Skip to content
AL-604 (B) · Information Security & Management/Quick Revision Short Notes

Information Security & Management (AL-604 (B)) - Unit 2 Short Notes

1. Fundamentals of Cloud Computing

Cloud Computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Essential Characteristics (NIST Definition):

  1. On-demand self-service: Users can provision computing capabilities automatically without human interaction.

  2. Broad network access: Capabilities are available over the network and accessed through standard mechanisms.

  3. Resource pooling: Provider's computing resources are pooled to serve multiple consumers.

  4. Rapid elasticity: Capabilities can be elastically provisioned and released to scale rapidly.

  5. Measured service: Resource usage is monitored, controlled, and reported, providing transparency.

Computing on Demand / Utility Computing:

  • Definition: A service provisioning model where computing resources (processing, storage, etc.) are provided as a metered service, similar to traditional utilities like electricity or water.

  • Mechanism: Enables dynamic provisioning by allowing users to request and release resources in real-time based on current need, paying only for what they consume. This is the economic engine behind cloud elasticity.

Grid Computing vs. Cloud Computing:

Feature Grid Computing Cloud Computing
Primary Goal Solve large, complex problems by aggregating resources from multiple administrative domains. Deliver on-demand, scalable IT resources and services over a network.
Resource Focus Compute-intensive (CPU cycles for scientific tasks). Service-oriented (IaaS, PaaS, SaaS).
Architecture Decentralized, heterogeneous resources (often geographically dispersed). Centralized or federated, homogeneous pools in large data centers.
Management Complex, often requires middleware for job scheduling & resource brokering. Simplified, managed by a single provider or consortium.
Elasticity Limited; resources are typically dedicated to a specific project/application. High; resources are pooled and can be rapidly scaled up/down.
Billing Model Often project-funded or institutional. Pay-per-use (utility model).
Example SETI@home, scientific simulations. AWS EC2, Google Workspace, Microsoft Azure.

[!TIP] Exam Focus: Grid is about collaborative problem-solving across organizations; Cloud is about service delivery with elasticity and utility billing. Both use resource pooling but with different intents.

Challenges & Risks in Cloud Adoption:

Perspective Key Challenges & Risks
Business Vendor Lock-in: Difficulty migrating between providers due to proprietary APIs/data formats.<br>Cost Management: Unpredictable bills from on-demand scaling ("bill shock").<br>Compliance & Legal: Data sovereignty laws (GDPR), jurisdiction issues.<br>Loss of Control: Dependency on provider's SLAs and operational stability.
IT/Technical Data Security & Privacy: Multi-tenancy risks, unauthorized access, data breaches.<br>Integration Complexity: Integrating cloud services with legacy on-premise systems.<br>Performance & Latency: Network dependence, "noisy neighbor" problem.<br>Downtime & Availability: Outages at provider level impact all customers.

2. Cloud Service Models

Model Infrastructure as a Service (IaaS) Platform as a Service (PaaS) Software as a Service (SaaS)
What it provides Virtualized computing resources (VMs, storage, networks). Development & deployment environment (OS, middleware, tools). Complete, ready-to-use applications.
User Control OS, Applications, Data. Provider manages physical hardware & hypervisor. Applications & Data. Provider manages OS, runtime, middleware. Data & Configuration. Provider manages everything else.
Management Responsibility User Shared (User: App; Provider: Runtime, OS, infra) Provider
Example AWS EC2, Azure VMs, Google Compute Engine. Heroku, Google App Engine, Microsoft Azure App Services. Gmail, Salesforce, Microsoft 365, Dropbox.
Use Case Migrating legacy apps, test/dev environments, full OS control. Developing cloud-native apps without managing infrastructure. End-user productivity tools (email, CRM, collaboration).

Comparative Analysis:

  • Abstraction Level: SaaS > PaaS > IaaS (highest user control to lowest).

  • Customization: IaaS offers maximum flexibility; SaaS offers least.

  • Management Overhead: Inversely proportional to abstraction level. SaaS has minimal IT overhead; IaaS has significant.

  • Deployment Speed: SaaS fastest (instant use), IaaS slower (provision & configure VMs).


