Review of paper: IoT and cloud security
Introduction
Development of the smart cities and explosive demands of data transportation transforming our society into a futuristic world where everything is connected with a single thread – the internet. Transportation of vast amounts of data from the providers to the end-users requires a revolutionary computing system that the current world heavily relies upon. From financial transactions, web formation to data transportation, and security, the IoT (Internet of Things) is rapidly changing and redefining what it means to create devices implementing new technologies. IoT primarily consists of physical devices manufactured, incorporating high tech methods, and getting refined with the emergence of new technologies every day. Cloud security, on the other hand, creates the transactional path or a data-way for the information to reach its correct destination.
Statement of purpose
As someone who grew up in the generation of the internet and high-speed wiring system, I have seriously considered this topic into consideration for a critical evaluation. The entire assessment heavily relied on the issues and resolutions of IoT and cloud systems in the 21st century. The investigation of the given article aims to list our findings and the methods used to collect data to form an opinion on giant tech corporations’ current situation where our everyday life is highly dependent on the cloud computing system. The work experience was personally gratifying, and I sincerely hope it would feed your appetite for credible information in this particular area, too. Although previously, I have taken initiation of doing such evaluative reports lack of resources and feasible information had hindered my research. Hence, this particular attempt can be considered the final step to completing something I have commenced earlier.
Body of report
Intention
The rapid and inevitable spread of the IoT in our society is enormous. The current review covers the span of the IoT application, starting from industrial automation to our home area network. The present paper attempts to provide an up-to-date and well-structured survey of the cloud computing system’s security issues in the era of the IoT revolution. With an elaborate discussion on a structured classification of cloud computing security issues and a cloud-centered perspective of IoT security, this review assessment aspires to provide information regarding the cloud computing paradigm’s background. The entire article sincerely covers the essential characteristics of the cloud computing systems as well. The three main types of service models that are heavily implemented in the modern cloud computing systems are also a contributively aspect of the entire investigation. With the deployment of the system comes several issues that are often not theorized. This assessment will also attempt to touch upon those security issues that come with the fruition of ideas that make IoT and cloud computing systems a reality.
Research method
The entire research method has implemented a simplified cloud structure for reference to classify security issues and further discuss how this classification is organized. I have considered the separation of cloud-specific security issues from generic ones and even further classified security issues. This present investigation has heavily relied on the traditional model of cloud security classification and solely on the figures of the structure to have an understanding of how the issues affect our data if they do, at all. The possibilities of losing data potentially causing a severe crash of data in cloud computing systems and finally the IoT errors that can significantly contribute to such mishaps.
To understand the security problems at level x of the cloud architecture and how it results into having an impact on the overall structure of the IoT architecture also falls under the research method of the assessment of the present article.
Case study
Taking up the research methods above mentioned, I have attempted to make the entire assessment an investigative one and a responsive review paper. On attempting to read the review paper one might be able to participate in the process of such reactive assessment where your input would also get seriously considered in the paper. The entire case study has employed all the methods mentioned to evaluate the concrete results that a refined IoT device and cloud computing system can potentially provide. By highlighting the relationship between each security issue, the cloud and the IoT devices, the review paper indicates the specific security issue that can potentially be exploited and the party that might be the victim of an attack perpetrated exploiting that issue. At an architectural level, we have focused on the issues of virtualization, application, network, data storage and multi-level crisis. The entire study has been assessed on these issues primarily focusing on a classification of cloud-specific and generic issues.
Observation
In the process of investigating the entire article we may include these observations, significant in the assessment. Confidentiality is one of the major issues where information can potentially get spread or can be made available to the unauthorised individuals. By presenting a classification of security issues the assessment would show how we can impair data confidentiality. Virtual tech being one of the key enablers of cloud computing systems, the article has successfully covered the multi-tenancy issues, VM (virtual machine) isolation issues, virtual network issues, virtual machine introspection issues, virtual machine management issues, VM migration issues and synchronisation mechanisms issues. Outsourcing and data-deletion issues are the two major issues in data storage level issues. Integrity issue has serious mention in the body of the article where the authentic value of the transported information is sincerely discussed and how much of its purpose can sufficiently be accurate is another aspect to it.
Findings
Survey method
Although, there has been visible mentions of the methods and procedures that are incorporated in the progression of this review assessment before, but the final discoveries have been mentioned below in an elaborate manner.
Application level issues
In the course of the review assessment we have found some major application level issues in the cloud computing systems and IoT enabled devices. The lack of transparency and combined outsourcing allow service providers to alter the results of computation or not even perform elaborations in the most prominent way. In addition to that, a cloud malware injection attack can potentially cause a serious inconvenience in the computation cheating.
Insecure APIs and management creates web vulnerabilities and can allow anybody on the internet to access data resulting in a breakage of application integrity. This is considered to be a significant problem in the IoT landscape. Storing personal data in plain text can allow unauthorized access and a consequent data leakage due to insecure application interface.
Isolation Issue
Isolation issues within IoT enabled platforms can affect the integrity of data and applications. In the Synchronization mechanism, vulnerabilities can also be exploited to compromise the integrity of data. Due to MitC (Man in the Cloud) attack the integrity of the data can be compromised and therefore the attacker can take advantage of tokens and authenticates as a different user to illegally access data and cause data spillage over the internet.
Data storage level issue
The outsourcing feature of data in the cloud system is another data integrity challenge. This article consists of a clear elucidation on the issues raised by such complications. Data outsourcing issues are a massive data integrity challenge that the IoT enabled landscape may confront and that can potentially crash the entire cloud computing system.
In the process of delivering data to the authorised users whenever it is needed, storing the information and finally processing them there has been a significant amount of virtualisation level issues that introduces new attack vectors that can be exploited to impact on the availability and performances of cloud systems.
Experiments
In the experimentation with the classified cloud security issues we get access to have a better understanding of these issues that can be a potential threat to the illegitimate data spread, data integrity issues on the internet and web vulnerabilities.
The essential characteristics of cloud computing systems relevant in the experimentation of this topic are:
- Accommodating multiple consumers dynamically allocating and de-allocating them according to consumer demands.
- Available computing capabilities over a massive network access.
- Systematically monitored and reported measure services are offered.
- An interactive consumer and customer provider session to avail self-services on demand.
Conclusion
The complete review consists of well analysed security issues, incorporative aspects and resolution of those issues in the IoT enabled devices and cloud cloud computing systems. Addressing all of these issues in a defining manner, this article had clearly guided the readers towards the solution of these problems that get raised in the course of this proposition. It also includes a well-structured and an up-to-date survey of these security issues distinguishing between cloud-specific and generic issues. We have significantly analysed how we can consider solving the major issues in the IoT system once the basic cloud shortcomings are remedied.
References