التحديات والحلول الأمنية في بيئات الحوسبة السحابية
مراجعة شاملة
DOI:
https://doi.org/10.64059/eiu.v3i1.227الكلمات المفتاحية:
الحوسبة السحابية، أمن الحوسبة السحابية، الأمن السيبراني، بنية انعدام الثقة، إدارة الهوية والوصول، أمن البيئات السحابية متعددة السحبالملخص
أصبحت الحوسبة السحابية نموذجًا أساسيًا لتوفير موارد حوسبية قابلة للتوسع ومرنة وفعالة من حيث التكلفة، وذلك من خلال منصات تعتمد على الإنترنت. وقد أسهم الانتشار السريع للحوسبة السحابية في مختلف القطاعات في تعزيز الكفاءة التشغيلية، وتحسين استغلال الموارد، والارتقاء بمستوى تقديم الخدمات. وعلى الرغم من هذه المزايا، لا تزال البيئات السحابية تواجه تحديات أمنية جوهرية تهدد سرية البيانات وسلامتها وتوافرها، فضلًا عن تهديد الخدمات المستضافة عليها.
تستعرض هذه الدراسة أهم التهديدات الأمنية التي تؤثر في بيئات الحوسبة السحابية، بما في ذلك اختراقات البيانات، والاستيلاء على الحسابات، والتهديدات الداخلية، وعدم أمان واجهات برمجة التطبيقات (APIs)، وسوء تهيئة البيئات السحابية، وهجمات حجب الخدمة الموزعة (DDoS)، والمخاطر المرتبطة بتعدد المستأجرين، وقضايا الامتثال للمتطلبات واللوائح التنظيمية. كما تحلل الدراسة الآثار الأمنية المرتبطة بمختلف نماذج الخدمات السحابية ونماذج نشر الحوسبة السحابية.
وعلاوة على ذلك، تستعرض الدراسة آليات الأمن السيبراني الحديثة واستراتيجيات الحد من المخاطر، بما في ذلك تقنيات التشفير، وإدارة الهوية والوصول (IAM)، والمصادقة متعددة العوامل (MFA)، وبنية انعدام الثقة (ZTA)، وإدارة الوضع الأمني للحوسبة السحابية (CSPM)، وأنظمة الأمن القائمة على الذكاء الاصطناعي، وممارسات DevSecOps، والحوسبة السرية (Confidential Computing).
إضافة إلى ذلك، تناقش الدراسة بصورة نقدية نقاط القوة والقيود في الأساليب الأمنية الحالية، مع تسليط الضوء على الاتجاهات الناشئة، والفجوات البحثية، والمسارات المستقبلية للبحث العلمي في مجال أمن الحوسبة السحابية. ومن خلال تجميع وتحليل التطورات الحديثة في مجال الأمن السحابي، تقدم هذه المراجعة للباحثين والممارسين وصنّاع القرار فهمًا شاملًا للتحديات الأمنية الراهنة والحلول الواعدة لتعزيز أمن بيئات الحوسبة السحابية الحديثة.
التنزيلات
المراجع
Alouffi, Bader, Hasnain, Muhammad, Alharbi, Abdullah, Alosaimi, Wael, Alyami, Hashem, & Ayaz, Muhammad. (2021). A Systematic Literature Review on Cloud Computing Security: Threats and Mitigation Strategies. IEEE Access, 9, 57792–57807. https://doi.org/10.1109/access.2021.3073203
Cloud Security, Alliance. (2024a). Top Threats to Cloud Computing 2024.
Chuka-Maduji, N., & Anu, V. (2021). Cloud Computing Security Challenges and Related Defensive Measures: A Survey and Taxonomy. SN Computer Science, 2(331).
Iqbal, S., Ahmad, Z., Naeem, W., & Ullah, M. O. (2024). Security Threats and Countermeasures in Cloud. Kashf Journal of Multidisciplinary Research, 1(12), 280–300.
Alharbi, A., & Alenezi, M. (2024). Security and Privacy Challenges in Cloud Computing: A Comprehensive Survey. Journal of Information Security and Applications, 78.
