CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Insider Threat For Service Account in Google Cloud Platform
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering.
2023 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

As most software industry is migrating from traditional servers and depending more on Cloud-based services, we are encountering new problems hitherto unknown to us. Due to the variousadvantages offered by Cloud services and the numerous problems whose solutions are providedby Cloud technologies, cloud-based services have become very popular. Organizations of allsizes widely use them to meet their day-to-day technology needs. Cloud infrastructure mainlyconsists of Cloud resources and services, which are accessed through user and service accounts.This thesis considers the challenge of securing service accounts of cloud providers by serviceaccount keys. In the realm of cloud security, a central challenge revolves around the effectiveprotection of service account keys to thwart unauthorized access and the potential for databreaches, all while ensuring that legitimate operations maintain the necessary access. Eachservice account is intricately linked to a set of credentials, comprising both private and publickeys used for interactions with external APIs. These credentials play a critical role inauthenticating the service account and granting it authorization to access resources withinGoogle Cloud Platform (GCP). Notably, when service account keys are not downloaded, theprivate key remains confined within the GCP environment, limiting service interactions.Conversely, the act of downloading the private key increases the risk of exploitation, as itrepresents the most sensitive component of the service account credentials. Without access tothe private key, the authentication of the service account and subsequent access to GCPresources becomes unattainable.To address the holistic challenges in this thesis, it's crucial to emphasize the importance ofsecuring service account keys and limiting access to authorized users. This led to the proposalof a key rotation process to achieve our research objectives. The approach taken in this studyinvolves both qualitative and quantitative methods. This includes a thorough literature reviewand interviews with cloud professionals, allowing us to gain insights into the threats throughcontent analysis and a SWOT-based assessment. This method is aimed at mitigating the risk ofservice account key exploitation.

Place, publisher, year, edition, pages
2023. , p. 56
National Category
Other Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
URN: urn:nbn:se:ltu:diva-102333OAI: oai:DiVA.org:ltu-102333DiVA, id: diva2:1810414
Subject / course
Student thesis, at least 30 credits
Educational program
Information Security, master's level (120 credits)
Presentation
2023-06-01, Zoom, 10:00 (English)
Supervisors
Examiners
Available from: 2023-11-17 Created: 2023-11-07 Last updated: 2023-11-17Bibliographically approved

Open Access in DiVA

fulltext(848 kB)20 downloads
File information
File name FULLTEXT01.pdfFile size 848 kBChecksum SHA-512
e1d7147bd452f0c501564ae1a4f600d9e0baab5dc3aea1760fc0fa703697d5a928674667c848805c29679bf6249c3a82366516bb8f62f24f4a7fb984074f40f0
Type fulltextMimetype application/pdf

By organisation
Department of Computer Science, Electrical and Space Engineering
Other Electrical Engineering, Electronic Engineering, Information Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 20 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 129 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf