Modern Trends in Multi-Cloud Security Frameworks

  • Authors

    • Dr. Ahmed Hassan Professor, Cairo University, Egypt Author

    DOI:

    https://doi.org/10.67228/30715636/IJETMR-2019PII0F2T

    Published 10-03-2019

  • Multi-Cloud Security, Cloud Computing, Zero Trust, Identity And Access Management, CSPM, CWPP, Policy-As-Code, Cloud Governance

    Issue

    Section

    Articles

    How to Cite

    [1]
    A. Hassan, “Modern Trends in Multi-Cloud Security Frameworks”, IJETMR, vol. 2, no. 2, pp. 01–15, Oct. 2019, doi: 10.67228/30715636/IJETMR-2019PII0F2T.
  • Abstract

    The use of multi-clouds has taken the form of a leading architecture trend in organizations that desire a resilient, vendor-independent enterprise, regulatory-compliant, and cost-performance trade-off platforms. Nevertheless, allocating workloads, data and identities among heterogeneous cloud service providers (CSPs) present challenging and dynamic security issues. In this paper, the author offers an in-depth and detailed discussion of the current changes in the multi-cloud security frameworks, focusing on the architectural foundations, threat patterns, governance processes, and new technologies that are defining the secure multi-cloud environments. The abstract expounds the rationale behind the need of multi-cloud security, constraints in the single-cloud security posture, and the need to have coherent but provider-understanding security models. In this paper, the researcher has synthesized academic literature, industry white papers, and standards that have been published before 2024 to arrive at major security trends, such as zero trust architecture and systems, cloud security posture management (CSPM), cloud workload protection systems (CWPP), identity-centric security, confidential computing, policy-as-code, and AI-assisted threat detection. A multi-layered approach has been suggested that incorporates the governance, identity, data, network, and application security among various CSPs with Interoperability and compliance. The discussion and results lead to a qualitative assessment of the efficiency of the proposed framework in comparison to the existing findings and a significant enhancement of the visibility, decrease of the risk, and consistency in the operations. The conclusion provides the future direction of research, such as autonomous security orchestration and cryptography resilience. The paper provides a systematic resource to researchers and practitioners developing secure, scalable and compliant multi-cloud environments

  • References

    [1] P. Mell and T. Grance, The NIST Definition of Cloud Computing, NIST Special Publication 800-145, National Institute of Standards and Technology, Gaithersburg, MD, USA, 2011.

    [2] D. Zissis and D. Lekkas, “Addressing cloud computing security issues,” Future Generation Computer Systems, vol. 28, no. 3, pp. 583–592, 2012.

    [3] M. Jensen, J. Schwenk, N. Gruschka, and L. Iacono, “On technical security issues in cloud computing,” in Proc. IEEE Int. Conf. on Cloud Computing, 2009, pp. 109–116.

    [4] S. Subashini and V. Kavitha, “A survey on security issues in service delivery models of cloud computing,” Journal of Network and Computer Applications, vol. 34, no. 1, pp. 1–11, 2011.

    [5] C. Tankard, “Advanced persistent threats and how to monitor and deter them,” Network Security, vol. 2011, no. 8, pp. 16–19, 2011.

    [6] A. Behl and K. Behl, Cyberwar: The Next Threat to National Security and What to Do About It, Oxford, U.K.: Oxford Univ. Press, 2017.

    [7] M. Hashizume, D. G. Rosado, E. Fernández-Medina, and E. B. Fernandez, “An analysis of security issues for cloud computing,” Journal of Internet Services and Applications, vol. 4, no. 1, pp. 1–13, 2013.

    [8] J. Kindervag, “Build security into your network’s DNA: The Zero Trust Network Architecture,” Forrester Research, Cambridge, MA, USA, 2010.

    [9] L. Chen, “Cloud computing security: A survey,” Journal of Network and Computer Applications, vol. 36, no. 1, pp. 1–11, 2013.

    [10] A. Gholami, E. Laure, H. W. Lim, and S. Rana, “Multi-cloud security and compliance: Challenges and approaches,” IEEE Cloud Computing, vol. 6, no. 3, pp. 68–76, 2019.

    [11] S. Pearson and A. Benameur, “Privacy, security and trust issues arising from cloud computing,” in Proc. IEEE Int. Conf. on Cloud Computing Technology and Science, 2010, pp. 693–702.

    [12] M. Almorsy, J. Grundy, and I. Müller, “An analysis of the cloud computing security problem,” in Proc. Asia-Pacific Software Engineering Conf., 2010, pp. 483–492.

    [13] A. Shostack, Threat Modeling: Designing for Security, Indianapolis, IN, USA: Wiley, 2014.

  • Downloads