Towards Resilient Cloud Storage: a Defense-Indepth Framework for Mitigating Insider Threats and External Cyberattacks
Abstract
The advent of cloud computing has made cloud storage an essential part of today's digital environment that is widely used in healthcare, finance, and public sectors among others to store sensitive information. Nevertheless, the widespread use of cloud storage solutions creates additional risks for the stored information, making it vulnerable to attacks from both external actors, such as ransomware actors and nation-state advanced persistent threats (APTs), and malicious or negligent insiders using their legitimate credentials. Current security solutions address these kinds of threats separately, resulting in a disconnect between perimeter security and internal processes' governance. This research presents a novel cloud storage security architecture that includes four innovative encryption methods, namely Partition and Primes-Based Algorithm (PBA), Invertible Non-Linear Function-Based Cryptographic System (INFCS), Primes-Structured Cipher Algorithm (PSCA), and Tailored AES Cryptographic Algorithm (TCA). They work within a zero-trust architecture (ZTA) enhanced with artificial intelligence/machine learning-enabled UEBA, audit provenance based on blockchain technology, HSM key management, and disaster recovery. The architectural design relies on a formally constructed threat model in accordance with the MITRE ATT&CK for Cloud and supported by arguments for security properties of confidentiality, integrity, availability, and non-repudiation. Mapping of the proposed cloud storage security model across eleven types of threats resulted in a coverage of 93.6% of the MITRE ATT&CK for Cloud technique matrix.