Skip to content
AL-604 (B) · Information Security & Management/Quick Revision Short Notes

Information Security & Management (AL-604 (B)) - Unit 4 Short Notes

UNIT 4: CLOUD COMPUTING & VIRTUALIZATION - EXAM FOCUS NOTES


1.0 CLOUD COMPUTING FUNDAMENTALS & CONCEPTS

1.1 Definition & Core Characteristics (NIST)

Cloud Computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Five Essential Characteristics:

  1. On-demand self-service: Provision resources automatically without human interaction.

  2. Broad network access: Accessible via standard mechanisms (e.g., mobile, laptops) over the network.

  3. Resource pooling: Multi-tenant model with physical/virtual resources dynamically assigned.

  4. Rapid elasticity: Resources scale rapidly outward/inward to meet demand.

  5. Measured service: Resource usage monitored, controlled, and reported (pay-per-use).

1.2 Computing on Demand / Utility Computing

  • Concept: Computing resources (processing, storage, software) are provided as a metered service, similar to traditional utilities (electricity, water). Users pay only for what they consume.

  • Role in Dynamic Provisioning: It is the business and economic model that underpins cloud computing's elasticity. The cloud provider's infrastructure enables the technical ability to provision resources on-demand, while utility computing defines the billing and consumption model for that dynamic allocation.

1.3 Historical Context: Grid vs. Cloud Computing

Feature Grid Computing Cloud Computing
Primary Goal Solve large-scale, complex scientific problems (batch processing). Deliver on-demand IT resources & services for diverse workloads.
Architecture Federated, decentralized. Resources from multiple administrative domains. Centralized, large-scale data centers (pooled resources).
Ownership Resources often owned by different organizations/institutions. Resources owned and managed by a single provider (or private entity).
Scalability Scale by adding more nodes to the grid. Scale vertically/horizontally within a pooled infrastructure.
Business Model Often non-commercial, collaborative (e.g., research). Clear commercial service model (SaaS, PaaS, IaaS).
Service Focus Compute-intensive, long-running jobs. Wide variety: web apps, dev platforms, storage, etc.
Resource Allocation Often scheduled (queues), not immediate. Immediate, elastic, on-demand.
Similarity Both are forms of distributed computing that enable resource sharing across networks.

1.4 Cloud Computing Reference Model (NIST)

A 3-layered model defining roles and activities:

  1. Cloud Consumer: Person/organization using cloud services.

  2. Cloud Provider: Entity managing cloud infrastructure & services.

  3. Cloud Broker: Optional, facilitates relationships between consumers & providers.

  4. Cloud Carrier: Provides network connectivity.

  5. Cloud Auditor: Independent assessment of cloud services. Key Components: Service Models (SPI), Deployment Models, Essential Characteristics.

1.5 Cloud Stack (Conceptual Layering)


┌─────────────────────────────────────┐

│      Applications (SaaS)             │

├─────────────────────────────────────┤

│  Platform (Runtime, Middleware)     │ ← PaaS

├─────────────────────────────────────┤

│   Virtualization (VMs, Containers)  │

├─────────────────────────────────────┤

│   Physical Hardware (Servers, Storage, Network) │

└─────────────────────────────────────┘

  • Bottom-up: Physical infrastructure → Virtualized layer → Platform → Applications.

  • Abstraction increases upwards. Consumer control decreases upwards.


2.0 CLOUD SERVICE & DEPLOYMENT MODELS

2.1 Service Models (SPI Model)

Model What is Delivered? Consumer Control Provider Management Examples
SaaS Complete applications over internet. Least. Use app config only. Most. App, data, runtime, middleware, OS, virtualization, HW. Gmail, Salesforce, Office 365
PaaS Platform (dev tools, DB, middleware) to build/deploy apps. Medium. Control over deployed apps & app config. Runtime, middleware, OS, virtualization, HW. Heroku, Google App Engine, AWS Elastic Beanstalk
IaaS Fundamental compute, storage, network resources (VMs). Most. Control over OS, apps, data, possibly networking. Virtualization, HW. AWS EC2, Azure VMs, Google Compute Engine

