0% found this document useful (0 votes)
88 views17 pages

Understanding Threat Agents in Cloud Security

Cloud security mechanism and threat agents
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
88 views17 pages

Understanding Threat Agents in Cloud Security

Cloud security mechanism and threat agents
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

THREAT AGENTS

Preetha V, AP/CSE, SRIT


6.2. Threat Agents
A threat agent is an entity that poses a threat because it is capable
of carrying out an attack.
Cloud security threats can originate either internally or
externally, from humans or software programs.
Figure 6.3 illustrates the role a threat agent assumes in relation to
vulnerabilities, threats, and risks, and the safeguards established
by security policies and security mechanisms.

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT
Figure 6.3. How security policies and security
mechanisms are used to counter threats,
vulnerabilities, and risks caused by threat agents.
Anonymous Attacker
An anonymous attacker is a non-trusted cloud service consumer
without permissions in the cloud (Figure 6.4).
It exists as an external software program that launches network-level
attacks through public networks.
When anonymous attackers have limited information on security
policies and defenses, it can inhibit their ability to formulate effective
attacks.
Therefore, anonymous attackers acts like bypassing user accounts or
stealing user credentials, while using methods that either ensure
anonymity or require substantial resources for prosecution.

Preetha V, AP/CSE, SRIT


Malicious Service Agent
A malicious service agent is able to intercept and forward the network traffic
that flows within a cloud (Figure 6.5).
It typically exists as a service agent (or a program pretending to be a service
agent) with compromised or malicious logic.
It may also exist as an external program able to remotely intercept and
potentially corrupt message contents

Preetha V, AP/CSE, SRIT


Trusted Attacker
A trusted attacker shares IT resources in the same cloud environment as
the cloud consumer and attempts to exploit legitimate credentials to target
cloud providers and the cloud tenants with whom they share IT resources
(Figure 6.6).
Unlike anonymous attackers (which are non-trusted), trusted attackers
usually launch their attacks from within a cloud’s trust boundaries by
abusing legitimate credentials or via the appropriation of sensitive and
confidential information.

Preetha V, AP/CSE, SRIT


Trusted attackers (also known as malicious tenants) can use cloud-based IT
resources for a wide range of exploitations, including the hacking of weak
authentication processes, the breaking of encryption, the spamming of e-mail
accounts, or to launch common attacks, such as denial of service campaigns.
Malicious Insider
Malicious insiders are human threat agents acting on behalf of or in relation to
the cloud provider.
They are typically current or former employees or third parties with access to
the cloud provider’s premises.
This type of threat agent carries tremendous damage potential, as the malicious
insider may have administrative privileges for accessing cloud consumer IT
resources.
Preetha V, AP/CSE, SRIT
6.3. Cloud Security Threats
Traffic Eavesdropping
Traffic eavesdropping occurs when data being transferred to or within a
cloud (usually from the cloud consumer to the cloud provider) is passively
intercepted by a malicious service agent for illegitimate information
gathering purposes (Figure 6.8).
The aim of this attack is to directly compromise the confidentiality of the
data and, possibly, the confidentiality of the relationship between the cloud
consumer and cloud provider.
Because of the passive nature of the attack, it can more easily go undetected
for extended periods of time.

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT
Malicious Intermediary
The malicious intermediary threat arises when messages are intercepted and
altered by a malicious service agent, thereby potentially compromising the
message’s confidentiality and/or integrity.
It may also insert harmful data into the message before forwarding it to its
destination.
Figure 6.9 illustrates a common example of the malicious intermediary
attack.

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT
Denial of Service
The objective of the denial of service (DoS) attack is to overload IT
resources to the point where they cannot function properly.
This form of attack is commonly launched in one of the following ways:
• The workload on cloud services is artificially increased with imitation
messages or repeated communication requests.
• The network is overloaded with traffic to reduce its responsiveness and
cripple its performance.
• Multiple cloud service requests are sent, each of which is designed to
consume excessive memory and processing resources .

Successful DoS attacks produce server degradation and/or failure, as


illustrated in Figure 6.10.

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT
Insufficient Authorization
The insufficient authorization attack occurs when access is
granted to an attacker erroneously or too broadly, resulting
in the attacker getting access to IT resources that are
normally protected.
This is often a result of the attacker gaining direct access to
IT resources that were implemented under the assumption
that they would only be accessed by trusted consumer
programs (Figure 6.11)

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT
Virtualization Attack
Virtualization provides multiple cloud consumers with access to IT
resources that share underlying hardware but are logically isolated from
each other.
Because cloud providers grant cloud consumers administrative access to
virtualized IT resources (such as virtual servers), there is an inherent risk
that cloud consumers could abuse this access to attack the underlying
physical IT resources.
A virtualization attack exploits vulnerabilities in the virtualization platform
to ensure its confidentiality, integrity, and/or availability.
This threat is illustrated in Figure 6.13, where a trusted attacker
successfully accesses a virtual server to compromise its underlying
physical server. With public clouds, where a single physical IT resource
may be providing virtualized IT resources to multiple cloud consumers,
such an attack can have significant repercussions.

Preetha V, AP/CSE, SRIT


Preetha V, AP/CSE, SRIT

You might also like