Cloud security issues & challenges – public cloud Literature Review By: Kunal & Joe
What is public cloud?
Cloud architecture
Who offers cloud services?
hypothesis public cloud could pose a huge potential security risk for the general public.
Importance – public cloud Provides huge benefit for the general public. Reduced excessive high cost of running, purchasing and maintenance by companies. Pay-per-use model at a very low cost. IaaS, PaaS and SaaS are provisioned from a pooled of shared resources that are accessible over the internet.
Potential review of security threats & challenges A thematic review on the security issues and privacy in the public cloud.
Issues highlighted Security & Privacy Infrastructure & Data Management Interoperability across different service providers. Ghanam, Y., Ferreira, J., & Maurer, F. (2012)
Privacy concerns Security standards in SLA Access controls – accounts/services in cloud Extensive use of virtualization – brings security concerns to tenants Ouahman, A. A. (2014)
challenges Outsourcing – tenants no longer retain physical control on hardware, software and data. Multi-tenancy – A shared physical machine that holds different tenants data. Therefore exploitation can occur. Massive data & intensive computation – traditional security mechanism may not suffice the new security requirements. That is due unbearable computation/communications overhead. Mosca, P., Zhang, Y., Xiao, Z., & Wang, Y. (2014)
Security concerns Cloud availability – under investigated CIA (Confidentiality, Integrity & Confidentiality) – the CIA triad has not yet been formally adapted to the cloud Khansa, L., & Zobel, C. W. (2014)
Legal issues Lack of uniformity – in the terms and the provider contracts and SLA (Service level Agreement) Information Policies (Private Industries) – governments have not provided a uniform & homogenous information policy regime where private industries are given clear guidance as to multi-jurisdictional risk, cyber terrorism risk, outage risk. Teng, K. (2012)
Security measures Malware detection & prevention Secure virtual machine managers Cloud resilience – the ability for the system to recover & continue to provide services after a loss of software and hardware occurs. Denz and Taylor. (2013)
Take - away As presented by the different reviews, there exist multiple challenges and issues regarding cloud. However, it is up to the cloud service provider to pick from a grab back of techniques to secure their infrastructure. It can also be deduced that some issues and challenges that practitioners consider important need further studies and research. In future, as a cloud service consumer it is advisable to conduct a thorough & diligent risk assessment of the potential threats of low to high risk inherent in the cloud.
references Alam, B., Doja, M. N., Alam, M., & Malhotra, S. (2013). Security issues analysis for cloud computing. International Journal of Computer Science and Information Security, 11(9), 117-125. Retrieved from http://search.proquest.com/docview/1468454405?accountid=28103 Data security; global public cloud market 2011-2014 report discusses the various challenges faced by this market including the growing concern for data security. (2012). Computers, Networks & Communications, 339. Retrieved from http://search.proquest.com/docview/929252047?accountid=28103 Denz and Taylor. (2013). A survey on securing the virtual cloud, Journal of Cloud Computing: Advances, Systems and Applications, 2:17 Retrieved from http://www.journalofcloudcomputing.com/content/2/1/17 Ghanam, Y., Ferreira, J., & Maurer, F. (2012). Emerging issues & challenges in cloud computing- A hybrid approach. Journal of Software Engineering and Applications, 5, 923-937. Retrieved from http://search.proquest.com/docview/1282113531?accountid=28103 Gonzalez et al. (2012). A quantitative analysis of current security concerns and solutions for cloud computing, Journal of Cloud Computing: Advances, Systems and Applications, 1:11 Retrieved from http://www.journalofcloudcomputing.com/content/1/1/11 Khansa, L., & Zobel, C. W. (2014). ASSESSING INNOVATIONS IN CLOUD SECURITY. The Journal of Computer Information Systems, 54(3), 45-56. Retrieved from http://search.proquest.com/docview/1526662556?accountid=28103 Mosca, P., Zhang, Y., Xiao, Z., & Wang, Y. (2014). Cloud security: Services, risks, and a case study on amazon cloud services. International Journal of Communications, Network and System Sciences, 7(12), 529-535. Retrieved from http://search.proquest.com/docview/1645562992?accountid=28103 National Institute of Standard and US Department of Commerce Technology, "The NIST Definition of Cloud Computing," 12 October 2012. http://csrc.nist.gov/publications/nistpubs/800-145/SP800-145.pdf Popovic, K., & Hocenski, Z. (2010, May). Cloud computing security issues and challenges. In MIPRO, 2010 proceedings of the 33rd international convention (pp. 344-349). IEEE. Teng, K. (2012). CLOUD COMPUTING: LEGAL AND PRIVACY ISSUES. Journal of Legal Issues and Cases in Business, 1, Retrieved from http://www.aabri.com/jlicb.html