Cloud Computing Security

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Cloud Computing Security - Presentation Transcript

    1. Practical Security Problems in Cloud Computing Alon Refaeli – Porticor Technologies [email_address] May 2009
    2. The Cloud Computing Main Elements
      • Infrastructure As a Service (IaaS) – switch , NT, access control etc.
      • Platform As a Service (PaaS) - .Net,Java,LAMP etc.
      • Software As a Service (SaaS) – CRM, ERP etc.
    3. Foundational Elements of Cloud Computing
      • Business Models :
      • Web 2.0
      • • Software as a Service (SaaS)
      • • Utility Computing
      • • Service Level Agreements
      • • Open standards, Data Portability, and Accessibility
      • Architecture :
        • Autonomic System Computing
        • Grid Computing
        • Platform Virtualization
        • Web Services
        • Service Oriented Architectures
        • Web application frameworks
        • Open source software
    4. Why Cloud Computing?
      • Capital Expenditure
      • Multitenancy
      • Scalability
      • Reliability
      • Security
      • Performance
      • Location Independence
    5. Cyber Threats – No End in Sight
      • Thousands of cyber attacks each day on key utilities
      • Well known infrastructure-based disruptions : September 11 Internet Inaccessibility , Estonian DDoS Attacks ,DNS Attacks ,Georgian Attacks from Russia
      • General consensus – attacks growing in sophistication and scale
    6. Security Threats + Cloud = ??
      • New challenges emerge as services become more distributed :
      • Nobody ‘owns’ the cloud
      • Everyone relies on the cloud
      • Each individual autonomous system is responsible for securing their section of the cloud
      • Impact of their actions now affects everyone – even more than before!
      • Bottom line… things that impact you and your business don’t end at your gateway anymore
    7. Cloud Computing Threats
    8. Security follows mainstream IT Platform Evolution 1990’s Operational Complexity Reduced 2000 2002 2005 Software Gateway Software Client-Server Appliance SaaS Software End-Point 2009 Virtual Machine Cloud Mobile
    9. Key Customer Questions on SaaS and Cloud Client type services Privacy Performance Availability Personalization Encryption Global/Local Caching Application Design Multi-Tenant
    10. What is the role of Access Management? Organizations don ’ t get a clear view of who has done what with a resource, so cannot demonstrate ‘ control ’ Common Pain points Who did access what? Who should have access to what? Siloed approach to authorization across hundreds or even thousands of applications Who has Access to what? Months to modify applications with embedded authorization policy or by deploying agents
    11. The 3 primary security concerns for Cloud Computing
      • 1. federated authentication
      • 2. entitlement/authorization control (based on multiple attributes)
      • 3. transaction logging for audit, compliance and forensics
    12. federated authentication
      • No.1 is available through Identity-as-a-service vendors such as Tricipher.
      • SAML will become the standard Federated Identity model once MS Geneva is rolled out.
    13. entitlement/authorization control
      • No.2 is more difficult.
      • Entitlement/AuthZ is built into apps such as salesforce today. However, enterprise web and file services (such as MS SharePoint) do not have the fine grained controls needed for audit & compliance. This is where network-based AuthZ players play.
    14. transaction logging
      • No.3 - transaction logging in my opinion is the big deal-breaker.
      • If you don't know 'who' has done 'what' in your cloud apps, then how will you survive a SOX or PCI audit?
      • This is probably one of the major questions that needs to be answered by new Cloud Security (start-ups) vendors.
    15. Standardization of security in Cloud Computing
      • It is still in early stage – this is the time to shape and influence – the NIST is trying to the role.
      • The main problem is the Identity and Access Management, which will be different from the current solutions.
    16. References
      • Amazon :
      • http://s3.amazonaws.com/aws_blog/AWS_Security_Whitepaper_2008_09.pdf
      • RSA Event 2009 :
      • http://www.vnunet.com/vnunet/news/2240794/rsa-2009-cryptography-experts
    SlideShare Zeitgeist 2009

    + alonrefaelialonrefaeli Nominate

    custom

    300 views, 0 favs, 0 embeds more stats

    Cloud Computing Security Needs,Trends & Problems

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 300
      • 300 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 52
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories