What is cloud bursting?


Steve Cassidy

4 Oct, 2018

Cloud bursting is a rather nebulous buzzword that sounds cool but, I’m afraid, has nothing to do with Kate Bush. Instead, it’s the term used to describe a setup where you run your business mostly on your own kit, but also have a set of cloud accounts sitting idle, ready to take on extra «bursts» of work when demand peaks.

Isn’t that already the idea behind hybrid cloud?

Yes and no. Hybrid cloud is an umbrella term for dividing up your computing resources across local and off-premises servers; cloud bursting is a specific way of using those resources.

In practice, a cloud burst setup might use containerised VMs and some form of load orchestration package to shift containers to locations where user sessions can reach them. It will probably require quite a lot of work at the database design level as well, so that this too can be replicated, multi-homed or remotely accessed. In short, cloud bursting isn’t an architecture or a computing philosophy, but a capability of your entire technology estate.


The infrastructure of enterprises is changing fast, but some of the strategic cloud opportunities aren’t being taken up because of the pace of the tech revolution. So what does the future hold for cloud in the enterprise? Find out more in this research paper.

Download now


Is it just an agile implementation of hybrid cloud?

That’s a question of semantics. A cloud bursting setup should quickly respond to unforeseen changes in demand, but this isn’t quite what’s conventionally meant by «agile». Agility is about being able to retool your code quickly to adapt to changing circumstances, whereas cloud bursting requires everything to be in place well before the high-load day comes.

You need to have your cloud accounts in place and paid up, you need to be sure that your code platform will run on the cloud, and you need to make sure that it’s actually capable of meeting the demands you want to place on it. Doing this properly involves a great deal of pre-emptive development and testing. I’d be very wary of a business that went into a cloud bursting project with an «agile» mindset.

Is a cloud bursting setup is cheaper than regular cloud hosting?

It might work out that way, but the two models aren’t perfectly comparable. Hybrid cloud usually tends to imply an IAAS model, whereas cloud bursting finds most interest from heavy SAAS users.

Cloud bursting also relies on your orchestration software correctly working out when to spin up the offsite services and incur the associated charges – which involves an element of voodoo, as it’s exquisitely difficult to distinguish between blips and booms as they’re happening. A hybrid cloud setup with plenty of slack capacity may or may not work out cheaper, but it’s likely to be more dependable, and have a more predictable cost.

When is cloud bursting the right answer?

There are some such scenarios, but they’re mostly inside the world of IT itself. For example, if you’re an antivirus developer combatting zero-day exploits, you’ll want the ability to scale your download links out into the cloud on bad virus days. Some classes of simulation can also easily parcel up workloads and hand them off to compute nodes with no regard for where those nodes are hosted. Unfortunately, this model has become controversial, since it’s currently mostly employed by Bitcoin-mining trojans.

What’s the key downside of a cloud bursting approach?

Finance directors probably aren’t going to love cloud burst projects, because (as we’ve noted) the costs are unpredictable by design. What’s more, since the whole point of cloud bursting is that you don’t use it regularly, it’s only when you really need to fire up those cloud servers that you discover that a recent update has unexpectedly broken your meticulously crafted handover routines.

These inherent risks will tend to push most businesses back in the direction of a more traditional hybrid architecture.


‘Blue sky thinking: Cloud computing, culture and the enterprise’ presents the results of cloud research from UK businesses, capturing the scope of cloud adoption in 2018.

Download now


Why are vendors pushing cloud bursting as the next big thing?

I suspect that the vendors aren’t trying to get you specifically into cloud bursting. They want to make you think more generally about where your computing resources live.

A little research, and my own anecdotal experience, suggests that very few companies have actually committed to a full-on cloud bursting model – which probably tells you everything you need to know.

