SECURITY IN CLOUD COMPUTING IN INDIAN GOVERNMENT

##plugins.themes.academic_pro.article.main##

Nitin Choudhari
Dr. Ashish Sasankar

Abstract

Abstract –Today Security issue is the topmost problem in the cloud computing environment. It leads to serious discomfort to the Governance and end-users. Numerous security solutions and policies are available however practically ineffective in use. Most of the security solutions are centered towards cloud technology and cloud service providers only and no consideration has been given to the Network, accessing, and device securities at the end-user level. The discomfort at the end-user level was left untreated. The security of the various public, private networks, variety of devices used by end-users, accessibility, and capacity of end-users is left untreated. This leads towards the strong need for the possible modification of the security architecture for data security at all levels and secured service delivery. This leads towards the strong need for the possible adaption of modified security measures and provisions, which shall provide secured hosting and service delivery at all levels and reduce the security gap between the cloud service providers and end-users. This paper investigates the study and analyze the security architecture in the Cloud environment of Govt. of India and suggest the modifications in the security architecture as per the changing scenario and to fulfill the future needs for the secured service delivery from central up to the end-user level.

##plugins.themes.academic_pro.article.details##

How to Cite
Choudhari, N., & Sasankar, D. A. (2021). SECURITY IN CLOUD COMPUTING IN INDIAN GOVERNMENT. International Journal of Next-Generation Computing, 12(3), 399–423. https://doi.org/10.47164/ijngc.v12i3.808

