Analysing security solutions in cloud computing technology

Ever more companies are proving that cloud computing continues to be a major trend in the IT field. For instance, IDC recently predicted that spending on public cloud services would reach $160 billion by the end of this year.

When it comes to security, however, the same issues and concerns persist today as they did several years ago. Take any research report which asks about organisations’ concerns with cloud migration and security is usually the number one. What if I get hacked? Where does my data go? In some ways, it is becoming even more of a problem today. A recent research report argued that as companies go further into their cloud ambitions their security becomes particularly problematic as their infrastructures become more complex.

So what do you need to know?

Advantages of cloud security and how to secure virtual machines

It is important to note that the cloud has multiple advantages in terms of hardware optimisation, including scalability, availability, high efficiency, and dedicated management. Scalability allows you to expand your resources dynamically to meet requirements at any given time; availability means the user does not have to worry about the performance of their own equipment, as their device displays the result of server-based data processing; high efficiency means data is not processed by a single device but by a computing cluster; and dedicated management means there is no need to use different sub-systems or additional functionalities.

In general, the client’s task is to select the range of cloud-based services required, and the supplier’s task is to provide a reliable solution with access to data.

Due to changes resulting from the amendment of data protection regulations, it is worth bearing in mind that cloud computing platforms should be secured. The cloud computing concept is very close to virtualisation – and thanks to the use of virtualisation on physical servers, there can be many virtual machines. This allows equipment performance to be maximised. The cloud computing layer connects users with physical servers, meaning virtual machines can be moved freely on the entire platform regardless of where the device is actually located.

Crucially, this means that the cloud computing environment allows a user to access their data via the Internet from anywhere in the world.

The virtual machines on which data is stored should be protected against attacks by cybercriminals. The most important tools for securing virtual machines include:

Firewall: The main task of the firewall is to monitor network traffic and to pass and block data packets in accordance with pre-defined security policies. By using firewalls, virtual machines will be separated on the network layer.

IPS: As a virtual machine emulates a physical device, it is just as vulnerable to hackers who exploit system errors and bugs. The intrusion prevention solution (IPS) can block attempts to break into the system.

Tools for verifying data integrity: Virtual machines are often stopped by an administrator to allow configuration changes, and backups are made so that new solutions can be tested. It is quite common that the data between the original machine and the one being tested are different, so it is important to compare the two in order to avoid file integrity errors.

Antivirus protection: A virtual machine, just like a physical one, can be infected by a virus. What’s more, the virtual machine can be infected when it is offline. A good antivirus system should be characterised by a fast and silent online scanner and a virus database that is updated at least daily. The system should also integrate well with the add-ons that support the virtual machine, and detect newly created VMs.

Conclusion

These examples are the foundations of protection for a virtual environment located on a cloud platform. It is also worth remembering the principle of rational use of the resource and employing cloud platform providers’ best practices. If in-house knowledge is lacking, there are organisations that can help. In this respect, Comarch ICT Department (to read more click here) has a cloud-based platform development team, and engineers who specialise in the whole spectrum of security for IT solutions.

Dariusz Wójcik – ICT Solutions Product Manager in Comarch, https://www.comarch.com/trade-and-services/ict/

Amazon Web Services acquires advanced threat platform provider Sqrrl

Amazon Web Services (AWS) has acquired Sqrrl, an advanced threat detection platform provider, according to an announcement from the latter.

A statement from Mark Terenzoni, CEO of Sqrrl, explained: “We’re thrilled to share that Sqrrl has been acquired by Amazon. We will be joining the Amazon Web Services family, and we’re looking forward to working together on customer offerings for the future.”

Sqrrl offers a ‘threat hunting’ platform which combines technology such as link analysis and user behaviour analytics, as well as being compatible with security information and event management (SIEM) systems. The majority of Sqrrl’s founders had previously worked for the NSA. The company has to date secured $26.5 million in funding across four rounds, with the most recent, a series C of $12.3m, landing in June last year.

The announcement confirms a story from Axios published last month which asserted AWS was in advanced acquisition talks. While the announcement does not give any indication as to how Sqrrl will fit into AWS going forward, it is worth noting that AWS launched Amazon GuardDuty, a managed threat detection service, at the company’s re:Invent showcase in November. Last month, Trend Micro announced a collaboration with AWS on its Enterprise Contracts for AWS Marketplace service.

