0% found this document useful (0 votes)
2 views22 pages

Module 2

Chapter 3 discusses the critical security and privacy issues associated with cloud computing, highlighting the vulnerabilities posed by multi-tenancy, data exposure, and inadequate security measures by providers. It emphasizes the importance of confidentiality, integrity, availability, authentication, authorization, auditing, and access control as key security goals for organizations using cloud services. The chapter also outlines various security concerns at different layers of cloud infrastructure and the challenges faced by customers in ensuring their data's protection while relying on cloud service providers.

Uploaded by

sharvaripk247
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views22 pages

Module 2

Chapter 3 discusses the critical security and privacy issues associated with cloud computing, highlighting the vulnerabilities posed by multi-tenancy, data exposure, and inadequate security measures by providers. It emphasizes the importance of confidentiality, integrity, availability, authentication, authorization, auditing, and access control as key security goals for organizations using cloud services. The chapter also outlines various security concerns at different layers of cloud infrastructure and the challenges faced by customers in ensuring their data's protection while relying on cloud service providers.

Uploaded by

sharvaripk247
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 3

Cloud Security and Privacy Issues

3.1 Introduction
The emergence of various cloud-based services has opened good opportunities
in various domains such as Internet of Things (IoT), Smart Grid, Healthcare,
Banking, and IT. However, security is one of the crucial aspects in the cloud
computing, which has been studied in detail by cloud service adopters, re-
searchers, and security professionals. Cloud offers various good features for
the better utilization of the resources. Many of such features have been dis-
cussed in previous chapters. However, various features such as multi-tenancy
and online access to data and applications from anytime and anywhere expose
some serious threats as well.
For example, multi-tenancy could be misused by some of the cloud ten-
ants to cause harm to the shared cloud resources and breach the security of
co-located VMs. Moreover, the availability of services can also become threat
to the cloud infrastructure as services are provisioned in online mode. Ad-
vanced attacks can eavesdrop the network connections and can gain access to
the information being shared between sender and receiver [60]. Moreover, the
data stored in the cloud storage servers can also be exposed to third party
organizations intentionally for gaining some financial benefits. Since the data
is stored in the shared storage resources. If proper isolation of virtual storage
volumes is not maintained in the physical storage, then it will be easy for an
attacker to access the data of other customers.
Furthermore, the vulnerabilities present in any component of the cloud
infrastructure such as controller server or computer server, network server,
hypervisor, virtual machine and user applications, etc., impose a direct threat
to the security and privacy of services. Some of the other vulnerabilities which
can hinder the security and privacy are: insecure live migration of the cus-
tomer’s data, random selection of cloud service provider, in secure application
and browser APIs at provider end, network vulnerabilities and insecure en-
cryption of data, etc. [91]. The vulnerabilities and threats present in cloud,
make it very difficult to develop a comprehensive security model that can
cover all possible vulnerabilities.
Due to some security reasons, cloud service providers do not allow the
cloud customer to impose their own security model at the cloud network, or

DOI: 10.1201/9781003004486-3 49
50 Cloud Security: Attacks, Techniques, Tools, and Challenges

integrate them with management services or API, etc. It is the responsibility


of the provider to secure each layer of cloud infrastructure. The customers
can however install some security tool inside their own VM for the analysis of
their own VM’s activity. If the VM is subverted, the security tool inside VM
will also be subverted. Therefore, security and privacy are major concerns for
cloud service vendors and end users before migrating their applications, data
or any services in cloud.
Security refers to the protection of cloud infrastructure along with as-
sociated data and applications from the unauthorized threats and attacks.
The protection of cloud resources is important to ensure the confidentiality,
integrity and availability (CIA) in cloud environment. For example, the unau-
thorized users should not be allowed to access and modify the cloud resources.
The services should be available anytime from anywhere and service outage
should be as minimum as possible. The user’s data could be very sensitive and
protection of data from the attackers is the responsibility of the cloud service
provider.
Privacy is one of the important rights of a person to not to share his pri-
vate data to public. Private data refers to the personal sensitive information
of person which he or she may want to share to restricted number of people
or with no one. In the context of cloud computing, privacy can be defined
as “the obligations and rights of an organization and individuals with respect
to the gathering, usage, retention, disposal and disclosure of private informa-
tion” [92]. The privacy concerns are also different for each cloud models. The
security concerns for public cloud are much higher than private clouds or hy-
brid clouds. As publically cloud can be accessed by anyone over the web and
hence more prone to security attacks. However, in private cloud, the resources
are shared mainly by organizational people and attacking risk is less due to
having restricted and controlled access to the resources.
Although security and privacy are defined in different ways. However, they
are highly related with each other. The security is a much broader term which
is used to ensure various security aspects, mainly confidentiality (unautho-
rized disclosure) , integrity (illegitimate modification of data) and availability
(smooth access to services) of services. Whereas privacy is mainly concerned
with the ability of an individual to seclude their information from public and
share with selective people based on personal choice. Various privacy preserv-
ing security frameworks [93, 94] have been introduced to preserve the privacy
of individuals and at the same time meeting other security goals of cloud.
Therefore, security is not privacy but techniques used to ensure that privacy
and others security factors such as CIA, are persevered in cloud.
However, there exist less transparency when we talk about attacking inci-
dents and corresponding security measures taken by vendors, in cloud envi-
ronment. If some security incident occurs, customers may not be aware about
same. In fact, the detailed report about the incidents such as vulnerabilities
exploited, malware details and any system damage, etc. is also not shared
with the customers. For example, there exist some backdoor attacks which
Cloud Security and Privacy Issues 51

are launched by attackers to again access to the VM instances running in


cloud. The detection and notification of such backdoor attacks is essential to
have in the primacy stage. However, as long as no such backdoor is reported
by provider, customers are still blindly trusting the provider’s security and
assuming that no such attack has happened. Although the security and pri-
vacy related aspects and services are usually highlighted in the Service Level
Agreement (SLA). Various popular cloud companies such as Google, Ama-
zon, Salesforce, etc. are dependent on detailed SLA to ensure the customers
that strong security is provided. However, there exists no one standard for
designing the SLAs.
Various cloud features also expose threat to the security and privacy of the
user’s personal information and cloud infrastructure. Handling and addressing
all possible security issues at all possible layer in cloud is still a challenging
task. Gradually, the enterprises or cloud service providers are expanding their
cloud services and hence the attack vector associated with various services is
also expanding. Each of the organization is interested in incorporating a secu-
rity framework for running the services in a protected environment. Moreover,
the security and privacy of the user’s data is as important as the infrastruc-
ture security. Each organization has to take care of choosing a secure cloud
computing platform before migrating their services and data to the remote
cloud servers.

3.2 Cloud Security Goals/Concepts


Cloud security is one of the essential need of today’ eras as most of the orga-
nizations are moving toward the adoption of cloud service platforms. There
is a strong requirement of having the proper controls, security policies, de-
fensive mechanisms, and procedures in place so as to protect complete the
eco-system. In this section, we will understand, various cloud security goals
that every organization wants to achieve.

3.2.1 Confidentiality
The confidentiality of data is a crucial issue when extremely sensitive data
is outsourced to the cloud system. It keeps the data secret from the users in
the cloud and the confidential data must not be accessible to an unauthorized
entity. To achieve confidentiality, mechanisms such as cryptography and iso-
lation has been adopted by cloud vendors. Encryption mechanisms such as
triple Data Encryption Standard (DES) or Rivest, Shamir, Adleman (RSA)
are used to gain confidentiality but key management or key distribution is the
big issue. Some examples of threats to confidentiality are insider user threats
such as malicious cloud provider users. Malicious cloud user and malicious
52 Cloud Security: Attacks, Techniques, Tools, and Challenges

FIGURE 3.1: Cloud security goals.

third-party user. The attacks by external attackers such as the attack on ap-
plication or infrastructure by remote software or hardware. Data leakage is
another threat to the confidentiality.

3.2.2 Integrity
Data integrity is the basic task that verifies the data and it provides the
guarantee for the exactness and quality of the data. It is important as the cloud
provides various services such as SaaS, PaaS, etc. The cloud services demands
have been increasing day-to-day, hence cloud service providers may require
increase storage. So, there are chances of data corruption or loss or maybe
the cause of failure of nodes, physical devices, or disk. The data integrity is
preserved in the cloud environment by various means so that data are not
be altered by an unauthorized entity. To avoid data corruption or crash in
the cloud, so watching the data integrity is very essential. As cloud-based
environments are distributed so it is harder to obtain integrity as compared to
the centralized environment. Examples of threats to integrity like user access,
data segregation, and data quality.

3.2.3 Availability
In the cloud-based system that includes application and infrastructure, the
goal of availability is to provide the services to its users from anywhere and
at any time. But some circumstances occur in which the availability of data
cannot be sure. There may be unavoidable circumstances such as natural
tragedies, hence it is essential to know the data can be used, authenticated,
or restored by the data users. The cloud users must know about the security
actions that are to be taken by the CSP and must read the Service Level Agree-
ment. The availability of cloud services is obtained by using fault-tolerant sys-
tems in the cloud environment that can tolerate the failure of the server or
Cloud Security and Privacy Issues 53

cloud. Redundancy and hardening are two mechanisms that can be applied
to increase the availability the services in the cloud-based system. Threats to
availability such as the denial of services like network DNS, data, and appli-
cation. Liu [95] discussed a novel cloud Denial of Service form. The effect is
normally reliant on existing, processing capacity, memory, and bandwidth in
flooding attacks.

3.2.4 Authentication
Authentication is the method of creating assurance in the identities of the user.
Authentication guarantee levels must be suitable for the application sensitiv-
ity and information resources accessed. An identity management schemes can
be used to authenticate users and cloud services using credentials. A big chal-
lenge related to Identity Management (IDM) in the cloud is interoperability
limitations. Password-based authentication techniques have a genetic draw-
back and have important risks. The IDM must secure sensitive and private
data concerning to users. As cloud service providers have been increasing day
by day they support a standard SAML that is used to authenticate the users
before administering the data and application access. SAML offers mecha-
nisms that exchange information among cooperating concerns. The request
and reply messages of SAML are mapped on SOAP that uses the XML for-
mat. Chow et al. [96] discussed that authentication is needed before offering
access to Software as a Service application is beneficial due to centralized
monitoring.

3.2.5 Authorization
The sensitive information and services of the users can be accessed by unautho-
rized users. To restrict data access authorization must be used. The identity
management system should be employed. Authorization is used to control the
access of data. Authorization is the method that allows a system to regulate
access level to a specific authenticated user. There are benefits of centralized
access control and alleviate many security and management actions. Though
that cannot be desirable in a case populated with data mix-up, that can be
happened in the future [96]. This is risky to gain access te sensitive infor-
mation when authorizing third party service. Grobauer et al. [91] recognized
faulty or unsatisfactory authorization tests as expected vulnerable vectors.

3.2.6 Auditing
Auditing is the monitoring task to know what is going on in the cloud-based
system. An additional layer can work for audibility in the virtual machine to
monitoring the system. As it can monitor the complete access duration, hence
it is safer than that is made in software or applications. Audit approaches
investigate service conditions, monitor malware, accesses, and other actions,
54 Cloud Security: Attacks, Techniques, Tools, and Challenges

and record logs with an exhaustive explanation of what occurs are appropriate.
The audibility simplifies the method of recognizing the authorized party legal
action situation that can be important to the cloud stakeholders. Auditability
contains in acting tests series to discover if all suitable implementations con-
form. In cloud environments, the other layer above virtualized guest operating
systems will also agree that [97].

3.2.7 Access control


To minimize the security risk, access control features can be used that main-
tain the control on access to the resources. Access control is part of identity
management. The eXtensible Access Control Markup Language (XACML) is
the standard that can be used for resource access control in the cloud envi-
ronment. XACML focus on techniques to take authorization decisions that
complement the focus of the SAML on the resources for carrying the decisions
of the authorization and authentication among cooperating domains. The pro-
tocols or transport methods are not provided by the XACML and it also does
not describe the method of validating the credential of the users. The trans-
mission of the message among XACML units is vulnerable to attacks that can
be performed by malicious third parties such as replay, unauthorized expose,
loss, and alteration attacks.

3.3 Cloud Security Issues


The rapid growth of cloud services and increased demand in the organizations,
have raised various security concerns. If there exist any flaw in the implemen-
tation of any cloud service, it could be a big threat which could raise serious
security issues. The migration or transitioning of services to public cloud en-
vironment also causes the transfer of responsibilities to service provider to
protect the data, applications, information and infrastructure, etc. It removes
the direct control on the cloud resources and management operations from the
customer side. This makes the customers highly dependent on the cloud ven-
dor for the smooth functioning of services. Various security critical operations
like incident response, auto-updation, continuous monitoring of services, etc.
are now performed by cloud vendors. Hence, cloud customers have to trust
on the clouds vendors. However, it has been reported by various organiza-
tions such ENISA [49] that insider threats can also cause major harm to the
cloud resources. The 65% of insider threats can harm the reputation of an
organization and can affect the finances. Since, the customer’s data is in re-
mote servers, which is sharing its resources with other customers, the data
breach can also occur from the outside personnel. Although there exist var-
ious protection laws and regulations which provides the guidelines for joint
Cloud Security and Privacy Issues 55

FIGURE 3.2: Cloud security issues in cloud.

responsibilities so that proper cooperation between cloud vendors and cus-


tomers can be achieved.
However, due to lack of physical contact with the servers and cloud person-
nel, its again challenging to enforce such guidelines. There are various cloud
security issues at each of the layer of cloud environment. These are application
level, virtualization level, network level, data storage level, cryptographic key
management level, identity management, and role-based access control, SLA
and trust level, auditing, governance and regulatory compliance and cloud
and CSP migration level security. Application level security issues are con-
cerned with the vulnerabilities and threats present in the web applications,
web browsers and application layer protocols, etc. Network layer security is-
sues are concerned with the security vulnerabilities present with network layer
protocols, network servers, networking applications and services and any at-
tacking study that is targeted through network.
The virtualization layer security issues are more concerned with the threats
and vulnerabilities associated with the virtual machines and hypervisor. The
data storage level security issues are concerned with the storage layer attacks
and vulnerabilities that can be exploited by attackers. The cryptographic key
management is more or less concerned with the key management schemes
and their limitations. The identity management and role-based control issues
are mainly associated with vulnerabilities in customers’ identity schemes and
granting the resources to them. The SLA and trust level issues talks about
the flaws present in the implementation of same. The auditing and regulatory
policies are also major security threat as improper implementation of same,
can cause severe security breach. There are various security issues associated
with live migration of cloud services as well. Let us discuss each of the security
issue one by one. These issues are also shown in Figure 3.2.

3.3.1 Application level security issues


Application level security issues are concerned with the security of web appli-
cations running in the cloud to provide cloud services. The SaaS application
56 Cloud Security: Attacks, Techniques, Tools, and Challenges

has to be managed over the web (using a browser). The web application secu-
rity is tightly coupled with the security of web browsers. A web browser is a
platform independent program, used to access the cloud services (SaaS), web
2.0 or web pages. A web browser uses SSL/TLS protocol for secure transmis-
sion. The security loop holes in the web applications create the vulnerabil-
ities in the SaaS applications. The web applications are prone to a number
of threats such as cross-site scripting (XSS), SQL injection attack, broken
authentication, insecure transport layer protection, cross-site request forgery
(CSRF), etc.
The security at the application level states the use of software and physi-
cal resources for protecting applications such that the adversary cannot gain
control over applications. Application-level security issues are concerned with
the security of web applications running in the cloud to provide cloud services.
The SaaS application has to be managed over the web (using a browser). As
software-as-a-service and web applications are tightly-coupled with offering
services, cloud services availability and protection rely on Web browsers and
APIs security. A Web browser is a platform-free client program by which
clients can access the SaaS and web applications. The protocols TSL/SSL
can be used to authenticate and protected data transfer. It uses SSL/TLS
protocols for secure transmission and authentication of data. The web appli-
cations are prone to several threats such as cross-site scripting (XSS), SQL
injection attack, broken authentication, insecure transport layer protection,
cross-site request forgery (CSRF), etc. Hence, the adversary can breach the
security of cloud applications when they target Cloud authentication based
on the browser. Any adversary can gain access to XML tokens that are
authentication-related passes of another customer that is helpful to get ac-
cess services of the target. The XML encryption and XML signature is the
useful mechanism to improve the security of the browser [64]. Though, the
XML Signature Wrapping attack allows the adversary to modify the content
of the signed portion and invalidating the signature is not included. Some AWS
accounts may be taken over due to the cross-site XSS scripting vulnerabilities
that may be the cause of the XML signature wrapping attack.

3.3.2 Network level security issues


Network level security issues are concerned with the security of the cloud net-
work. One of the key issues at network level is unavailability of services. Denial
of Service (DoS) and Distributed Denial of Service (DDoS) are main threats
to service unavailability. These attacks cause inconvenience to customers and
prevent their access to the cloud services. HTTP-based and XML-based DDoS,
are called as Economic Denial of Sustainability (EDoS) which affect the pricing
model of cloud [98]. The key security issues at the network-level are autho-
rization, authentication, intrusion detection, vulnerability assessment, session
hijacking, etc. Some common attacks at network-layer are sniffing, scanning,
IP/MAC spoofing, and DNS poisoning, etc.
Cloud Security and Privacy Issues 57

The authorized clients of cloud who may be inside network adversary and
they can gain access the resources of the other customers. The internals is
privileged and they have more information than the external adversary. This
information is important to know about the network, security approaches,
and resources. Hence, this is convenient for an internal to perform the attacks
than external adversaries. The key security problems at the network level are
backdoor attacks, Internet protocol vulnerabilities, session hijacking. Many
cloud service providers such as Azure, Amazon, etc. use a firewall to cope up
with few challenges at the network level, but it cannot be helpful for inside
attacks. Some challenges can be solved using integration with network-based
IDS. Though, a network-based IDS must be set up for sensing not only external
but also internal intrusions. This must also be proficient in sensing intrusions
from encrypted traffic.

3.3.3 Virtualization level security issues


Virtualization level security issues are concerned with security of virtualiza-
tion layer. The major vulnerability is the multi-tenancy in which multiple
tenants share and utilize the cloud platform [60]. As the number of TVMs
running above Hypervisor increase, the security issues with the new TVMs
also increases. Maintaining the security policies of all TVMs is challenging
task. Malicious code running inside a TVM may try to gain root privilege of
the Hypervisor with an intention to take full access of the system. Security of
TVMs is one of the crucial concerns in the cloud environment. Once Hyper-
visor is compromised, all TVMs running on it will be under the control of the
attacker [99]. Infact, an improperly configured Hypervisor can fail to provide
proper isolation among TVMs, leading to disclosure of the tenants’ sensitive
data.
When more virtual machines are added to the hypervisor, the security
concern with new VMs increase as this is impossible to keep up with all
virtual machines. Therefore, it is hard to maintain the security of those VMs.
There may occur that a guest VM attempts to execute a malicious code on
the host to gain full control of the system so that other VMs access could be
blocked. The physical infrastructure is shared among multiple clients and if
one user is malicious, then he can be a threat to other users who are sharing
the same infrastructure. If an attacker can gain control over the hypervisor,
he can modify any guest operating system and gain control over the contents
moving through the hypervisor. The attackers can exploit the vulnerabilities
of the hypervisor and get control over the virtual machines. Some examples
of attacks are Subvit, DKSM, and Bluepill that are still an open challenge.

3.3.4 Data security


Data security is vastly an open research area. Data can be in transit (com-
municated via network channels) or in rest (stored in data centers). The
58 Cloud Security: Attacks, Techniques, Tools, and Challenges

vulnerabilities in the network protocols and/or poor encryption directly af-


fect the confidentiality and integrity of data. The data stored in the servers
needs to be physically and logically segregated and have control policies. A
few years back, Amazon reported that its Elastic Block Store (EBS) volumes
were trapped which affected its EC2 instances [100]. During data-in-transit,
the attack in the network will affect data integrity and confidentiality. The
major risks in the case of data-in-transit can be network protocols and bad
encryption approaches. Data linage refers to trace the path of the data and
this is essential for auditing in the cloud. This is a critical task for the provi-
sion of data lineage. As the data flow in a virtualized environment within the
Cloud is no longer linear, it complicates the task of mapping the data flow
to provide data integrity. Managing data integrity is a critical issue in the
Cloud, because of the shared environment. Data-at-rest refers to data that is
kept in cloud storage that requires the policies of the logical, physical, and
access control.
The major issue in data-at-rest in the cloud is losing control due to the data
accessing by unauthorized users in a shared environment. In-built encryption
schemes in storage are not able to avert unauthorized access as an attacker
can steal keys used for encryption/decryption. A lockbox method in which the
real keys are kept in a lockbox and there is another key for the lockbox that
can be used for the mentioned scenario but with the requirement of lockbox
key, it can cause key management the issue. Data remanence refers to data
which is left out after transfer or removal of VM. Data recovery is preferred
when data is lost because of some accidental damage. Data segregation is the
organization of the data of various users residing in the same location. En-
suring the isolation between the user’s data is an important security concern.
Data integrity ensures that there is no illegitimate modification in the user’s
data [101]. Data deduplication is an approach for removing duplicate copies
of data. Secure data deduplication is a major research concern [102]. Data re-
covery is another biggest challenging issue. There is the possibility for natural
tragedy or accidental harm to the storage devices and due to these reasons,
data can be destroyed and data availability can be at risk. Data location, find-
ing the data location is critical in the cloud environment, as data of the user
are placed dynamically from one country to another. This raises security and
data privacy risk as the data possessor can lose control of his data. In data
moving or data removing, data left out, known as data Remanence. Due to
it, there is less security threat such as the expose of critical information.

3.3.5 Identity management and access control


Identity management and access control issues are also important security
concern. Identity management (IDM) deals with identifying the entities in
cloud and controlling their access to resources. Information privacy and
sensitivity are highly dependent on the IDM policies and mechanisms in
cloud. Identity authentication and verifying them are the features of identity
Cloud Security and Privacy Issues 59

management. So, avoiding information accessing from unauthorized access is


a big concern in the cloud. Identify management is a wide administrative area
that has the responsibilities to recognize the individual entities, cloud entity,
managing resource access as per predefined policies [103].
As the customers’ credentials are transmitted via internet, it imposes a
great risk to user’s sensitive data. The issue is addressed by providing the
support for federation protocols such as Service Provisioning Markup Lan-
guage (SPML) or Security Assertion Markup Language (SAML) [104] to some
extent. SAML supports both authentication and authorization. Some other
protocols are created after SAML such as OpenID and OAuth2. OAuth2 is an
open standard for authorization and OpenID is an open standard for authen-
tication. The cloud-based IDM are prone to serious threats such as brute-force
attack, cookie replay attacks, eavesdropping attack, denial of service attack
and data tampering attack, etc. There is a need to design strong security
measures for IDM systems. There is a need of providing fine-grained access
control mechanisms for controlling access to user’s data. For example, Google
App uses eXtensible Access Control Markup Language (XACML) for autho-
rization and access control. Mon et al. [105] combined the Attribute-based
Access Control with Role-based Access Control (RBAC) to ensure the pri-
vacy and security of user’s data.

3.3.6 Improper cryptographic keys management


Improper cryptographic keys management leads to failure of cloud security
measures [106]. The cryptographic approaches such as cryptographic hash
function, digital signature and message authentication code, etc. are used to
authenticate the VM templates in cloud. They may prone to the bootstrap-
ping problem and hence, requires a strong security analysis. The key security
requirements for key management systems must be ensured. Some of them
are discussed as follows. The key management commands and data should be
secure from spoofing and illegitimate modification. The third party who does
key management should be authentic. All the secret and private keys should
also be protected from disclosure. The cryptographic mechanism employed for
protecting keys should be strong enough and robust from attacks.
There are a variety of security algorithms that can be used to confirm
data privacy and confidentiality from service providers. An encryption ap-
proach provides adequately robust security. ABE (Attribute-based Encryp-
tion) is a recently designed public key cryptographic approach that works in
a one-to-many manner, also known as fuzzy encryption. Public key encryp-
tion approaches save encrypted data on third-party servers and decryption
keys are distributed to authorized clients. Though, there are various limita-
tions in it, such as this is hard the private keys distribution efficiently to the
valid customers, scalability and flexibility problem and It is necessary for data
possessors to be online when data is encrypted or re-encrypted data, or pri-
vate keys are distributed. The Attribute-based Encryption approach reduces
60 Cloud Security: Attacks, Techniques, Tools, and Challenges

the mentioned confines by minimizing the internet overhead of communica-


tion and growing scalability, and fine-grained access control and flexibility for
huge-scale systems.

3.3.7 Service level agreement (SLA)


Service level agreement (SLA) and trust level security is another important
concern. The customers lose their control over data and programs which are
outsourced to cloud servers. Cloud service providers limit the visibility of
data location, network and system monitoring to customers which generate
the trust issues with service provider. It is very difficult to assure trust in
cloud environment. However, the use of signature techniques and advanced
cryptographic techniques can be used to deal with the trust issues to some
extent. SLA is another way to deal with the trust issues to certain limit. An
SLA is signed at the time of registration, describing the minimum performance
criteria a CSP should meet when delivering services. If a certain service fails
to meet the customers need or quality of service (QoS) do not meet the SLA,
cloud customers can lose their trust with the CSP [64].
The clients do not have total control over the cloud resources, but they
must ensure the availability, reliability, and resource quality offered by cloud
service providers after cloud migration, which is possible with a service level
agreement (SLA). With SLA, the clients can use cloud services securely, hence
it needs reputation administration. SLA comprises performance, coarseness,
clarity vs. complexity, and tradeoffs to fend client requirements and expec-
tations. The cutting-edge SLA schemes rely on clients’ feedback concerning
main issues such as Cloud interoperability and what is to be migrated. There
are various kinds of resources for cloud migration, such as applications related
to business, IT organization, deployment of the application. There are various
issues that are required to be addressed when business data is migrated. The
other challenge is interoperability, in which many clouds that have different
methods of client communications with the cloud. Interoperability purposes
of identifying the smooth data flow across cloud.

3.3.8 Regular audit and compliances


Regular audit and compliances to manage cloud resources must be done to
ensure whether internal and external processes are meeting the customer re-
quirements, regulations and laws. The policies should be monitored regularly.
There are some general governance standards that are also applicable to cloud
computing environment such as ISO/IEC 38500 – IT Governance [107], Con-
trol Objectives for Information and Related Technology (COBIT) [108], Cloud
Security Alliance (CSA) Cloud Controls Matrix [109], etc. The law and reg-
ulations of different countries are different. Therefore, some of the compli-
ance operate at country-level, or regional-level [64]. Some of the standards
are applicable to specific company or data. The Health Insurance Portability
Cloud Security and Privacy Issues 61

and Accountability Act (HIPAA) [110] requires the U.S. health care organi-
zation to maintain the confidentiality of protected health information (PHI).
Payment Card Industry Data Security Standard (PCI-DSS) [111] defines the
minimum security controls to secure the customer data. The Federal Informa-
tion Security Modernization Act (FISMA) [112] is a compliance framework
that enforces the protection of information systems and assets of all federal
government agencies and contractors. Sarbanes-Oxley Act (SOX) [113], a fed-
eral regulation, provides the standards for all U.S. publicly traded companies
to ensure security to all shareholders and public from fraudulent actions. It
maintains the information policies and prevent the illegitimate data tamper-
ing.

3.3.9 Cloud and CSP migration, SLA and trust level issues
One of the major issues in the cloud environment is trust level issues. As cloud
customers have control deficiency on resources, they have to depend on trust
schemes agreements in alliance with schemes that offer compensation. In a
heterogeneous environment, trust calculation is complex which is measured
by a social trust or human. Services may be sub-serving without awareness
of the customers. The customers have less visibility of system monitoring
and networks that is a big trust challenge. The staff who have authorized
access and can be malicious insiders in the organization and attacks could be
executed that can influence the privacy and confidentiality of other customer’s
data and also resources. There can be a trust problem due to public relations
lacking. Trust problems can be addressed by offering suitable measures for
the visibility of the observing system. There must be means for dealing with
the related risks. Access control vulnerability, Cross-site scripting, doubtful
configuration, and storage are few examples of threats.
Service Level Agreements (SLA) is an agreement between the service
providers and their clients that documents the services provided by the
providers and states the service standards. Most SLAs attention to contracts
concerning the attempt that will be performed by Software-intensive systems
(SIS) providers when the problem takes place. Though, no assurances are
stated concerning the service’s efficiency for business processes of the client
and their business purposes. The issue of availability, unintended resource al-
location, deceptive computation, and loss of data are, however, issues that can
tamper SLAs [114]. Cloud and CSP Migration, when the users migrate to the
cloud, they move their complete setup to the cloud. Where the provider will
maintain the computing environment. Though, that is a difficult procedure
for several organizations since they had to leave off a specific level of control
to the cloud provider. Also, the transfer in itself is a challenge since there are
certain aspects in it that the user has to be attentive. When an organization or
cloud customer is entering into the cloud or shifting from one CSP to another
CSP, the following migrations will be considered: Data (application) migra-
tion and Cloud migration. Migration is one of the challenging research areas.
62 Cloud Security: Attacks, Techniques, Tools, and Challenges

It involves the secure transmission of the tenants’ data with strong application
and network security measures together with governance compliance. There
are many questions that need to be resolved with tenants such as What tech-
nology is used in migration? Is the CSP migrating the data with appropriate
policies in place? Is the migrated data secure? Is the migration secure from
attackers? etc [115].

