is available only in offices
d) Requires VPN always

10. Measured service in cloud computing refers to: [ ]


a) Tracking and optimizing resource usage
b) Limiting internet speed
c) Reducing bandwidth
d) Manual billing process

11. Which of the following is a key characteristic that allows resources to be shared
among multiple tenants? [ ]
a) On-demand service
b) Resource pooling
c) Rapid elasticity
d) Broad network access

12. Which of these is most related to scalability? [ ]


a) Broad network access
b) Rapid elasticity
c) Measured service
d) On-demand self-service

13. Which layer in the reference model deals with user applications? [ ]
a) SaaS
b) PaaS
c) IaaS
d) Hardware

14. Which layer manages development platforms and tools? [ ]


a) SaaS
b) PaaS
c) IaaS
d) Middleware

15. Which is the lowest layer in the reference model? [ ]


a) SaaS
b) PaaS
c) IaaS
d) None

16. The “shared responsibility model” means [ ]


a) Only customer is responsible for security
b) Only provider is responsible
c) Both share security tasks
d) None

Department of CSE Cloud computing challenges Page 31


CLOUD COMPUTING UNIT – IV R – 23

17. The layer most responsible for virtualization is [ ]


a) SaaS
b) PaaS
c) IaaS
d) DaaS

18. In cloud security architecture, “data at rest” refers to [ ]


a) Data being transmitted
b) Data stored on disk
c) Data in RAM
d) None

19. The term “cloud bursting” refers to [ ]

a) Service termination
b) Scaling workloads from private to public cloud
c) Data deletion
d) None

20. Which protocol is used for cloud storage access? [ ]


a) HTTP/HTTPS
b) SMTP
c) FTP only
d) POP3

21. Energy-aware data centers mainly use [ ]


a) Renewable energy
b) Diesel generators
c) Manual cooling
d) None

22. The main goal of fault tolerance is [ ]


a) System downtime
b) Reliability and continuity
c) Manual recovery
d) Cost increase

23. Interoperability can be achieved through [ ]


a) Vendor lock-in
b) Open standards and APIs
c) Proprietary software
d) Closed protocols

24. Which of these is not a deployment model? [ ]


a) Public cloud
b) Private cloud
c) Hybrid cloud
d) Static cloud

Department of CSE Cloud computing challenges Page 32


CLOUD COMPUTING UNIT – IV R – 23

25. SLA stands for [ ]


a) System Level Agreement
b) Service Level Agreement
c) Security Layer Agreement
d) Software License Agreement

26. Security risk in cloud due to multi-tenancy is [ ]


a) Data isolation failure
b) Dedicated servers
c) More privacy
d) No Privacy

27. Public cloud resources are [ ]


a) Owned by user organizations
b) Owned and operated by third-party providers
c) Only for government use
d) Limited to LAN

28. Private cloud resources are accessible to [ ]


a) General public
b) Specific organization only
c) Multiple unrelated customers
d) All of the above

29. Which model mixes public and private clouds? [ ]


a) Hybrid
b) Community
c) Multi-cloud
d) Shared cloud

30. Cloud data encryption ensures [ ]


a) Data confidentiality
b) Vendor lock-in
c) Increased latency
d) None of the above

31. Which deployment model offers the most control? [ ]


a) Public cloud
b) Private cloud
c) Hybrid cloud
d) Community cloud

32. Which deployment model is best for highly sensitive government data? [ ]
a) Public cloud
b) Private cloud
c) Hybrid cloud
d) Community cloud

33. Which organization defines cloud standards? [ ]


a) NIST

Department of CSE Cloud computing challenges Page 33


CLOUD COMPUTING UNIT – IV R – 23

b) ISRO
c) NASA
d) IEEE only

34. Fault tolerance can be achieved using [ ]


a) Load balancing
b) Data replication
c) Redundancy
d) All the above

35. Virtual machines are part of which layer? [ ]


a) Application
b) Platform
c) Infrastructure
d) Network

36. Which of the following improves energy efficiency? [ ]


a) Idle resource usage
b) Dynamic resource scaling
c) Fixed servers
d) Constant full load

