SlideShare uma empresa Scribd logo
1 de 34
Cohesive Flexible Technologies




                             Securing Enterprise Assets in the Cloud
                                            Chris Purrington, CohesiveFT




Copyright CohesiveFT 2009                                1
CohesiveFT - on boarding solutions for
                              public, private and hybrid clouds




                                    Team looks like this


Copyright CohesiveFT 2009                    2
CohesiveFT - on boarding solutions for
                              public, private and hybrid clouds




                                      We do this




Copyright CohesiveFT 2009                   3
The cloud is not a panacea for bad design.
                             But moving applications to the cloud can quickly
                            reduce capital expenditure, speed time to market.




Copyright CohesiveFT 2009             4
The first question on everyone’s mind:
                                                     Is my stuff safe up there?



                                                        ?
                               ?

                              ?
        ?
                                    ?                                   ?
    ?
                                                                ?
                       ?

                                                               ?
?                                                                        ?



        Copyright CohesiveFT 2009   5
Security and control remain top concerns




Copyright CohesiveFT 2009     6
Use “your father’s VPN”



Copyright CohesiveFT 2009              7
Typical VPN: Remote office access




Copyright CohesiveFT 2009                8
Typical VPN: Remote office access




                                           X
                                       X
                                   X
                                       X
                                           X



Copyright CohesiveFT 2009                      9
Uhhh...no.



Copyright CohesiveFT 2009       10
I know...cloud-to-cloud DR



Copyright CohesiveFT 2009          11
Do x-cloud fail over...somehow....

                  Cloud A




Copyright CohesiveFT 2009                   12
Somehow...

                  Cloud A




Copyright CohesiveFT 2009       13
Do this!
                            (somehow)


                  Cloud A               Cloud B




Copyright CohesiveFT 2009       14
Speaking of security...



                            What’s inside this VM?



Copyright CohesiveFT 2009              15
Speaking of security...



                            What’s inside this VM?



Copyright CohesiveFT 2009              16
Speaking of security...
                                     What’s inside this VM?




                            I know, let’s ask him...   Picture from: www.sysadminday.com




Copyright CohesiveFT 2009                       17
Speaking of security...
                             What’s inside this VM?




                                 ...or him.   Picture from: www.sysadminday.com




Copyright CohesiveFT 2009              18
Server “assembly” costs are THE
Enterprise IT cost
        20-year journey from single file deployment
        to homogenous architecture (the “C”
        program on Unix) to single file deployment
        on heterogeneous architecture (the VM to
        everywhere)


As such - assembly error and
propagation represents one of the
biggest security risks as well
                                                          Photo credit: Zach Rosing, May 25, 2007,




  Copyright CohesiveFT 2009                          19
Do you have evil clones?

Good clones?

There is going to be a lot of them.

Run the numbers...
                                           Photo credit: Paramount



10,000,000 - today
250,000,000 - 2015
2,500,000,000 - is not impossible


  Copyright CohesiveFT 2009           20
Repeat after me:

“P2V and SLA are
mutually EXCLUSIVE!”

Why? The 3 rules of hardware
computing...

1) When you get a physical machine installed and
working - NEVER MOVE IT
2) When you get the software installed and
                                                        PHYSICAL TO VIRTUAL........easy.
working - NEVER TOUCH IT
3) When you “touch it”, don’t tell anyone.



   Copyright CohesiveFT 2009                       21
So...I am highlighting 2 issues in
                              securing your assets in the cloud




Even if using a cloud...it needs                    Working from a “bill of materials”
to be YOUR infrastructure in                        approach is the only way to safely
        YOUR control                                     survive the clone wars

  Copyright CohesiveFT 2009                    22
YOUR infrastructure in YOUR control
                                       in the clouds


                                   Use an “overlay network”
                                  that you acquire, configure,
                                      deploy and manage.


                                 Enterprise IT is about checks,
                                 balances, and risk mitigation.



Copyright CohesiveFT 2009                      23
Use an overlay network




CONTROL:
- Your addressing
- Your topology
- Your protocols
- Your secure communications




  Copyright CohesiveFT 2009             24
I have software that REQUIRES
                                    multicast for service discovery

This is true of many enterprise software
packages (grid computing packages, database
clusters, wikis and more). 

Even inside the enterprise complexity and lead
times prevent shared use of available resources
in disparate customer controlled data centers
because VLAN reconfiguration would be too
expensive. 