Announcing @PCCWGlobal to Exhibit at @CloudEXPO New York | #Cloud #CIO #IoT #SmartCities #Blockchain #DigitalTransformation

PCCW Global is a leading telecommunications provider, offering the latest voice and data solutions to multi-national enterprises and communication service providers. Our truly global coverage combined with local, on the ground knowledge has helped us build best in class connections across the globe; and especially in some of the remotest, hard-to-reach areas in exciting growth markets across Asia, Africa, Latin America and the Middle East.

read more

Oracle reveals Autonomous NoSQL Database Service


Clare Hopping

3 Oct, 2018

Oracle has unveiled its Oracle Autonomous NoSQL Database, helping developers deploy massive applications, with low latency, high-security and simple scaling.

The company explained the addition to its autonomous database portfolio has been specifically designed for apps such as those that demand heavy UI personalisation, shopping carts, online fraud detection, gaming and advertising, thanks to its flexibility.

It uses simple APIs for developers to introduce into their apps to cut down the amount of manual manipulation they need to do in order to get the apps up and running. For example, instead of dealing with and managing servers, storage expansion, cluster deployments, software installation, or backup, they can instead focus on the output – ie., the applications themselves.

Oracle Autonomous NoSQL Database also supports Python, Node.JS and Java, as well as offering interoperability with standard relational and standard JSON data models, whether a business wants to deploy their apps in the cloud or on-premises.

“We continue to leverage our revolutionary autonomous capabilities to transform the database market,» said Andrew Mendelsohn, executive vice president, Oracle Database. «Our latest self-driving database cloud service, Oracle Autonomous NoSQL Database, provides extreme reliability and performance at very low costs to achieve a highly flexible application development framework.”

Oracle’s autonomous database was first introduced last October, with its automated cybersecurity the first product in the line. It now comprises the Autonomous Data Warehouse Cloud and an autonomous transaction processing service under the same brand name. IT also includes Oracle Autonomous Analytics Cloud, Oracle Autonomous Integration Cloud and Oracle Autonomous Visual Builder Cloud – all launched in May.

“Embedding AI and machine learning in these cloud services will help organizations innovate in revolutionary new ways,” Amit Zavery, executive vice president of development at Oracle Cloud Platform said after the launch of Oracle Autonomous Analytics Cloud, Oracle Autonomous Integration Cloud, and Oracle Autonomous Visual Builder Cloud. “These new cloud services are the latest in a series of steps from Oracle to incorporate industry-first autonomous capabilities that will enable customers to significantly reduce operational costs, increase productivity, and decrease risk.”

How identities are the new security perimeter

  • Privileged credentials for accessing an airport’s security system were recently for sale on the Dark Web for just $10, according to McAfee.
  • 18% of healthcare employees are willing to sell confidential data to unauthorized parties for as little as $500 to $1,000, and 24% of employees know of someone who has sold privileged credentials to outsiders, according to a recent Accenture survey.
  • Apple employees in Ireland have been offered as much as €20,000 ($22,878) in exchange for their privilege access credentials in 2016, according to Business Insider.
  • Privileged access credentials belonging to more than 1 million staff at a top UK law firm have been found for sale on the Dark Web.

There’s been a 135% year-over-year increase in financial data for sale on the Dark Web between the first half of 2017 and the first half of 2018. The Dark Web is now solidly established as a globally-based trading marketplace for a myriad of privileged credentials including access procedures with keywords, and corporate logins and passwords where transactions happen between anonymous buyers and sellers. It’s also the online marketplace of choice where disgruntled, angry employees turn to for revenge against employers. An employee at Honeywell, angry over not getting a raise, used the Dark Web as an intermediary to sell DEA satellite tracking system data he accessed from unauthorized accounts he created to Mexican drug cartels for $2M. He was caught in a sting operation, the breach was thwarted, and he was arrested.

Your most vulnerable threat surface is a best seller

Sites on the Dark Web offer lucrative payment in bitcoin and other anonymous currencies for administrators’ accounts at leading European, UK and North American banking institutions and corporations. Employees are offering their privileged credentials for sale to the highest bidder out of anger, revenge or for financial gain anonymously from online auction sites.

Privileged access credentials are a best-seller because they provide the intruder with “the keys to the kingdom.” By leveraging a “trusted” identity, a hacker can operate undetected and exfiltrate sensitive data sets without raising any red flags. This holds especially true when the organizations are not applying multi-factor authentication (MFA) or risk-based access controls to limit any type of lateral movement after unauthorized access. Without these security measures in place, hackers can quickly access any digital businesses’ most valuable systems to exfiltrate valuable data or sabotage systems and applications.

81% of all hacking-related breaches leverage either stolen and weak passwords, according to Verizon’s 2017 Data Breach Investigations Report. A recent study by Centrify and Dow Jones Customer Intelligence titled, CEO Disconnect is Weakening Cybersecurity (31 pp, PDF, opt-in), found that CEOs can reduce the risk of a security breach by rethinking their Identity and Access Management (IAM) strategies. 68% of executives whose companies experienced significant breaches in hindsight believe that the breach could have been prevented by implementing more mature identity and access management strategies.

In a Zero Trust world, identities are the new security perimeter

The buying and selling of privileged credentials are proliferating on the Dark Web today and will exponentially increase in the years to come. Digital businesses need to realize that dated concepts of trusted and untrusted domains have been rendered ineffective. Teams of hackers aren’t breaking into secured systems; they’re logging in.

Digital businesses who are effective in thwarting privileged credential access have standardized on Zero Trust Security (ZTS) to ensure every potentially compromised endpoint, and threat surface within and outside a company is protected. Not a single device, login attempt, resource requested or other user-based actions are trusted, they are verified through Next-Gen Access (NGA).

Zero Trust Security relies upon four pillars: real-time user verification, device validation, access and privilege limitation, while also learning and adapting to verified user behaviors. Leaders in this area such as Centrify are relying on machine learning technology to calculate risk scores based on a wide spectrum of variables that quantitatively define every access attempt, including device, operating system, location, time of day, and several other key factors.

Depending on their risk scores, users are asked to validate their true identity through MFA further. If there are too many login attempts, risk scores increase quickly, and the NGA platform will automatically block and disable an account. All this happens in seconds and is running on a 24/7 basis ― monitoring every attempted login from anywhere in the world.

A recent Forrester Research thought leadership paper titled, Adopt Next-Gen Access to Power Your Zero Trust Strategy (14 pp., PDF, opt-in), provides insights into how NGA enables ZTS to scale across enterprises, protecting every endpoint and threat surface. The study found 32% of enterprises are excelling at the four ZTS pillars of verifying the identity of every user, validating every device using Mobile Data Management (MDM) and Mobile App Management (MAM), limiting access and privileges and learning and adapting using machine learning to analyze user behavior and gain greater insights from analytics.

NGA is a proven strategy for thwarting stolen and sold privileged access credentials from gaining access to a digital business’ network and systems, combining Identity-as-a-Service, Enterprise Mobility Management (EMM) and Privileged Access Management (PAM). Forrester found that scalable Zero Trust Security strategies empowered by NGA lead to increased organization-wide productivity (71%), reduced overall risk (70%) and reduced cost on compliance initiatives (70%).

Additionally, insights gained from user behavior through machine learning allow for greater efficiency — both on reduced compliance (31% more confident) and overall security costs (40% more likely to be confident), as well through increased productivity for the organization (8% more likely to be confident). The following graphic from the study ranks respondents’ answers.

Conclusion

Making sure your company’s privileged access credentials don’t make the best seller list on the Dark Web starts with a strong, scalable ZTS strategy driven by NGA. Next-Gen Access continually learns the behaviors of verified users, solving a long-standing paradox of user experience in security and access management. However, every digital business needs to focus on how the four pillars of Zero Trust Security apply to them and how they can take a pragmatic, thorough approach to secure every threat surface they have.

Firefox Focus tweaked with improved browsing features


Clare Hopping

3 Oct, 2018

Firefox Focus, Mozilla’s private browsing experience update has now been revealed, with new features, such as custom tabs, a tracker counter and a full-screen mode. 

