Showing posts with label cloud confusion. Show all posts
Showing posts with label cloud confusion. Show all posts

Monday, April 15, 2013

Conversation with One of CloudNOW’s Top 10 Women: Lori MacVittie

F5 Sr. Technical Marketing Manager Lori MacVittie received CloudNOW’s prestigious Top 10 Women in Cloud award for her exceptional contributions to the cloud community. CloudNOW, an executive consortium of the leading women in cloud computing, presented the award during UBM Tech’s Cloud Connect—the premier technology event for cloud computing.

I've had the good fortune to have known and worked with Lori for almost 7 years and sat down with her to talk about cloud, convergence and application delivery.

Peter: First, Congratulations Lori on yet another award. If I remember correctly, this is the 2nd year in a row that your contributions, accomplishments, and thought leadership has been recognized by CloudNOW. How’d you get so smart?

Lori: I don’t necessarily think it’s being so smart myself that’s key, it’s being afforded a platform on which smart ideas – many of which are instigated by other, very smart people - can be promoted that made that happen. I won’t say I don’t have smart ideas myself, but there’s so many talented folks in the industry that it’s more a collaborative, bouncing-off-each-other process that’s critical to coming up with ways to solve new challenges.

Peter: Public, private, hybrid. Is there a clear cloud choice or organizations or does it depend on what they are trying to accomplish? What are the advantages and pitfalls of each?

Lori: Wow, that’s at least one if not two or three blog posts right there. I think it depends on what the organization is trying to achieve and what kind of applications are critical to achieving those goals. The reality is that hybrid is going to dominate the cloud landscape by virtue of sheer necessity. There’s too many needs that can’t be met by just public or just private that require a more integrated, business-driven approach to deployments. That means hybrid is going to win, hands down.

Peter: Some in the industry believe the term ‘cloud’ is starting to get a bit cliché due to potential overuse, misuse and abuse. What do you think? Has it lost some luster?

Lori: Did it ever have luster other than as link-bait? Seriously, like any new technology market the term is overused, hyped, and abused. It means different things to different people and more confusing, to different markets. It still has power, but it is losing its status as technology darling du jour to more up and coming technology that has infrastructure bling, like SDN.

Peter: Cloud Standards. The IEEE Cloud Computing Initiative has originated two working drafts (P2301 and P2302); The Cloud Security Alliance works together to define best practices in cloud security; the Open Cloud Consortium supports the development of standards among others. First, will there ever be standards and if so, what will that provide to both customers and providers? Will standards be the final keystone for those waiting in the wings?

Lori: Standards for what? Integration? Bridging? Brokering? Cloud management? We are so far away from standardization of cloud anything at this point that we’re going to have to wait and see. When customers start demanding support for a standard X or Y or Z as table stakes for being considered as a viable provider, then we’ll start seeing real movement around those standards. So in the meantime, we’re going to continue to see each provider and vendor offering up their own “standards” and maneuvering with partnerships and support of APIs. When we start seeing accepted – even de facto – standards around cloud we’ll know it’s reached maturity.

Peter: In your opinion, what are the biggest challenges facing cloud computing? Security? Availability? The misuse of the term? Standards? Confusion?

Lori: Integration and portability. There is no such thing as “cloud security”, only network, application and data security applied in the cloud or in the data center. :-) The biggest challenge facing cloud is that it requires a new way of looking at application deployment challenges and ultimately that trickles down to how we architect at the network, its topology. That’s a bigger challenge than simply giving up control of infrastructure; after all, we did that when we adopted managed hosting. Cloud is forcing us to rethink how we architect from the network up, and that’s harder than anything else because it’s a paradigm shift (there’s a phrase we haven’t used in a decade or so, but it’s the one that fits best – and probably better now than it did then).

Peter: You presented on two topics at Cloud Connect – ‘App Delivery in the Cloud’ and ‘Managing Hybrid Cloud’. Can you give a synopsis of each?

Lori: Let’s see. On the first one: successfully delivering applications and managing access in a cloud computing environment is about balancing control with flexibility: integrating processes and leveraging the power of standards like SAML to extend enterprise governance over cloud deployed applications while distributing control into the cloud to enable consistent control over delivery policies. Managing hybrid cloud. It’s all about integration. Integrating processes, integrating networks, integrating resources. Once you do that, the management is easy. Okay, maybe not easy but easier, which is a good thing considering the state of infrastructure integration today.