37. Cloud scalability supports [ ]


a) Vertical and horizontal scaling
b) Only hardware scaling
c) Only vertical scaling
d) On-demand self-service

38. Cloud elasticity allows [ ]


a) Static resource allocation
b) Dynamic allocation and release
c) Manual scaling
d) On-demand self-service

39. Which one is a private cloud feature? [ ]


a) Shared infrastructure
b) Controlled access
c) Public usage
d) Manual configuration

40. Virtualization enhances [ ]


a) Energy consumption
b) Resource utilization
c) Downtime
d) Manual work

41. The primary goal of cloud economics is [ ]


a) Reduce cost per use
b) Increase capital investment

Department of CSE Cloud computing challenges Page 34


CLOUD COMPUTING UNIT – IV R – 23

c) Reduce elasticity
d) More IT staff required

42. Which of the following is a cloud security tool? [ ]


a) IAM
b) HTTP
c) DNS
d) DHCP

43. Security in deployment models depends on [ ]


a) Responsibility division
b) Same for all models
c) No difference
d) Local-only access

44. Which is a key principle of computer security? [ ]


a) Confidentiality, Integrity, Availability
b) Accessibility only
c) Confidentiality only
d) Accessibility only

45. Cloud audit ensures [ ]


a) No accountability
b) Transparency and compliance
c) More downtime
d) Measured service

46. Virtual machine migration improves [ ]


a) Load balancing
b) Fault Tolerance
c) Both the above
d) Measured service

47. Which one is not a cloud layer? [ ]


a) SaaS only
b) IaaS only
c) PaaS only
d) CaaS only

48. Security challenges in clouds increase due to [ ]


a) Centralized data
b) Decentralized control
c) Multi Tenancy
d) All the above

49. Identity and Access Management (IAM) controls [ ]


a) User authentication and authorization
b) Server Pooling
c) Power Supply
d) Accessibility

Department of CSE Cloud computing challenges Page 35


CLOUD COMPUTING UNIT – IV R – 23

50. Federated clouds are also known as [ ]


a) Multi-cloud systems
b) Centralized clouds
c) Static Clouds
d) Hybrid Cloud

Part – B : SHORT ANSWER QUESTIONS


1. Define cloud interoperability.
2. What is fault tolerance in cloud computing?
3. Explain the pay-as-you-go model.
4. Define federated clouds with an example.
5. What is energy efficiency in cloud data centers?
6. Classify different types of clouds.
7. What kinds of needs is addressed be heterogeneous clouds?
8. What are the main components of cloud security architecture?
9. Explain the term “shared responsibility model.”
10. What are the key principles of computer security?
11. Define scalability in cloud systems.
12. What are the main challenges in cloud security?

Part – C : DESCRIPTIVE QUESTIONS


1. Explain the economics of the cloud and discuss how cost optimization is achieved.
2. Describe the fundamental features of the economic and business model behind cloud
computing.
3. Describe cloud interoperability and standards with examples of existing frameworks.
4. Explain scalability and fault tolerance in detail with suitable architectures.
5. Discuss techniques used for energy efficiency in cloud data centers.
6. What are federated clouds? Explain their architecture, advantages, and challenges.
7. Discuss the fundamentals of computer security in the context of cloud environments.
8. Explain the cloud security architecture with neat diagram and its layers.
9. Describe the cloud shared responsibility model for IaaS, PaaS, and SaaS.
10. Compare security issues in different cloud deployment models (public, private, hybrid,
community).
11. Differentiate vulnerabilities, threats and risks in computer security.
12. Outline the cloud shared responsibility model that encompasses Iaas, Paas, and SaaS.
13. Write a detailed note on modern challenges in cloud computing and possible future
solutions.
14. List some of the challenges in cloud computing.

Department of CSE Cloud computing challenges Page 36

You might also like