<p>Cloud storage misconfiguration continues to be a major source of security incidents in public cloud environments, particularly in widely used object storage platforms such as Amazon Simple Storage Service (Amazon S3). Although cloud providers offer a broad set of built-in security controls, their effectiveness depends on how consistently and correctly they are implemented. In practice, manual configuration, inconsistent deployment processes, and configuration drift often create avoidable security risks. This study presents a policy-enforced Infrastructure-as-Code (IaC) framework designed to reduce common Amazon S3 misconfiguration risks during infrastructure deployment. Using Terraform, the framework integrates security controls directly into the provisioning process, including server-side encryption with AWS Key Management Service (SSE-KMS), HTTPS-only transport enforcement, public access restrictions, least-privilege identity and access management, and audit logging through AWS CloudTrail and S3 server access logging. Rather than relying exclusively on post-deployment monitoring or compliance verification, the proposed framework applies security constraints during infrastructure provisioning to reduce the likelihood of insecure configurations being introduced. The framework was implemented and evaluated within an AWS environment using representative misconfiguration scenarios involving insecure transport, missing encryption parameters, public exposure attempts, and access policy violations. The findings indicate that embedding policy-based security controls within Infrastructure-as-Code workflows can improve deployment consistency, reduce configuration errors, and support alignment with established security guidance, including NIST SP 800–53 Revision 5 and the CIS AWS Foundations Benchmark. This study contributes a structured implementation framework for applying deployment-time security enforcement to Amazon S3 cloud storage environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Preventing Amazon S3 Cloud Storage Misconfiguration Using Infrastructure-as-Code: A Policy-Enforced Security Framework

  • Taiwo Justice Olorunlana

摘要

Cloud storage misconfiguration continues to be a major source of security incidents in public cloud environments, particularly in widely used object storage platforms such as Amazon Simple Storage Service (Amazon S3). Although cloud providers offer a broad set of built-in security controls, their effectiveness depends on how consistently and correctly they are implemented. In practice, manual configuration, inconsistent deployment processes, and configuration drift often create avoidable security risks. This study presents a policy-enforced Infrastructure-as-Code (IaC) framework designed to reduce common Amazon S3 misconfiguration risks during infrastructure deployment. Using Terraform, the framework integrates security controls directly into the provisioning process, including server-side encryption with AWS Key Management Service (SSE-KMS), HTTPS-only transport enforcement, public access restrictions, least-privilege identity and access management, and audit logging through AWS CloudTrail and S3 server access logging. Rather than relying exclusively on post-deployment monitoring or compliance verification, the proposed framework applies security constraints during infrastructure provisioning to reduce the likelihood of insecure configurations being introduced. The framework was implemented and evaluated within an AWS environment using representative misconfiguration scenarios involving insecure transport, missing encryption parameters, public exposure attempts, and access policy violations. The findings indicate that embedding policy-based security controls within Infrastructure-as-Code workflows can improve deployment consistency, reduce configuration errors, and support alignment with established security guidance, including NIST SP 800–53 Revision 5 and the CIS AWS Foundations Benchmark. This study contributes a structured implementation framework for applying deployment-time security enforcement to Amazon S3 cloud storage environments.