3.3.10 Hardware-level security issues


The hardware layer is the lowest level in the stack. The hardware or phys-
ical level is employed in data centers. At the hardware level, all hardware
resources such as physical servers, switches, routers, cooling, and power sys-
tem are maintained. The hardware layer can also be termed as the physical
or server layer. The applications are used by the service providers to observe
memory, CPU loads, storage, etc. The users can interact only with the virtu-
alized environment. The adversaries can exploit the hardware layer and can
gain physical access to the system. They break the security at the hardware
layer and perform attacks on the data integrity and privacy that exist on the
secondary storage and main memory. Trusted Platform Module (TPM) may
be altered to dump the data of the internal registers and sensitive data can be
fetched like the secret key. The adversary obtains a message that is exchanged
between TPM and authorized user and after that message can be misused ma-
liciously. Attacks such as side-channel can be performed. The access to the
physical resources such as network devices, storage, and processing servers
must be constrained physically only authorized persons must be allowed with
security authorization to manage the actions. Some hardware-based solutions
[116] for cloud focus more on hardware security.
Researchers are working in different domains of security as discussed above
to address the security issues. We have considered intrusion detection as one
of the key security aspects to detect attacks at different layers in cloud. The
security issues are briefly described in Table 3.1.

3.4 Security Requirements for Privacy


Privacy is a more critical issue than security due to dealing with the public.
The cloud service provider has the opportunity to examine and escapade large
volume of personal data one example is, the service provider could know the
number of persons who are suffering from cancer due to showing their interest
to search chemotherapy which could be shared to the organization related to
the insurance that could use this information to categorize a person as higher-
risk for greater premium. We discuss some security requirements below:
TABLE 3.1: Security issues

Security Issues Sub Category Threat/Vulnerabilities Solution


Untrusted hypervisor element,
hypervisor-based rootkits,
Virtualization level Monitoring virtual machines Hypervisor inspection, Better authentication and
security Issues isolation, interposition, authorization.
[117, 101, 91] zero-day attacks, VM escape Strong isolation between
Side-channel attacks, VMs.
VM hopping, Use of secure hypervisor.

Cloud Security and Privacy Issues


[118, 119] cross-VM attacks, Monitor activities at the
VM-level
Malware injection, hypervisor.
Covert-channel attacks,
[91] VM reset vulnerabilities
Packet sniffing and spoofing,
Impact of network security
Virtualized networking devices on virtual networks,
[120] Virtualized communication
channels
VM sprawl, Image stealing
and code injection,
Managing images
[91] Large-sized images
cryptographic overhead
Live VM migration MITM attack,
Mobility
VM mobility, VM cloning
VM rollback,
Malware Malware escape approaches,
Malware expanding to the VMs
[67] Cost Service price associated issues, Cost management based on
Not giving the particularized SLA overcomes
Resources
quantity of resources, these problems and
Service Level Agreement
Risk computation management gives an effective solution
Risk management to control the resources allocation for controlling the cost of
based on SLA allocated resources
based on the hosted

63
application’s defined
policies.
64
TABLE 3.1: Security issues

Security Issues Sub Category Threat/Vulnerabilities Solution


Customers waiting in line
Waiting time for an extended duration

Cloud Security: Attacks, Techniques, Tools, and Challenges


for using service
Service Performance may be affected
due to the high workload.
Performance The clients will not be fulfilled
due to bad performance and the
revenue will be affected
Applications must perform in
the care of their consumers and
SLA negotiation
cloud services must be
available in SLA negotiation.
Cloud and
Cross-site scripting,
CSP Migration, Advanced cryptographic
Service provider, cloud access control weaknesses,
and techniques and signature
migration and Trust insecure storage,
Trust level issues techniques
and insecure configuration
[121]
SQL Injection attack, EDoS, Check service integrity
Application Level Cross-site scripting, using a hash function.
Security Issues Unauthorized Accessing Cookie Poisoning, Google Hacking, Web service security.
[64, 122] Hidden field manipulation, Use secure web browsers
Backdoor and debug options and APIs.
The adversary in the network
Data Integrity,
affects the confidentiality and
Data security Confidentiality and lockbox approach
the integrity of data,
Access
non-authorized user accesses
TABLE 3.1: Security issues

Security Issues Sub Category Threat/Vulnerabilities Solution


Data should be transmitted
via a secured channel and
fine-grained.
Identity management [123] Authentication and
Identity and access control Signature Wrapping Attack
and access control authorization
techniques, hierarchical
identity-based

Cloud Security and Privacy Issues


cryptography (HIBC)
IPsec Implement security
Eavesdropping, Port Scanning,
Data confidentiality policies.
Network Level Clearance of Old ARP
Replay attack, Sybil attack,
Security Issues [64, 122] addresses from the cache.
Proper configuration,
Reused IP address, DDoS attack,
Data availability MD5/TTL protection
Restriction of ICMP and
BGP Prefix Hijacking,
SYN packets on the
DNS Attacks,
router interfaces.
Domain name system
Data Integrity Sniffer Attack, DoS attack
security Extensions

65
66 Cloud Security: Attacks, Techniques, Tools, and Challenges

3.4.1 Fine-grained access control


Fine-grained access control commonly used method in the cloud environment. Using
this mechanism every data entity is assigned its own access control policy. Every user
can access only its data for which he is allowed and he should not be able to access
data for which he is unauthorized. One who wants to access the data entity requires
to provide its authorizations to a policy enforcer (not data owner in the cloud).
For example, when an organization keeps data in the cloud, the organization allows
only some authorized persons who are related to the projects, can see the data. The
access control policies and the authorizations may disclose some information that is
not allowed for the policy enforcer. To control the access to susceptible data or code
fine-grained access controls must be accessible. In cloud computing, Cryptography is
a good option to attain fine-grained access control [124]. In these schemes, Attribute-
Based Encryption (ABE) is applied for data encryption. The decryption only can be
performed by those who have the required attributes. These types of access control
schemes are created by the storage service provider to store the data. To cloud
resources control accessing, eXtensible Access Control Markup Language (XACML)
standard is used for access policies. Some examples using XACML are GoogleMaps
and salesforce, these providers use it for access control and authorization selection.
The one challenge with the fine-grained access control methods is the policy enforcers
can see partially the access control policies.

