Cloud computing system design plays crucial role in ability to withstand cyber attacks
The way cloud computing systems are designed and built is just as important in defending against cyber-attacks as the security measures and safeguards companies put in place, researchers have said in a new study.
Led by Keele’s Dr Amro Al-Said Ahmad, the new paper published in the Journal of Cloud Computing looked at how different types of cloud computing architecture performed against high-traffic HTTP flood attacks, a common type of cyber-attack leveraged against large organisations.
A HTTP flood attack works by sending huge numbers of fake web requests to a website to overwhelm the system and make it slow or unavailable.
Many modern websites and apps run in cloud-based systems using something called cloud-native architecture, which means they can automatically add more servers when traffic increases to cope with demand; a process known as auto-scaling.
There are different types of auto-scaling that different systems use, and Dr Al-Said Ahmad and his colleagues wanted to investigate whether different architectures and types of auto-scaling were more or less susceptible to these types of attacks.
To test this, they built cloud-native systems in Amazon Web Services using different types of architecture, and used a technique called chaos engineering to deliberately attack them and observe the effects.
Over more than 80 hours they attacked these apps with more than 10 million HTTP requests and observed how each type of architecture responded.
Their results showed that while all of the different architectures performed similarly under normal conditions, major differences emerged when they were all subjected to “attack” conditions.
The best performing style was a custom Virtual Private Cloud (VPC) architecture, which tries to prevent bad traffic from reaching application servers in the first place, reducing the amount of work the system has to do to fight off attacks.
The results showed that the VPC-based applications reported a 12% reduction in system failures, meaning users were more likely to receive successful responses rather than errors, as well as a 60% reduction in traffic actually reaching the application.
These results are important as they show that instead of trying to identify and mitigate against cyber threats, companies can adopt a “resilience by design” approach to cyber security, designing systems that are naturally more resistant to such attacks.
Dr Amro Al-Said Ahmad said: “Cyber resilience is not only about detecting and blocking attacks; how we design systems also determines how well they keep operating when an attack happens.
“Our experiments show that a carefully designed, scalable cloud architecture with built-in network security measures can make services significantly more resilient under intense HTTP flood conditions. This supports the idea of resilience-by-design, which involves building systems that are prepared to withstand disruption while complementing traditional security controls that prevent and detect attacks.”
Most read
- Keele celebrates success in National Student Survey 2026 with 13 subjects ranked Top 10 in England
- Keele named University of the Year at national social mobility awards
- Keele Business School wins top honour at Midlands Education Awards 2026
- Keele University ranked in Top 10 in England for international student experience
- Researchers developing new injectable gel to repair damaged cartilage
Contact us
Andy Cain,
Media Relations Manager
+44 1782 733857
Abby Swift,
Senior Communications Officer
+44 1782 734925
Adam Blakeman,
Press Officer
+44 7775 033274
Ashleigh Williams,
Senior Internal Communications Officer
Strategic Communications and Brand news@keele.ac.uk.