Peter: How does some of these new technologies like SDN (Software Defined Networking) and NFV (Network Function Virtualization) fit into the Cloud equation?

Lori: SDN is really about enabling elasticity for scale and flexibility in topology at the network layer. In that respect, it affords cloud a very dynamic foundation on which to deploy value-added services at the application layer that can address some of the challenges with cloud noted above with respect to thinking differently about how we deploy infrastructure services in a topologically-hampered environment. NFV continues to be of most interest to service providers, and their goal is fast, flexible, programmability in the network that enables rapid development and deployment of new services that increase ARPU by offering new value and competitive advantages. As far as cloud goes, NFV could be layered atop SDN to provide a layer of elasticity and dynamic provisioning for value added services, but right now service providers are more concerned about services than they are the core network (because they rearchitected that when IMS and similar architectures became popular).

Excellent stuff, Lori! Thanks! You can connect with and follow Lori on DevCentral or Twitter

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, March 13, 2013

This Blog May Have Jumped the Shark

Really?  Already?!?

For whatever reason, the phrase 'Jump the Shark' has been jumping out at me recently.  From the Jump the Shark Hat Tutorial to watching past episodes of Supernatural on Netflix to Cloud Computing to the many #jumptheshark tags added to tweeps tweets.  Originally linked to the Happy Days episode where the water-skiing Fonz jumps over a shark, it has since become the term to describe when writer's storylines have moved into the absurd and the show itself quickly deteriorates.  Today it is attached to almost anything that has either hung around too long, is past it's prime or is simply fallen off the hype-cliff.  I sometimes feel this way after producing a bunch of videos (like the last two weeks) and need to get back to writing...like this entry.  So I decided to investigate a couple recent hype technologies (that I also write about) and if they've already Jumped the Shark.

Rumblings of Cloud Computing jumping the shark came as early as 2009 and 2010.  In 2009 PCWorld ran an article titled, Has Cloud Computing Jumped the Shark? talking about the different definitions of cloud, which company prefers what definition and the rush of vendors into the space.  In 2010, a ServerWatch article titled, Did Cloud Computing Jump the Shark? discusses how various analyst firms view and predict cloud's future along with the differing opinions about it's hype and hope.  Another 2010 article from ebizQ titled Has Cloud Computing Jumped the Shark? references another Infoworld article named Confessions of a cloud skeptic which, in the first sentence says, "the cloud" has jumped the shark.  There are many more articles from 2010 wondering if Cloud has become chum.  I think this was due to the hype, battling opinions on just what cloud is/was and eventually can be, along with the types - SaaS, PaaS and IaaS and the categories of public, private, hybrid.  Now some 3 years later, has it officially jumped, crashed or landed safely on the other side?  Depends on who you ask. 

Throughout 2012, there were plenty of articles titled 'Cloud Computing is Here to Stay' filled with survey results, anecdotal evidence and analyst cites.  At RSA this year, however, I heard a few folks say that the term 'Cloud' was forbidden to be uttered in the Expo Hall.  While the term itself has been overused, abused, misconstrued, and has probably Jumped the Shark, the underlying technology/philosophy will be a part of an organization's hybrid and distributed infrastructure for years to come.  Mobility is one of the main cloud drivers.

Which brings me to my other check.

Has BYOD Jumped the Shark?  Maybe.  Or it might be heading up the ramp.  Almost every pundit thinks BYOD, using one's personal device for work, will be the trend of the year for 2013 but some are questioning that.  A few weeks ago I wrote Is BYO Already D? talking about the few surveys indicating that BYOD could cost more than imagined including The Aberdeen Group who says BYOD could cost organizations 33% more than a IT owned mobile device plan.  The Nov 2012 CITEWorld article titled Has BYOD jumped the shark? One researcher thinks so also talks about the Aberdeen research but adds a research note from Nucleus which predicts that BYOD will decline as enterprise mobility heats up. They explain that support costs, compliance risks and usage reimbursement will lead to higher TCO with no discernable ROI or productivity gains.