2.2 Deployment Models

Model Definition Key Characteristics Advantages Disadvantages Use Cases
Public Cloud infrastructure available to general public, owned by provider. Multi-tenant, shared resources, pay-as-you-go. No CapEx, high scalability, no maintenance. Less control, security concerns, compliance limits. Web apps, email, dev/test environments.
Private Infrastructure for single organization (on/off-premises). Single-tenant, dedicated resources, more control. High security, customization, compliance. High CapEx/OpEx, limited scalability, management overhead. Sensitive data (finance, govt), legacy apps.
Hybrid Composition of two or more clouds (private+public) with orchestration. Workload portability, data/application integration. Flexibility, balance of control/scalability, cloud bursting. Integration complexity, security gaps at boundaries, management tooling. Bursting to public for peak loads, backup to public cloud.
Community Shared by several organizations with common concerns (security, compliance). Multi-tenant within community, often managed by 3rd party. Cost-sharing for niche needs, compliant environment. Limited scale, potential for conflict among members. Government agencies, consortiums (e.g., healthcare).

2.3 Criteria for Selecting Deployment Model

  • Business Requirements: Need for agility, innovation speed.

  • Compliance & Regulations: Data sovereignty (GDPR, HIPAA), industry standards.

  • Cost: Capital Expenditure (CapEx) vs. Operational Expenditure (OpEx) tolerance.

  • Control & Customization: Level of control needed over infrastructure & software stack.

  • Scalability Needs: Predictable vs. highly variable workloads.

  • Data Sensitivity: Classification of data (public, confidential, secret).


3.0 VIRTUALIZATION TECHNOLOGIES (Core Enabler)

3.1 Virtualization Concept

Abstraction of physical hardware resources (CPU, memory, storage, network) to create multiple, isolated virtual machines (VMs) or environments on a single physical machine.

  • Benefits:

    • Increased Utilization: Consolidate servers (10:1+ ratios).

    • Isolation: VMs are isolated from each other (crash/security).

    • Flexibility & Mobility: VMs can be moved, cloned, snapshotted.

    • Encapsulation: Entire VM state in files.

3.2 Types of Virtualization

  • Server Virtualization: Multiple OS instances on one physical server. (e.g., VMware, Hyper-V).

  • Storage Virtualization:

    • Concept: Pooling physical storage from multiple devices into a single logical storage unit.

    • SAN (Storage Area Network): Dedicated high-speed network (Fibre Channel) connecting servers to block-level storage. Appears as local disk to OS.

    • NAS (Network Attached Storage): File-level storage device connected via standard network (Ethernet). Appears as network file share (NFS, SMB).

    • Key Difference: SAN = Block storage (high perf, complex); NAS = File storage (easier, shared access).

  • Network Virtualization: Combine physical network resources into virtual networks (VLANs, software-defined networking - SDN).

  • Desktop Virtualization (VDI): Host desktop OS on central server, deliver to thin clients.

3.3 Hypervisors / Virtual Machine Monitors (VMM)

  • Function: Software layer that creates and manages VMs. Allocates physical resources, enforces isolation, provides virtual hardware interfaces.

  • Type 1 (Bare-metal): Runs directly on host hardware. High performance, secure.

    • Examples: VMware ESXi, Microsoft Hyper-V, KVM (Linux), Xen (with privileged domain).
  • Type 2 (Hosted): Runs on top of a host OS. Easier setup, lower performance.

    • Examples: VMware Workstation, Oracle VirtualBox, Parallels Desktop.

3.4 Hardware-Assisted Virtualization (HVM)

  • Concept: CPU provides specific instructions (e.g., Intel VT-x, AMD-V) to assist the hypervisor in running VMs with near-native performance.

  • Benefit: Enables full virtualization (unmodified guest OS) without the performance penalty of software emulation (paravirtualization).

3.5 Logical Partitioning (LPAR)

  • Concept: Firmware-level (often on POWER/IBM mainframe) partitioning of a physical server into independent logical partitions. Each LPAR has dedicated/virtualized resources (CPU, memory, I/O).