3.4.2 Privacy-preserving
Cloud computing is very powerful as compared to personal computing but the cloud
also comes with new security issues to the data of the users. Data security and user
privacy meet with various threats. Lots of work have been done to preserve the
privacy of the user. The privacy information of users such as user credentials should
not be revealed to the cloud. To understand the powerful and privacy-preserving
service of data sharing in the cloud environment, some requirements must be attained
such as the data possessor must be able o take decide that who can access his data in
the cloud. Another is, the user’s privacy must be secured in the cloud and lastly, the
data must be accessed by low computing devices such as tablets and smartphones,
etc. Dynamic accumulator-based technique for privacy-preserving access control has
proposed by Slamanig [79], in which permissions read, delete, write are given by
using Access Control List (ACL) to other users who can do tasks on outsourced
data elements with mentioned permissions. With this technique granting or denying
access can be decided. The user of the data can allow or gain access permissions
to/from other users, although the Cloud service provider cannot recognize these
users. The drawback of this technique is that if the owner of the data wishes to
repeal permission from the user, then that user has to repeal given permissions from
other users. This is complex computation to manage the chain of users.

3.4.3 Collision resistance


No user should not be allowed to share her/his private key user. Users cannot de-
crypt encrypted data by merging their features because each feature is associated
with a random number or polynomial. Merging features from several sets of fea-
tures within a specified key is an actual issue. Avoiding collision by ignoring users
Cloud Security and Privacy Issues 67

from merging features from several keys is another issue. Park et al. [125] pre-
sented Sec-DPoS a deduplicatable proof of storage system which is based on the
symmetric key that guarantees confidentiality with brute-force attack resilience. It
supports symmetric key cryptography-based integrity auditing of the outsourced
data. They described some building blocks such as collision-resistant hash function,
pseudorandom function, key derivation function, and pseudorandom permutation,
authenticated encryption, deterministic symmetric encryption.
They have four protocols in their system. Key and index distribution protocol,
initial upload protocol, and the Deduplication Protocol , and finally they discuss the
integrity auditing protocol. In key and index distribution protocol, a preliminary
uploader creates a possible response set for a file to audit Integrity with the help
of a message-derived key that is distributed from the management server. The file
and possible response set is uploaded. The other customer who is using the same file
then he can use the possible response set created by the previous uploader. In the
initial upload protocol, it is considered that the uploaded file is new data not earlier
uploaded. Therefore, the customer creates the possible response set which will be
used in the integrity auditing and another possible response set is created by the
cloud server that will be used for ownership check. In the deduplication protocol, the
deduplication procedure considers that the uploaded file is a duplicated data from
an earlier upload. Therefore, the cloud server must check that the customer has the
file. And in integrity auditing protocol, the customer who is the file owner then he
can audit outsourced data’s integrity at any time.

3.5 Privacy Issues in Cloud


Cloud computing uses virtualization technology, so, the personal information of the
users may be dispersed in several virtualized data centers. When users access cloud
services, they may disclose private information. The major goal of cloud security
is securing data privacy. It is hard to avoid threats in a cloud environment due to
its sharing environment that relies on a shared infrastructure. Therefore, data will
be unprotected from unauthorized access. There are some privacy-related issues are
discussed below.

3.5.1 Defining roles to actors


In the cloud environment, there are many types of the actor with different privilege.
The main actor is the owner of the data, which can be called the data owner. An-
other important factor is the cloud service provider who can process private data like
transfer, storage, research duplicate, etc and able to perform undeclared activities
that can be a threat to data privacy like they can reveal private data by reading
and also they could obtain user’s data that can be useful for big financial advan-
tage. Cloud-based services actors that may require to access private information to
perform some actions and is the owner of the service who have the access to the
database from where he can access the private information of the users [126].
68 Cloud Security: Attacks, Techniques, Tools, and Challenges

Some other actors are cloud auditor, cloud agent, and cloud carrier. The cloud
carrier is a mediator that makes available connectivity and transportation of cloud
services from Cloud service providers to cloud Customers. The cloud broker is the
individual who controls the routine, performance, and provision of cloud services and
negotiates associations between service providers and cloud customers. The cloud
auditor is the entity that can perform an independent evaluation of cloud services,
performance, information system operations, and cloud security employment.

3.5.2 Compliance
Compliance states the responsibility of the company to work in agreement with ex-
isting standards, rules, and regulations. Different countries have their security and
privacy rules and regulations that make compliance very complex and it becomes
a critical issue in the cloud. Data location is a big challenge for the organization
in compliance. The Service Level Agreement is important in the cloud base system.
This is the agreement that is signed by the communicating parties that contain rule
and regulation and all service information. There are various compliance issues, such
as data sites or laws and regulations. Data site is the general compliance challenge
encountered by the companies [127]. The organizations that use an internal com-
puting center permit to design their computing environment.
Hence they have the detail information about the data storage and what se-
curity is being used, whereas, in various cloud computing services, data are ware-
housed in many physical sites, and complete information about the site of the data
of the companies is not available or not open for the service users. This condition
makes it problematic to determine whether adequate protections are in location and
whether legal and governing compliance needs are met, such as NARA regulations
that have ability requirements federal records storage and instruct the least height
above and move away from a flood plain. The other issue is law and regulations, for
U.S. Federal agencies, the key privacy and security compliance involves the Office
of Management and Budget (OMB), Clinger-Cohen Act of 1996, 1974 privacy Act,
2002 E-Government Act like FISMA .

