Cloud Computing Security Vulnerabilities
Dr. Mohammad Shoab
What is Cloud Computing?
NIST Definition
Architecture and Service Definitions
1. Infrastructure as a Service (IaaS)
2. Platform as a Service (PaaS)
3. Software as a Service (SaaS)
1. Public
2. Private
3. Community
4. Hybrid
CSA Cloud Reference Model
Hypervisors
Native Hypervisor
Vulnerabilities
Authentication, Authorization, and Accounting (AAA)
User Provisioning
Remote Access To Management Interface
Hypervisor
Lack of Resource Isolation
Lack of Reputation Isolation
Communication Encryption
Weak or No Encryption
Unable to Process Data in Encrypted Form
Poor Encryption Key Management
Low Entropy for Random Number Generation
Inaccurate Modeling of Resource Usage
No Control of Vulnerability Assessment Process
Internal (Cloud) Network Probing
Co-residence Checks
Media Sanitization
Service Legal Agreement (SLA)
Inadequate Resource Provisioning and Investments in Infrastructure
No Policies for Resource Capping
Storage of Data in Multiple Jurisdictions
Lack of Information on Jurisdictions
Lack of Cloud Security Awareness
Lack of Vetting Processes
Unclear Roles and Responsibilities
Poor Enforcement of Role Definitions
Inadequate Physical Security Procedures
Mismanagement
Poor Identification of Project Requirements
Application Vulnerabilities and Poor Patch Management
Additional Vulnerabilities
Thank You