BTCE | 5th Sem
SPC SubjectUnit 1

SPC Unit 1: Complete Concepts Guide

Unit 1: Fundamentals of Cloud Security, Design and Architecture for Cloud -> Generated and Prepared By Thiruselvan (ThiruXD)

TABLE OF CONTENTS

  1. Overview of Cloud Security
  2. Security Services in Cloud Computing
  3. Security Design Principles for Cloud Computing
  4. Comprehensive Data Protection
  5. End-to-End Access Control
  6. Common Attack Vectors and Threats
  7. Network and Storage Security
  8. Secure Isolation Strategies, Virtualization Strategies
  9. Inter-tenant Network Segmentation Strategies
  10. Data Protection Techniques
  11. Data Retention, Deletion, and Archiving Procedures for Tenant Data
  12. Public Key Infrastructure (PKI) and Key Management

Chapter Overview

This comprehensive guide covers the foundational concepts of cloud security design and architecture as presented in Unit I. The material is organized to provide a structured understanding of cloud security principles, controls, and implementation strategies.


1. Core Concepts

1.1 What is Cloud Security?

Definition: Cloud security is the collection of policies, technologies, processes, and controls used to protect cloud-based systems, data, and services.

Key Components:

  • Identity and Access Management (IAM)
  • Encryption
  • Network security
  • Data protection
  • Monitoring
  • Secure configuration
  • Compliance
  • Incident response
  • Tenant isolation

Why Cloud Security is Different:

  • Systems are no longer limited to internal data centers
  • Users access services from multiple devices and locations
  • Applications run across multiple regions
  • Data moves between services through APIs
  • Security must be identity-centered, automated, and continuously monitored

1.2 The Shared Responsibility Model

This model divides security responsibilities between the cloud provider and the customer:

Service ModelProvider ResponsibilityCustomer Responsibility
IaaSPhysical infrastructure, hardware, networkingOS, applications, identities, data
PaaSInfrastructure + platformApplications, data, access policies
SaaSMost of the application environmentUsers, data classification, access policies, safe usage

Important Principle: Cloud security is NOT only the provider’s responsibility. Customers must configure services securely, manage identities carefully, protect data, and monitor usage.


2. Security Services in Cloud Computing

Major Service Categories:

CategoryExamplesFunction
Identity & AccessIAM, SSO, MFA, Directory ServiceManage users, groups, roles, permissions
Network SecurityFirewall, WAF, Security Groups, Network ACLsFilter traffic, protect endpoints
Data ProtectionKMS, Secret Manager, Backup, DLPProtect data, keys, secrets, recovery
Threat DetectionCloud Threat Detection, Vulnerability ScanningFind suspicious activity, exposed resources
Logging & MonitoringCloud Logs, SIEM, MetricsCollect events for investigation
ComplianceSecurity Posture Management, Policy EnforcementCheck regulatory compliance
ResilienceBackup, Replication, DRSupport availability during failures

Best Practice: Enable logging, MFA, encryption, and backup early in the cloud design phase.


3. Security Design Principles

Core Principles:

PrincipleMeaningCloud Example
Shared ResponsibilityUnderstand what provider secures vs. customer securesCustomer configures IAM even when provider secures hardware
Defense in DepthUse multiple layers of protectionIAM + Private Network + Encryption + WAF + Logging
Least PrivilegeGrant only needed permissionsBackup service can read storage but cannot delete databases
Secure by DefaultStart with restricted accessStorage buckets are private by default
Zero TrustVerify every access requestRequire MFA and policy checks even from internal networks
SegmentationSeparate workloads, tenants, trust zonesUse separate VPCs for web, app, database tiers
AutomationUse templates and policies to reduce manual errorsInfrastructure as Code with security checks
Continuous MonitoringObserve logs, metrics, behaviorGenerate alerts for unusual login or public exposure

4. Comprehensive Data Protection

Data Lifecycle Protection:

Data StateRiskProtection Technique
Data at RestUnauthorized access to stored filesStorage encryption, access policies, backup protection
Data in TransitInterception during network transferTLS, VPN, private connectivity, certificate validation
Data in UseExposure during processingLeast privilege, secure enclaves, application controls
Data Shared ExternallyAccidental sharingDLP, expiration links, data classification, tokenization
Data ArchivedLong-term exposureRetention schedule, encrypted archive, access review
Data DeletedRecoverable remnantsSecure deletion, crypto-shredding, documented process

Data Protection Strategies:

  1. Classification - Identify data sensitivity (public, internal, confidential, PII, financial, medical, restricted)
  2. Minimization - Collect only necessary information
  3. Encryption - Protect at rest, in transit, and in use
  4. Access Control - Restrict who can view or change data
  5. Backup & Recovery - Tested backups protected from deletion
  6. DLP & Monitoring - Detect unauthorized sharing
  7. Retention & Deletion - Keep data only as long as required

5. End-to-End Access Control

Access Control Components:

ComponentDescriptionExample
AuthenticationVerifies identityPassword + MFA, SSO, certificate-based identity
AuthorizationDetermines allowed actionsRead-only role for auditors; admin role for security team
Policy EnforcementApplies access rulesDeny public storage access unless approved
Privileged AccessControls administrative accountsJust-in-time admin access with approval and expiry
Access ReviewChecks if access is still neededRemove accounts of completed students or ex-employees
Audit LoggingRecords access attemptsLog successful and failed console/API actions

Pseudo-Policy Example:

ALLOW user_group = "BackupOperators"
ACTION = ["read_storage", "create_backup", "restore_backup"]
RESOURCE = "production-storage"
DENY ACTION = ["delete_storage", "change_encryption_key"]
CONDITION = "MFA required and request logged"

6. Common Attack Vectors and Threats

Major Cloud Threats:

ThreatExampleMain Control
Credential TheftAttacker uses leaked access keyMFA, secret scanning, key rotation, least privilege
MisconfigurationPublic database or storage bucketPolicy checks, secure defaults, configuration scanning
Insecure APIAPI accepts unauthorized requestsAPI gateway, authentication, authorization, rate limiting
DDoSFlood of traffic against web applicationDDoS protection, CDN, WAF, scaling, rate limits
Malware/RansomwareCompromised VM encrypts filesEndpoint protection, backups, segmentation, patching
Insider ThreatAuthorized user downloads excessive dataDLP, monitoring, access review, separation of duties
Supply Chain AttackCompromised container image deployedImage scanning, trusted registries, signed artifacts

Three-Phase Threat Management:

  1. Prevention: Secure configuration, least privilege, policies
  2. Detection: Logging, anomaly detection, alerts
  3. Response: Containment, investigation, recovery, lessons learned

7. Network and Storage Security

Network Security Controls:

AreaControlPurpose
Virtual NetworkVPC/VNet segmentationCreates isolated network boundaries
Subnet DesignPublic, private, data subnetsSeparates internet-facing and internal resources
Firewall RulesSecurity groups, network ACLsAllows only necessary ports and directions
Private ConnectivityVPN, private link, direct connectionReduces exposure to public internet

Storage Security Controls:

TypeControlsPurpose
Object StorageBucket policy, encryption, versioningPrevents public leakage, supports recovery
Database StorageEncryption, backup, private endpointProtects confidentiality and availability
Backup StorageImmutable backups, retention lockDefends against ransomware and accidental deletion

Practical Design Rule: Expose only the minimum required endpoints to the internet. Keep databases, message queues, internal APIs, and backup storage in private zones.


8. Secure Isolation Strategies

Isolation Layers:

LayerTechniqueExample
OrganizationalSeparate accounts/projectsProduction, development, testing in separate accounts
NetworkVirtual networks, subnets, firewallsDatabase subnet not reachable from internet
IdentitySeparate roles and service accountsApplication role cannot access security audit logs
ComputeVM isolation, container namespacesUntrusted jobs run in restricted containers
DataSeparate storage, row-level rulesEach tenant can read only their own records
Key ManagementSeparate keys per tenantTenant A data encrypted with Tenant A key

Virtualization Security:

ModelSecurity Consideration
Virtual MachinePatch OS, secure images, restrict management ports
ContainerScan images, avoid privileged mode, protect secrets
ServerlessSecure functions, IAM roles, triggers, environment variables
Bare MetalUseful for strict compliance or licensing needs
Confidential ComputingProtects data in use with hardware-backed TEE

Important: Containers are not automatically more secure than VMs. Their security depends on image quality, host security, runtime settings, network policy, and secrets handling.


9. Inter-Tenant Segmentation Strategies

Segmentation Approaches:

StrategyHow It WorksUse Case
Separate Virtual NetworksEach tenant gets isolated networkLarge enterprise tenants or regulated workloads
Subnet SegmentationWeb, app, data layers use separate subnetsThree-tier application security
Security Groups/Firewall RulesOnly approved traffic allowed between zonesAllow app-to-database traffic on required port
Private EndpointsAccess managed services through private pathsPrivate database or storage access
Tenant-Aware AuthorizationApplication checks tenant identityMulti-tenant SaaS with shared application layer
MicrosegmentationFine-grained control between workloadsHigh-security environments and zero trust

Note: In SaaS applications, network isolation alone isn’t enough - the application must also enforce tenant identity, tenant IDs, row-level access, and audit logging.