This is not to mention the wide-ranging security snafus around the Meltdown and Spectre vulnerabilities publicly disclosed earlier this month. AWS was among many cloud providers who issued statements fairly sharpish about how they were combating the problem. According to the most recent update, as of January 23, all instances across the Amazon EC2 fleet were protected with no ‘meaningful performance impact’ for the majority of EC2 workloads.

“For now, it is business as usual at Sqrrl,” Terenzoni added. “We will continue to work with customers to provide advanced threat hunting capabilities. And, over time, we’ll work with AWS to do even more on your behalf.”

Snowflake and Tigera secure funding for data warehousing and cloud app connectivity

A couple of interesting cloudy companies who have raised capital in recent days; Snowflake Computing has closed $263 million in growth funding, while Tigera has secured an additional $10 million in funding.

Snowflake Computing, based in San Mateo, offers cloud-based data warehousing. The company aims to help organisations made their data more easily available and actionable in the cloud, with three claimed elements to help it: a unique architecture to provide complete elasticity, a database engine that natively handles both semi-structured and structured data, and technology which eliminates the need for manual data warehouse management.

The company said it will use the funding to double down on R&D and expand current operations across North America, Europe and Asia Pacific regions ‘to address the global surge in demand for Snowflake’s data warehouse as a service’. The capital takes Snowflake’s total funding to $473m in growth funding, with a pre-money valuation of $1.5 billion.

Tigera, however, is in the application connectivity and security space. As this publication noted earlier this month, organisations are making more cloud investments and, as a result, their infrastructure becomes more complex. Where Tigera comes in is to make app integration easier as technologies such as containers and microservices are being utilised.

Madrona Ventures Group has a stake in both deals. The Seattle-based firm was named as an existing funding partner who contributed to Snowflake, but was the lead partner in the Tigera round. In a post announcing the news, Madrona managing director S. Somasegar explained its rationale.

“While containers have been the rage for the last 18-24 months, the complexity that grows from this technology quickly escalates to an unmanageable level from an application connectivity and security perspective,” wrote Somasegar. “This conundrum has been an issue for large enterprises as they look to benefit from these new methods of software architecture and management.”

Snowflake’s round was led by ICONIQ Capital, Altimeter Capital and newcomer Sequoia Capital, alongside Capital One Growth Venture, Redpoint Ventures, Sutter Hill Ventures and Wing Ventures, alongside Madrona. CEO Bob Muglia said in a statement the announcement “further validates Snowflake’s continued mission to enable a true data economy by removing the barriers that prevent enterprises from easily acquiring insight from all their data no matter where that data resides.”

Reykjavik city administration manages Mac with Microsoft SCCM

In this blog post, we will talk about how Iceland’s capital Reykjavik city administration manages Mac with Parallels Mac Management for Microsoft SCCM. “The expense of the comparatively small Mac flotilla in our organization sometimes made me break out in a sweat… Thanks to Parallels Mac Management, this nightmare is now over. If I don’t […]

The post Reykjavik city administration manages Mac with Microsoft SCCM appeared first on Parallels Blog.

DX World EXPO, LLC Acquires @CloudExpo Trademarks and Associated Brands

DX World EXPO, LLC, a Lighthouse Point, Florida-based startup trade show producer and the creator of “DXWorldEXPO® – Digital Transformation Conference & Expo” has announced its executive management team. The team is headed by Levent Selamoglu, who has been named CEO. “Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation,” he said in making the announcement.

read more

Organisations are aware of quantum computing security threats – but are not taking action yet

Quantum computing promises much – but are organisations secure enough to make the most of it? According to a new report from the Cloud Security Alliance (CSA), companies are aware of the risk of quantum computing but not yet ready to take action.

The alliance had previously put together the Quantum Safe Security Working Group (QSS WG) to assess the risks of the emerging technology. According to today’s report, which polled more than 100 CSA members with more than 90% working in either IT or information security, only 14% said they were not aware of quantum computing and its impact on data security. In contrast, only 12% said they were ‘very confident’ in their current security options to protect against quantum attacks.