While I don't think that BYOD has officially moved to the absurd, for 2013 I do think organizations will better understand the BYOD implications  and how it fits in the overall Enterprise Mobility strategy.  Enterprise Mobility includes BYOD, managed devices and other communication tools, including laptops potentially.  Just like cloud, I think organizations will have a mix of options to support a mash of devices - including those you use at or bring from home.  There will still be IT issued fully managed devices (that require a VPN tunnel) for years to come mixed in with unmanaged personal devices where just the corporate data and apps are under IT control.  This is the BYOD 2.0 stuff we've been talking about with the F5 Mobile App Manager.  So while the term BYOD might be starting to hit saturation, Enterprise Mobility should be the focus.  Access to any app, from any device, from anywhere.

So, has this blog Jumped the Shark?  While some of the topics, err, terms I cover might be candidates, only you can determine if/when I've crossed into that absurdity realm.  I do hope you'll let me know when I start resembling a cool dude wearing a leather jacket while water skiing.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, May 30, 2012

The Cloud’s Hidden Costs

Survey says…and many companies believe that moving architecture, resources or other IT infrastructure pieces to the cloud will save them money.  That’s been one of the biggest selling points of cloud computing – pay as you go, metered service, pay what you use – the internet as a utility offering.  And while simple deployments can be cost effective, complete architectural maneuvers often put pressure on the cloud’s main value proposition according to a recent Information Week article.

Burning through metered service when you think most everything is off can easily happen, as any of us are aware with lights, water, electricity and gas in our own homes.  In the IT world, a development team may have spun up some servers for testing and forgot to decommission; another group may have commandeered some servers for a specific campaign; or, the overflow/burst/DR model went into play due to some holiday and the servers are still running well after the wrapping paper is stuffed in the garbage recycle bin.  The ability for anyone with a credit card to procure cloud infrastructure services can lead to that same someone also forgetting to turn off the lights, spigot, stove and internet.  We’ve all done it.  And when that bill arrives, the envelope suddenly drops and the paper insert slowly floats to the floor as we attempt to understand ‘what the heck was left running!?!’

Visibility seems to be the primary culprit.   As cloud providers continue to expand and grow, often their visibility into and control over usage patterns decreases.  And CIOs can’t take full advantage of cloud economies since they may not know the who, what, where, when and how of the application(s) running in the cloud and thus, the overall cost implications.  Cloud management tools, which are also evolving, primarily focus on provisioning, capacity, utilization and workflows but not always the total cost of ownership.  Most organizations are not even fully aware of the costs until that big envelope arrives and they might not deal with or have a plan for ‘overages’ until it happens.  In addition, as more companies look to the cloud for business continuity/disaster recovery scenarios, as the recent disaster planning study from AT&T suggests, those ‘deer in the headlights’ gazes may become more common.

According to the article, these four situations account for cloud's most common hidden costs:

1. Runaway VMs: One of the key tenets of the cloud is self-service, making it easy for users to gain access to compute power wherever and whenever they need it. Often what happens, though, is users are so empowered to spin up compute resources that they overprovision or go over budget because there are no guidelines or caps in place to limit their usage.

2. Zombie VMs: This is something referred to as the "living dead" concept. Think back to the group of developers who spun up a bunch of clouds for load testing, which they never brought down, or even a handful of licenses for a software-as-a-service (SaaS) application purchased on credit cards by a lone business group, which after a period of brief usage lies dormant. While individually these expenses may not account for much, cumulatively they can add up, especially if there's no visibility for tracking, and months, even years, go by without turning off the spigot.

3. Choosing the wrong pricing model: Cloud providers price their services differently and often, the costs are a moving target.  Many organizations will opt for more expensive on-demand pricing because they don't want to make a long-term commitment to the provider, but they do so without having the proper context.

4. Maintenance costs: A move to the cloud means support and maintenance comes off of IT's plate. Well, that's the idea, but not necessarily the reality.  Also, all of the groups that have tapped cloud resources on their own (so-called shadow IT) come calling on IT, not the support folks at the Amazon cloud, when something goes wrong.

