CloudSec , don't forget Security in the Cloud !

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    CloudSec , don't forget Security in the Cloud ! - Presentation Transcript

    1. CloudSec The real voyage of discovery consists in having new eyes . Marcel Proust
    2. Kris Buytaert
      • Senior Linux and Open Source Consultant @inuits.be
      • „ Infrastructure Architect“
      • Building Clouds since 2004
      • Surviving the 10 th floor test
      • Co-Author Virtualization with Xen
      • Guest Editor at Virtualization.com
    3. The Cloud ? Cloud computing refers to the use of Internet ("cloud") based computer technology for a variety of services. It is a style of computing in which dynamically scalable and often virtualised resources are provided as a service over the Internet. The concept incorporates software as a service (SaaS), Web 2.0 and other recent, well-known technology trends, in which the common theme is reliance on the Internet for satisfying the computing needs of the users.
    4. SAAS <(>) Cloud PAAS <(>) Cloud IAAS > Cloud
    5. Cloud and Open Source
      • Xen
      • Enomalism
      • openQRM
      • OpenNebula
      • SnowFlock
      • Eucalyptus
      • ScalR
      • Python (Google AppEng)
      • Puppet
      • Chef
      • Hadoop
      • MemcacheD
    6. Cloud and Open Source Imagine having to pay software licenses for machines that have only lived 1 hour. And 10000 of them each month
    7. The Cloud in 2005 for host in `seq 1 10000` create_vhost { Create LVM partitions Chroot Rsync Configure }
    8. CloudSec
      • Deploying in an untrusted domain
        • This is not your average DMZ
        • You don't even own the Vhost
      • Cloud Datacenters Attrackt Attackers
        • Identical Hypervisors => Only 1 exploit needed
        • Cloud Hijacking
      • Pre and Post Deployment
        • What was there and what stays behind ?
    9. What changed with Cloud ?
      • Deployment Methods
      • Scale
        • 1 physical machine => MANY VM's
        • Deploy on demand
      • The Network stack
        • System vs Network vs Virtualization
        • Who's network is this anyhow ?
    10. What changed with Cloud ? Involvement of IT, or the lack thereof!
    11. Flux and Scale
      • Can Traditional HIDS follow the quick changing state of Hosts ?
      • My HA Clusters, are Active Passive, Active Active, or N+M too. Their state is in constant flux too
      • The role Config Management and Platform Automation grows every second.
    12. Static Security was DEAD before Virtualization Cloud
      • High Availability Clusters
      • VM Relocation
      • Live Migration
      • Rapid ReDeployment
      • Multiple Instances of a service
    13. Image Sprawl, your update nightmare
      • Image sprawl
        • Copy VM, Deploy VM, Modify VM, Copy VM
      • How do you patch 1 VM ?
      • Did you patch before or after that one was copied ?
      • How do you patch 100 VM's ?
      • What about machines that are offline ?
    14. Image Sprawl, your update nightmare The biggest challenges we have in virtualization cloud are operational and organizational rather than technical. Christofer Hoff
    15. For better nights
      • Automate Deployment
      • Implement Configuration Management
      • Map Security management to Config Mgmt
      • Prepare to Survive the 10 th floor test !
    16. Security Advise
      • Increase security as never before
      • Encrypt all inter Vhost traffic
      • FireWall as Never before
      • Don't store critical data in the cloud
        • Use it for analytics
        • Workload offload
        • Volatile data
      • Build your own Private Cloud
    17. Security still isn't a product you can buy It's not even a process It's a lifestyle
    18. ` Kris Buytaert < [email_address] > Further Reading http://www.krisbuytaert.be/blog/ http://www.inuits.be/ http://www.virtualization.com/ http://www.oreillygmt.com/ ? !
    19. SaaSSec
      • One Vendor
      • Full control over
        • His application
        • His application stack
      • Supposed to manage his platform in Secure Fashion
      • But do you TRUST him ?

    + Kris BuytaertKris Buytaert, 7 months ago

    custom

    717 views, 0 favs, 1 embeds more stats

    My CloudSec Lightning talk at CloudCamp Antwerp

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 717
      • 688 on SlideShare
      • 29 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 15
    Most viewed embeds
    • 29 views on http://www.krisbuytaert.be

    more

    All embeds
    • 29 views on http://www.krisbuytaert.be

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories