Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Friday, December 4, 2009

The Economists Cloud Debate: Microsoft

The rise of cloud computing is not just shifting Microsoft’s centre of gravity. It is changing the nature of competition within the computer industry.

Technological developments have hitherto pushed computing power away from central hubs: first from mainframes to minicomputers, and then to PCs.

Now a combination of ever cheaper and more powerful processors, and ever faster and more ubiquitous networks, is pushing power back to the centre in some respects, and even further away in others.

The cloud’s data centres are, in effect, outsize public mainframes. At the same time, the PC is being pushed aside by a host of smaller, often wireless devices, such as smart-phones, netbooks (small laptops) and, perhaps soon, tablets (touch-screen computers the size of books).

Although Windows still runs 90% of PCs, the fading importance of the PC means that Microsoft is no longer an all-powerful monopolist. Others are also building big clouds, including Google, a giant of the internet, and Apple, renowned as a maker of hardware, with a market capitalisation that now exceeds those of both Google and IBM, its original arch-rival (see chart above).

Read More.....

Saturday, November 28, 2009

EU Security Agency Highlights Cloud Computing Risks

Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).
Comments By Mikael Ricknäs

Fri, November 20, 2009 — IDG News Service — Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

The agency highlighted those problems as having the most serious consequences and being among the most likely for companies using cloud computing services, according to ENISA.

ENISA examined the assets that companies put at risk when they turn to cloud computing, including customer data and their own reputation; the vulnerabilities that exist in cloud computing systems; the risks to which those vulnerabilities expose businesses, and the probabilities that those risks will occur.

When moving to cloud-based computing services, companies have to hand over control to the cloud provider on a number of issues, which may affect security negatively. For example, the provider's terms of use may not allow port scans, vulnerability assessment and penetration testing. At the same time, service level agreements (SLAs) may not include those services. The result is a gap in defenses, ENISA said in the report.

Compliance could also prove to be a big problem if the provider can't offer the right levels of certification or the certification scheme hasn't been adapted for cloud services, the report said.

One of the advantages of cloud services is that data can be stored in multiple locations, which could save the day in the event of an incident in one of the data centers. However, it could also be a big risk if the data centers are located in countries with a shaky legal system, according to the report.

Other areas of concern are vendor lock-in, failure of mechanisms separating different companies, management interfaces that get accessed by hackers, data not deleted properly and malicious insiders.

To minimize these risks the report proposes a list of questions that a company needs to ask potential cloud providers. For example, what guarantees does the provider offer that customer resources are fully isolated, what security education program does it run for staff, what measures are taken to ensure third-party service levels are met, and so on.

In the end a good contract can lessen the risks, according to the report. Companies should especially pay attention to their rights and obligations related to data transfers, access to data by law enforcement and notifications of breaches in security, it said.

ENISA's report isn't all doom and gloom, though. Using cloud computing services can result in more robust, scalable and cost-effective defenses against certain kinds of attack, according to the report. For example, the ability to dynamically allocate resources could provide better protection against DDoS (distributed denial-of-service) attacks, ENISA said.

Friday, October 16, 2009

Malware Loses its Impact Power and Surprise Factor After 24 Hours in the Cloud

Security vendors—particularly those with Web filtering and antivirus products, boast about the exponential growth in malware. Symantec, McAfee and others say the number of malware samples detected over the last two years is approaching 3 million. Strange, that's more than all the samples of unique and variant viruses and worms detected in the last two decades.

Volume doesn't necessarily equal damage. 52% of malware lose it's power within 24 hours of being released into the wild (Cloud).

It's a surprising statistic that reflects the changing nature of malware. Many malware writers are using a malicious cloud computing model to capture valuable data. They're spreading worms and Trojans that either direct users to compromised or bogus Websites, or use a specific domain to send command and control instructions to their compromised clients.

McAfee recently reported, the volume of malware that's designed to monitor specific domains such as banks and gaming sites to stealthily steal access credentials increased more than 400 percent in 2008.

We already know that malware creators will not stick around, waiting to get caught. They're quickly moving or deactivating their controlling domains to avoid detection.

Also, carriers, hosting services and law enforcement are acting quickly to block or take down such malicious domains. The result is that those malware bots, dependent upon those malicious domains, are rendered inert within the first 24 hours. Therefore the impact power and surprise factor of malware, decreases over the next 72hours.

This is good news, right? Not always. It takes time for antivirus vendors and researchers to detect and create conventional signatures for new malware, somewhere in the order of 72 hours. This means most organisations are exposed to high infection rates and compromise, during the most dangerous time of malware infection.

The 24-hour window of vulnerability is an opportunity for solution providers to talk with customers about the benefits of adding synergistic security technologies that augment and complement traditional antivirus packages. Technologies such as data loss prevention, intrusion prevention, and Web and traffic monitoring and filtering can help detect and isolate malicious traffic and stop data loss.