Quantum computing differs from classical computing in that it has the potential to find patterns and insights based on data which does not exist, rather than finding patterns in vast amounts of existing data. Its potential applications include improving security through quantum physics and enhancements to machine learning and artificial intelligence. Readers of this publication will be aware of quantum computing through the work IBM – who, it has to be said, are experts when it comes to research and development of emerging technologies – is doing.

So what threats are there – and how are organisations taking measures against them? In essence, quantum computers will be able to break all public key systems and render them vulnerable. Yet only 40% of respondents today said they were working to future-proof their data to protect against the threat.

When it came to specific quantum-safe technologies, respondents were most likely to be aware of longer symmetric keys and longer hash functions, as opposed to quantum random number generation and key distribution. The report added that many respondents do not believe a one-size-fits-all solution yet exists to counteract quantum threats effectively.

It’s worth noting at this juncture that while the sample rate was comparatively low, the CSA argues the data provides a ‘valuable snapshot of the perception of quantum-safe issues in the industry.’

“While there is still a tremendous amount of work to be done in convincing the industry of the importance of including the threat of quantum computing in enterprise security strategies, the good news is that there is a great deal of interest in learning more about the threat quantum presents and how it can be mitigated,” said Jane Melia, CSA QSS WG co-chair in a statement.

“This latest report provides an excellent context for moving forward in our efforts to educate the industry.”

You can read the full report here (email required).

Deloitte acquires cloud migration platform provider ATADATA

Deloitte may be best known in the cloud industry for its forecasts and reports – but the consulting firm is making waves of its own with the acquisition of cloud platform provider ATADATA.

ATADATA offers a migration and mapping service across almost any infrastructure one cares to think of, from Amazon Web Services (AWS) to Google Cloud, Oracle and VMware, with the company claims to be the only platform which can migrate SAP to AWS and Google.

Last year saw the launch of ATAsphere, certified by AWS, compatible with Azure and recommended by Google, which in the company’s own words is “the industry’s first managed workload mobility platform that enables borderless automation for hybrid IT and cloud environments.”

From Deloitte’s perspective, the move will ‘expand [the company’s] robust end-to-end offerings – from the strategy phase to the build and operate phases.’ Charles Wright, the CEO and CTO of ATADATA, will join the Deloitte team, alongside chief commercial officer Ian Easton.

“Deloitte has demonstrated exceptional success in driving innovation using cloud, digital, and cognitive technologies for a wide range of enterprise clients,” said Wright in a statement. “We are excited to amplify that success by enabling simple, scalable data and application stacks for on-premise, private and public clouds.”

In March last year, Deloitte announced the acquisition of cloud consulting firm Day1 Solutions, the opening of a series of cloud studios in Orlando, New York and Washington D.C., as well as adding 3,000 US-based high tech engineering jobs. At the time, the company said cloud was ‘the backbone of innovation’ and that the additions to its portfolio would give clients ‘access to deeper cloud expertise and even more innovative capabilities.’

Tech News Recap for the Week of 01/22/18

If you had a busy week in the office and need to catch up, here’s our tech news recap of articles you may have missed the week of 01/22/2017!

VMware recently updated vSphere to 6.5, find out why you should be upgrading. HPE partners with Portworx for easier Kubernetes deployment. Evolving IoT data storage in 2018. Cisco acquires Skyport Systems to bolster its hybrid cloud positioning and more top news this week you may have missed! Remember, to stay up-to-date on the latest tech news throughout the week, follow @GreenPagesIT on Twitter.

Tech News Recap

Fighting Modern Threats with Next-Gen Firewalls with GreenPages’ network expert, Bobby Mazzotti

IT Operations

Microsoft

  • Microsoft shields Azure Stack hybrid cloud users from patent trolls
  • Microsoft unleashes new cloud growth via go-to-market program including customers as partners
  • Windows 10 can now show you all the data it’s sending back to Microsoft

VMware

  • VMware recently updated vSphere to 6.5, find out why you should be upgrading
  • Tips for upgrading to vSphere 6.5 in a large-scale environment
  • VMware adds edge computing support to vSphere through AWS Greengrass integration

HPE 

Cisco

AWS

  • Amazon’s new data-driven convenience store, Amazon Go, uses AI to check you out

Cloud

Security

  • Spectre flaw: Dell and HP pull Intel’s buggy patch, new BIOS update coming
  • US economy could lose $15B if one major cloud provider went down for a few days
  • Cyber attacks on the cloud could cost retail $3.4B
  • OnePlus.net suffered script injection; 40K customers’ payment details compromised

Thanks for checking out our tech news recap!

