Showing posts with label cloudfucius. Show all posts
Showing posts with label cloudfucius. Show all posts

Thursday, March 24, 2011

Has The Sky Cleared on Cloud Security?

Last year I embarked on a blog series, lead by my trusty advisor CloudFucius, that evolved into an exploration of the numerous cloud computing surveys, reports, statistics and other feelings about the technology.  At the time, 4-5 surveys a week were being released covering some aspect of cloud computing and security was cited as the biggest hurdle in almost 90% of the surveys.  I also found that availability, control and a general lack of understanding were also drivers in challenges to cloud adoption.   Almost 6 months have passed since the last CloudFucius entry and I wanted to see if the same fears were still lingering or at least, were the current surveys reporting the same concerns from a year ago about Cloud Computing.

First up, is UK based technology publication, Computing.   Working with Symantec.cloud, they surveyed 150 IT decision makers and learned that as more companies embrace Cloud Computing, they are finding that the cloud solutions meet or beat, not only their expectations but also their own existing in-house solutions.  While on-premise security solutions might be adequate today, as the security threats evolve, the cloud providers may have the advantage over time due to the infrastructure investments in advanced filtering and detection along with 24/7 trained staff.  Last year, availability and uptime also emerged as concerns and today there is great interest in the contractual SLAs offered by cloud providers since it often surpasses what they are capable of in-house.  Resiliency and disaster recovery across multiple data centers can ensure that if there is an outage in one location, the customers can still access their data.  Management and control still create some anxiety but many IT teams are happy to abdicate routine maintenance, like OS patching and hardware upgrades, in exchange for management SLAs.  Now that the hype of cloud services has passed and many providers are proving themselves worthy, it is now becoming part of the overall IT strategy.  As the perceived threats to data security in the cloud dwindle, trust in the cloud will grow.

The Cloud Connect Conference in Santa Clara also released a survey during their gathering.  In that one, elasticity and speed of deployment were the top motivators to using cloud services.  Elasticity or the flexibility to quickly add or reduce capacity, can greatly influence the availability of data.  These folks however were less motivated by improved security or access to the provider’s IT staff.  Their top concerns were data privacy and infrastructure control.  I do find it interesting that last year the term ‘security,’ which can encompass many things, was the primary apprehension of going to the cloud while today, it has somewhat narrowed to specifically data privacy.  That too can mean several things but areas like outsider’s physical access to systems doesn’t seem to worry IT crews as much any more.

When it comes to our school/educational system, Panda Security released a study that focused on IT security in K-12 school districts.  Like many companies, they must deal with unauthorized user access, malware outbreaks and admit that IT security is time and resource intensive.  They do believe however that the cloud can offer security benefits and improve their overall infrastructure.  91% see value in cloud solutions and are planning to implement over the next couple years with 80% saying improved security was a main reason to deploy cloud-based security.

Finally on the consumer front, GfK Business & Technology surveyed 1000 adults about cloud services and storing content in the cloud.  With all of our connected devices – cell phone, computer, tablet, etc. – there will be a greater demand to move data to the cloud.  Not real surprising, less than 10% of the consumers surveyed fully understand what the cloud actually does.  The know of it, but not what it accomplishes.  With what you don’t understand comes fear.  61% said that they were concerned about storing their data in the cloud and almost half said they would never use the cloud unless it was easy to store and retrieve data.  As businesses begin to feel content with the cloud, they then need to both educate and communicate cloud benefits to their consumers.

So it does appear like comfort with the cloud is beginning to take hold and as cloud offerings mature, especially around security, err ah, I mean data privacy solutions, the fear, uncertainty and doubt from last year is starting to loosen and it sure seems like greater adoption is on the horizon.

And one from Confucius: They must often change who would be constant in happiness or wisdom.

ps

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, cloud survey, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, October 11, 2010

CloudFucius Closes This Cloud Canon

Konfuzius-1770 Well, this is the 27th entry (26 not counting the intro) in the CloudFucius Series and what an interesting ride!  What started out as a cloud version of the 26 Short Topics about Security series, soon turned into an exploration of the numerous cloud computing surveys, reports, statistics and other feelings about the technology.  I also intended to investigate areas of cloud computing that I was not so familiar with and there were a few areas that I was able to dig further – like Radio and the NFL.  Readers really seemed to like the ‘CloudFucius’ notion and while this is the last of this series, CloudFucius is not retired.  We’ll bring him back from time to time to help decipher some of those cloud surveys.  Another interesting tid-bit is that a few weeks into the series, someone from the Pacific Northwest actually created a twitter handle @cloudfucius.  It wasn’t me but I had great interest in that, as you can imagine.  I tried contacting them several times and then within the last week or so, the account disappeared.  If you are out there, give me a shout!!  Lastly, I included a real Confucius quote in each entry since his words seem to resonate when it comes to cloud computing.