VPN-Cubed allows you to get the multicast
traffic into the overlay network before it is
rejected by the underlying network
infrastructure. This allows you control of your
protocols.


       Copyright CohesiveFT 2009                  25
I want to control my own network addresses


I am an early adopter of cloud computing and
love the flexibility provided by public cloud like
Amazon EC2 but I want to control my own
network addresses, not be given some different
set of VLAN addresses when I reboot my
servers. 

VPN-Cubed gives you control of your
addressing allowing you to give your cloud
servers static addresses that only change when
YOU want them to.  Local infrastructure
control of addressing in the public clouds!




       Copyright CohesiveFT 2009                    26
Can’t I use my existing data center NOC?

I have completed some of my “datacenter to
cloud” migrations but am now under pressure
to use new monitoring and management tools. 
Can’t I use my existing datacenter NOC
(network operations center)? 

VPN-Cubed allows you to simply set up an
overlay network for the express purpose of
connecting cloud VLANS (at EC2 for example)
to data center management installations using
popular commercial systems like Tivoli,
Unicenter, OpenView, as well as leading open
source systems like Nagios, Hyperic and
GroundWorks.



       Copyright CohesiveFT 2009                27
I want to use EC2 USA and EC2 Europe for both
                        fail over and data privacy issues


I am a cloud early adopter and I want to use
both Amazon EC2 USA and Amazon EC2
Europe for both fail over and data privacy
issues.  How can I securely link the two
environments and treat them as one logical
network? 

VPN-Cubed does this “out of the box” with a
pre-packaged solution “VPN-Cubed for EC2”
available for self-service clients as well as those
needing some professional services support.




        Copyright CohesiveFT 2009                     28
Isn’t there a way I can test ISV solutions
                                       as if on my local network?
I have an ISV who has a solution which I would
like to evaluate but it will be quite disruptive
for me to install. Can’t I can test their solution
as if it was on my local network? 

VPN-Cubed allows your ISV to install their
solution as a virtual server in a public cloud like
EC2, yet make it available to a DMZ or
particular set of VLANs in your corporate
environment. 

The burden of testing the ISV solution should
rest with your vendor with minimal impact or
workload on your team.



       Copyright CohesiveFT 2009                      29
YOUR infrastructure in YOUR control
                                       in the clouds




                              THIS            or             THIS


                                 Enterprise IT is about checks,
                                 balances, and risk mitigation.
Copyright CohesiveFT 2009                      30
With a BOM approach:

- Identity
- Customization
- Provenance


This is an EC2 server...             Bill of Materials
right?

Look again...


    Copyright CohesiveFT 2009   31
With a BOM approach:
                                     Bill of Materials
Re-master device:
- new cloud
- new VM type
- new OS

Make clones with unique
IDs, unique MAC
addresses

It the BOM!

    Copyright CohesiveFT 2009   32
<a little overlay network demo>
                         or
              <a little BOM demo>
                         or
          <let’s take some questions>

Copyright CohesiveFT 2009   33
<thanks>

            <pjkerpan (at) cohesiveft.com>


Copyright CohesiveFT 2009      34

Mais conteúdo relacionado

Semelhante a Securing Enterprise Assets In The Cloud

Onboarding For Public Private And Hybrid Clouds Aws 30.04.09
Onboarding For Public Private And Hybrid Clouds Aws 30.04.09Onboarding For Public Private And Hybrid Clouds Aws 30.04.09
Onboarding For Public Private And Hybrid Clouds Aws 30.04.09Chris Purrington
 
Cloud deep-dive0212
Cloud deep-dive0212Cloud deep-dive0212
Cloud deep-dive0212Accenture
 
Beware the pitfalls when migrating to hybrid cloud with openstack
Beware the pitfalls when migrating to hybrid cloud with openstackBeware the pitfalls when migrating to hybrid cloud with openstack
Beware the pitfalls when migrating to hybrid cloud with openstackShuquan Huang
 
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011Is There Such a Thing as a Private Cloud? Citrix Synergy 2011
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011Randy Bias
 
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...Data center 2.0: The journey to the cloud from the datacenter perspertive by ...
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...HKISPA
 
Track2 -刘希斌----c ie-net-openstack-2012-apac
Track2 -刘希斌----c ie-net-openstack-2012-apacTrack2 -刘希斌----c ie-net-openstack-2012-apac
Track2 -刘希斌----c ie-net-openstack-2012-apacOpenCity Community
 
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...HKITF
 
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...VirtualTech Japan Inc.
 