By Jake Cryan, Digital Marketing Specialist

Upcoming Webinar:

AWS or Azure? How to Move from Analysis Paralysis Toward a Smart Cloud Choice

Click here to register!

If you think you don’t have a hybrid cloud strategy – you’re wrong

Cloud has spread like wildfire through the majority of businesses. Its flexibility, scalability and price-point often makes it the natural data storage solution. 

With cloud follows the notion of a ‘hybrid cloud strategy’, and whether the IT manager recognises it or not, the business probably has one. Take for example, a company that is slowly moving applications out of the data centre and chooses SaaS applications where possible – the business may not consider this a ‘formal’ hybrid cloud strategy but, like it or not, it is.

No one person is responsible, but many have contributed. Over the years, with each additional SaaS service purchased, each new application that was brought in and hosted with a public cloud provider, and each new upgrade to the existing onsite data centre, a hybrid cloud ecosystem has developed.

Once implemented it is easy for cloud to spread throughout the business. Every month new services are added and old applications are taken offline, and so a hybrid cloud ecosystem evolves.

The attraction of hybrid cloud may not be something that can be entirely set in stone in a formal strategy. By its very nature, perhaps it has to be a living, breathing ecosystem, that flexes and changes as new situations arise: perhaps one year a data centre failure means more services than usual are moved to the cloud; or the company’s ERP provider moves to a pure cloud play strategy so the businesses is forced to turn to the SaaS world for its central business applications.

It is not always possible to plan for this change.  With Microsoft Dynamics now being Azure-led, customers may be moving central systems to the cloud earlier than their strategies previously anticipated.

All this being said, it doesn’t mean a strategy doesn’t exist. Rather it just means that maybe the traditional way of deciding on a long term IT strategy doesn’t fit in a world where new providers can launch applications on the fly, or the industry’s largest vendors can change their position regarding onsite or public cloud hosting overnight. 

A hybrid IT strategy is all about being flexible enough to allow for change both internally (i.e. what the business decides to do commercially and operationally) and externally (i.e. what the market dictates and also what technology industry and vendors offer each year).

Previously, vendors may have introduced a newer, shinier box – but it was just a newer, shinier version of the previous box. It didn’t necessitate throwing out the old IT strategy and starting again. Today, an application vendor deciding to only release its updated version as a SaaS product means that a strategy to keep that application in-house for the foreseeable future changes. And perhaps it has a knock-on effect on other business applications – maybe it makes it too costly to keep other applications in-house.

The stakeholders responsible for a hybrid IT strategy have also changed. Shadow IT and the proliferation of cloud services means that the people involved in making a decision about the company’s hybrid IT strategy may be sitting in diverse roles across different departments of the business. They may, for example, have been purchasing their own cloud services for over 10 years and now have a key voice in decisions about future IT strategy of the organisation.

The business landscape of IT has changed dramatically over the last decade. IT strategy is now a top boardroom-level priority with more people taking notice and more people involved in making decisions.

So, the question is, do you have a hybrid IT strategy or has your company sorted it while you weren’t looking?

Fighting Modern Threats with Next Gen Firewalls

Listen to GreenPages’ network expert, Bobby Mazzotti, discuss how next gen firewalls go beyond basic threat management to deliver advanced intrusion protection capabilities and provide companies with superior visibility and control of their network. By inspecting traffic packets coming in from the host, next gen firewalls provide the extra layer of security necessary to protect businesses from modern threats such as ransomware and backdoor trojans. Check out the video below to learn more:

As a vendor agnostic solutions provider, GreenPages is in a perfect position to help you evaluate and deploy the best tech depending on your unique business goals. Please reach out to us or your account manager to get started.

By Jake Cryan, Digital Marketing Specialist

The cloud news categorized.