Threat Detection and Incident Response in Cloud Security
Satheeshkumar Rajendran, A. Valarmathi, M. Satheesh Kumar · 2022
A set of policies, procedures, controls, and technologies integrated together to protect the cloud infrastructure and its associated systems and data is called cloud security. Protecting data stored online and protecting digital assets are the key points of having security in cloud computing. Cloud security is vital to cloud storage providers as they have to protect the sensitive information while following certain regulatory requirements. While the data remain the same, these regulatory requirements differ based on the geolocation. Threat detection is a defensive technique for identifying any kind of malicious activity that could compromise the network. Incident response (IR) is mitigating the detected threat, without compromise in the system/network. IR should be done quicker before the detected threat can exploit the present vulnerabilities in the system. Data loss/data leakage is the most common security risk in cloud computing. This chapter deals with the key cloud security threats such as data breaches, malware infection, denial-of-service attack, and hijacking accounts and how they are detected in cloud environment before a compromise, and if compromised how they are mitigated minimizing the business impacts.