Even with the vast potential that cloud computing has, so far, it has not been adopted by the consumers with the enthusiasm and pace that it be worthy; this is a very reason statement why consumers still hesitated of using cloud computing for their sensitive data and the threats that prevent the consumers from shifting to use cloud computing in general and cloud storage in particular. The cloud computing inherits the traditional potential security and privacy threats besides its own issues due to its unique structures. Some threats related to cloud computing are the insider malicious attacks from the employees that even sometime the provider unconscious about, the lack of transparency of agreement between consumer and provider, data loss, traffic hijacking, shared technology and insecure application interface. Such threats need remedies to make the consumer use its features in secure way. In this review, we spot the light on the most security and privacy issues which can be attributed as gaps that sometimes the consumers or even the enterprises are not aware of. We also define the parties that involve in scenario of cloud computing that also may attack the entire cloud systems. We also show the consequences of these threats.
翻译:尽管云计算潜力巨大,但迄今为止,消费者尚未以应有的热情和速度采纳它;这正是消费者仍对将敏感数据用于云计算、尤其是云存储犹豫不决的原因,也是阻碍消费者转向使用云计算(尤其是云存储)的威胁所在。云计算除了自身独特结构带来的问题外,还继承了传统的潜在安全与隐私威胁。与云计算相关的部分威胁包括:来自员工的内部恶意攻击(有时甚至服务商也毫无察觉)、消费者与服务商之间协议缺乏透明度、数据丢失、流量劫持、共享技术以及不安全的应用程序接口。此类威胁需采取补救措施,使消费者能够安全地使用其功能。在本综述中,我们着重指出最突出的安全与隐私问题,这些问题可归为消费者甚至企业有时未意识到的漏洞。我们还明确了云计算场景中可能攻击整个云系统的参与方,并展示了这些威胁的后果。