Abstract:
Fortifying Cloud Security has become inevitable due to challenges such as misconfigurations, coding errors, and compromised secrets or passwords that impact infrastructur...Show MoreMetadata
Abstract:
Fortifying Cloud Security has become inevitable due to challenges such as misconfigurations, coding errors, and compromised secrets or passwords that impact infrastructure as a service during infrastructure such as code automation (IaC). These challenges require code analysis tools to enhance security during infrastructure automation. Setting up a simple cloud architecture is quick, but human errors are still common, especially when cloud infrastructure can be deployed with just a few clicks. Terraform provides a ready-made infrastructure as code modules to build and scale cloud-hosted applications. However, cyber attackers exploit these vulnerabilities and gain access to sensitive data or resources without authorization due to configuration errors, inadequate storage, and infrastructure manipulation, resulting in unauthorized deployments or alterations. That affects the availability of resources during infrastructure deployment using attacks such as DoS attacks, injection attacks, Man in the Middle (MITM), malware spread, remote code execution (RCE), and phishing attacks to penetrate the cloud infrastructures. The paper aims to analyze Terraforms infrastructure as code in cloud security to fortify codes and assist DevSecOps engineers in identifying misconfiguration in Terraform scripts. The paper's contributions are threefold. First, we explore cloud security by securing IaC solutions on Terraform. We consider security issues, including misconfigurations and coding errors, present in Terraform IaC. Secondly, we implement a static analysis tool for terraform by comparatively analyzing existing tools. Finally, we provide a comparative analysis of terraform IaC on tools including Checkov, Tfsec, Tflint, and Terrascan for suitability based on their key features and performance metrics to enhance security.
Published in: 2024 International Conference on Electrical and Computer Engineering Researches (ICECER)
Date of Conference: 04-06 December 2024
Date Added to IEEE Xplore: 18 March 2025
ISBN Information: