Cloudtrust 091204053223 Phpapp01

63
Not so fast! “I’m Cloud Confused” series In Cloud We Trust

description

 

Transcript of Cloudtrust 091204053223 Phpapp01

Page 1: Cloudtrust 091204053223 Phpapp01

Not so fast!

“I’m Cloud Confused” series

In CloudWe Trust

Page 2: Cloudtrust 091204053223 Phpapp01

http://www.slideshare.net/Guppers/im-cloud-confused

If you’re new to Cloud Computing, or just confused…

Please try

Page 3: Cloudtrust 091204053223 Phpapp01

the biggest Cloud Computing concerns are…

Security Privacy

Page 4: Cloudtrust 091204053223 Phpapp01

Is Cloud Computingsecurity weaker

than

EnterpriseSecurity?

Fundamental Question

Page 5: Cloudtrust 091204053223 Phpapp01

a Typical Reaction

when asks about security

SHA256

PKCS

X.509

AES

DES

Salt

IV

Page 6: Cloudtrust 091204053223 Phpapp01

Heard

it

on

the street

Security is….

Complex Boring

Hacker stuff

Necessary EvilComplicates my life

Kills usability

Page 7: Cloudtrust 091204053223 Phpapp01

Let’s make it simple

Child Play

Page 8: Cloudtrust 091204053223 Phpapp01

You worked hard this year, you bought a pile of gold bars

Let’s pick a simple story

Page 9: Cloudtrust 091204053223 Phpapp01

Your BankYour House

Where should you store them?

House? Bank?

Page 10: Cloudtrust 091204053223 Phpapp01

What does this thief think?

Page 11: Cloudtrust 091204053223 Phpapp01

Plenty of valuable assets,

but it may have elaborate security protection in place

Bank

Page 12: Cloudtrust 091204053223 Phpapp01

Some valuable assets,

security protection may notas elaborate

House

Page 13: Cloudtrust 091204053223 Phpapp01

What would you do to boostyour protection?

Page 14: Cloudtrust 091204053223 Phpapp01

Yes, build layers of defense

Page 15: Cloudtrust 091204053223 Phpapp01

Put Put the fence up

Page 16: Cloudtrust 091204053223 Phpapp01

Install additional door locks

Page 17: Cloudtrust 091204053223 Phpapp01

Let’s also install alarm system

and surveillance cameras

Page 18: Cloudtrust 091204053223 Phpapp01

Feel Better?

Page 19: Cloudtrust 091204053223 Phpapp01

Oh, don’t forget about

a disaster plan

Page 20: Cloudtrust 091204053223 Phpapp01

Knock, knock

Who’s there?

Page 21: Cloudtrust 091204053223 Phpapp01

You control who

has access to your house

Page 22: Cloudtrust 091204053223 Phpapp01

And, pretty sure

your inner circle won’t steal from you

Page 23: Cloudtrust 091204053223 Phpapp01

Let’s translate…

Corporate Data

IT Assets(Software, Hardware)

Employees

Page 24: Cloudtrust 091204053223 Phpapp01

You feel totally in control

Page 25: Cloudtrust 091204053223 Phpapp01

Why in the world

you would give up control?

Page 26: Cloudtrust 091204053223 Phpapp01

..and many eyes aim at big prizes

Page 27: Cloudtrust 091204053223 Phpapp01

a few things to consider….

when delegating security to other…

Page 28: Cloudtrust 091204053223 Phpapp01

It’s all about Trust

Trust

It’s all about

Page 29: Cloudtrust 091204053223 Phpapp01

Do you trust them that they’ll still be in the

business tomorrow? Help!

Ex-Cloud Provider willwork for Food

Page 30: Cloudtrust 091204053223 Phpapp01

Didn’t we see this before?

Page 32: Cloudtrust 091204053223 Phpapp01

Data Lost

It is unlikely.

Reputable Cloud Providers copy data 3-4 times

Page 33: Cloudtrust 091204053223 Phpapp01

However, it is normal to store highly value-able data in

two or more different cloud providers

Cloud Provider 1 Cloud Provider 2

Servicereplicated replicated

Data

Page 34: Cloudtrust 091204053223 Phpapp01

Data Privacy

Confidentiality

Page 35: Cloudtrust 091204053223 Phpapp01

Data in Transit

Cloud Provider

It can be secured using encryption technology, e.g. SSLIt is used especially for sensitive data

Internetdata

Page 36: Cloudtrust 091204053223 Phpapp01

Data at Rest

More and more cloud providers are developing native data encryption Even if it is stolen, it will be useless for attackers

Biggest prize for attackers!

Cloud Provider

Page 37: Cloudtrust 091204053223 Phpapp01

You can pick where your data resides

Page 38: Cloudtrust 091204053223 Phpapp01

Physi

cal A

ccess

Data CenterCloud Provider

Page 39: Cloudtrust 091204053223 Phpapp01

Security processes are typically in place for physical access Background Check

Two factor authentication

Video surveillance

Intrusion detection system

Audit

Page 40: Cloudtrust 091204053223 Phpapp01

Multi tenantInfrastructure

Corporate 1 Corporate 2 Corporate 3 Corporate 4

…infrastructure is shared by many corporations (tenant)

Page 41: Cloudtrust 091204053223 Phpapp01

Will vulnerability in one company

affect others in the cloud?

Page 42: Cloudtrust 091204053223 Phpapp01

VirtualizationData Isolation

Cloud Providers use

isolation techniques

Computing Isolation

a vulnerability in one tenant has little impact on other tenants

Page 43: Cloudtrust 091204053223 Phpapp01

Identity

Page 44: Cloudtrust 091204053223 Phpapp01

Employees

Customers Suppliers

Cloud Computing

Unwanted guest

Page 45: Cloudtrust 091204053223 Phpapp01

XYZCorp.com

Potential External Entry Points

Web SiteHTTP(S)

Web ServicesHTTP(S)

Database Blob(Files, Docs)

Queue Custom

Worker VM

Page 46: Cloudtrust 091204053223 Phpapp01

Typical access to a web site hosted in the Cloud

Page 47: Cloudtrust 091204053223 Phpapp01

Example of

a stronger authentication process

for sensitive web site

A8KP

Page 48: Cloudtrust 091204053223 Phpapp01

Accessing other Cloud Services(Example)

https://aservice.mycloudprov.net

Address

Key1

R3ZhU3xAmLIEAnRRyiMHx…

Key2

xFAlNx4VeRDGQgSQI…

Page 49: Cloudtrust 091204053223 Phpapp01

Control which network or machines have access

98.237.178.63 83.231.32.17

Page 50: Cloudtrust 091204053223 Phpapp01

Let’s look at from cloud infrastructure provider’s

perspectives

Page 51: Cloudtrust 091204053223 Phpapp01

Typical SLAs to compete

99.95% uptime

around

Page 52: Cloudtrust 091204053223 Phpapp01

It is in their best interest to maintain reputation, best security practice

their business depends on it

Page 53: Cloudtrust 091204053223 Phpapp01

Headlines they try hard to avoid

…. has been downsince yesterday

Data is stolen from ….

Security breach at data center….

Page 54: Cloudtrust 091204053223 Phpapp01

Should you migrate all to Cloud?

Page 55: Cloudtrust 091204053223 Phpapp01

NOCloud Computing is still at infancy

Page 56: Cloudtrust 091204053223 Phpapp01

Trust is Always Earned,

Never Given---R. Williams

Page 57: Cloudtrust 091204053223 Phpapp01

Enterprise

Migrate non-critical business operations,

departmental level data first

and Observe!

Page 58: Cloudtrust 091204053223 Phpapp01

It’s not as difficult as you think

simplicity, agility and elasticity (another topic for further discussion)

Page 59: Cloudtrust 091204053223 Phpapp01

Excited about new possibilities in

cloud space?

Page 60: Cloudtrust 091204053223 Phpapp01

Follow discussions andpresentations on

http://www.facebook.com/pages/Im-Cloud-Confused/219897591208?ref=ts

“I’m Cloud Confused”

facebook

Page 61: Cloudtrust 091204053223 Phpapp01

Us You

10 simple questions,

2 minutes to completehttp://surveymonkey.com/s.aspx?sm=NrndNTZkoG6j8BWJYejC1g_3d_3d

Will Publish Results on

facebook

Page 62: Cloudtrust 091204053223 Phpapp01

Want to try Cloud for your business now ?

Only a few minutes to setup

http://www.slideshare.net/Guppers/guppers-3-minute-walkthrough

Page 63: Cloudtrust 091204053223 Phpapp01

For more presentations like this, visit, follow, subscribe to:

Blog: http://www.andyharjanto.com Twitter: http://twitter.com/harjanto

Contact: [email protected]