Home / Current Issue / Paper 1706386
Emerging Threats in Cloud Computing Security: A Comprehensive Review
Subject area: Science,Engineering and Technology · Area of research: Cloud Computing and Cyber Security
Abstract
The meteoric rise of cloud computing has ushered in a new era of security challenges, encompassing data breaches, misconfigurations, insider threats, and shared vulnerabilities. As organizations increasingly migrate to the cloud, these risks have become more pronounced, demanding new and sophisticated security frameworks to manage them. AI and machine learning are now effective in identifying anomalies and potential breaches, offering instant threat detection and predictive analysis. AI-driven security tools have significantly reduced misconfiguration-related vulnerabilities, improving overall system resilience. In this article, we will examine the diverse risks that threaten the integrity and security of cloud-based systems. This article also explores the role of regulatory frameworks, including the General Data Protection Regulation (GDPR) and The Health Insurance Portability and Accountability Act (HIPAA), in shaping cloud security standards. Governments and industry leaders are increasingly focused on establishing standardized, global security measures through international cooperation initiatives like the Paris Call for Trust and Security in Cyberspace. As cloud security continues to evolve, it is clear that both technological innovation and regulatory oversight will be essential in safeguarding cloud environments against emerging threats. This comprehensive analysis shows the critical need for a diverse approach, blending technology, governance, and international collaboration to secure the future of cloud computing.
Keywords
Cloud security, AI in cybersecurity, Data breaches, Internal threats, Misconfigurations, Zero Trust, CASBs, Serverless computing, GDPR, HIPPA, Cloud security frameworks
References
[1] Alquwayzani, A., Aldossri, R., & Frikha, M. (2024). Prominent Security Vulnerabilities in Cloud Computing. International Journal of Advanced Computer Science and Applications, 15. https://doi.org/10.14569/IJACSA.2024.0150281
[2] Benaroch, M. (2021). Third-party Induced Cyber Incidents—Much Ado About Nothing? Journal of Cybersecurity. https://doi.org/10.1093/cybsec/tyab020
[3] Cloud Security Alliance. (2020). The Notorious Nine: Cloud Computing Top Threats in 2020. Retrieved from CSA
[4] Cybersecurity and Infrastructure Security Agency. (2022). Cloud Security Guidance. Retrieved from CISA
[5] Ekran 2024. Insider Threat Statistics for 2024: Reports, Facts, Actors and Costs.
[6] Furlong, P. (2023). The Rise of Zero Trust Security. InformationWeek. Retrieved from InformationWeek
[7] Forrester. (2024). Zero Trust Security Framework (ZTX). Retrieved from Forrester
[8] Gartner. (2019). Is the Cloud Secure? Understanding Your Shared Responsibility Model. Retrieved from Gartner
[9] Gartner. (2020). Secure Access Service Edge (SASE) Framework. Retrieved from Gartner
[10] Gartner. (2022). Cloud Security Posture Management (CSPM): How to Improve Security in Multi-Cloud Environments. Retrieved from https://fedtechmagazine.com/sites/fedtechmagazine.com/files/document_files/mkt49867-whitepaper-cspm.pdf
[11] IBM. (2021). Cost of a Data Breach Report 2021. Retrieved from IBM
[12] IBM Security. (2024). IBM X-Force Threat Intelligence Index 2024. Retrieved from IBM Security
[13] IEEE. (2022). Microsoft Power Apps Misconfiguration Incident. IEEE Xplore. Retrieved from https://ieeexplore.ieee.org/abstract/document/9854268
[14] Insikt Group. (2021). Understanding Accellion’s FTA Appliance Compromise, DEWMODE, and Its Supply Chain Impact. Retrieved from Recorded Future
[15] ISO/IEC 27002:2022. (2022). Information Security Controls. International Organization for Standardization.