References

  1. Accountabilityindia.in. 2021. Sustainability and accountability issues of common service centres. https://accountabilityindia.in/blog/sustainability-and-accountability-issuesof-common-service-centres/.
  2. Ardagna, C. Sept 2015. From security to assurance in the cloud: A survey. vol. 48, No.50. Attrapadung, N., Herranz, J., Laguillaumie, F., Libert, B., de Panafieu, E., and Rafols, C. ` Mar 2012. Attribute-based encryption schemes with constant-size ciphertexts. Theor. Comput. Sci. vol. 422, pp.15–38.
  3. Banyal, R., Jain, P., and Jain, V. K. 2013. Multi-factor authentication framework for cloud computing. In 5th Intl. Conf. on Computational Intelligence, Modelling, and Simulation. pp.105–110.
  4. Barakat, O. 2013. Malware analysis performance enhancement using cloud computing. J. Comput. Virol. Hacking Tech. vol. 10, No.1, pp.1–10.
  5. Boutaba, R., Zhang, Q., and Zhani, M. F. 2014. Virtual machine migration in cloud computing environments. Communication Infrastructures for Cloud Computing, IGI Global, pp.383–408.
  6. Buyya, R., Vecchiola, C., and Selvi, S. T. 2013. Mastering cloud computing: foundations and applications programming. Morgan Kaufmann.
  7. Chonka, A., Xiang, Y., Zhou, W., and Bonti, A. 2013. Cloud security defense to protect cloud computing against http-dos and xml-dos attacks. J. Netw. Comput. Appl. vol. 34, No.4, pp.1097–1107.
  8. Cloud-Security-Alliance. 2017. Security guidance for critical areas of focus in cloud computing v4.0. PP24-25, https://downloads.cloudsecurityalliance.org/assets/research/securityguidance/security-guidance-v4-FINAL.pdf.
  9. Cloud-Security-Alliance. 8 June 2019. Top threats to cloud computing: Egregious eleven. https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computingegregious-eleven/.
  10. Cloud.Report. 2017. State of the cloud report. Right Scale, ). https://www.rightscale.com/lp/state-of-the-cloud.
  11. Cowan, C. Jan. 1998. Stackguard: Automatic adaptive detection and prevention of buffer overflow attacks. 7th USENIX Security Symp., San Antonio, Texas. C.P.Pfleeger and S.L.Pfleeger. 2006. Security in computing. Prentice Hall.
  12. CSC. 2021. Common service centre scheme. https://www.csc.gov.in/.
  13. CSCC. December 2017. Security for cloud computing. ten steps to ensure success version 3.0. Cloud Standards Customer Council, https://www.omg.org/cloud/deliverables/CSCCSecurity-for-Cloud-Computing-10-Steps-to-Ensure-Success.pdf.
  14. Cyber.Education. 9 Aug. 2018. What is cloud security? Forcepoint, https://www.forcepoint.com/cyber-edu/cloud-security.
  15. DEF. 10 Nov 2012. National digital literacy mission. Digital Empowerment Foundation, DEF, https://www.defindia.org/national-digital-literacy-mission/.
  16. Despotovic-Zraki ´ c, M. ´ , Milutinovic, V. ´ , and Belic, A. ´ Mar 2014. Handbook of research on high performance and cloud computing in scientific research and education. In IGI Global.
  17. DigitalNIC. 2021. Nic webvpn , digitalnic dashboard. https://saccess.nic.in/DigitalNIC/. Dorban, B. 2 August 2018. What is cloud security and what are the benefits ? https://phoenixnap.com/blog/what-is-cloud-security.
  18. Duncan, A., Creese, S., and Goldsmith, M. 2012. Insider attacks in cloud computing. In 11th IEEE Intl. Conf. on Trust, Security, and Privacy in Computing and Communications, TrustCom. pp.857–862.
  19. Durcevic, S. 10 Jan. 2019. Cloud computing risks, challenges problems businesses are facing. Datapine, https://www.datapine.com/blog/cloud-computing-risks-and-challenges/.
  20. FACTLY. 25 Aug 2020. Government’s digital literacy targets not met because of paucity of funds. FACTLY, https://factly.in/review-governments-digital-literacy-targets-not-metbecause-of-paucity-of-funds/.
  21. GI-Cloud. 2021a. Cloud brochure. cloud services from national informatics centre. https://cloud.gov.in/about.php.
  22. GI-Cloud. 2021b. On boarding procedure. https://cloud.gov.in/about.php.
  23. GI-Cloud. 2021c. Terms and conditions, national cloud of india. https://cloud.gov.in/termsandconditions.php.
  24. Halfond, W., Viegas, J., and Orso, A. March 2006. A classification of sql injection attacks and countermeasures,. In Intl. Symp. on Secure Software Engineering. pp.857–862.
  25. HARIHARAN, M. Nov 2017. Website security guidelines. NIC-Computer Emergency Response Team (CERT), NIC, Govt. of India, https://nic-cert.nic.in.
  26. IBM-Cloud.Education. 3 October 2019. What is cloud security? IBM, https://https://www.ibm.com/cloud/learn/cloud-security.
  27. Jamil, D. and Zaki, H. 2011. Security issues in cloud computing and countermeasures. Intl. J. Eng. Sci. Technol. vol. 3, No.4, pp.2672–2676.
  28. Jones, E. 25 March 2021. A comprehensive guide to cloud security in 2021. Kinsta https://kinsta.com/blog/cloud-security/.
  29. Krutz, R. and Vines, R. 2010. Cloud security: a comprehensive guide to secure cloud computing. Wiley.
  30. Kumar, A. 2018. How does cloud-based security work? https://jktech.com/insight/blogs/howdoes-cloud-based-security-work/.
  31. Lee, I., Jeong, S., Yeo, S., and Moon, J. Jan 2012. A novel method for sql injection attack detection based on removing sql query attribute values. Math. Comput. Model vol. 55, No.2, pp.58–68.
  32. MeitY. 2 July 2013a. It act 2000. https://www.meity.gov.in/content/information-technologyact-2000.
  33. MeitY. 2 July 2013b. National cyber security policy 2013. , https://www.meity.gov.in/content/national-cyber-security-policy-2013-1.
  34. MeitY. 2021. Gi cloud (meghraj) national cloud of india. National Cloud of India, Ministry of Electronics and Information Technology, Govt. of India, https://www.meity.gov.in/content/gi-cloud-meghraj.
  35. Mitrokotsa, A. and Douligeris, C. 2005. Detecting denial of service attacks using emergent self-organizing maps. In 5th IEEE Intl. Sym. on Signal Processing and Information Technology. pp.375–380.
  36. Morabito, V. 2013. Big data in trends and challenges in digital business innovation. In Springer Intl. Publishing. pp.3–21.
  37. Naccache, u. 2011. Buffer overflow attacks,” encyclopedia of cryptography and security. Boston, MA: Springer US, pp.174–177.
  38. NCIPC. 15 Mar 2021. Common vulnerabilities and exposures(cve) report. National Critical Information Infrastructure Protection Centre, https://nciipc.gov.in.
  39. NIC-AarogyaSetu. 2021. Dashboard. NIC WEB VPN, https://saccess.nic.in/.
  40. NIC-CERT. November 2017. Information security incident management policy. NIC Computer Emergency Response Team (CERT),NIC, Govt. of India, https://niccert.nic.in/pdf/Information Security Incident Management Policy.pdf.
  41. NIC-Servicedesk. 2021. Help desk for nic services. National Informatics Centre,Government of India https://servicedesk.nic.in/.
  42. Nvshq.Org. 22 Apr.2021. What is csc. https://nvshq.org/scheme/common-service-centre-apnacsc/. Ramey, J. and Rao, P. 2011. The systematic literature review as a research genre. In IEEE Intl. Professional Comm. Conf. pp.1–7.
  43. Rocha, F., Abreu, S., and Correia, M. 2011. The final frontier: Confidentiality and privacy in the cloud. IEEE Computer vol. 44, No.9, pp.44–50.
  44. Solanki, P. 24 Apr. 2020. 10 major cloud computing challenges to face in 2021. MindInventory, https://www.mindinventory.com/blog/cloud-computing-challenges/.
  45. Stackpath. 2021. What is edge computing? https://www.stackpath.com/edge-academy/what is-edge-computing.
  46. Thales. 2020. Digital transformation and data privacy. https://www6.thalesgroup.com/wpdigital-transformation-data-privacy.pdf.
  47. TRAI. 2017. Recommendations on cloud services. 38-40 https://trai.gov.in/.
  48. Utley, G. 12 April 2018. 6 most common cloud computing security issues. , https://www.coursehero.com/file/62232851/6-Most-Common-Cloud-Computing-SecurityIssues-CWPSpdf/.
  49. Varanasi, P. 8th July 2020. 5 must-have cloud computing features. Cloudcodes https://www.cloudcodes.com/blog/5-cloud-computing-security-features.html.
  50. Wood K, P. E. 2010. An investigation into cloud configuration and security. In International Conference for Internet Technology and Secured Transactions. pp.1–6.