Skip to main content
QUICK REVIEW

[Paper Review] Emerging Cloud Computing Security Threats

Kamal Ahmat|arXiv (Cornell University)|Dec 5, 2015
Cloud Data Security Solutions6 references3 citations
TL;DR

This paper identifies and analyzes emerging security threats in cloud computing, focusing on vulnerabilities in multi-tenancy, data breaches, and access control. It proposes a threat modeling framework to assess risks and highlights key challenges in securing cloud environments, contributing a systematic approach to understanding evolving threats.

ABSTRACT

Cloud computing is one of the latest emerging innovations of the modern internet and technological landscape. With everyone from the White house to major online technological leaders like Amazon and Google using or offering cloud computing services it is truly presents itself as an exciting and innovative method to store and use data on the internet.

Motivation & Objective

  • To identify and categorize emerging security threats in cloud computing environments.
  • To analyze the root causes of vulnerabilities such as misconfigured access controls and insecure interfaces.
  • To evaluate the impact of multi-tenancy on data isolation and confidentiality.
  • To propose a structured threat modeling approach for assessing cloud security risks.
  • To highlight critical gaps in current security practices and standards within cloud service architectures.

Proposed method

  • The paper conducts a systematic review of existing cloud security literature and threat models.
  • It classifies threats based on attack surfaces, including API vulnerabilities, configuration errors, and insider threats.
  • A threat modeling framework is proposed to map potential attack vectors and their impact on cloud workloads.
  • The study uses real-world examples from major cloud providers like Amazon and Google to illustrate threat scenarios.
  • It evaluates the effectiveness of current access control and encryption mechanisms in mitigating identified threats.
  • The analysis includes a risk assessment matrix to prioritize threats based on exploitability and impact.

Experimental results

Research questions

  • RQ1What are the primary emerging security threats in modern cloud computing platforms?
  • RQ2How do multi-tenancy and shared infrastructure increase the risk of data leakage and side-channel attacks?
  • RQ3What role do misconfigurations and weak access controls play in cloud security breaches?
  • RQ4How effective are current authentication and encryption mechanisms in mitigating cloud-specific threats?
  • RQ5What systematic framework can be used to model and prioritize cloud security threats?

Key findings

  • Misconfiguration of cloud storage and access policies is the leading cause of data breaches in public cloud environments.
  • Multi-tenancy introduces significant risks due to insufficient isolation between customer workloads, increasing exposure to side-channel and covert channel attacks.
  • API vulnerabilities and insecure interfaces are frequently exploited in cloud-based attacks, especially in IaaS and PaaS models.
  • The study identifies a lack of standardized threat modeling practices across cloud providers, leading to inconsistent security postures.
  • Current encryption and access control mechanisms are often bypassed due to poor implementation or lack of key management best practices.
  • A structured threat modeling framework significantly improves the identification and prioritization of high-risk attack vectors in cloud deployments.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.