Back close

Course Detail

Course Name Cloud and Infrastructure Security
Course Code 26SN631
Program M. Tech. in Cyber Security Systems & Networks
Credits 3
Campus Amritapuri

Syllabus

Syllabus

Cloud Computing Essentials: Characteristics, Cloud Computing Models, Service Models, Deployment Models, Shared Responsibility Model, NIST Reference Architecture, Cloud Native Architecture, Virtualization, Containers, Popular Cloud Platforms and Open-source Cloud Architecture.

Threats and Attacks in Cloud Computing: Attacks in Various Layers of Cloud Computing, Infrastructure and Host Threats, Service Provider Threats, Multi-tenant Threats, Container and Kubernetes Threats, API Threats, Generic Threats, Threat Assessment, Cloud Security Alliance (CSA) Top Threats and Countermeasures.

Risk and Trust in Cloud Computing: Risk Assessment, Risk and Trust Models, Security Service Level Agreements (SLA), Shared Responsibility Model and Zero Trust Architecture.

Protecting Data in the Cloud: Encryption at Rest and in Transit, Tokenization, Cryptographic Key Management, Secrets Management, Data Loss Prevention (DLP), Homomorphic Encryption.

Vulnerability Management: Differences from Traditional IT, Vulnerable Areas, Vulnerability Assessment and Management, Container Vulnerabilities, Infrastructure as Code Security, Finding and Fixing Vulnerabilities.

Cloud Security Architecture: General Issues, Trusted Cloud Computing Platform, Identity Management and Access Control, Authentication, Authorization, Federated Identity Management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Role Based Access Control (RBAC), Attribute Based Access Control (ABAC), Privileged Access Management (PAM).

Monitoring, Incident Response and Compliance: Logging and Monitoring, Security Information and Event Management (SIEM), Incident Response, Cloud Forensics, Cloud-centric Regulatory Compliance Issues and Mechanisms.

Emerging Trends: DevSecOps, Multi Cloud Security, Serverless Security, Confidential Computing, AI/ML for Cloud Security, Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platform (CNAPP)

Text Books / References
  1. Ronald L. Krutz and Russell Dean Vines, “Cloud Security: A Comprehensive Guide to Secure Cloud Computing”, Wiley India, 2010.
  2. Tim Mather, Subra Kumaraswamy and Shahed Latif, “Cloud Security and Privacy”,  O’Reilly Media, 2009.
  3. Chris Dotson, “Practical Cloud Security: A Guide for Secure Design and Deployment”, O’Reilly Media, 2022.
  4. Rajkumar Buyya, James Broberg and Andrzej Goscinski, “Cloud Computing: Principles and Paradigms”, Wiley, 2011.
  5. Liz Rice, “Container Security”,  O’Reilly Media, 2020.
  6. NIST Special Publication 800-144, “Guidelines on Security and Privacy in Public Cloud Computing”,   National Institute of Standards and Technology (NIST), 2011.
  7. Cloud Security Alliance (CSA), “Security Guidance for Critical Areas of Focus in Cloud Computing”, Latest Edition.

Introduction

Cloud computing has become the backbone of modern digital infrastructure, offering scalable and on-demand computing, storage, and networking services. However, the adoption of virtualization, containers, cloud-native applications, and distributed infrastructures has introduced new security challenges and attack surfaces. This course provides a comprehensive understanding of cloud and infrastructure security, covering threats, vulnerabilities, risk management, identity and access management, data protection, virtualization and container security, compliance, and incident response. Emerging paradigms such as Zero TrustArchitecture, DevSecOps, Multi-Cloud Security, and Cloud Native Security are also discussed. The laboratory component provides hands-on experience in securing cloud platforms and infrastructure using contemporary tools and frameworks.

Objectives and Outcomes

Course Objective:

  • Understand cloud computing architectures, deployment and service models, virtualization technologies, and cloud-native infrastructures.
  • Analyze threats, vulnerabilities, risks, and security challenges associated with cloud and infrastructure environments.
  • Apply identity and access management, data protection, and secure architecture principles to design secure cloud infrastructures.
  • Develop practical skills in securing containers, Kubernetes clusters, APIs, and Infrastructure as Code (IaC) using contemporary tools and frameworks.
  • Evaluate emerging technologies and paradigms such as Zero Trust Architecture, DevSecOps, Multi-Cloud Security, Serverless Security, CSPM, and CNAPP for securing modern cloud infrastructures.

Course Outcomes

CO Description
CO1 Understand cloud computing architectures, deployment and service models, virtualization technologies, and security challenges in cloud and infrastructure environments.
CO2 Analyze threats, vulnerabilities, risks, and attack vectors in cloud infrastructures, virtualized environments, containers, and cloud-native applications.
CO3 Design and implement secure identity and access management, data protection mechanisms, and cloud security architectures using contemporary frameworks and standards.
CO4 Perform vulnerability assessment, security monitoring, incident response, and implement security controls for containers, Kubernetes, APIs, and Infrastructure as Code (IaC).
CO5 Evaluate emerging technologies such as Zero Trust Architecture, DevSecOps, Multi-Cloud Security, Serverless Security, CSPM, and CNAPP for enhancing cloud and infrastructure security.

Pre-requisite: Basic knowledge of Computer Networks, Operating Systems, Information Security and Virtualization Technologies.

Evaluation Pattern

CO-PO Mapping

CO / PO PO1 PO2 PO3
CO1 1 3
CO2 3 3
CO3 2 2 3
CO4 3 1 3
CO5 3 2 3
CO Justification
CO1 Understanding cloud architectures, deployment models, and virtualization contributes strongly to specialization knowledge (PO3) and moderately to problem analysis.
CO2 Analysis of threats, vulnerabilities, and risks requires investigation and analytical skills (PO1) and strengthens domain expertise (PO3).
CO3 Designing IAM, data protection mechanisms, and cloud security architectures involves design skills, use of modern tools/frameworks, and technical communication (PO2).
CO4 Vulnerability assessment, incident response, and implementation of security controls for containers, Kubernetes, APIs, and IaC require research skills (PO1), modern tools, and specialization knowledge (PO3).
CO5 Evaluation of emerging technologies such as Zero Trust, DevSecOps, Multi-Cloud Security, Serverless Security, CSPM, and CNAPP requires investigation (PO1), technical reporting (PO2), and mastery of cloud security concepts (PO3).

Evaluation Pattern – 70:30

  • Midterm Exam – 30 %
  • Assignments – 10 %
  • Lab Assignments – 30%
  • Final Examination – 30%

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now