At one point or another, we all have forgotten to turn off a light, the water, a heater, the AC or any other item that uses the traditional utilities.  The new Smart meter Edison installed on the side of my house is supposed to give me visibility into my usage for proper cost analysis.  Organizations need something similar as part of the cloud management tools to give them the ability to properly plan if and when sticker shock hits their system.

ps

References:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, March 24, 2011

Has The Sky Cleared on Cloud Security?

Last year I embarked on a blog series, lead by my trusty advisor CloudFucius, that evolved into an exploration of the numerous cloud computing surveys, reports, statistics and other feelings about the technology.  At the time, 4-5 surveys a week were being released covering some aspect of cloud computing and security was cited as the biggest hurdle in almost 90% of the surveys.  I also found that availability, control and a general lack of understanding were also drivers in challenges to cloud adoption.   Almost 6 months have passed since the last CloudFucius entry and I wanted to see if the same fears were still lingering or at least, were the current surveys reporting the same concerns from a year ago about Cloud Computing.

First up, is UK based technology publication, Computing.   Working with Symantec.cloud, they surveyed 150 IT decision makers and learned that as more companies embrace Cloud Computing, they are finding that the cloud solutions meet or beat, not only their expectations but also their own existing in-house solutions.  While on-premise security solutions might be adequate today, as the security threats evolve, the cloud providers may have the advantage over time due to the infrastructure investments in advanced filtering and detection along with 24/7 trained staff.  Last year, availability and uptime also emerged as concerns and today there is great interest in the contractual SLAs offered by cloud providers since it often surpasses what they are capable of in-house.  Resiliency and disaster recovery across multiple data centers can ensure that if there is an outage in one location, the customers can still access their data.  Management and control still create some anxiety but many IT teams are happy to abdicate routine maintenance, like OS patching and hardware upgrades, in exchange for management SLAs.  Now that the hype of cloud services has passed and many providers are proving themselves worthy, it is now becoming part of the overall IT strategy.  As the perceived threats to data security in the cloud dwindle, trust in the cloud will grow.

The Cloud Connect Conference in Santa Clara also released a survey during their gathering.  In that one, elasticity and speed of deployment were the top motivators to using cloud services.  Elasticity or the flexibility to quickly add or reduce capacity, can greatly influence the availability of data.  These folks however were less motivated by improved security or access to the provider’s IT staff.  Their top concerns were data privacy and infrastructure control.  I do find it interesting that last year the term ‘security,’ which can encompass many things, was the primary apprehension of going to the cloud while today, it has somewhat narrowed to specifically data privacy.  That too can mean several things but areas like outsider’s physical access to systems doesn’t seem to worry IT crews as much any more.

When it comes to our school/educational system, Panda Security released a study that focused on IT security in K-12 school districts.  Like many companies, they must deal with unauthorized user access, malware outbreaks and admit that IT security is time and resource intensive.  They do believe however that the cloud can offer security benefits and improve their overall infrastructure.  91% see value in cloud solutions and are planning to implement over the next couple years with 80% saying improved security was a main reason to deploy cloud-based security.

Finally on the consumer front, GfK Business & Technology surveyed 1000 adults about cloud services and storing content in the cloud.  With all of our connected devices – cell phone, computer, tablet, etc. – there will be a greater demand to move data to the cloud.  Not real surprising, less than 10% of the consumers surveyed fully understand what the cloud actually does.  The know of it, but not what it accomplishes.  With what you don’t understand comes fear.  61% said that they were concerned about storing their data in the cloud and almost half said they would never use the cloud unless it was easy to store and retrieve data.  As businesses begin to feel content with the cloud, they then need to both educate and communicate cloud benefits to their consumers.

So it does appear like comfort with the cloud is beginning to take hold and as cloud offerings mature, especially around security, err ah, I mean data privacy solutions, the fear, uncertainty and doubt from last year is starting to loosen and it sure seems like greater adoption is on the horizon.

And one from Confucius: They must often change who would be constant in happiness or wisdom.

ps

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, cloud survey, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 20, 2010

CloudFucius Asks: Will Open Source Open Doors for Cloud Computing?

