BTCE | 5th Sem
SPC SubjectExtra Questions

SPC Unit 4: Assignment Q/A

Generated and Prepared By Thiruselvan (ThiruXD)

1. Proactive Activity Monitoring

  • Definition: Proactive activity monitoring is the continuous, real-time observation, collection, and automated analysis of cloud infrastructure, workload, and user behaviors to identify operational anomalies, misconfigurations, and security threats before they cause outages or breaches.
  • Activities Monitored:
    • API Call Telemetry: Tracking control-plane actions, such as modifications to IAM roles, security groups, or storage bucket access policies.
    • User Authentication and Session Behavior: Monitoring login attempts, privilege escalation actions, and concurrent sessions across different geographical locations.

2. Difference Between an Event and an Alert

ParameterEventAlert
DefinitionAny observable occurrence or state change within a cloud system, network, or application.A prioritized notification triggered when an event (or sequence of events) violates a predefined threshold or security rule.
ActionabilityInformational; does not inherently require human intervention or remediation.Actionable; requires immediate assessment, investigation, or incident response.
ExampleA user successfully logs in to the AWS Management Console at 09:30 AM via MFA.Ten consecutive failed administrative logins within two minutes followed by a successful login from a previously unrecorded foreign IP address.

3. Incident Response & Lifecycle Stages

  • Definition: Incident response (IR) is the structured methodology and set of technical procedures an organization uses to detect, investigate, contain, remediate, and recover from cybersecurity incidents and security compromises.
  • Lifecycle Stages (NIST SP 800-61 / ISO 27035 standard):
    1. Preparation: Establishing incident response policies, communication channels, trained response personnel, and monitoring tools.
    2. Detection and Analysis: Identifying signs of compromise, evaluating indicators of attack (IoAs), and determining the scope and severity of the incident.
    3. Containment, Eradication, and Recovery: Isolating affected cloud workloads, removing malicious artifacts or access vectors, and safely restoring systems to normal production status.

4. Quality of Service (QoS) & Key Metrics

  • Definition: Quality of Service (QoS) is the measurement of the overall performance, availability, and reliability delivered by a cloud service provider or workload against agreed-upon performance baselines or Service Level Agreements (SLAs).
  • QoS Metrics:
    • Network Latency / Round-Trip Time (RTT): The time delay incurred for a data packet to travel from the user to the cloud endpoint and back.
    • Throughput / Transaction Rate: The volume of data transferred or transactions processed per unit of time (e.g., requests per second, IOPS, or Mbps).

5. Auditing in Cloud Systems & Key Purposes

  • Definition: Cloud auditing is the systematic, independent evaluation and verification of system activity logs, configurations, operational processes, and access records to assess system integrity, security posture, and compliance.
  • Purposes:
    • Regulatory & Standards Compliance: Demonstrating verification of data governance requirements mandated by frameworks such as SOC 2, ISO/IEC 27001, PCI DSS, or GDPR.
    • Forensic Investigation & Accountability: Establishing non-repudiation by providing an immutable trace of which entity performed what specific action, when, and from where.

6. SIEM & Key Security Functions

  • Definition: Security Information and Event Management (SIEM) is a centralized security software solution that aggregates, correlates, and analyzes log data and events from across multi-cloud environments, networks, endpoints, and applications to deliver real-time threat intelligence.
  • Functions:
    • Log Ingestion & Normalization: Collecting disparate log formats (JSON, Syslog, CEF) from multiple services (e.g., CloudTrail, VPC Flow Logs, Azure Monitor) and parsing them into a standardized schema.
    • Cross-Source Event Correlation & Automated Threat Detection: Applying statistical rules, anomaly models, and machine learning to link separate events into single security alerts.

7. Malicious Traffic & Examples

  • Definition: Malicious traffic refers to any network communication, packet stream, or API request transmitted across internal or external networks intended to exploit vulnerabilities, disrupt service availability, exfiltrate data, or compromise system control.
  • Examples:
    • Distributed Denial of Service (DDoS) Floods: Volumetric SYN flood or UDP reflection attacks targeting cloud ingress load balancers to exhaust compute and network resources.
    • Command-and-Control (C2) Communication: Encrypted beaconing traffic originating from an infected virtual machine instance reaching out to a known adversarial IP address or domain.

8. User Management vs. Identity Management

  • User Management:
    • The administrative and operational process of onboarding, maintaining, and offboarding individual user accounts across specific applications or operating systems.
    • Encompasses credential lifecycle management, password resets, assigning user attributes, adding users to department groups, and activating or disabling access accounts.
  • Identity Management:
    • The broader governance and architectural framework that defines, establishes, and verifies digital identities across distributed cloud systems.
    • Focuses on directory integration (e.g., Azure AD/Entra ID, Okta), Single Sign-On (SSO), identity federation (SAML 2.0, OIDC), attribute assertions, and cryptographic identity verification for both human users and non-human identities (workloads, microservices, API service principals).