  • Architecture: Hypervisor (PHYP) sits directly on hardware. Creates partitions. Resources can be static or dynamic (micro-partitioning).

  • Advantages:

    • Strong isolation and security (hardware-enforced).

    • Fine-grained resource allocation and sharing.

    • High availability (partition mobility).

    • Consolidation without virtualization overhead.

  • Disadvantages/Considerations: Proprietary (IBM), complex management, less flexible than software VMs for rapid provisioning.

3.6 Virtual Machine (VM) Concepts

  • Creation: From template/ISO, cloning, or via API.

  • Management: Start/stop, configure, resource allocation (vCPU, vRAM), snapshotting.

  • Migration:

    • Live Migration: Move a running VM from one physical host to another with minimal downtime (seconds). Requires shared storage and compatible CPUs.

    • Cold Migration: Move a powered-off VM.


4.0 CLOUD ARCHITECTURE & DESIGN PRINCIPLES

4.1 Virtualized Data Center Architecture

  • Components:

    1. Virtualized Servers: Pool of x86/other servers running hypervisors.

    2. Virtualized Storage: SAN/NAS providing shared block/file storage for VM disks.

    3. Virtualized Networking: Software-defined networking (SDN) controllers, virtual switches (vSwitch), virtual LANs (VLANs) for VM connectivity.

  • Interconnection: High-speed, low-latency network (10/40/100 GbE) connecting all physical nodes. Management network separate from data network.

  • Management Layer: Cloud Management Platform (CMP) sits atop to orchestrate all resources.

4.2 Service-Oriented Architecture (SOA) in Cloud

  • Principles:

    • Loose Coupling: Services are independent, minimal knowledge of each other.

    • Service Reusability: Services designed for reuse across applications.

    • Interoperability: Standards-based (SOAP, REST, XML/JSON) for cross-platform communication.

  • Role in Cloud: SOA is the architectural style that enables building cloud-native applications as a composition of discrete, network-accessible services. It facilitates:

    • Integration: Combining services from different cloud providers (multi-cloud).

    • Interoperability: On-premises apps communicating with cloud services.

    • Agility: Rapid composition of new apps from existing services.

  • Implementation: Cloud-based services (AWS Lambda, Azure Functions) are often SOA-compliant microservices.

4.3 Role of Independent Software Vendors (ISVs)

  • Develop commercial off-the-shelf (COTS) software applications.

  • In Cloud Context:

    • "Lift-and-Shift": Re-host existing on-premise apps on IaaS.

    • Cloud-Native: Re-architect apps to leverage PaaS/SaaS (microservices, containers).

    • Marketplace Distribution: Deploy apps on cloud provider marketplaces (AWS Marketplace, Azure Marketplace).

    • Challenge: Need to adapt licensing, security, and integration models for cloud delivery.

4.4 Cloud Management Platforms (CMPs) & Tools

  • Concept: Software that provides a unified interface to manage cloud resources across multiple providers (hybrid/multi-cloud). Handles provisioning, orchestration, monitoring, billing.

  • Examples:

    • OpenNebula: Open-source CMP for building and managing enterprise clouds & virtualized data centers. Focus on simplicity, stability. Supports KVM, VMware, LXC.

    • Nimbus: Open-source toolkit for providing IaaS capabilities (compute & storage clouds). Used by scientific communities. Provides cloud-like interfaces to cluster/grid resources.


5.0 SECURITY IN CLOUD COMPUTING (Major Focus)

5.1 Importance & Shared Responsibility Model

  • Importance: Data breaches, service disruption, compliance failures can be catastrophic. Cloud introduces new attack surfaces (API, multi-tenancy).

  • Shared Responsibility Model:

    • Provider Responsibility: Security OF the cloud (physical infrastructure, hypervisor, network fabric).

    • Consumer Responsibility: Security IN the cloud (data, apps, OS, access control, network config).

    • Division varies by Service Model: SaaS (Provider does most), IaaS (Consumer does most).

5.2 Cloud-Specific Security Challenges & Risks

  1. Multi-tenancy & Data Isolation: Risk of data leakage between tenants on shared hardware.

  2. Data Location & Jurisdiction: Unknown physical location of data → compliance (GDPR, data sovereignty laws).

  3. Loss of Physical Control: Consumer cannot physically secure hardware.

  4. API Security: Insecure APIs can be exploited for data theft, DoS, account takeover.

  5. Account/Service Hijacking: Stolen credentials lead to data manipulation, eavesdropping.

  6. Insider Threats: Malicious employees at provider or consumer organization.

  7. System Vulnerabilities: Shared hypervisor is a critical piece of software; a flaw could compromise all VMs.

  8. VM Sprawl: Uncontrolled VM creation increases attack surface, management complexity.

5.3 Cloud Security Aspects (Holistic View)

Aspect Key Controls & Technologies
Data Security Encryption (at rest/in transit), Data Loss Prevention (DLP), tokenization, secure deletion.
Network Security Virtual Firewalls, IDS/IPS, VPNs (site-to-site, client), DDoS mitigation, micro-segmentation.
Identity & Access Mgmt (IAM) Centralized identity (SSO, federation), MFA, least privilege, RBAC.
Service Security Hardened VM images, secure configuration baselines, regular patching (of OS/apps by consumer).
Compliance & Governance Audit logs, compliance reporting (ISO 27001, SOC 2), policy enforcement, Cloud Security Posture Management (CSPM).

5.4 Secure Execution Environments & Communications

  • Encryption Mechanisms:

    • Symmetric (AES): Fast, for bulk data encryption (at rest).

    • Asymmetric (RSA, ECC): For key exchange, digital signatures.

    • Key Management: Critical! Use provider's KMS (AWS KMS, Azure Key Vault) or bring your own (BYOK).

  • Secure Protocols: TLS/SSL (for data in transit), IPsec (for network-level VPNs).

  • Secure Bootstrapping & TPM:

    • Secure Boot: Ensures only signed OS/bootloaders run.

    • TPM (Trusted Platform Module): Hardware chip for key storage, attestation. Cloud providers offer virtual TPM (vTPM) for VMs to prove integrity.

5.5 Securing Virtual Machines (VMs) in Cloud

  • VM-Specific Risks:

    • VM Escape: Exploit hypervisor from within a VM to access host/other VMs.

    • Snapshot Risks: Unencrypted snapshots contain sensitive data in memory/disk.

    • Resource Exhaustion (Noisy Neighbor): One VM monopolizes shared resources (CPU, network, disk I/O).

    • VM Sprawl: Unmanaged VMs become vulnerable.

  • Security Best Practices:

    1. Hardened VM Images: Use minimal, patched, CIS-benchmarked images from trusted sources.

    2. Network Segmentation (Micro-segmentation): Use software-defined per-VM or per-group firewalls (security groups, NSGs). Zero-trust model.

    3. VM Activity Monitoring & Logging: Enable guest OS logging, collect via cloud logging (CloudWatch, Azure Monitor). Monitor for anomalous behavior.

    4. VM Sprawl Management: Enforce tagging, lifecycle policies (auto-terminate), regular audits.

    5. Hypervisor Hardening: (Provider's job, but consumer should verify provider's compliance).

5.6 Access Control Models: Role-Based Access Control (RBAC) in Cloud

  • Concept: Permissions are assigned to roles (e.g., Admin, Developer, ReadOnly), and users/entities are assigned to roles.

  • Cloud Context: Central to IAM systems (AWS IAM, Azure AD, GCP IAM).

    • Principle of Least Privilege: Grant minimum permissions necessary.

    • Separation of Duties: Critical roles split (e.g., billing admin vs. security admin).

    • Federation: Integrate with on-premises identity provider (Active Directory) using SAML/OIDC.

  • Why RBAC? Scalable management of permissions for large teams and dynamic cloud resources.


6.0 SUPPORTING TECHNOLOGIES & MANAGEMENT CONCEPTS

6.1 Quality of Service (QoS) in Cloud

  • Definition: The overall performance and reliability of a cloud service, often formally defined in a Service Level Agreement (SLA).

  • Key Parameters:

    • Availability: % uptime (e.g., 99.9%).

    • Reliability: Mean Time Between Failures (MTBF).

    • Performance: Throughput, response time, latency.

    • Capacity: Bandwidth, storage I/O, compute units.

  • Key Issues & Challenges:

    1. Measurement: How to accurately measure multi-tenant, distributed services?

    2. Guarantees: Providing hard guarantees vs. best-effort. Trade-off with cost.

    3. SLA Negotiation & Enforcement: Defining, monitoring, and compensating (credits) for SLA violations.

    4. Resource Contention: "Noisy neighbor" problem impacts QoS.

    5. Dynamic Workloads: Defining QoS for elastic, unpredictable workloads.

6.2 Storage Cloud

  • Concept: Cloud service model providing storage capacity over the internet (object, block, file storage).

  • Architecture: Typically uses distributed storage systems (e.g., Ceph, Swift) across many commodity servers. Data replicated/erasure-coded for durability.

  • Service Models:

    • Object Storage (S3-like): Unstructured data (blobs), accessed via REST API. Highly scalable, durable. (AWS S3, Azure Blob).

    • Block Storage (EBS-like): Virtual disks for VMs. Low latency, persistent. (AWS EBS, Azure Disk).

    • File Storage (NAS-like): Shared file systems (NFS, SMB). (AWS EFS, Azure Files).

6.3 OLAP (Online Analytical Processing) in Cloud

  • Functionality: Analyze large volumes of data from multiple perspectives (business intelligence, data warehousing).

  • Core Operations (on a multi-dimensional cube):

    • Roll-up (Drill-up): Aggregate data (summarize by dimension, e.g., city → country).

    • Drill-down: Reverse of roll-up; get finer detail (country → city).

    • Slice: Select a single dimension value (e.g., all data for "Q1").

    • Dice: Select on multiple dimensions (e.g., "Q1" AND "Product A").

    • Pivot (Rotate): Re-orient the cube (swap row/column dimensions).

  • Cloud Benefit: Scalable compute/storage for large datasets, pay-per-query models (e.g., Amazon Redshift, Google BigQuery, Snowflake).

6.4 Cloud Infrastructure Benchmarks

  • Purpose: Objectively measure and compare performance, scalability, and efficiency of cloud platforms/infrastructures.

  • Key Metrics:

    • Performance: Throughput (IOPS, network b/w), latency.

    • Scalability: How performance scales with added resources (linear?).

    • Efficiency: Resource utilization (CPU, memory), performance per watt, cost per transaction.

  • Tools & Frameworks:

    • SPEC Cloud IaaS: Standardized benchmark for IaaS performance & scalability.

    • YCSB (Yahoo! Cloud Serving Benchmark): For NoSQL/cloud data services.

    • Custom Application Workloads: Most realistic but not standardized.

    • Cloud Provider Benchmarks: Often publish their own results (use with caution).


[!TIP] Exam Strategy:

  • Definitions are Key: Always start with a crisp definition (e.g., for Grid vs. Cloud, SPI models, Virtualization).
  • Use Comparison Tables: For Service Models, Deployment Models, SAN vs. NAS, Grid vs. Cloud. They are high-scoring.
  • Draw Diagrams (in exam): For NIST Reference Model, Cloud Stack, Virtualized Data Center, Shared Responsibility Model. Label clearly.
  • Security is a Hotspot: Be ready to list specific risks (e.g., VM escape, noisy neighbor) and specific controls (e.g., micro-segmentation, hardened images). Link risks to controls.
  • "Explain" Questions: Structure as: 1) Concept, 2) How it works/Key components, 3) Benefits/Challenges, 4) Example (if applicable).
  • Prioritize: Focus heavily on Sections 1.3, 2.1/2.2, 3.0, 5.0, 5.5 as per past paper frequency.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in