Konfuzius-1770 There has been a lot of press already about OpenStack’s announcement yesterday about their new open source cloud computing software.  OpenStack says that the goal is, ‘to allow any organization to create and offer cloud computing capabilities using open source software running on standard hardware.’  The software is intended to to allow companies to automatically create and manage large deployments of virtual private servers and remove the concern of vendor lock-in since the software will allow customers to span multiple cloud providers.  Customers and service providers alike can use their own physical hardware to create large cloud environments, public or private, across the globe.  It is also positioned to give customers more choice in how they want their specific cloud environment designed and deployed.  Almost 30 companies are participating with the folks at Rackspace and NASA (Nebula cloud computing platform) leading the charge.

Certainly, there are several attractive pieces to this, including the notion of cloud-standards, but will it finally open the flood gates for mass adoption of Cloud deployments?  Maybe not for the enterprise, at least initially.  Openstack honestly admits, ‘OpenStack is probably not something that the average business would consider deploying themselves yet. The big news for end customers is the potential for a halo effect of providers adopting an open and standard cloud: easy migration, cloud-bursting, better security audits, and a large ecosystem of compatible tools and services that work across cloud providers.’  This means that Openstack is really aimed at *very* technical enterprises (very large with lots of resources) and service providers.  Thus, the play for the enterprise does not exist (yet) here, *except* for management layer players who could leverage it to build something they could sell to enterprises to “make it easy” for them.  (thanks Lori!)

In addition, as Ted Julian of the Yankee Group points out in this story, security is still the great unknown since there doesn’t seem to be a security vendor on the list of Openstack participants.  I’m sure that list will grow over time, especially with the press that it’s getting, and the ever present cloud security concerns will eventually be addressed.  This project is in the very early stages and will continue to evolve as folks pick up the code, test it and decide how it might work for them.  Maybe it’ll also help push along and enable the whole Inter-Cloud notion.

And one from Confucius: The cautious seldom err.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet, openstack

twitter: @psilvas

Digg This

Wednesday, July 14, 2010

CloudFucius Tunes into Radio KCloud

Konfuzius-1770 Set the dial and rip it off – all the hits from the 70s, 80s, 90s and beyond – you’re listening to the K-Cloud.  We got The Puffy & Fluffy Show to get you going in the morning, Cumulous takes you through midday with lunchtime legion, Mist and Haze get you home with 5 o’clock funnies and drive-time traffic while Vapor billows overnight for all you insomniacs.  K-Cloud; Radio Everywhere.

I came across this article which discusses Radio’s analogue to digital transition and it’s slow but eventual move to cloud computing.  How ‘Embracing cloud computing requires a complete rethinking of the design, operation and planning of a station’s data center.’  Industries like utilities, technology, insurance, government and others are already using the cloud while the broadcast community is just starting it’s exploration, according to Tom Vernon, a long-time contributor to Radio World. 

Like many of you, I grew up listening to the radio (music, I’m not that old) and still have a bunch of hole-punched record albums for being the 94th caller.  I listened to WHJY (94-HJY) in Providence and still remember the day in 1981 when it switched from JOY, a soft, classical station to Album-Orientated Rock.  Yes, I loved the hair-metal, arena rock, new wave, pop and most what they now call classic rock.  It’s weird remembering ‘Emotional Rescue’ and ‘Love Rollercoaster’ playing on the radio as Top 40 hits and now they are considered ‘classics.’   Um, what am I then?!? 

That article prompted me to explore the industries that have not embraced the cloud, and why.  Risk adverse industries immediately come to mind, like financial and health care.  There have been somewhat contradictory stories and surveys recently indicating both that, they are hesitant to adopt the cloud and ready to embrace the cloud.  A survey by LogLogic says that 60% of the financial services sector felt that cloud computing was not a priority or they were risk-averse to cloud computing.  This is generally an industry that historically has been an early adopter of new technologies.  The survey indicates that they will be spending IT dollars on ‘essential’ needs and that security questions and data governance concerns is what’s holding them back from cloud adoption.

About a week later, results from a survey done by The Securities Industry and Financial Markets Association (SIFMA) and IBM reports that there is now a strong interest in cloud computing after a couple years of reluctance.  The delay was due to the cost of implementing new technologies and the lack of talent needed to mange those systems.  Security is not the barrier that it once was since their cloud strategies include security ramifications.  They better understand the security risks and calculate that into their deployment models.  This InformationWeek.com story says that the financial services industry is indeed interested in cloud computing, as long as it’s a Private Cloud.  The one’s behind the corporate firewall, not Public floaters.  And that security was not the real issue, regulations and compliance with international border laws were the real holdback.