9. Indicators of Unauthorized Access in a Cloud System

  1. Anomalous Login Geographies and "Impossible Travel": Concurrent or rapidly successive authentication events for the same account originating from geographically distant physical locations (e.g., logins from Tokyo and Frankfurt within 20 minutes).
  2. Unscheduled Control-Plane Modifications: Sudden creation of high-privilege IAM roles, generation of new permanent access keys, or modifications to root/admin security policies during non-business hours.
  3. Unexpected Security Group / Firewall Rules: Opening administrative ports (such as SSH port 22 or RDP port 3389) directly to public CIDR blocks (0.0.0.0/0) without an associated change ticket.
  4. Sudden Spikes in API Enumeration Activity: High-volume execution of discovery API calls (e.g., Describe*, ListBuckets, GetSecretValue) by an account or instance profile that historically executes a minimal set of commands.

10. Tamper-Proof Audit Logs: Importance and Protection Methods

  • Importance: Audit logs serve as the ultimate source of truth during forensic investigations, breach attribution, legal litigation, and compliance audits. If threat actors can alter, truncate, or wipe log trails, they destroy non-repudiation, conceal unauthorized access paths, and invalidate regulatory compliance standing.
  • Protection Methods:
    • Write-Once-Read-Many (WORM) Storage & Object Locking: Enforcing immutable storage compliance mode (e.g., AWS S3 Object Lock, Azure Immutable Blob Storage) that prohibits record alteration or deletion even by root or subscription owners until retention periods expire.
    • Cryptographic Hashing and Digest Validation: Generating automated SHA-256 log digest files containing cryptographic hashes of past logs to continuously verify chain-of-custody and instantly detect mid-stream log tampering.
    • Segregated Account Storage: Routing all enterprise audit logs out of operational workloads into a dedicated, isolated logging cloud account with strict, highly restricted IAM read-only access.

11. Detecting Malicious Traffic in a Cloud Network

Malicious network traffic is identified through a multi-layered combination of signature-based, anomaly-based, and flow-level inspection techniques:

  • VPC Flow Log Analysis: Ingesting source/destination IPs, protocol numbers, packet counts, and accept/reject flags to identify port scans, brute-force attempts, and unauthorized lateral network movement.
  • Network Threat Intelligence Integration: Comparing outbound connection requests against continuously updated threat intelligence feeds containing known malicious command-and-control (C2) IPs, botnet nodes, and Tor exit relays.
  • Deep Packet Inspection (DPI) & Web Application Firewalls (WAF): Inspecting the application layer (Layer 7) payload of HTTP/HTTPS traffic to detect injection attacks (SQLi, XSS), path traversals, and deserialization exploits before they reach compute workloads.
  • Behavioral Heuristics & Machine Learning: Establishing an adaptive baseline of normal network throughput, protocol distributions, and connection intervals to flag sudden asymmetric spikes or subtle low-and-slow data exfiltration attempts.

12. Preventing Privilege Abuse: Least Privilege, Separation of Duties, and Just-In-Time Access

  • Principle of Least Privilege (PoLP):
    • Restricts user and service accounts to exclusively the minimal set of permissions needed to execute their designated operational responsibilities.
    • Limits the blast radius by preventing standard application services or low-tier engineers from executing destructive actions, such as resource deletion or security-policy editing.
  • Separation of Duties (SoD):
    • Disperses critical, sensitive tasks across multiple distinct roles or individuals so that no single identity possesses end-to-end control over an entire workflow.
    • Prevents unilateral abuse by requiring, for instance, that the identity who creates or requests a code deployment cannot also be the sole entity that approves and deploys it to production.
  • Just-In-Time (JIT) Access:
    • Replaces standing administrative privileges with temporary, on-demand privilege elevations that expire automatically after a designated window (e.g., 2 hours).
    • Drastically shrinks the vulnerability window: if an administrator's credentials are breached while JIT is inactive, the attacker inherits zero standing administrative capabilities.