[16] Khan, S., Kabanov, I., Hua, Y., & Madnick, S. (2022). A Systematic Analysis of the Capital One Data Breach: Critical Lessons Learned. ACM Transactions on Privacy and Security, 26. https://doi.org/10.1145/3546068
[17] Mahi, M., et al. (2017). Cloud Computing Security Breaches and Threats Analysis. Retrieved from researchgate.net
[18] Marinos, A., & Briscoe, G. (2009). Community Cloud Computing. CloudCom. https://doi.org/10.1109/CLOUD.2009.58
[19] McKinsey & Company. (2020). The State of Cybersecurity in the Cloud. Retrieved from McKinsey
[20] Microsoft. (2022). Microsoft Zero Trust Solutions Deliver 92 Percent Return on Investment. Retrieved from Microsoft Security Blog
[21] MIT CISR. (2019). Capital One Data Breach: Learning from Cloud Security Failures. Retrieved from cams.mit.edu
[22] Montra. (2023). Why a Cybersecurity Compliance Program is Necessary for Every Business. Montra Solutions. Retrieved from https://montra.io/why-a-cybersecurity-compliance-program-is-necessary-for-every-business/
[23] National Institute of Standards and Technology. (2019). Application Container Security Guide (Special Publication 800-190). Retrieved from NIST
[24] NIST. (2020). SP 800-53, Revision 5: Security and Privacy Controls for Information Systems and Organizations. Retrieved from NIST
[25] Ozarslan, S. (2022). Key Threats and Cyber Risks Facing Financial Services and Banking Firms in 2022. Retrieved from Picus Security
[26] Pandey, A., & Tiwari, P. (2015). A Hybrid Protocol to Secure the Cloud from Insider Threats. Retrieved from researchgate.net
[27] SANS Institute. (2021). Cloud Security and Compliance. Retrieved from SANS
[28] Secureworks. (2021). Securing the Cloud: Protecting Your Cloud Environment from Threats. Retrieved from SecureWorks
[29] Station X. 75+ Surprising Cloud Security Statistics You Should Know in 2024
[30] Sudo Consultants. (2023). Cloud Access Security Brokers (CASB): Safeguarding AWS Data. Retrieved from https://sudoconsultants.com/cloud-access-security-brokers-casb-safeguarding-aws-data/
[31] TechRepublic. (2021). Microsoft Power Apps Misconfiguration Exposes Data from 38 Million Records. Retrieved from https://www.techrepublic.com/article/microsoft-power-apps-misconfiguration-exposes-data-from-38-million-records/
[32] The Hacker News. (2021). 38 Million Records Exposed from Misconfigured Microsoft Power Apps. Retrieved from https://thehackernews.com/2021/08/38-million-records-exposed-from.html
How to cite this paper
@article{1706386,
author = {Ibraheem Adebayo Yoosuf},
title = {Emerging Threats in Cloud Computing Security: A Comprehensive Review},
journal = {Iconic Research And Engineering Journals},
year = {2024},
volume = {8},
number = {4},
pages = {199-210},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1706386.pdf},
abstract = {The meteoric rise of cloud computing has ushered in a new era of security challenges, encompassing data breaches, misconfigurations, insider threats, and shared vulnerabilities. As organizations increasingly migrate to the cloud, these risks have become more pronounced, demanding new and sophisticated security frameworks to manage them. AI and machine learning are now effective in identifying anomalies and potential breaches, offering instant threat detection and predictive analysis. AI-driven security tools have significantly reduced misconfiguration-related vulnerabilities, improving overall system resilience. In this article, we will examine the diverse risks that threaten the integrity and security of cloud-based systems. This article also explores the role of regulatory frameworks, including the General Data Protection Regulation (GDPR) and The Health Insurance Portability and Accountability Act (HIPAA), in shaping cloud security standards. Governments and industry leaders are increasingly focused on establishing standardized, global security measures through international cooperation initiatives like the Paris Call for Trust and Security in Cyberspace. As cloud security continues to evolve, it is clear that both technological innovation and regulatory oversight will be essential in safeguarding cloud environments against emerging threats. This comprehensive analysis shows the critical need for a diverse approach, blending technology, governance, and international collaboration to secure the future of cloud computing.},
keywords = {Cloud security, AI in cybersecurity, Data breaches, Internal threats, Misconfigurations, Zero Trust, CASBs, Serverless computing, GDPR, HIPPA, Cloud security frameworks},
month = {October},
}