63
Not so fast! “I’m Cloud Confused” series In Cloud We Trust

In Cloud We Trust

  • View
    6.151

  • Download
    0

Embed Size (px)

DESCRIPTION

Security and privacy are the major concerns for many companies to move forward with cloud computing. This presentation describes a few security and privacy issues related to cloud computing and where we as industry addressing these issues.

Citation preview

Page 1: In Cloud We Trust

Not so fast!

“I’m Cloud Confused” series

In CloudWe Trust

Page 2: In Cloud We Trust

http://www.slideshare.net/Guppers/im-cloud-confused

If you’re new to Cloud Computing, or just confused…

Please try

Page 3: In Cloud We Trust

the biggest Cloud Computing concerns are…

Security Privacy

Page 4: In Cloud We Trust

Is Cloud Computingsecurity weaker

than

EnterpriseSecurity?

Fundamental Question

Page 5: In Cloud We Trust

a Typical Reaction

when asks about security

SHA256

PKCS

X.509

AES

DES

Salt

IV

Page 6: In Cloud We Trust

Heard

it

on

the street

Security is….

Complex Boring

Hacker stuff

Necessary EvilComplicates my life

Kills usability

Page 7: In Cloud We Trust

Let’s make it simple

Child Play

Page 8: In Cloud We Trust

You worked hard this year, you bought a pile of gold bars

Let’s pick a simple story

Page 9: In Cloud We Trust

Your BankYour House

Where should you store them?

House? Bank?

Page 10: In Cloud We Trust

What does this thief think?

Page 11: In Cloud We Trust

Plenty of valuable assets,

but it may have elaborate security protection in place

Bank

Page 12: In Cloud We Trust

Some valuable assets,

security protection may notas elaborate

House

Page 13: In Cloud We Trust

What would you do to boostyour protection?

Page 14: In Cloud We Trust

Yes, build layers of defense

Page 15: In Cloud We Trust

Put Put the fence up

Page 16: In Cloud We Trust

Install additional door locks

Page 17: In Cloud We Trust

Let’s also install alarm system

and surveillance cameras

Page 18: In Cloud We Trust

Feel Better?

Page 19: In Cloud We Trust

Oh, don’t forget about

a disaster plan

Page 20: In Cloud We Trust

Knock, knock

Who’s there?

Page 21: In Cloud We Trust

You control who

has access to your house

Page 22: In Cloud We Trust

And, pretty sure

your inner circle won’t steal from you

Page 23: In Cloud We Trust

Let’s translate…

Corporate Data

IT Assets(Software, Hardware)

Employees

Page 24: In Cloud We Trust

You feel totally in control

Page 25: In Cloud We Trust

Why in the world

you would give up control?

Page 26: In Cloud We Trust

..and many eyes aim at big prizes

Page 27: In Cloud We Trust

a few things to consider….

when delegating security to other…

Page 28: In Cloud We Trust

It’s all about Trust

Trust

It’s all about

Page 29: In Cloud We Trust

Do you trust them that they’ll still be in the

business tomorrow? Help!

Ex-Cloud Provider willwork for Food

Page 30: In Cloud We Trust

Didn’t we see this before?

Page 32: In Cloud We Trust

Data Lost

It is unlikely.

Reputable Cloud Providers copy data 3-4 times

Page 33: In Cloud We Trust

However, it is normal to store highly value-able data in

two or more different cloud providers

Cloud Provider 1 Cloud Provider 2

Servicereplicated replicated

Data

Page 34: In Cloud We Trust

Data Privacy

Confidentiality

Page 35: In Cloud We Trust

Data in Transit

Cloud Provider

It can be secured using encryption technology, e.g. SSLIt is used especially for sensitive data

Internetdata

Page 36: In Cloud We Trust

Data at Rest

More and more cloud providers are developing native data encryption Even if it is stolen, it will be useless for attackers

Biggest prize for attackers!

Cloud Provider

Page 37: In Cloud We Trust

You can pick where your data resides

Page 38: In Cloud We Trust

Physi

cal A

ccess

Data CenterCloud Provider

Page 39: In Cloud We Trust

Security processes are typically in place for physical access Background Check

Two factor authentication

Video surveillance

Intrusion detection system

Audit

Page 40: In Cloud We Trust

Multi tenantInfrastructure

Corporate 1 Corporate 2 Corporate 3 Corporate 4

…infrastructure is shared by many corporations (tenant)

Page 41: In Cloud We Trust

Will vulnerability in one company

affect others in the cloud?

Page 42: In Cloud We Trust

VirtualizationData Isolation

Cloud Providers use

isolation techniques

Computing Isolation

a vulnerability in one tenant has little impact on other tenants

Page 43: In Cloud We Trust

Identity

Page 44: In Cloud We Trust

Employees

Customers Suppliers

Cloud Computing

Unwanted guest

Page 45: In Cloud We Trust

XYZCorp.com

Potential External Entry Points

Web SiteHTTP(S)

Web ServicesHTTP(S)

Database Blob(Files, Docs)

Queue Custom

Worker VM

Page 46: In Cloud We Trust

Typical access to a web site hosted in the Cloud

Page 47: In Cloud We Trust

Example of

a stronger authentication process

for sensitive web site

A8KP

Page 48: In Cloud We Trust

Accessing other Cloud Services(Example)

https://aservice.mycloudprov.net

Address

Key1

R3ZhU3xAmLIEAnRRyiMHx…

Key2

xFAlNx4VeRDGQgSQI…

Page 49: In Cloud We Trust

Control which network or machines have access

98.237.178.63 83.231.32.17

Page 50: In Cloud We Trust

Let’s look at from cloud infrastructure provider’s

perspectives

Page 51: In Cloud We Trust

Typical SLAs to compete

99.95% uptime

around

Page 52: In Cloud We Trust

It is in their best interest to maintain reputation, best security practice

their business depends on it

Page 53: In Cloud We Trust

Headlines they try hard to avoid

…. has been downsince yesterday

Data is stolen from ….

Security breach at data center….

Page 54: In Cloud We Trust

Should you migrate all to Cloud?

Page 55: In Cloud We Trust

NOCloud Computing is still at infancy

Page 56: In Cloud We Trust

Trust is Always Earned,

Never Given---R. Williams

Page 57: In Cloud We Trust

Enterprise

Migrate non-critical business operations,

departmental level data first

and Observe!

Page 58: In Cloud We Trust

It’s not as difficult as you think

simplicity, agility and elasticity (another topic for further discussion)

Page 59: In Cloud We Trust

Excited about new possibilities in

cloud space?

Page 60: In Cloud We Trust

Follow discussions andpresentations on

http://www.facebook.com/pages/Im-Cloud-Confused/219897591208?ref=ts

“I’m Cloud Confused”

facebook

Page 61: In Cloud We Trust

Us You

10 simple questions,

2 minutes to completehttp://surveymonkey.com/s.aspx?sm=NrndNTZkoG6j8BWJYejC1g_3d_3d

Will Publish Results on

facebook

Page 62: In Cloud We Trust

Want to try Cloud for your business now ?

Only a few minutes to setup

http://www.slideshare.net/Guppers/guppers-3-minute-walkthrough

Page 63: In Cloud We Trust

For more presentations like this, visit, follow, subscribe to:

Blog: http://www.andyharjanto.com Twitter: http://twitter.com/harjanto

Contact: [email protected]