Soveizi, Nafiseh, Turkmen, Fatih, & Karastoyanova, Dimka. (2023). Security and privacy concerns in cloud-based scientific and business workflows: A systematic review. Future Generation Computer Systems, 148, 184–200. https://doi.org/10.1016/j.future.2023.05.015
Ahmadi, Sina. (2024). Systematic Literature Review on Cloud Computing Security: Threats and Mitigation Strategies. Journal of Information Security, 15(02), 148–167. https://doi.org/10.4236/jis.2024.152010
Cloud Security, Alliance. (2024b). Cloud Security in 2024: Addressing the Shifting Landscape. Cloud Security Alliance Blog.
Khan, Hamza Mehmood, & Zaidi, Syed Murtaza Haider. (2024). Detecting Security System Misconfiguration Threats in Cloud Computing Environments Using AI. American Journal of Innovation in Science and Engineering, 3(3), 31–40. https://doi.org/10.54536/ajise.v3i3.3272
Gambo, M. L., & Almulhem, A. (2025). Zero Trust Architecture: A Systematic Literature Review. IEEE Access. https://doi.org/10.48550/arXiv.2503.11659
Feng, Dengguo, Qin, Yu, Feng, Wei, Li, Wei, Shang, Ketong, & Ma, Hongzhan. (2024). Survey of research on confidential computing. IET Communications, 18(9), 535–556. https://doi.org/10.1049/cmu2.12759
Ahmed, F. (2023). Cloud Security Posture Management (CSPM): Automating Security Policy Enforcement in Cloud Environments. ESP International Journal of Advancements in Computational Technology, 1(3), 157–166. https://doi.org/10.56472/25838628/IJACT-V1I3P117
Pratik, Jain. (2025). Identity and Access Management in the Cloud. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 11(2), 1528–1535. https://doi.org/10.32628/cseit25112523
Cloud Security, Alliance. (2025a). Top Threats to Cloud Computing - Deep Dive 2025.
Alshamrani, A., & Bahattab, A. (2022). Identity and Access Management in Cloud Computing: A Systematic Review. IEEE Access, 10.
Abioye, T. E., Kolo, A. K., Ahmed, A., Umoru, K., & Alarood, A. A. (2021). Cloud-Based Business Process Security Risk Management. Applied Sciences, 11(12).
Theodoropoulos, Theodoros, Rosa, Luis, Benzaid, Chafika, Gray, Peter, Marin, Eduard, Makris, Antonios, Cordeiro, Luis, Diego, Ferran, Sorokin, Pavel, Girolamo, Marco Di, Barone, Paolo, Taleb, Tarik, & Tserpes, Konstantinos. (2023). Security in Cloud-Native Services: A Survey. Journal of Cybersecurity and Privacy, 3(4), 758–793. https://doi.org/10.3390/jcp3040034
Alzoubi, Yehia Ibrahim, Mishra, Alok, & Topcu, Ahmet Ercan. (2024). Research trends in deep learning and machine learning for cloud computing security. Artificial Intelligence Review, 57(5). https://doi.org/10.1007/s10462-024-10776-5
Singh, Atul Kumar, & Bhushan, Kriti. (2025). In‐Depth Literature Review of Cloud Computing Data Hazards and Mitigation Strategies. Concurrency and Computation: Practice and Experience, 37(27-28). https://doi.org/10.1002/cpe.70393
Albugmi, H., Alassafi, M. O., Walters, R., & Wills, G. (2024). Data Security in Cloud Computing: A Systematic Review of Encryption and Access Control Techniques. Future Internet, 16(4).
Mostafa, Ayman Mohamed, Ezz, Mohamed, Elbashir, Murtada K., Alruily, Meshrif, Hamouda, Eslam, Alsarhani, Mohamed, & Said, Wael. (2023). Strengthening Cloud Security: An Innovative Multi-Factor Multi-Layer Authentication Framework for Cloud User Authentication. Applied Sciences, 13(19). https://doi.org/10.3390/app131910871
Godwin, Nzeako, & Rahman Akorede, Shittu. (2024). Implementing zero trust security models in cloud computing environments. World Journal of Advanced Research and Reviews, 24(3), 1647–1660. https://doi.org/10.30574/wjarr.2024.24.3.3500
Uddoh, Jeanette, Ajiga, Daniel, Okare, Babawale Patrick, & Aduloju, Tope David. (2021). AI-Based Threat Detection Systems for Cloud Infrastructure: Architecture, Challenges, and Opportunities. Journal of Frontiers in Multidisciplinary Research, 2(2), 61–67. https://doi.org/10.54660/.Ijfmr.2021.2.2.61-67
Sinan, Maysa, Shahin, Mojtaba, & Gondal, Iqbal. (2025). Integrating Security Controls in DevSecOps: Challenges, Solutions, and Future Research Directions. Journal of Software: Evolution and Process, 37(6). https://doi.org/10.1002/smr.70029
Arif, T., Jo, B., & Park, J. H. (2025). A Comprehensive Survey of Privacy-Enhancing and Trust-Centric Cloud-Native Security Techniques Against Cyber Threats. Sensors (Basel), 25(8). https://doi.org/10.3390/s25082350
Zhang, J. Y., & Zhang, Y. (2024). Quantitative DevSecOps Metrics for Cloud-Based Web Microservices. IEEE Access, 12. https://doi.org/10.1109/ACCESS.2024.3864314
Shin, Daemin, Kim, Jiyoon, Pawana, I. Wayan Adi Juliawan, & You, Ilsun. (2025). Enhancing cloud-native DevSecOps: A Zero Trust approach for the financial sector. Computer Standards & Interfaces, 93. https://doi.org/10.1016/j.csi.2025.103975
Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains. Sensors (Basel), 25(19). https://doi.org/10.3390/s25196118
Le, Tran Duc, Le-Dinh, Thang, & Uwizeyemungu, Sylvestre. (2025). Cybersecurity Analytics for the Enterprise Environment: A Systematic Literature Review. Electronics, 14(11). https://doi.org/10.3390/electronics14112252
Anasuri, S. (2023). Confidential Computing Using Trusted Execution Environments. International Journal of AI, BigData, Computational and Management Studies, 4(2). https://doi.org/10.63282/3050-9416.Ijaibdcms-v4i2p111
Mohammed, Khwaja, Shanmugam, Bharanidharan, & El-Den, Jamal. (2025). Evolution of DevSecOps and Its Influence on Application Security: A Systematic Literature Review. Technologies, 13(12). https://doi.org/10.3390/technologies13120548
Saleh, S. M., Madhavji, N., & Steinbacher, J. (2024). A Systematic Literature Review on Continuous Integration and Deployment (CI/CD) for Secure Cloud Computing.
Carlos Bautista Ramos, Roberto, & Yoo, Sang Guun. (2025). Cybersecurity in DevOps Environments: A Systematic Literature Review. IEEE Access, 13, 191959–191979. https://doi.org/10.1109/access.2025.3582892
Deng, S., Zhao, H., Huang, B., Zhang, C., Chen, F., Deng, Y., Yin, J., Dustdar, S., & Zomaya, A. Y. (2024). Cloud-Native Computing: A Survey from the Perspective of Services.
Silverthorne, V. (2024). Cloud Native 2024: Approaching a Decade of Code. Cloud.
Cloud Security, Alliance. (2025b). Top Threats Working Group Charter 2025.
Dhiman, P., Saini, N., Gulzar, Y., Turaev, S., Kaur, A., Nisa, K. U., & Hamid, Y. (2024). A Review and Comparative Analysis of Relevant Approaches of Zero Trust Network Model. Sensors (Basel), 24(4). https://doi.org/10.3390/s24041328
التنزيلات
منشور
خطاب توفر البيانات
, , , , ,
إصدار
القسم
الفئات
الرخصة
الحقوق الفكرية (c) 2026 للمؤلف (المؤلفين)

هذا العمل مرخص بموجب Creative Commons Attribution 4.0 International License.