Tutorials › Core Cloud Architecture › Security Fundamentals in the Cloud

Core Cloud Architecture · Part 11 of 13

Security Fundamentals in the Cloud

Identity decides who's allowed in. Encryption, segmentation, and audit protect everything around that decision.

Past deciding who and what is allowed to act, a cloud system needs layers that protect data and infrastructure regardless of who's asking: encryption, network boundaries, and the visibility to notice when something's gone wrong.

Encryption at rest and in transit

Encryption at rest protects stored data (on disk, in a database, in object storage) so that anyone who gains access to the underlying storage medium without the right key sees only ciphertext. Most managed cloud storage and database services enable this by default today, which wasn't always true, so confirm it rather than assume it. Encryption in transit protects data as it moves across a network, almost always via TLS (transport layer security), the protocol behind HTTPS, which also authenticates the server the client is talking to and protects against a third party silently reading or altering traffic in between.

Key management and secrets

Encryption is only as good as control over the keys that unlock it. A key management service (KMS) creates, stores, rotates, and controls access to encryption keys, and can keep keys inside hardware security modules designed to make extraction extremely difficult, so an application encrypting data through a KMS never handles the raw key material directly. A secrets manager serves a related purpose: storing and controlling access to application secrets (database passwords, third-party API keys, the long-lived credentials worth minimizing) with the same access-controlled, audited retrieval a KMS provides for encryption keys, instead of those secrets sitting in a config file or environment variable in plain text.

Network segmentation and private endpoints

Network segmentation is the security application of the subnet and security-group concepts from the networking article: splitting infrastructure into isolated zones so that compromising one segment (a public-facing web tier, say) doesn't automatically grant access to another (a database holding sensitive data). A private endpoint lets a resource (a database, a storage bucket) be reached only from inside a private network, never over the public internet, even if its access policy would otherwise allow it. That removes a whole category of exposure by making the resource unreachable from outside, instead of leaning on access rules alone to keep outsiders out.

Vulnerability management

Vulnerability management is the ongoing process of finding and fixing known weaknesses (outdated dependencies with published vulnerabilities, container base images missing security patches, misconfigured resources) before someone else finds them first. Most cloud providers offer automated scanning for container images and dependencies; the harder part is consistently acting on what's found, since a scanner whose findings nobody triages protects nothing.

WAF and DDoS protection

A web application firewall (WAF) inspects HTTP traffic for known attack patterns (SQL injection attempts, cross-site scripting payloads) and blocks matching requests before they reach the application. DDoS protection defends against distributed denial-of-service attacks, traffic floods designed to overwhelm a service rather than exploit a specific vulnerability, typically by absorbing and filtering traffic at the network edge before it ever reaches the origin infrastructure. The major cloud providers now include a baseline of automatic DDoS protection at no cost; a dedicated WAF is a deliberate extra layer, worth its cost once an application is a plausible target and handles the kind of traffic (public-facing, receiving user input) a WAF is built to filter.

Audit logging

Audit logging records who did what, when, across the cloud environment itself (who created this resource, who changed that permission, who read this piece of data), independent of whatever logging the application does about its own business logic. It's the record that answers "what happened" after an incident, and it has to be switched on before the incident: events that were never recorded can't be reconstructed later.

Compare: security services across the three major clouds

ConceptAWSGCPAzure
Key managementKMSCloud KMSKey Vault
Secrets managementSecrets ManagerSecret ManagerKey Vault
WAFAWS WAFCloud ArmorAzure WAF
DDoS protectionShieldCloud ArmorAzure DDoS Protection
Threat detection / posture managementGuardDutySecurity Command CenterMicrosoft Defender for Cloud
Audit loggingCloudTrailCloud Audit LogsAzure Monitor activity logs
GCP's Cloud Armor covers both the WAF and DDoS rows, one service where AWS and Azure ship two.