In the healthcare sector, according to yet another survey,  Accenture says that 73% said they are planning cloud movements while nearly one-third already have deployed cloud environments.  This story also says that ‘healthcare firms are beginning to realize that cloud providers actually may offer more robust security than is available in-house.’ 

Is there a contradiction?  Maybe.  More, I think it shows natural human behavior and progression when facing fears.  If you don’t understand something and there is a significant risk involved we’ll generally say, ‘no thanks’ to preserve our safety and security.  As the dilemma is better understood and some of the fears are either addressed or accounted for, the threat level is reduced and progress can be made.  This time around, while there are still concerns, we are more likely to give it a try since we know what to expect.  A risk assessment exercise gives us the tools to manage the fears.  Maybe the threat is high but the potential of it occurring is low or the risk is medium but we now know how to handle it.  It’s almost like jumping out of a plane.  If you’ve never done it, that first 3000ft tethered leap can be freighting – jumping at that height, hoping a huge piece of fabric will hold and glide you to a safe landing on the ground.  But once you’ve been through training, practiced it a few times, understand how to deploy your backup ‘chute and realize the odds are in your favor, then it’s not so daunting.  This may be what’s happening with risk averse industries and cloud computing.  Initially, the concerns, lack of understanding, lack of visibility, lack of maturity, lack of control, lack of security mechanisms and their overall fear kept these entities away, even with the lure of flexibility and potential cost savings.  Now that there is a better understanding of what types of security solutions a cloud provider can and cannot offer along with the knowledge of how to address specific security concerns, it’s not so scary any more.

Incidentally, I had initially used KCLD and WCLD for my cloud stations until I realized that they were already taken by real radio stations out of Minnesota and Mississippi.

And one from Confucius: Everything has its beauty but not everyone sees it.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12

Related:

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet

twitter: @psilvas

Digg This

Tuesday, June 1, 2010

CloudFucius Shares: Cloud Research and Stats

Konfuzius-1770 Sharing is caring, according to some and with the shortened week, CloudFucius decided to share some resources he’s come across during his Cloud exploration in this abbreviated post.  A few are aged just to give a perspective of what was predicted and written about over time.

Some Interesting Cloud Computing Statistics (2008)

Mobile Cloud Computing Subscribers to Total Nearly One Billion by 2014 (2009)

Server, Desktop Virtualization To Skyrocket By 2013: Report (2009)

Gartner: Brace yourself for cloud computing (2009)

A Berkeley View Of Cloud Computing : An Analysis – the good, the bad and the ugly (2009)

Cloud computing belongs on your three-year roadmap (2009)

Twenty-One Experts Define Cloud Computing (2009)

5 cool cloud computing research projects (2009)

Research Clouds (2010)

Cloud Computing Growth Forecast (2010)

Cloud Computing and Security - Statistics Center (2010)

Cloud Computing Experts Reveal Top 5 Applications for 2010 (2010)

List of Cloud Platforms, Providers, and Enablers 2010 (2010)

The Cloud Computing Opportunity by the Numbers (2010)

Governance grows more integral to managing cloud computing security risks, says survey (2010)

The Cloud Market EC2 Statistics (2010)

Experts believe cloud computing will enhance disaster management (2010)

Cloud Computing Podcast (2010)

Security experts ponder the cost of cloud computing (2010)

Cloud Computing Research from Business Exchange (2010)

Just how green is cloud computing? (2010)

Senior Analyst Guides Investors Through Cloud Computing Sector And Gives His Top Stock Winners (2010)

Towards Understanding Cloud Performance Tradeoffs Using Statistical Workload Analysis and Replay (2010)

…along with F5’s own Lori MacVittie who writes about this stuff daily.

And one from Confucius: Study the past if you would define the future.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Wednesday, May 26, 2010

CloudFucius Listens: F5’s Cloud Computing Solutions

Konfuzius-1770 About a month ago, CloudFucius Hollered about F5’s On-Demand IT solutions which offers a holistic approach to enable a common cloud architectural model—regardless of where IT resources actually reside.  That post contained links to the various whitepapers specifically covering F5’s Cloud Computing Solutions which were designed to unleash the true potential of virtualization and cloud computing.  It’s a comprehensive approach that integrates disparate technologies for application delivery, security, optimization, data management, and infrastructure control—all critical technologies needed to realize the true flexibility and agility of virtualization and cloud computing solutions.  CloudFucius is now excited to announce the availability of those whitepapers in audio format. 

For your listening pleasure:

Audio White Paper - The F5 Powered Cloud - How F5 solutions power a cloud computing architecture capable of delivering highly-available, secure, and optimized on-demand application services.  Read the full pdf of the whitepaper here.

Audio White Paper - The Optimized and Accelerated Cloud - As more organizations begin moving applications into the cloud, congestion will become an increasingly critical issue. F5 offers solutions for optimizing and accelerating applications in the cloud, making them fast and available wherever they reside.  Read the full pdf of the whitepaper here.

Audio White Paper - Securing the Cloud - Cloud computing has become another key resource for IT deployments, but there is still fear of securing applications and data in the cloud. With F5 devices, you can keep your most precious assets safe, no matter where they live.  Read the full pdf of the whitepaper here

Audio White Paper - Cloud Balancing: The Evolution of Global Server Load Balancing - Cloud balancing evolves global server load balancing from traditional routing options based on static data to context aware distribution across cloud-based services.  Read the full pdf of the whitepaper here.

Audio White Paper - Availability and the Cloud - Cloud computing offers IT another tool to deliver applications. While enticing, challenges still exist in making sure the application is always available. F5’s flexible, unified solutions ensure high availability for cloud deployments.  Read the full pdf of the whitepaper here

And one from Confucius: Learning without thought is labor lost; thought without learning is perilous.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Tuesday, May 25, 2010

CloudFucius Combines: Security and Acceleration

Konfuzius-1770 CloudFucius has explored Cloud Security with AAA Important to the Cloud and Hosts in the Cloud along with wanting An Optimized Cloud.  Now he desires the sweet spot of Cloud Application Delivery combining Security and Acceleration.  Few vendors want to admit that adding a web application security solution can also add latency, which can be kryptonite for websites.  No website, cloud or otherwise, wants to add any delay to users’ interaction.  Web application security that also delivers blazing fast websites might sound like an oxymoron, but not to CloudFucius.  And in light of Lori MacVittie’s Get your SaaS off my cloud and the accompanying dramatic reading of, I’m speaking of IaaS and PaaS cloud deployments, where the customer has some control over the applications, software and systems deployed.

It’s like the old Reese’s peanut butter cups commercial, ”You’ve stuck your security in our acceleration.”  “Yeah, well your acceleration has broken our security.”  Securing applications and preventing attacks while simultaneously ensuring consistent, rapid user response, is a basic web application requirement.  Yet web application security traditionally comes at the expense of speed.  This is an especially important issue for online retailers, where slow performance can mean millions of dollars in lost revenue and a security breach can be just as devastating as more than 70 percent of consumers say they would no longer do business with a company that exposed their sensitive information.

Web application performance in the cloud is also critical for corporate operations, particularly for remote workers, where slow access to enterprise applications can destroy productivity.  As more applications are being delivered through a standard browser from the cloud, the challenge of accelerating web applications without compromising security grows.  This has usually required multiple dedicated units either from the customer or provider, along with staff to properly configure and manage them.  Because each of these “extra” devices has its own way of proxying transactions, packets can slow to a crawl due to the extra overhead of TCP and application processing.  Fast and secure in a single, individually wrapped unit does seem like two contrary goals.