10. Data Protection Techniques

10.1 Encryption

TechniqueDescriptionExample
SymmetricSame key for encryption and decryptionAES-based storage encryption
AsymmetricPublic key encrypts; private key decryptsTLS certificates, digital signatures
HashingOne-way transformation for verificationPassword hashing, file integrity checks
TLSProtocol for secure network communicationHTTPS access to web applications
Envelope EncryptionData key encrypts data; master key encrypts data keyCloud KMS protecting storage encryption keys
Client-SideData encrypted before reaching cloud providerSensitive file encrypted before upload

Important: Encryption protects confidentiality but doesn’t replace access control, logging, backup, or secure application design.

10.2 Data Redaction

Removes or masks sensitive information from documents, logs, or reports.

TypeExampleUse Case
Full RedactionName: [REDACTED]Remove sensitive fields from reports
Partial RedactionPhone: ******7890Show limited identifying information
Dynamic RedactionDifferent users see different detail levelsAdmin sees full value; support sees masked
Log RedactionPassword parameter removed from logsPrevent secrets in monitoring systems

10.3 Tokenization

Replaces sensitive data with non-sensitive tokens stored in a secured vault.

Original DataTokenized FormWhy It Helps
Card numbertok_pay_7H9K2Process payments without storing card numbers
Student IDtok_stu_20491Link records without exposing actual identifier
Bank accounttok_acc_83FA1Customer service tools use token
Patient numbertok_med_01X9BResearch data pseudonymized before analysis

Comparison: Encryption is reversible using a key. Tokenization is reversible only through a controlled token mapping system. Both require strong access control.

10.4 Obfuscation

Makes data, code, or configuration harder to understand.

TechniqueDescriptionExample
MaskingHide part of the valueEmail: a***@example.com
SubstitutionReplace real value with fakeAmit → User001
ShufflingRearrange values between recordsShuffle dates of birth in test dataset
GeneralizationReduce precisionExact address → city only
Code ObfuscationMake code harder to understandRenaming variables, restructuring code
Synthetic DataGenerate artificial recordsFake student dataset for lab practice

11. Data Retention, Deletion, and Archiving

Key Procedures:

ProcedureWhat It DefinesSecurity Requirement
Retention PolicyHow long each category is keptMust match legal, academic, or business requirements
ArchivingHow inactive data is moved to long-term storageArchive must remain encrypted and access-controlled
Deletion RequestHow a tenant requests removalVerify tenant identity and authorization
Secure DeletionHow data is removed or made unrecoverableDelete records, remove indexes, manage backups and keys
Crypto-shreddingDestroy encryption key to make data unreadableUseful when direct deletion is difficult
Audit EvidenceProof that deletion/archiving was completedMaintain logs without exposing deleted data

Best Practice: Retention and deletion should be documented before collecting tenant data. Otherwise, organizations may keep sensitive information longer than necessary.


12. PKI and Key Management

Public Key Infrastructure (PKI):

The framework for creating, managing, distributing, validating, and revoking digital certificates.

Components:

ElementPurposeSecurity Consideration
Certificate AuthorityIssues and signs certificatesMust be trusted and protected
CertificateBinds identity to a public keyRenew before expiry, revoke if compromised
Public KeyShared key for encryption/verificationCan be distributed openly
Private KeySecret key for decryption/signingMust be protected, never exposed in code or logs

Key Management Lifecycle:

  1. Generation - Create keys using secure cryptographic standards
  2. Storage - Protect keys in secure services
  3. Distribution - Securely transmit keys when necessary
  4. Use - Apply keys for encryption/decryption with logging
  5. Rotation - Replace old keys with new keys periodically
  6. Backup - Maintain secure copies for recovery
  7. Revocation - Invalidate compromised keys
  8. Expiration - Set key expiry dates
  9. Destruction - Securely destroy keys when no longer needed

Cloud Key Management Services:

ServiceFunctionSecurity Features
KMSManages cryptographic keys in cloudIAM policies, rotation, audit logs
HSMHardware-backed secure key storageHigh-value keys, compliance requirements
Secret ManagerStores secrets, passwords, API keysEncrypted storage, rotation, access logging

Best Practice: Store secrets and private keys in a dedicated key management or secrets management service. Never hard-code passwords, API keys, or private keys in source code.


On this page