Building Kubernetes images at scale with Tanzu Build Service
Building Kubernetes images at scale with Tanzu Build ServiceBuilding Kubernetes images at scale with Tanzu Build Service
Building Kubernetes images at scale with Tanzu Build ServiceVMware Tanzu
 
Hack In Paris 2011 - Practical Sandboxing
Hack In Paris 2011 - Practical SandboxingHack In Paris 2011 - Practical Sandboxing
Hack In Paris 2011 - Practical SandboxingTom Keetch
 
20090911 virtualizationandcloud
20090911 virtualizationandcloud20090911 virtualizationandcloud
20090911 virtualizationandcloudDebabrata Debnath
 
Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationCloud Standards Customer Council
 
Cloud Storage State of the Union
Cloud Storage State of the UnionCloud Storage State of the Union
Cloud Storage State of the UnionAmazon Web Services
 
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...Proact Netherlands B.V.
 
2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinarAlgoSec
 
EMC World 2015 devops-st06 Containers and Converged Infrastructure Deployment
EMC World 2015 devops-st06 Containers and Converged Infrastructure DeploymentEMC World 2015 devops-st06 Containers and Converged Infrastructure Deployment
EMC World 2015 devops-st06 Containers and Converged Infrastructure DeploymentKendrick Coleman
 
The-evolution-of-the-private-cloud
The-evolution-of-the-private-cloudThe-evolution-of-the-private-cloud
The-evolution-of-the-private-cloudGeorge Gilbert
 

Semelhante a Securing Enterprise Assets In The Cloud (20)

Onboarding For Public Private And Hybrid Clouds Aws 30.04.09
Onboarding For Public Private And Hybrid Clouds Aws 30.04.09Onboarding For Public Private And Hybrid Clouds Aws 30.04.09
Onboarding For Public Private And Hybrid Clouds Aws 30.04.09
 
Cloud deep-dive0212
Cloud deep-dive0212Cloud deep-dive0212
Cloud deep-dive0212
 
Beware the pitfalls when migrating to hybrid cloud with openstack
Beware the pitfalls when migrating to hybrid cloud with openstackBeware the pitfalls when migrating to hybrid cloud with openstack
Beware the pitfalls when migrating to hybrid cloud with openstack
 
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011Is There Such a Thing as a Private Cloud? Citrix Synergy 2011
Is There Such a Thing as a Private Cloud? Citrix Synergy 2011
 
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...Data center 2.0: The journey to the cloud from the datacenter perspertive by ...
Data center 2.0: The journey to the cloud from the datacenter perspertive by ...
 
Track2 -刘希斌----c ie-net-openstack-2012-apac
Track2 -刘希斌----c ie-net-openstack-2012-apacTrack2 -刘希斌----c ie-net-openstack-2012-apac
Track2 -刘希斌----c ie-net-openstack-2012-apac
 
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...
Government 2.1 - Let The Virtual Journey Begins, NOW: From Desktop To the Clo...
 
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...
NTT Docomo's Challenge looking ahead the world pf 5G × OpenStack - OpenStack最...
 
Building Kubernetes images at scale with Tanzu Build Service
Building Kubernetes images at scale with Tanzu Build ServiceBuilding Kubernetes images at scale with Tanzu Build Service
Building Kubernetes images at scale with Tanzu Build Service
 
Hack In Paris 2011 - Practical Sandboxing
Hack In Paris 2011 - Practical SandboxingHack In Paris 2011 - Practical Sandboxing
Hack In Paris 2011 - Practical Sandboxing
 
20090911 virtualizationandcloud
20090911 virtualizationandcloud20090911 virtualizationandcloud
20090911 virtualizationandcloud
 
Kubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing FoundationKubernetes and Container Technologies from Cloud Native Computing Foundation
Kubernetes and Container Technologies from Cloud Native Computing Foundation
 
Cloud Storage State of the Union
Cloud Storage State of the UnionCloud Storage State of the Union
Cloud Storage State of the Union
 
The mainframe and the cloud
The mainframe  and the cloudThe mainframe  and the cloud
The mainframe and the cloud
 
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
 
2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar
 
EMC World 2015 devops-st06 Containers and Converged Infrastructure Deployment
EMC World 2015 devops-st06 Containers and Converged Infrastructure DeploymentEMC World 2015 devops-st06 Containers and Converged Infrastructure Deployment
EMC World 2015 devops-st06 Containers and Converged Infrastructure Deployment
 
Vr storm cips_03nov2010
Vr storm cips_03nov2010Vr storm cips_03nov2010
Vr storm cips_03nov2010
 
Portability In The Cloud
Portability In The CloudPortability In The Cloud
Portability In The Cloud
 
The-evolution-of-the-private-cloud
The-evolution-of-the-private-cloudThe-evolution-of-the-private-cloud
The-evolution-of-the-private-cloud
 

Mais de Chris Purrington

PaulJohnston CloudCamp London Ethics Climate Change Nov 2019
PaulJohnston CloudCamp London Ethics Climate Change Nov 2019PaulJohnston CloudCamp London Ethics Climate Change Nov 2019
PaulJohnston CloudCamp London Ethics Climate Change Nov 2019Chris Purrington
 
Lucy Craddock CloudCampLondon - AI Ethics - Bias in Data
Lucy Craddock CloudCampLondon -   AI Ethics - Bias in DataLucy Craddock CloudCampLondon -   AI Ethics - Bias in Data
Lucy Craddock CloudCampLondon - AI Ethics - Bias in DataChris Purrington
 
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...Chris Purrington
 
Chris Swan Intro CloudCamp London November 2019
Chris Swan Intro CloudCamp London November 2019Chris Swan Intro CloudCamp London November 2019
Chris Swan Intro CloudCamp London November 2019Chris Purrington
 
@cpswan on what is hybridcloud and shouldn't you have hybridstrategy
@cpswan on what is hybridcloud and shouldn't you have hybridstrategy@cpswan on what is hybridcloud and shouldn't you have hybridstrategy
@cpswan on what is hybridcloud and shouldn't you have hybridstrategyChris Purrington
 
CloudCamp. Rhys Sharp Applications & PaaS
CloudCamp. Rhys Sharp   Applications & PaaSCloudCamp. Rhys Sharp   Applications & PaaS
CloudCamp. Rhys Sharp Applications & PaaSChris Purrington
 
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...Chris Purrington
 
CloudCamp. Julian Fischer Anynines - migrating a cloud foundry from vm war...
CloudCamp.  Julian Fischer   Anynines - migrating a cloud foundry from vm war...CloudCamp.  Julian Fischer   Anynines - migrating a cloud foundry from vm war...
CloudCamp. Julian Fischer Anynines - migrating a cloud foundry from vm war...Chris Purrington
 
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...Chris Purrington
 
CloudCamp. Anthony Stanley - 'The Anatomy of an App.. Everything but the App...
CloudCamp. Anthony Stanley -  'The Anatomy of an App.. Everything but the App...CloudCamp. Anthony Stanley -  'The Anatomy of an App.. Everything but the App...
CloudCamp. Anthony Stanley - 'The Anatomy of an App.. Everything but the App...Chris Purrington
 
CloudCamp. Philip Carey: 'Grey Cloud' do you pass the Yorkshire Test. A lig...
CloudCamp.  Philip Carey:  'Grey Cloud' do you pass the Yorkshire Test. A lig...CloudCamp.  Philip Carey:  'Grey Cloud' do you pass the Yorkshire Test. A lig...
CloudCamp. Philip Carey: 'Grey Cloud' do you pass the Yorkshire Test. A lig...Chris Purrington
 
CloudCamp justin cormack hypervise my app!
CloudCamp   justin cormack    hypervise my app! CloudCamp   justin cormack    hypervise my app!
CloudCamp justin cormack hypervise my app! Chris Purrington
 
Steve chambers cloud psychopaths- cloud camplondon 24.10.12
Steve chambers   cloud psychopaths- cloud camplondon 24.10.12Steve chambers   cloud psychopaths- cloud camplondon 24.10.12
Steve chambers cloud psychopaths- cloud camplondon 24.10.12Chris Purrington
 
Chris swan big data - a little analysis - cloud camp london 24.10.12
Chris swan   big data - a little analysis - cloud camp london 24.10.12Chris swan   big data - a little analysis - cloud camp london 24.10.12
Chris swan big data - a little analysis - cloud camp london 24.10.12Chris Purrington
 
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12Chris Purrington
 
Joe baguley cloudcamp london intro 24.10.12
Joe baguley   cloudcamp london intro 24.10.12Joe baguley   cloudcamp london intro 24.10.12
Joe baguley cloudcamp london intro 24.10.12Chris Purrington
 
5. shanley cloudcamplondon
5. shanley cloudcamplondon5. shanley cloudcamplondon
5. shanley cloudcamplondonChris Purrington
 
4. james Governor cloud camp july 4 2012
4. james Governor cloud camp july 4 20124. james Governor cloud camp july 4 2012
4. james Governor cloud camp july 4 2012Chris Purrington
 
1. fran bennett 2012 07 04_cloudcamp
1. fran bennett 2012 07 04_cloudcamp1. fran bennett 2012 07 04_cloudcamp
1. fran bennett 2012 07 04_cloudcampChris Purrington
 
Ubuntu in the cloud What's Coming - Nick Barcet, Canonical
Ubuntu in the cloud What's Coming - Nick Barcet, CanonicalUbuntu in the cloud What's Coming - Nick Barcet, Canonical
Ubuntu in the cloud What's Coming - Nick Barcet, CanonicalChris Purrington
 

Mais de Chris Purrington (20)

PaulJohnston CloudCamp London Ethics Climate Change Nov 2019
PaulJohnston CloudCamp London Ethics Climate Change Nov 2019PaulJohnston CloudCamp London Ethics Climate Change Nov 2019
PaulJohnston CloudCamp London Ethics Climate Change Nov 2019
 
Lucy Craddock CloudCampLondon - AI Ethics - Bias in Data
Lucy Craddock CloudCampLondon -   AI Ethics - Bias in DataLucy Craddock CloudCampLondon -   AI Ethics - Bias in Data
Lucy Craddock CloudCampLondon - AI Ethics - Bias in Data
 
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...
Dr Caitlin McDonald CloudCamp London - Sustainable Digital Ethics through Evo...
 
Chris Swan Intro CloudCamp London November 2019
Chris Swan Intro CloudCamp London November 2019Chris Swan Intro CloudCamp London November 2019
Chris Swan Intro CloudCamp London November 2019
 
@cpswan on what is hybridcloud and shouldn't you have hybridstrategy
@cpswan on what is hybridcloud and shouldn't you have hybridstrategy@cpswan on what is hybridcloud and shouldn't you have hybridstrategy
@cpswan on what is hybridcloud and shouldn't you have hybridstrategy
 
CloudCamp. Rhys Sharp Applications & PaaS
CloudCamp. Rhys Sharp   Applications & PaaSCloudCamp. Rhys Sharp   Applications & PaaS
CloudCamp. Rhys Sharp Applications & PaaS
 
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...
CloudCamp. Paul Hopton, @relayr_cloud - 'The WunderBar - Bootstrapping the In...
 
CloudCamp. Julian Fischer Anynines - migrating a cloud foundry from vm war...
CloudCamp.  Julian Fischer   Anynines - migrating a cloud foundry from vm war...CloudCamp.  Julian Fischer   Anynines - migrating a cloud foundry from vm war...
CloudCamp. Julian Fischer Anynines - migrating a cloud foundry from vm war...
 
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...
CloudCamp. Richard Weerasinghe, ElasticBox - 'Cloud-Enabling Enterprise Appli...
 
CloudCamp. Anthony Stanley - 'The Anatomy of an App.. Everything but the App...
CloudCamp. Anthony Stanley -  'The Anatomy of an App.. Everything but the App...CloudCamp. Anthony Stanley -  'The Anatomy of an App.. Everything but the App...
CloudCamp. Anthony Stanley - 'The Anatomy of an App.. Everything but the App...
 
CloudCamp. Philip Carey: 'Grey Cloud' do you pass the Yorkshire Test. A lig...
CloudCamp.  Philip Carey:  'Grey Cloud' do you pass the Yorkshire Test. A lig...CloudCamp.  Philip Carey:  'Grey Cloud' do you pass the Yorkshire Test. A lig...
CloudCamp. Philip Carey: 'Grey Cloud' do you pass the Yorkshire Test. A lig...
 
CloudCamp justin cormack hypervise my app!
CloudCamp   justin cormack    hypervise my app! CloudCamp   justin cormack    hypervise my app!
CloudCamp justin cormack hypervise my app!
 
Steve chambers cloud psychopaths- cloud camplondon 24.10.12
Steve chambers   cloud psychopaths- cloud camplondon 24.10.12Steve chambers   cloud psychopaths- cloud camplondon 24.10.12
Steve chambers cloud psychopaths- cloud camplondon 24.10.12
 
Chris swan big data - a little analysis - cloud camp london 24.10.12
Chris swan   big data - a little analysis - cloud camp london 24.10.12Chris swan   big data - a little analysis - cloud camp london 24.10.12
Chris swan big data - a little analysis - cloud camp london 24.10.12
 
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12
Ali khajeh hosseini -plan forcloud - cloudcamp london 24.10.12
 
Joe baguley cloudcamp london intro 24.10.12
Joe baguley   cloudcamp london intro 24.10.12Joe baguley   cloudcamp london intro 24.10.12
Joe baguley cloudcamp london intro 24.10.12
 
5. shanley cloudcamplondon
5. shanley cloudcamplondon5. shanley cloudcamplondon
5. shanley cloudcamplondon
 
4. james Governor cloud camp july 4 2012
4. james Governor cloud camp july 4 20124. james Governor cloud camp july 4 2012
4. james Governor cloud camp july 4 2012
 
1. fran bennett 2012 07 04_cloudcamp
1. fran bennett 2012 07 04_cloudcamp1. fran bennett 2012 07 04_cloudcamp
1. fran bennett 2012 07 04_cloudcamp
 
Ubuntu in the cloud What's Coming - Nick Barcet, Canonical
Ubuntu in the cloud What's Coming - Nick Barcet, CanonicalUbuntu in the cloud What's Coming - Nick Barcet, Canonical
Ubuntu in the cloud What's Coming - Nick Barcet, Canonical
 

Último

Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 

Último (20)

Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 

Securing Enterprise Assets In The Cloud

  • 1. Cohesive Flexible Technologies Securing Enterprise Assets in the Cloud Chris Purrington, CohesiveFT Copyright CohesiveFT 2009 1
  • 2. CohesiveFT - on boarding solutions for public, private and hybrid clouds Team looks like this Copyright CohesiveFT 2009 2
  • 3. CohesiveFT - on boarding solutions for public, private and hybrid clouds We do this Copyright CohesiveFT 2009 3
  • 4. The cloud is not a panacea for bad design. But moving applications to the cloud can quickly reduce capital expenditure, speed time to market. Copyright CohesiveFT 2009 4
  • 5. The first question on everyone’s mind: Is my stuff safe up there? ? ? ? ? ? ? ? ? ? ? ? ? Copyright CohesiveFT 2009 5
  • 6. Security and control remain top concerns Copyright CohesiveFT 2009 6
  • 7. Use “your father’s VPN” Copyright CohesiveFT 2009 7
  • 8. Typical VPN: Remote office access Copyright CohesiveFT 2009 8
  • 9. Typical VPN: Remote office access X X X X X Copyright CohesiveFT 2009 9
  • 12. Do x-cloud fail over...somehow.... Cloud A Copyright CohesiveFT 2009 12
  • 13. Somehow... Cloud A Copyright CohesiveFT 2009 13
  • 14. Do this! (somehow) Cloud A Cloud B Copyright CohesiveFT 2009 14
  • 15. Speaking of security... What’s inside this VM? Copyright CohesiveFT 2009 15
  • 16. Speaking of security... What’s inside this VM? Copyright CohesiveFT 2009 16
  • 17. Speaking of security... What’s inside this VM? I know, let’s ask him... Picture from: www.sysadminday.com Copyright CohesiveFT 2009 17
  • 18. Speaking of security... What’s inside this VM? ...or him. Picture from: www.sysadminday.com Copyright CohesiveFT 2009 18
  • 19. Server “assembly” costs are THE Enterprise IT cost 20-year journey from single file deployment to homogenous architecture (the “C” program on Unix) to single file deployment on heterogeneous architecture (the VM to everywhere) As such - assembly error and propagation represents one of the biggest security risks as well Photo credit: Zach Rosing, May 25, 2007, Copyright CohesiveFT 2009 19
  • 20. Do you have evil clones? Good clones? There is going to be a lot of them. Run the numbers... Photo credit: Paramount 10,000,000 - today 250,000,000 - 2015 2,500,000,000 - is not impossible Copyright CohesiveFT 2009 20
  • 21. Repeat after me: “P2V and SLA are mutually EXCLUSIVE!” Why? The 3 rules of hardware computing... 1) When you get a physical machine installed and working - NEVER MOVE IT 2) When you get the software installed and PHYSICAL TO VIRTUAL........easy. working - NEVER TOUCH IT 3) When you “touch it”, don’t tell anyone. Copyright CohesiveFT 2009 21
  • 22. So...I am highlighting 2 issues in securing your assets in the cloud Even if using a cloud...it needs Working from a “bill of materials” to be YOUR infrastructure in approach is the only way to safely YOUR control survive the clone wars Copyright CohesiveFT 2009 22
  • 23. YOUR infrastructure in YOUR control in the clouds Use an “overlay network” that you acquire, configure, deploy and manage. Enterprise IT is about checks, balances, and risk mitigation. Copyright CohesiveFT 2009 23
  • 24. Use an overlay network CONTROL: - Your addressing - Your topology - Your protocols - Your secure communications Copyright CohesiveFT 2009 24
  • 25. I have software that REQUIRES multicast for service discovery This is true of many enterprise software packages (grid computing packages, database clusters, wikis and more).  Even inside the enterprise complexity and lead times prevent shared use of available resources in disparate customer controlled data centers because VLAN reconfiguration would be too expensive.  VPN-Cubed allows you to get the multicast traffic into the overlay network before it is rejected by the underlying network infrastructure. This allows you control of your protocols. Copyright CohesiveFT 2009 25
  • 26. I want to control my own network addresses I am an early adopter of cloud computing and love the flexibility provided by public cloud like Amazon EC2 but I want to control my own network addresses, not be given some different set of VLAN addresses when I reboot my servers.  VPN-Cubed gives you control of your addressing allowing you to give your cloud servers static addresses that only change when YOU want them to.  Local infrastructure control of addressing in the public clouds! Copyright CohesiveFT 2009 26
  • 27. Can’t I use my existing data center NOC? I have completed some of my “datacenter to cloud” migrations but am now under pressure to use new monitoring and management tools.  Can’t I use my existing datacenter NOC (network operations center)?  VPN-Cubed allows you to simply set up an overlay network for the express purpose of connecting cloud VLANS (at EC2 for example) to data center management installations using popular commercial systems like Tivoli, Unicenter, OpenView, as well as leading open source systems like Nagios, Hyperic and GroundWorks. Copyright CohesiveFT 2009 27
  • 28. I want to use EC2 USA and EC2 Europe for both fail over and data privacy issues I am a cloud early adopter and I want to use both Amazon EC2 USA and Amazon EC2 Europe for both fail over and data privacy issues.  How can I securely link the two environments and treat them as one logical network?  VPN-Cubed does this “out of the box” with a pre-packaged solution “VPN-Cubed for EC2” available for self-service clients as well as those needing some professional services support. Copyright CohesiveFT 2009 28
  • 29. Isn’t there a way I can test ISV solutions as if on my local network? I have an ISV who has a solution which I would like to evaluate but it will be quite disruptive for me to install. Can’t I can test their solution as if it was on my local network?  VPN-Cubed allows your ISV to install their solution as a virtual server in a public cloud like EC2, yet make it available to a DMZ or particular set of VLANs in your corporate environment.  The burden of testing the ISV solution should rest with your vendor with minimal impact or workload on your team. Copyright CohesiveFT 2009 29
  • 30. YOUR infrastructure in YOUR control in the clouds THIS or THIS Enterprise IT is about checks, balances, and risk mitigation. Copyright CohesiveFT 2009 30
  • 31. With a BOM approach: - Identity - Customization - Provenance This is an EC2 server... Bill of Materials right? Look again... Copyright CohesiveFT 2009 31
  • 32. With a BOM approach: Bill of Materials Re-master device: - new cloud - new VM type - new OS Make clones with unique IDs, unique MAC addresses It the BOM! Copyright CohesiveFT 2009 32
  • 33. <a little overlay network demo> or <a little BOM demo> or <let’s take some questions> Copyright CohesiveFT 2009 33
  • 34. <thanks> <pjkerpan (at) cohesiveft.com> Copyright CohesiveFT 2009 34