3. Cloud Deployment Models

Model Public Cloud Private Cloud Hybrid Cloud Community Cloud
Ownership/Operation Third-party provider (AWS, Azure). Single organization (on/off-premise). Combination of two or more models. Shared by several organizations with common concerns.
Cost Model Operational Expenditure (OpEx), pay-per-use. Capital Expenditure (CapEx) + OpEx. Both CapEx and OpEx. Shared cost among community members.
Control & Security Least control; provider manages security. Highest control & security; internal management. Balanced; critical data on private, scalable workloads on public. Shared policies/security for common goals.
Scalability Highly elastic & scalable. Limited to owned/leased capacity. Highly flexible; can "burst" to public cloud. Scalable within community constraints.
Example Netflix on AWS. Government data center using VMware. Company uses private cloud for DBs, public for web front-end. Healthcare consortium sharing a cloud for patient data.

Criteria for Selecting Deployment Models:

  1. Data Sensitivity & Compliance: Highly regulated data (finance, health) → Private/Community.

  2. Workload Predictability: Steady, predictable workloads → Private; variable/spiky → Public/Hybrid.

  3. Cost Structure: Preference for OpEx vs. CapEx.

  4. Required Control: Need for deep infrastructure customization → IaaS on Private/Public.

  5. Performance & Latency: Low-latency needs may dictate on-premise Private.

  6. Security Posture: Internal security maturity vs. trust in provider.

[!TIP] Common Pitfall: "Private Cloud = On-premise." A private cloud can be hosted by a third party but dedicated to a single tenant (e.g., AWS VPC with dedicated instances).

Public vs. Private Cloud Comparison (Key Differentiators):

Aspect Public Cloud Private Cloud
Tenancy Multi-tenant Single-tenant
Cost Variable OpEx, no upfront CapEx High upfront CapEx, lower long-term OpEx for steady workloads
Security Provider's responsibility (shared model); audit visibility limited. Organization's full responsibility; complete audit & control.
Customization Limited to provider's offerings. Full customization of hardware, network, software stack.
Scalability Near-infinite on-demand. Bounded by owned/leased capacity; scaling takes time/money.

4. Virtualization Technologies

Concept of Virtualization & Hardware Abstraction:

  • Virtualization is the creation of a virtual (rather than actual) version of something, including virtual hardware platforms, storage devices, and network resources.

  • Hardware Abstraction Layer (HAL): The key mechanism. It decouples the physical hardware (CPU, memory, disk, NIC) from the software (OS, applications). The hypervisor presents virtual hardware (vCPU, vRAM, vDisk, vNIC) to each Virtual Machine (VM), which runs a standard OS as if it were on real hardware.

Hypervisors (Virtual Machine Monitors - VMMs):

Type Type 1: Bare-Metal Type 2: Hosted
Architecture Runs directly on the physical hardware. Runs as an application on a standard host OS (e.g., Windows, Linux).
Examples VMware ESXi, Microsoft Hyper-V, Xen, KVM. VMware Workstation, Oracle VirtualBox, Parallels Desktop.
Performance Higher (direct hardware access, lower overhead). Lower (host OS adds overhead, resource contention).
Primary Use Server virtualization, data centers, cloud infrastructure. Desktop virtualization, development/testing, personal use.
Security Smaller attack surface (no underlying OS). Larger attack surface (host OS vulnerabilities).

Functions & Applications of Hypervisors:

  • Resource Allocation & Scheduling: Shares physical CPU, memory, and I/O among VMs.

  • Isolation: Ensures VMs are isolated from each other (fault & security).

  • Hardware Emulation/Paravirtualization: Presents virtual hardware to VMs; may use optimized paravirtual drivers.

  • Live Migration: Move running VMs between physical hosts with minimal downtime.

  • Snapshotting & Cloning: Save/restore entire VM state; create copies.

  • Applications: Server consolidation, data center consolidation, cloud computing foundation, disaster recovery, sandboxed testing.

Hardware Virtual Machine (HVM):

  • A VM that uses hardware-assisted virtualization (Intel VT-x, AMD-V).

  • The hypervisor uses CPU extensions to run unmodified guest OSes with near-native performance.

  • Contrasts with Paravirtualization (PV), where the guest OS is modified to make hypercalls for better performance but requires OS porting.

Virtual Machines (VMs):

  • Creation: Defined by a VM Image (disk file) and a configuration file (vCPU, RAM, NICs). Created via hypervisor management tools.

  • Management: Start, stop, pause, migrate, snapshot, clone via hypervisor console or API (e.g., vCenter, OpenStack Nova).

  • Lifecycle: Provision → Configure → Run → Suspend/Stop → Decommission.

  • Security Risks:

    • VM Escape: Malware breaking out of VM to host hypervisor.

    • VM-to-VM Attacks: Lateral movement within same host.

    • Snapshot Risks: Sensitive data in snapshots; insecure snapshot files.

    • Resource Exhaustion (DoS): "Noisy neighbor" consuming host resources.

  • Security Benefits:

    • Strong Isolation: Process-level isolation between VMs on same host.

    • Rapid Patching/Recovery: Can revert to clean snapshot; patch template images.

    • Encapsulation: Entire system (OS+app) is a portable file, easing secure deployment.

Storage Virtualization:

  • Definition: Abstracting physical storage resources (disks, arrays) into a single, logical, manageable storage pool.

  • SAN (Storage Area Network):

    • Architecture: Dedicated, high-speed network (Fibre Channel, iSCSI) connecting servers to block-level storage devices.

    • Access: Servers see SAN disks as local drives (LUNs).

    • Use Case: High-performance databases, enterprise applications requiring block storage.

  • NAS (Network Attached Storage):

    • Architecture: Standard IP network (Ethernet) connecting to a dedicated file-level storage appliance.

    • Access: Servers access files via protocols like NFS, SMB/CIFS.

    • Use Case: File sharing, home directories, content repositories.

  • Storage Cloud Concepts: Object storage (S3, Swift), block storage volumes (EBS), file storage services. Provides scalable, durable, pay-per-use storage over HTTP/API.

Logical Partitioning (LPAR):

  • Definition: A physical server is divided into multiple logical partitions, each acting as a separate system with its own OS, memory, and resources. Common in IBM Power Systems, HP-UX, Oracle SPARC.

  • Advantages:

    • Improved Resource Utilization: Better than full physical servers.

    • Strong Isolation: Hardware-enforced separation between partitions.

    • Dynamic Resource Allocation: Can add/remove vCPUs, memory online.

    • High Availability: Partition can be moved to another physical frame.

  • Disadvantages:

    • Complex Management: Requires specialized tools (HMC - Hardware Management Console).

    • Vendor Lock-in: Often proprietary to specific hardware (e.g., IBM Power).

    • Less Flexible than Hypervisors: Typically fewer VMs per host compared to Type 1 hypervisors.

    • Cost: Specialized hardware is expensive.

Virtualized Data Center Architecture:

  • Layers:

    1. Physical Layer: Servers, storage arrays, network switches (top-of-rack, spine-leaf).

    2. Virtualization Layer: Hypervisors on servers; storage virtualization (SAN/NAS controllers); virtual networking (vSwitches, SDN controllers).

    3. Management & Orchestration Layer: vCenter, OpenStack, CloudStack. Provides unified portal, API, automation.

    4. Service Layer: IaaS (VMs, volumes), PaaS (containers, functions), SaaS delivered from the virtualized pool.

  • Key Components: Virtualized servers (compute), storage (SAN/NAS/object), networking (virtual switches, VLANs, overlays like VXLAN).

Requirements for Virtualization Platform Implementation:

  1. Hardware Support: CPUs with virtualization extensions (Intel VT-x, AMD-V); sufficient cores, RAM, I/O.

  2. Hypervisor Selection: Type 1 for production data centers; Type 2 for desktop/test.

  3. Management Infrastructure: Centralized management server/console, database for inventory/state.

  4. Networking: Configure virtual switches, VLANs, and physical NIC teaming for VM connectivity and isolation.

  5. Storage: High-performance, shared storage (SAN/NAS) for VM disk files and live migration.

  6. Security: Hardened hypervisor hosts, network segmentation (VM networks), VM template security.

  7. High Availability & Disaster Recovery: Configure HA clusters, shared storage, and replication.


5. Cloud Security

Importance & Challenges:

  • Importance: Protects sensitive data, ensures service availability, maintains customer trust, meets regulatory requirements (GDPR, HIPAA, PCI-DSS).

