With the increasing use of multi-cloud environments, security professionals face challenges in configuration, management, and integration due to uneven security capabilities and features among providers. As a result, a fragmented approach toward security has been observed, leading to new attack vectors and potential vulnerabilities. Other research has focused on single-cloud platforms or specific applications of multi-cloud environments. Therefore, there is a need for a holistic security and vulnerability assessment and defense strategy that applies to multi-cloud platforms. We perform a risk and vulnerability analysis to identify attack vectors from software, hardware, and the network, as well as interoperability security issues in multi-cloud environments. Applying the STRIDE and DREAD threat modeling methods, we present an analysis of the ecosystem across six attack vectors: cloud architecture, APIs, authentication, automation, management differences, and cybersecurity legislation. We quantitatively determine and rank the threats in multi-cloud environments and suggest mitigation strategies.
翻译:随着多云环境的日益普及,由于不同供应商之间安全能力与特性不均,安全专业人员在配置、管理和集成方面面临挑战。由此导致安全措施呈现碎片化趋势,催生了新的攻击向量和潜在漏洞。现有研究多聚焦单一云平台或多云环境的特定应用场景,因此亟需一套适用于多云平台的整体性安全与漏洞评估及防御策略。本文通过风险与漏洞分析,从软件、硬件和网络层面识别攻击向量,并探究多云环境中的互操作性安全问题。应用STRIDE与DREAD威胁建模方法,我们从云架构、API、身份认证、自动化、管理差异及网络安全立法六大攻击向量维度,对生态系统进行了全面分析。通过定量评估与排序,我们确定了多云环境中的主要威胁,并提出了相应的缓解策略。