The Security Half
As the cloud has evolved, so have security issues.  And as more companies become comfortable deploying critical systems in the cloud, solutions like web application firewalls are a requirement, particularly for regulatory compliance situations.  Plus, as the workforce becomes more mobile, applications need to be available in more places and on more devices, adding to the complexity of enforcing security without impacting productivity.  Consider that a few years back, the browser’s main purpose was to surf the net.  Today, browser usage is a daily tool for both personal and professional needs.  In addition to the usual web application activities like ordering supplies, checking traffic, and booking travel, we also submit more private data like health details and payroll information.  The browser acts as a secret confidant in many areas of our lives since it transmits highly sensitive data in both our work and social spheres.  And it goes both ways; while other people, providers, sites, and systems have our sensitive data, we may also be carrying someone else’s sensitive data on our own machines.  Today, the Could and really the Internet at large is more than a function of paying bills or getting our jobs done—it holds our digital identity for both work and play.  And once a digital identity is out there, there’s no retracting it.  We just hope there are proper controls in place to keep it secret and safe.

The Acceleration Half
For retail web applications and search engines, downtime or poor performance can mean lost revenue along with significant, tangible costs.  A couple years ago, the Warwick Business School published research that showed it can be more than $500,000 in lost revenue for an unplanned outage lasting just an hour.  For financial institutions, the loss can be in the several million dollar range.  And downtime costs more than just lost revenue.  Not adhering to a service level agreement can incur remediation costs or penalties and non-compliance with certain regulatory laws can result in fines.  Additionally, the damage to a company’s brand reputation—whether it’s from an outage, poor performance, or breach—can have long-lasting, detrimental effects to the company.

These days, many people now have high-speed connections to the home accessing applications in the cloud.  But applications have matured and now offer users pipe-clogging rich data like video and other multi-media.  If the website is slow, users will probably go somewhere else.  It happens all the time.  You type in a URL only to watch the browser icon spin and spin. You might try to reload or retype, but more often, you simply type a different URL to a similar site.  With an e-commerce site, poor performance usually means a lost sale because you probably won’t wait around if your cart doesn’t load quickly or stalls during the secure check-out process.  If it’s a business application and you’re stuck with a sluggish site, then that’s lost productivity, a frustrated user and can result in a time-consuming trouble ticket for IT.  When application performance suffers, the business suffers.

What’s the big deal?
Typically, securing an application can come at the cost of end-user productivity because of deployment complexity.  Implementing website security—like a web application firewall—adds yet another mediation point where the traffic between the client and the application is examined and processed.   This naturally increases the latency of the application especially in the cloud, since the traffic might have to make multiple trips.  This can become painfully apparent with globally disbursed users or metered bandwidth agreements but the solution is not always simple. Web application performance and security administration can cross organizational structures within companies, making ownership splintered and ambiguous.  Add a cloud provider to the mix and the finger pointing can look like Harry Nilsson's The Point! (Oh how I love pulling out obscure childhood references in my blogs!!)

The Sweet Spot
Fortunately, you can integrate security and acceleration into a single device with BIG-IP Local Traffic Manager (LTM) and the BIG-IP LTM Virtual Edition (VE).  By adding the BIG-IP Application Security Manager (ASM) module and the BIG-IP WebAccelerator module to BIG-IP LTM, not only are you able to deliver web application security and acceleration, but the combination provides faster cloud deployment and simplifies the process of managing and deploying web applications in the cloud.  This is a true, internal system integration and not just co-deployment of multiple proxies on the same device.  These integrated components provide the means to both secure and accelerate your web applications with ease.  The unified security and web application acceleration takes a single platform approach that receives, examines, and acts upon application traffic as a single operation, in the shortest possible time and with the least complexity. The management GUI allows varying levels of access to system administrators according to their roles.  This ensures that administrators have appropriate management access without granting them access to restricted, role-specific management functions.  Cloud providers can segment customers, customers can segment departments.

The single-platform integration of these functions means that BIG-IP can share context between security and acceleration—something you don’t get with multiple units and enables both the security side and the acceleration side to make intelligent, real-time decisions for delivering applications from your cloud infrastructure.  You can deploy and manage a highly available, very secure, and incredibly fast cloud infrastructure all from the same unified platform that minimizes WAN bandwidth utilization, safeguards web applications, and prevents data leakage, all while directing traffic to the application server best able to service a request.  Using the unified web application security and acceleration solution, a single proxy secures, accelerates, optimizes, and ensures application availability for all your cloud applications.

And one from Confucius: He who will not economize will have to agonize.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6

Related:
Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog, law
twitter: @psilvas
Digg This