  • Challenges:

    • Shared Responsibility Model Confusion: Unclear division of security duties between provider and customer.

    • Multi-Tenancy: Risk of data leakage between tenants on same physical host.

    • Visibility & Control: Limited logging/auditing access into provider's infrastructure.

    • Dynamic & Elastic Nature: Traditional security perimeters dissolve; assets appear/disappear rapidly.

    • API Security: Cloud APIs are the primary management interface; their compromise is catastrophic.

Security Aspects:

  • Data Security:

    • Encryption: Data-at-rest (AES-256 on disks/volumes), Data-in-transit (TLS/SSL).

    • Integrity: Hashes (SHA-256), digital signatures.

    • Confidentiality: Access controls, encryption, tokenization.

  • Network Security:

    • Virtual Firewalls (Security Groups/NACLs): Stateful/stateless filtering at VM/vSwitch level.

    • Intrusion Detection/Prevention Systems (IDS/IPS): Monitor network traffic for malicious activity.

    • DDoS Protection: Cloud-based scrubbing services (AWS Shield, Cloudflare).

  • Identity and Access Management (IAM):

    • Principle of Least Privilege: Grant minimum necessary permissions.

    • Role-Based Access Control (RBAC): Permissions assigned to roles, users assigned to roles. Centralized policy management.

    • Multi-Factor Authentication (MFA): Critical for admin accounts.

    • Federation: Use existing corporate identities (SAML, OIDC) for cloud access.

  • Compliance & Governance:

    • Audit Trails & Logging: Centralized log collection (CloudTrail, CloudWatch Logs).

    • Configuration Management: Ensure resources comply with security baselines (CIS Benchmarks).

    • Policy-as-Code: Automate compliance checks (AWS Config, Azure Policy).

Secure Execution Environments & Communications:

  • Encryption Techniques:

    • Data-at-rest: Server-side encryption (provider-managed keys), client-side encryption (customer-managed keys), envelope encryption (KMS).

    • Data-in-transit: TLS 1.2/1.3 for all communications (management APIs, application traffic).

  • Secure Protocols:

    • TLS/SSL: For web traffic, API calls.

    • IPsec: For site-to-site VPNs, encrypting entire IP packets between networks.

    • SSH: For secure remote administration of VMs.

  • Secure Bootstrapping Mechanisms:

    • Measured Boot: Each boot component (firmware, bootloader, OS) is measured (hashed) and stored in TPM. Attestation verifies boot integrity.

    • Trusted Platform Module (TPM): Hardware chip for secure key storage and attestation.

    • Cloud-Init/Cloud-Config: Secure, automated first-boot configuration for VMs.

Securing Virtual Machines (VMs):

  1. Hardened VM Images:

    • Build from minimal, patched base OS.

    • Remove unnecessary packages, services, users.

    • Apply security benchmarks (CIS).

    • Sign images to prevent tampering.

  2. Network Segmentation:

    • Place VMs in separate subnets/VPCs based on function (web, app, DB).

    • Use security groups (stateful) and network ACLs (stateless) for layer-3/4 filtering.

    • Implement micro-segmentation with software-defined per-VM policies.

  3. VM Activity Monitoring & Logging:

    • Enable guest OS logging (syslog, Windows Event Log) and forward to central SIEM.

    • Use host-based intrusion detection (HIDS) inside VMs.

    • Monitor hypervisor logs for VM creation, migration, configuration changes.

    • Implement VM-aware firewalls and IDS/IPS that understand virtual network traffic.


6. Architectural Frameworks and Models

Cloud Computing Reference Model (NIST):

  • A 5-layer model defining core functions and actors.

  • Layers (Bottom-Up):

    1. Physical Layer: Servers, storage, network hardware.

    2. Virtualization Layer: Hypervisors, virtual switches, storage virtualization.

    3. Platform Layer: OS, middleware, runtime (PaaS offering).

    4. Application Layer: SaaS applications, custom cloud apps.

    5. Management Layer (Cross-Cutting): Orchestration, provisioning, monitoring, security, billing for all layers.

  • Actors: Cloud Consumer (uses services), Cloud Provider (owns/operates cloud), Cloud Carrier (provides connectivity), Cloud Auditor (independent evaluation).

DiagramCANVAS: A 5-tier pyramid. Base: Physical Layer. Above: Virtualization Layer. Then Platform Layer. Then Application Layer. Surrounding all layers: Management Layer (orchestration, security, billing) as a ring. Actors (Consumer, Provider, Carrier, Auditor) shown interacting with the model from outside.

Service-Oriented Architecture (SOA) in Cloud:

  • Role in Interoperability & Integration:

    • Loose Coupling: Services communicate via standardized interfaces (WSDL, REST APIs), independent of underlying platform/language.

    • Reusability: Services are designed as modular, reusable business functions.

    • Discoverability: Services can be published in a registry (UDDI, cloud marketplace).

    • Composition: Complex cloud applications built by orchestrating multiple cloud/on-premise services (BPEL, AWS Step Functions).

  • Cloud Design & Implementation Using SOA:

    1. Identify core business capabilities as candidate services.

    2. Define service contracts (API specs, data models).

    3. Implement services as independent, stateless components (can be hosted on PaaS).

    4. Use an Enterprise Service Bus (ESB) or cloud-native API gateway for mediation, routing, transformation.

    5. Orchestrate services to create composite applications and business processes.

Cloud Stack (Layered Model):

  • A practical view of cloud service delivery layers:

    1. Physical Infrastructure Layer: Bare-metal servers, racks, power, cooling.

    2. Virtualization Layer: Hypervisor, virtual networking, storage abstraction.

    3. Platform Layer: OS images, middleware, databases, development tools (PaaS runtime).

    4. Application Layer: End-user applications (SaaS) and custom cloud apps.

  • Example: A SaaS application (e.g., Salesforce) sits at the top, running on a PaaS platform (Heroku), which runs on VMs (IaaS - AWS EC2), virtualized by a hypervisor (ESXi), on physical servers in a data center.


7. Quality of Service (QOS) in Cloud

Definition: QOS refers to the non-functional characteristics and performance guarantees of a cloud service, as defined in a Service Level Agreement (SLA). It measures the overall performance, reliability, and availability of the service from the user's perspective.

Key Issues & Challenges:

Issue Explanation
Performance Measured by response time, throughput, latency. Challenged by multi-tenancy ("noisy neighbor"), network congestion, VM migration overhead.
Availability Uptime percentage (e.g., 99.9%). Challenged by provider outages, regional failures, maintenance windows. Requires redundant architecture across availability zones.
Scalability Ability to handle increased load by adding resources (scale-out) or upgrading resources (scale-up). Elasticity is automatic, rapid scalability. Challenges: application design for statelessness, database scaling bottlenecks.
Reliability Probability of failure-free operation over time. Involves fault tolerance, redundancy (N+1, 2N), automated recovery.
Security & Compliance Ensuring QOS includes meeting security SLAs (encryption, audit frequency) and regulatory compliance as a service attribute.
Cost-Efficiency Balancing QOS guarantees with cost. Higher QOS (e.g., 99.99%) requires more redundant infrastructure, increasing price.

[!TIP] Exam Focus: QOS is SLA-driven. Always link QOS attributes (performance, availability) to SLA metrics and penalties (service credits).


8. Cloud Platforms and Tools

OpenNebula:

  • Architecture: Modular, component-based. Key components:

    • OneCore: Central scheduler and orchestrator.

    • OneFlow: Orchestrates multi-tier applications.

    • OneGate: Gateway for cloud APIs (EC2, OCCI, OpenStack).

    • Drivers: Interface with hypervisors (KVM, LXC, vCenter), storage (Ceph, NFS), networking (Open vSwitch, 802.1Q).

  • Use in Cloud Computing: An open-source cloud management platform for building and managing private, public, and hybrid IaaS clouds. Focuses on interoperability and flexibility, allowing integration with existing data center infrastructure. Provides a simple, stable alternative to OpenStack for some use cases.