3.5.3 Legal issues and multi-location issues


The cloud business model adopts Service Level Agreement to specify the contracts
over a particular service. This service might be SaaS, PaaS, or IaaS. The Service
Level Agreement is contracted to legally decide the cost per service. Therefore, there
can be an indirect subjectivity on the attainment of these contracts. The cloud ac-
tions increase several legal and challenges. The most important is the multi-location
specific properties in cloud computing. Cloud service providers have the data centers
in which they have sufficient resources to be spread worldwide. Irrespective of that,
few countries do not permit data to leave their borders. Due to this situation, many
challenges arise. If data moves beyond the boundaries, it is difficult to know due
to which country jurisdiction data crashes. If it happens, it is difficult to declare to
which area legal jurisdiction can reach to discover liable parties. It contains evaluat-
ing that government departments are able to access the data outside the boundaries
of the country in which information was created in the first place.
Cloud Security and Privacy Issues 69

3.5.4 Privacy issues on CIA


Privacy of the data has issues on integrity, authorized access, or availability. When
information is copied or stolen by an unauthorized user , this condition is known as
a confidentiality loss. When information is changed in an unexpected means, this
condition is known as integrity loss. When information is missing or not accessible,
this condition is known as availability loss. The data integrity provides the surety
that data has not been modified during communication. Authorized access avoids
data from attacks whereas backups and copies permit access of data properly even
technical issues. Data is communicated at the common network backbone. There-
fore, attackers can position concealed proxy applications between the Cloud service
provider and customer to look for session detail and login credentials information
of login. Attackers may do IP-spoofing or packet sniffing and they can get access to
sensitive information.
Cloud services must be available all the time. In Infrastructure-as-a-service,
the availability of hardware and logical resources such as computing servers and
databases are required to run processing operations of programs and operations re-
lated to obtaining the data, respectively. Subashini et al. [101] discussed that a
multi-tier design must be embraced that is reinforced by a load-balanced farm of
application instances operating on various servers. This method lets DoS attacks
resiliency by developing software and hardware breakdown measures in every tier.

3.5.5 Protection of the data


In the public cloud, the gathered data exists in the shared environment. Organiza-
tions keep sensitive data in the public cloud. There is a requirement of mechanisms
in place so that the data access can be controlled and the data is stored securely.
In today’s era, data is currency and cloud storage is bank safe. Data is becoming
gradually favorite target because of collective values [128]. The companies that have
gathered data is at high risk and may cause DoS, as an accidental loss from an attack
targeted against the companies. The physical attacks against the cloud resources of
prestigious companies have side effects. For data security, data sanitization and iso-
lation of data approaches can be used. Data can be found in various forms such as
application development in the cloud and data can be scripts, programs, etc.
For installed applications, it contains records and other data produced or used
by the applications. The access control methods are one way to keep data away
from unauthorized clients. Furthermore, the method is encryption. Access control
can be client’s identity-based authentication that is a critical challenge in the cloud.
Encryption is the only method to ensure the security of the data as less physi-
cal control over data storage. The data sanitization performs that a cloud service
provider implements have apparent security effects. Sanitization contains erasing
data from storage by overwriting or demagnetizing, or destroying media itself to
avoid unauthorized exposure of data.

3.5.6 User control lacking


The private data are warehoused in the public cloud in distant machines that are
controlled by the cloud service provider. There is a need for transparency for storage
location, copies of data, and data processing. Sometimes it is almost impossible to
70 Cloud Security: Attacks, Techniques, Tools, and Challenges

get to know about privacy violations and who did them. In the cloud computing
environment, computation and customer’s sensitive data sharing do not have suf-
ficient control, heading to threats such as stolen, exploit, or unauthorized access
[129]. The software-as-a-service platform provides control of the data to the service
provider, so the data control and visibility will be restricted. The attacker can steal
or corrupt the data as users do not have control over the cloud. Moreover, there is no
data transparency, for instance, data location, ownership of data, and data usage.
Though data disclosure can occur during data moving, various countries have the
law for data accessing if they suspect. A user control can be either a legal problem
or one raised by the user himself.

3.5.7 Data movement


Data movement can occur between countries and local rules. Hence, it is another
big challenge in the cloud environment. Data invisibility can be the solution for the
privacy and security of the data of users. Fatema et al. [130] presented a . This
model provides visibility into the place of data. XML-based policies are used in this
model. The one drawback is a single point of failure. The central controller is inside
the cloud and manages all data accesses and also data movement. If the accesses are
made inside the same cloud, it can be the bottleneck. They consider inter-cloud data
transfer, but every cloud needs to be managed own policy archive. The Directive
of the European Union to secure the data (95/46/EC) related to moving personal
data to the third countries came into existence in 1998 that permits moving sensitive
data to third countries. The regulation and directives of the European Union are
used to tie its member states. As an outcome, the United States Department of
Commerce proposed a contract to permit the United States-based organization to
share private data with their European complements without disruptions.
Some other privacy issues such as resource privacy sharing, sharing resource
privacy in the cloud environment with protecting users is a significant issue. Data
isolation can be used as a solution to this issue in which isolation is provided for each
user’s data, and one more big privacy issue is the data source nature as data comes
from various sources. So, it is necessary to secure and control the data carefully,
and only authorized users can access the data. Privacy of users must be controlled
when data is gathered, warehoused, or carried. Data gathering from various sources
is challenging in cloud computing because it exposes sensitive information of the
users. To attain an adequate level of privacy in cloud, various problems need to
be discussed, such as inadequate customer control over their data, data revealing
in-transit across the cloud, illegal secondary storage of delicate data, uncontrolled
data propagation, and dynamic provision of legal difficulties [131]. One other issue
is the advanced service level agreement method relies on the customers’ feedback
concerning significant challenges such as Cloud interoperability, data, resources, and
processes that can be moved to the cloud.

You might also like