13. Critical Fields in a Cloud Security Audit Record

A robust, forensically sound audit log entry must capture standard contextual metadata:

  • Timestamp: High-precision, synchronized time indicator (UTC format with millisecond resolution) detailing precisely when the event took place.
  • Event Name / Action: The specific API call, command, or operational procedure invoked (e.g., AuthorizeSecurityGroupIngress, DeleteBucketPolicy).
  • Source Identity & Principal ID: The unique user ARN, role identifier, service account, or federated identity initiating the call, including assumed-role session names.
  • Source IP Address & User Agent: The originating network IP address of the caller and the software agent, browser, or CLI tool used to dispatch the request.
  • Target Resource Identifier: The specific cloud asset being acted upon (e.g., resource ARN, database instance ID, bucket name).
  • Response Status / Error Code: The final disposition of the request—whether it succeeded (Success) or failed due to permission denial (AccessDenied) or invalid parameters.
  • Request & Response Parameters: Specific inputs provided in the request payload and corresponding outputs returned, helping reconstruct changes made to system states.

14. QoS Monitoring in Identifying DDoS and Resource Exhaustion

Quality of Service metrics serve as early behavioral indicators of security attacks by highlighting physical and logical stress anomalies:

  • Uncorrelated Latency Spikes: A sharp surge in end-to-end latency alongside increased HTTP 504 (Gateway Timeout) errors often signals an application-layer (Layer 7) slow HTTP POST or Slowloris attack designed to hold open server thread pools.
  • Abnormal Packet/Bandwidth Discrepancies: Real-time QoS network bandwidth monitors flagging sustained, massive spikes in inbound UDP or TCP-SYN volumes—deviating sharply from standard historical business traffic curves—directly identify volumetric network DDoS attacks.
  • Memory and CPU Saturation: Sudden drops in transaction throughput coupled with pinned 100% CPU or memory utilization across compute nodes can uncover resource exhaustion attacks (such as "ReDoS" regular expression attacks or hash-table collision flooding).
  • I/O Bottlenecks and Queue Growth: Severe increases in disk read/write wait times or message queue backlogs indicate abnormal resource consumption, highlighting potential unauthorized cryptographic mining or unthrottled database query injection attacks.

15. Incident Response Process: Suspected Compromised Cloud Administrator Account

  1. Immediate Revocation & Session Invalidation: Terminate all active console sessions, revoke federated tokens, and cycle/disable all active API access keys and secret keys associated with the administrator account.
  2. Access Freezing & Credential Reset: Change the master password, enforce new Multi-Factor Authentication (MFA) token re-registration, and temporarily attach an explicit DenyAll IAM policy to the identity to prevent further operations.
  3. Forensic Audit & Action Scoping: Query cloud audit logs (e.g., AWS CloudTrail, Azure Activity Log) filtering by the compromised principal’s identity across the preceding 7–30 days. Catalog every API call, resource modification, and data query executed by the account.
  4. Backdoor & Persistence Eradication: Systematically search for and eliminate persistent access vectors introduced by the attacker, such as newly generated IAM users, modified trust policies, rogue SSH keys injected into VMs, or unauthorized security group rules.
  5. System Validation & Recovery: Validate the integrity of all cloud infrastructure modified during the breach window from known-good Infrastructure-as-Code (IaC) baselines; restore compromised data from protected, isolated backups if necessary.
  6. Post-Incident Review: Document the entry vector (e.g., phishing, exposed developer token, credential stuffing), refine IAM detection rules, adjust conditional access policies, and publish a post-mortem report.

16. SIEM Pipeline: Collection, Correlation, and Analysis of Multi-Cloud Security Events

  • Collection (Ingestion & Aggregation):
    • SIEM agents, event listeners, and API push/pull connectors extract events from disparate multi-cloud sources, including cloud management trails (AWS CloudTrail, GCP Cloud Audit Logs), network flow captures, OS host agents, identity providers (Entra ID, Okta), and container runtimes.
    • Ingested data is parsed and normalized into a standard common taxonomy (such as the Elastic Common Schema or CIM) so that disparate terms (like src_ip, sourceIPAddress, and c-ip) are unified into a single searchable field.
  • Correlation (Cross-Source Contextualization):
    • The correlation engine runs real-time rule sets across normalized events occurring within defined time windows.
    • It maps distinct individual events together: for instance, linking an initial brute-force failed login event on an identity provider to a subsequent successful login from a new IP, followed immediately by an unusual CreateSecurityGroupRule call in a cloud compute account.
  • Analysis (Threat Detection & Prioritization):
    • Rule-Based Analysis: Matches incoming sequences against predefined signatures and MITRE ATT&CK cloud matrices.
    • User and Entity Behavior Analytics (UEBA): Applies statistical baselines to detect anomalous user actions, such as an identity downloading sensitive files far outside standard operational hours.
    • Alert Generation & Risk Scoring: Assigns a composite severity score based on the critical nature of the affected assets, deduplicating repetitive alerts and routing actionable incidents directly to security operations teams (SOC) or automated SOAR runbooks.

On this page