Nimbus:

  • Architecture: A cloud toolkit providing:

    • Nimbus Context Broker: Implements OGF's Open Cloud Computing Interface (OCCI). Provides a simple RESTful interface for managing VMs (start, stop, deploy).

    • Nimbus Workspace Service: Manages the lifecycle of VMs on a cluster (typically using Xen or KVM).

    • Nimbus Cloud Client: Command-line tool for users.

  • Use in Cloud Computing: Primarily used to create science clouds and community clouds. Its lightweight, standards-based (OCCI) design makes it suitable for research environments needing simple, controlled IaaS. Often deployed on HPC clusters.

Other Relevant Tools:

  • Eucalyptus: AWS-compatible open-source IaaS platform (now commercial). Allows running AWS-like private clouds.

  • Apache CloudStack: Complete IaaS management platform (like OpenStack). Manages compute, storage, networking. Known for simplicity and scalability.

  • OpenStack: Comprehensive, modular open-source cloud operating system (Nova, Neutron, Cinder, Swift, etc.). Industry standard for private clouds but complex.

  • VMware vSphere: Commercial, market-leading suite (ESXi, vCenter) for server virtualization and private cloud.


9. Specialized Topics

Role of ISVs in Cloud-Based e-Business Applications:

  • Independent Software Vendors (ISVs) develop and sell software applications (e.g., SAP, Oracle, Adobe).

  • Role in Cloud:

    1. Cloud-Native Development: Building new applications specifically for cloud platforms (using microservices, containers, PaaS).

    2. Re-architecting Legacy Apps: Modifying traditional monolithic apps for cloud deployment (lift-and-shift vs. refactor).

    3. Marketplace Deployment: Listing applications on cloud provider marketplaces (AWS Marketplace, Azure Marketplace) for easy discovery, trial, and consumption.

    4. Subscription Models: Shifting from perpetual licenses to SaaS/subscription models, providing recurring revenue and easier updates.

    5. Integration Focus: Ensuring applications integrate seamlessly with other cloud services (APIs, data sources).

OLAP (Online Analytical Processing) in Cloud:

  • Functionality: Enables complex analytical queries against large, historical, aggregated datasets (data warehouses/data marts). Supports business intelligence, reporting, data mining.

  • Core Operations (The "OLAP Cube" Operations):

    • Slice: Select a single dimension from a cube, creating a sub-cube. (e.g., View sales for "2023" only).

    • Dice: Select specific values on multiple dimensions. (e.g., Sales for "2023" in "Q1" and "Q2" for "Product A" and "Product B").

    • Drill-Down: Navigate from summarized to more detailed data. (e.g., From "Year" → "Quarter" → "Month" → "Day").

    • Roll-Up (Drill-Up): Navigate from detailed to summarized data. (e.g., From "City" → "State" → "Country").

    • Pivot (Rotate): Reorient the cube, swapping dimensions between rows and columns for different analytical views.

  • Cloud Advantage: Scalable, on-demand compute/storage for large datasets; pay-per-query models; separation of compute and storage.

Cloud Infrastructure Benchmarks:

  • Purpose: Objective measurement and comparison of cloud provider performance, cost, and features.

  • Performance Metrics:

    • Compute: CPU performance (SPECint, Linpack), VM launch time, network throughput (iperf), disk I/O (IOPS, throughput with fio).

    • Storage: Object storage GET/PUT latency, durability claims.

  • Evaluation Frameworks:

    • Standardized Benchmarks: CloudHarmony (now part of Gartner), SPEC Cloud (SPECvirt, SPEC Cloud IaaS), YCSB (Yahoo! Cloud Serving Benchmark) for NoSQL.

    • Methodology: Define consistent test workloads, instance types, geographic regions. Measure key metrics repeatedly.

    • Considerations: Test duration (steady-state vs. burst), instance type selection (burstable vs. dedicated), network topology (same AZ vs. cross-region), storage type (SSD vs. HDD).

    • Output: Comparative reports on price-performance (cost per unit of work), raw performance, consistency of performance.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in