All the core features of Firefox Focus are now presented on the homescreen of the application, offering hints and tips for users about how to protect their identity while browsing online. 

You can also get search suggestions from the homescreen, although this is only activated if you wish it to be via the settings, because the whole point of Firefox Focus is so no one knows what you’re searching for. But to switch it on, just heard to the Firefox Focus settings and choose to turn it on.

The design of Firefox Focus has also seen quite an overhaul to be more in line with Android Pie. The update for Android users includes new icons, a customised URL bar and simplified settings menu to make it almost look part of Google’s operating system.

iOS users arguably get the tastiest new features, including Siri Shortcuts, which allows them to set their favourite websites and open them on demand, just by using their voice through Siri. They will also be able to erase their history and erase activity in the background using shortcuts.

Underneath the UI, Firefox Focus has been updated at a more core level. In fact, Mozilla explained it’s completely revamped the underlying framework. Focus is now built on GeckoView, Mozilla’s own mobile engine to make it more focused on security and privacy. Specifically, it means no third parties will be able to collect data.

Mozilla promised that although there doesn’t seem to be a huge amount of changes in this version, there’s a lot more coming soon to protect users’ privacy while browsing on mobile.

What Is Your IT department Good for: Efficient Service or Unwanted Workout?

A midsize or large organization with dozens, hundreds, or even thousands of PCs is difficult to imagine without Microsoft System Center Configuration Manager (SCCM). This hardware and software administration solution allows handling asset management, software distribution, remote maintenance, license monitoring, reporting, and software threat defense from a single, centralized console. Eliminating countless manual tasks helps […]

The post What Is Your IT department Good for: Efficient Service or Unwanted Workout? appeared first on Parallels Blog.

Deloitte Named Technology Sponsor of @CloudEXPO NY | @Deloitte @DeloitteUS #Cloud #CIO #IoT #Serverless #DevOps

«Deloitte» is the brand under which tens of thousands of dedicated professionals in independent firms throughout the world collaborate to provide audit & assurance, consulting, risk and financial advisory, risk management, tax, and related services to select clients. These firms are members of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee («DTTL»). Each DTTL member firm provides services in particular geographic areas and is subject to the laws and professional regulations of the particular country or countries in which it operates.

read more

Atmosera Named «Technology Sponsor» of @CloudEXPO NY | @Atmosera @Azure #Cloud #DevOps #CIO #DataCenter #Monitoring

Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures. Offering private, hybrid, and public cloud solutions, Atmosera works closely with customers to engineer, deploy, and operate cloud architectures with advanced services that deliver strategic business outcomes. Atmosera’s expertise simplifies the process of cloud transformation and our 20+ years of experience managing complex IT environments provides our customers with the confidence and trust that they are being taken care of.

read more

Retail, advertising and marketing are furthest on the road to hybrid cloud

Every industry is moving towards a hybrid cloud world – with retail, advertising and marketing making the biggest push.

That’s the key finding from a new report by container and cloud technology provider Mesosphere. The study, which focused its responses on more than 700 Mesosphere users, found that almost two thirds (64%) of retail and eCommerce respondents polled said they had hybrid environments.

This is considerably more than advertising, marketing and PR (42%) and IT consulting (40%), which came next in the list. The lowest performing industry is education, with only one in five (21%) proffering hybrid.

Not one respondent in the healthcare industry said they had a primarily cloud-based stack; 71% were on-prem and 29% had hybrid. For education, 64% have wholly cloud and only 14% were on-premise. “Healthcare is going straight from on-prem to hybrid and skipping cloud-only altogether. This is likely due to the size of the data and confidentiality requirements,” the report noted. “Education still trails, possibly due to a large footprint in high performance computing infrastructure.”

The figures don’t correlate with company size. 38% of organisations with 10,000 employees or more are hybrid, compared with 35% for 5,001-10,000 and 39% for 1,001 to 5,000.

Container adoption is seeing steady progress. 84% of Mesosphere users are running containers in production today, up significantly from 62% in 2016. Not surprisingly, Kubernetes was top dog among the respondents. On average, users are running three or more frameworks on Mesosphere, with Kubernetes the most popular ahead of big data service Kafka and open source server Jenkins. The vast majority of those polled (97%) said they were using Kubernetes to simplify deployment.

“The growth of Kubernetes usage on Mesosphere clearly echoes its popularity in the market,” the report notes, “and customers are adopting Kubernetes and leveraging the Mesosphere platform for automation and management.”

Writing in a company blog, Dayna Rothman, Mesosphere VP marketing, explained: “Clearly, the main drivers for implementing Kubernetes on Mesosphere are around simplicity, scale, and flexibility. These drivers are especially critical for enterprise organisations and companies who need to operate multiple Kubernetes clusters.”

Multi-cloud has also gone up considerably in the past couple of years. In the 2016 report, 86% of respondents said they were using only one cloud provider, a number which had gone down to 76% this time around.

Microsoft, Amazon and Google infrastructure-centric: Why the cloud is increasingly ‘magic’

Opinion We hear the term ‘the year of the cloud’ many times. I profess that it is ‘the decade of the cloud’ – and what’s more, we haven’t even really started yet.

Having been in the cloud industry for more than 12 years, and had a wealth of opportunity to engage with business across vertical sectors – from small local businesses to global enterprises and across geographic regions – I have witnessed an evolutionary change in acceptance of cloud technologies. This has gone from adamant “we resist” no-cloud policies through to “all in” cloud-first strategies.

We seem to have settled down now into a world where there is acceptance that cloud options should always be considered and the fear of cloud has diminished to a point where questions are asked and diligence done – rightly so, but as a necessary checkpoint, rather than a barrier to progressing.

Cloud is going to rapidly proliferate, not through the name – who says ‘I want some cloud’? – but due to the accelerated and rapid growth of emerging technologies powered by cloud somewhere or somehow. These are fast becoming the norm in everyday life and are appearing on business agendas across sectors. We find big data, AI, IoT, VR, and even drones all appearing in ever more interesting and applicable ways, with their prices becoming consumable by even the smallest of firms. By 2020, we can expect to be seeing AI and IoT increasingly in our everyday lives – often transparent to us, and with cloud hidden away powering their wonderous delivery.

We now hear the terms edge computing and fog computing, as well as wider use of ‘as a service’ as the cloud sector matures. With this maturing comes a wave of change in the underlying delivery mechanisms and platforms.

We started with hosting, data centres hosting your own racked equipment, or providing racks where you could remotely install your applications onto your own single tenancy instance. Heading towards 2020, we are seeing an acceleration of re-platforming and customers moving their workloads to the public cloud, where the early concerns have gone and we now see compute and storage costs constantly reducing on what is known as the race to zero (who will be the first to give it away?). This whilst performance, reliability and function have increased. We have never seen a time in compute previously where the power and function went up at as high an exponential as prices are coming down.

Compounding this is technology vendors who are themselves re-platforming, moving their SaaS offerings from their own hosted data centres to the likes of the big three – AWS, Azure, or Google. We have seen major technology SaaS firms doing this and, in my experience, both where I have worked and those I know well in the sector, this is increasingly commonplace. Cloud firms are realising their core is the IP and expertise, not running the traditional cloud infrastructure itself. Add to this that we are seeing a growth of hosting firms, traditionally fighting against these public cloud giants, not getting on board, instead reselling their hosting and wrapping their cloud expertise around the unbeatable ‘compute power <> price’ ratio that the goliaths can deliver.

By 2020, we can expect cheaper prices throughout the cloud chain, the emergence of eye-opening new tech at home and in the workplace – and a change under the covers of how the cloud providers themselves deliver and monetarise their own offerings.

Ian Moyse is a cloud industry thought leader and cloud sales director at Natterbox.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.