What did I learn?  While I would notice various cloud surveys during my weekly perusal of the internet, I didn’t realize that there are/were so many, so frequently.  Some weeks, literally 4-5 surveys would be released covering some aspect of cloud computing – adoption, budget, compliance, deployment, effectiveness, fears, guests, hijacking, insiders, justification, PKI, litigation, management, networks, open standards, public vs. private, questions, reliability, social media, IPv6, user experience, virtualization, gaming, control, vendors and security just to name 26.  Security is cited as the biggest hurdle in almost 90% of the surveys but I also found that availability, control and a general lack of understanding are also drivers in challenges to cloud adoption.  I also wondered if ‘security’ is the real culprit or are IT professionals just answering with that to keep the assets in-house and under their control.  I bet a little of both.  The ease of shoving stuff to the cloud has made anyone with a office cube an instant IT administrator.  That has brought challenges too.  Those who have touched the clouds, clearly see and recognize the benefits and continue to move more assets to the cloud.  Those who haven’t, are hesitant or risk averse.  And then there’s the group who are either testing or investigating ways to take advantage of the flexibility, scalability, cost savings and agility.

This final entry wouldn’t be complete without some reporting on the most recent cloud surveys.  Hubspan reported that 64% said that 'moving to the cloud for applications, infrastructure, integration and other solutions is a strategic direction for their organization and department.'  Main reasons for not moving to the cloud are lack of understanding the benefits and IT having their own way of doing things.  Finally some honesty.

CA Technologies recently found in their Mainframe - The Ultimate Cloud Platform? survey that '79% of IT organizations consider the mainframe to be an essential component of their cloud computing strategy.'  The kicker is that they are having trouble finding and retaining skilled mainframe professionals.  44% of surveyed companies said they are "grappling" with staffing issues to manage and maintain their production systems.
A new TechTarget survey of more than 800 IT pros found that SMBs are not convinced that Private Clouds are beneficial.  Virtualization Decisions 2010 survey shows that while large organizations might be building and experimenting with cloud technologies, almost two-thirds  said they have no plans to try the private cloud model.  They have enough to do and with smaller budgets, they don’t have the luxury of experimenting with  new technologies.  Also, unlike most surveys, security was not the major barrier.  The number 1 reason was that they really didn't need a couple key components – metered usage and department chargeback – 35% said so.  Complexity and skilled staff also keep them from adopting.

And just to magnify the TechTarget survey, a new Harris Interactive poll of more than 200 IT pros at large enterprises indicates a 'much broader adoption of cloud computing, and shows accelerating momentum behind developing private cloud infrastructures.'  89% said that private clouds are the next logical step for organizations already implementing virtualization.  With this one, we’re also back to citing Security as the main barrier – 91% are concerned about security issues in the public cloud, with 50 percent indicating security as the primary barrier to implementation.

So the survey results are in and more will arrive this week, next week, next month and into the foreseeable future as long as there are questions surrounding the cloud.  I do think I covered a good portion of the survey data available over the last couple months so if you need to research cloud statistics or if you missed any CloudFucius columns, here they are in order:

The CloudFucius Series
And one from Confucius: The superior man, when resting in safety, does not forget that danger may come. When in a state of security he does not forget the possibility of ruin. When all is orderly, he does not forget that disorder may come. Thus his person is not endangered, and his States and all their clans are preserved.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25

Resources:
Technorati Tags: F5, infrastructure 2.0, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, infrastructure 2.0, web, internet
twitter: @psilvas
Digg This

Wednesday, August 18, 2010

CloudFucius’ Money: Trickles to the Cloud

Konfuzius-1770 No, I’m not investing some seed money in a cool new company or technology but banks are certainly looking to take advantage of cloud computing services.  At least that’s the message from a recent survey by Bank Systems & Technology and InformationWeek Analytics.  70% of those that expressed interest in cloud computing said that the ‘Ability to meet user demands quickly and achieve scale,’ was the top consideration factor.  Among the financial services applications that are currently being deployed in the cloud, Payment Applications (23%), Core banking applications (22%) and Retail banking applications (21%) topped the list.  Mobile banking applications came in at 19% but another 19% plan to use the cloud for mobile banking and another 32% are currently evaluating the cloud for mobile applications, highest of any financial services apps.  Shows where they think future traffic will be coming from. 
chart09
As with most cloud surveys and the financial industry in general, Security along with Compliance/Audit were the top concerns.  58% said ‘cloud technology does not provide adequate security safeguards’ and one-third noted a concern about the audit trail.  We’ve mentioned here before that the financial industry usually jumps all over new technologies and is an early adopter for many things tech.  No so with Cloud.  38% said that Cloud technology is too new and untested.
chart05
Another interesting factor that is inhibiting cloud adoption is legacy systems.  Most of the current banking applications were written for in-house systems and servers and have not been made ‘cloud-aware’ or ‘cloud-enabled.’  They face a tough choice to either invest now to make those apps ‘cloud-ready’ or wait until cloud vendors have matured and resolved some of the concerns.  Yet another issue is spreading the IT mess, according to Ovum senior analyst Laurent Lachal.  Today, many banking systems are in a secure data center (or several with GSLB) or located in-house.  IT knows which room the data resides rather than somewhere, anywhere out in vapor land.  The problem occurs when another department uses a cloud service without IT’s knowledge and the mess that creates across boundaries.  The integration headache occurs when the same workflow is being done by two different applications.  Cost effectiveness gets negated by inefficiencies.
I started thinking about the future of banking and giving the customer the choice of having their data stored in the cloud or on a dedicated, physical server.  There is not much we could do if our financial institution decided to put sensitive data in the cloud and I’m sure some of it is there already.  But for those many folks who are not comfortable with that (at least for now), I wondered if the ‘dedicated server’ will become the ‘ultra-premium’ service of the future.  It’s kinda far-fetched but go with me on this – maybe, when you open a bank account of the future, you get the choice of having your data in the cloud (get free checking with that, if checks are even still around) or you select a dedicated server for a nominal monthly fee.  The promotion could go something like: ‘In order to provide you with the most cost effective banking solutions, we have two options for your data storage – a secured cloud environment with our trusted cloud provider (free with any account) or a dedicated physical server housed in our data center (for a small monthly fee).  All the security protections and guarantees are built into both options, but we feel that it’s important that you choose and know where we store your data.’  Now, that would be interesting.
And one from Confucius: By nature, men are nearly alike; by practice, they get to be wide apart.
ps
The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17
Related:
Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet
twitter: @psilvas
Digg This

Wednesday, July 28, 2010

CloudFucius Investigates: The Comeback Cloud

Konfuzius-1770 Not that it was ever down and out, but the whole cloud computing concept has gotten off to a grand but challenging start.  It was all the rage when first ‘conceived’ as the new way of hosting applications with the promise of cost savings, automation, flexible/dynamic architectures, fast and repeatable deployment and a pay-as-you-go model.  The Coin Operated Cloud but with very little understanding of all the buttons, functions and risks.  As IT started to comprehend the nuances of the cloud, then some very serious questions regarding it’s ability to protect and secure information came to light.  This arrived at a time when the economic downturn could have vaulted the shared, less expensive infrastructure offerings to the top of any IT list since budgets were tight and resources scarce.  It was the perfect storm of tight budgets and cost effective computing.  However, the risk of data loss kept folks questioning the viability of putting sensitive data in the cloud.  Plus, no consent on standards kept the mix of cloud offerings all over the place while limiting the customer’s ability to mix and match.

As cloud offerings matured and *some* security concerns addressed along with IT having a better grasp on risks and mitigation, the cloud is gradually becoming more attractive to enterprises.  Like anything else that suddenly bursts on to the scene, the hype outweighs the reality and it takes time to fully understand and realize the benefits.

It seems that almost weekly a shiny new cloud computing survey is released and this week, Vanson Bourne (commissioned by Savvis) released a report that ties cloud computing to the economic recovery.  Specifically, ‘68 percent of respondents said cloud computing will help their businesses recover from the recession.’  The survey found that 54% of respondents said cost cutting and more flexible IT provisioning is the biggest issue they face and they are optimistic with the prospect that cloud computing can cut costs.  A significant number of IT decision makers, 96%, said they are as confident or more confident than they were last year that cloud computing is enterprise ready.  Yankee Group also released a report that says cloud computing is on the cusp of broad enterprise adoption.  They also indicate that the concept of cloud computing as a business enabler has jumped from 37% to 60% of respondents in just a year. 

But can cloud computing save the economy? 

That’s a stretch, according to David Linthicum in this article.  The logic goes, if companies can save money with cloud computing and are more optimistic about the prospect of cloud computing, then they will start spending IT dollars for cloud deployments.  This will, in turn, boost the cloud economy since providers will have to prepare and hire for the influx of customers.  Since accelerated growth would occur, that would attract public and private investments in cloud computing technologies.  The ‘catalyst,’ as Linthicum notes, is to get more investment dollars back into the technology industry, which should fuel the tech economy at least.  Betting that cloud computing will turn the entire economy is a huge long-shot and unrealistic.  The survey also revealed that even with all that confidence, security remains as the key adoption barrier.  52% of those who do not use cloud computing said ‘security of sensitive data’ as a top concern.

In a slightly related story, LimeWire Planning A Serious, Cloud-Based Comeback

And one from Confucius: And remember, no matter where you go, there you are.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet, openstack

twitter: @psilvas

Digg This

Wednesday, July 14, 2010

CloudFucius Tunes into Radio KCloud

Konfuzius-1770 Set the dial and rip it off – all the hits from the 70s, 80s, 90s and beyond – you’re listening to the K-Cloud.  We got The Puffy & Fluffy Show to get you going in the morning, Cumulous takes you through midday with lunchtime legion, Mist and Haze get you home with 5 o’clock funnies and drive-time traffic while Vapor billows overnight for all you insomniacs.  K-Cloud; Radio Everywhere.

I came across this article which discusses Radio’s analogue to digital transition and it’s slow but eventual move to cloud computing.  How ‘Embracing cloud computing requires a complete rethinking of the design, operation and planning of a station’s data center.’  Industries like utilities, technology, insurance, government and others are already using the cloud while the broadcast community is just starting it’s exploration, according to Tom Vernon, a long-time contributor to Radio World. 

Like many of you, I grew up listening to the radio (music, I’m not that old) and still have a bunch of hole-punched record albums for being the 94th caller.  I listened to WHJY (94-HJY) in Providence and still remember the day in 1981 when it switched from JOY, a soft, classical station to Album-Orientated Rock.  Yes, I loved the hair-metal, arena rock, new wave, pop and most what they now call classic rock.  It’s weird remembering ‘Emotional Rescue’ and ‘Love Rollercoaster’ playing on the radio as Top 40 hits and now they are considered ‘classics.’   Um, what am I then?!? 

That article prompted me to explore the industries that have not embraced the cloud, and why.  Risk adverse industries immediately come to mind, like financial and health care.  There have been somewhat contradictory stories and surveys recently indicating both that, they are hesitant to adopt the cloud and ready to embrace the cloud.  A survey by LogLogic says that 60% of the financial services sector felt that cloud computing was not a priority or they were risk-averse to cloud computing.  This is generally an industry that historically has been an early adopter of new technologies.  The survey indicates that they will be spending IT dollars on ‘essential’ needs and that security questions and data governance concerns is what’s holding them back from cloud adoption.

About a week later, results from a survey done by The Securities Industry and Financial Markets Association (SIFMA) and IBM reports that there is now a strong interest in cloud computing after a couple years of reluctance.  The delay was due to the cost of implementing new technologies and the lack of talent needed to mange those systems.  Security is not the barrier that it once was since their cloud strategies include security ramifications.  They better understand the security risks and calculate that into their deployment models.  This InformationWeek.com story says that the financial services industry is indeed interested in cloud computing, as long as it’s a Private Cloud.  The one’s behind the corporate firewall, not Public floaters.  And that security was not the real issue, regulations and compliance with international border laws were the real holdback.

In the healthcare sector, according to yet another survey,  Accenture says that 73% said they are planning cloud movements while nearly one-third already have deployed cloud environments.  This story also says that ‘healthcare firms are beginning to realize that cloud providers actually may offer more robust security than is available in-house.’ 

Is there a contradiction?  Maybe.  More, I think it shows natural human behavior and progression when facing fears.  If you don’t understand something and there is a significant risk involved we’ll generally say, ‘no thanks’ to preserve our safety and security.  As the dilemma is better understood and some of the fears are either addressed or accounted for, the threat level is reduced and progress can be made.  This time around, while there are still concerns, we are more likely to give it a try since we know what to expect.  A risk assessment exercise gives us the tools to manage the fears.  Maybe the threat is high but the potential of it occurring is low or the risk is medium but we now know how to handle it.  It’s almost like jumping out of a plane.  If you’ve never done it, that first 3000ft tethered leap can be freighting – jumping at that height, hoping a huge piece of fabric will hold and glide you to a safe landing on the ground.  But once you’ve been through training, practiced it a few times, understand how to deploy your backup ‘chute and realize the odds are in your favor, then it’s not so daunting.  This may be what’s happening with risk averse industries and cloud computing.  Initially, the concerns, lack of understanding, lack of visibility, lack of maturity, lack of control, lack of security mechanisms and their overall fear kept these entities away, even with the lure of flexibility and potential cost savings.  Now that there is a better understanding of what types of security solutions a cloud provider can and cannot offer along with the knowledge of how to address specific security concerns, it’s not so scary any more.

Incidentally, I had initially used KCLD and WCLD for my cloud stations until I realized that they were already taken by real radio stations out of Minnesota and Mississippi.

And one from Confucius: Everything has its beauty but not everyone sees it.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12

Related:

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet

twitter: @psilvas

Digg This

Thursday, June 10, 2010

Connecting to a Cloud while Flying thru the Clouds

Konfuzius-1770 CloudFucius checked out some In-flight WiFi this week while traveling to Seattle.  Alaska Air offers GoGo Inflight Internet on their 737 fleet flying the 48 contiguous for $4.95, but the service is free through July 2010.  An instruction card is located in the magazine pouch located in front of your seat and after the climb to 10,000 ft, you can connect with your WiFi enabled device.  The setup is simple: 1. Turn on WiFi; 2. Find ‘gogoinflight’ signal (which happens to be the only one found at 10,000 ft); 3. Launch browser and log in.  You do need to create an account, if you haven’t already, and fill out a couple pages of info – not at all cumbersome.  We got connected fairly easily and quickly without any issues.  We even got connected to F5’s corporate VPN and was able to open Outlook and download any new email along with anything else I usually do while working remotely.  The signal was strong and the speed was usable.  There have been a couple articles about the latency and performance challenges of these cellular connections once more than a few fliers connect.  Limited number of power ports on planes might also discourage flyers, especially on long flights.  Plus, according to this article, ‘Of the 230 respondents who guide corporate travel policy within their organizations, only 34 percent said it's OK for travelers to unsheathe their corporate cards to access Wi-Fi on all flights.’   The Business Travel News survey found that only 7% would reimburse in-flight internet access and only on very long flights.  I usually use business air travel time to rest, play a game on the handheld, read and other relaxing activities but Internet-in-the-Sky does allow the classic road-warrior to stay productive, procrastinators to complete tasks and personal travelers to surf the web. 

Internet on a Plane got me thinking about the security implications of connecting while looking down at actual clouds.  Certainly, you need to be aware of all the usual cautions and risks while connected to a typical open, unencrypted WiFi signal like protecting both your privacy and computer.  Use a VPN if you have access to one, encrypt file transfers, enable your firewall & antivirus, ensure OS patches are up to date and disable any file shares. 

In-air Internet does pose some new threats. 

gogo Over the shoulder eavesdropping is certainly a concern.  Who hasn’t snuck a peek, glanced or outright watched the row in front, through the 2 inch seat separation either out of boredom or nosiness?  While viewing someone edit a corporate PowerPoint isn’t that much of a threat; being able to see emails, VPN credentials or an internal web application URL and log in info being typed in, certainly is a risk.  Call it back seat key logging.  Forget about malware, I’ll watch and jot down what they type.  I found myself feeling a little anxious as I entered the small bit of sensitive information required to create the GoGo account.  Seeing the screen is also a concern and do believe there will be an uptick in privacy filters that protect computer screens from unwanted eyes.  Protecting data in public places is hard enough, but in a cramped airplane there is almost no privacy and you really can’t just get up and leave.   I’ve never been one who favored ‘save password’ but in this instance, having auto-filled asterisks instead of typing it in public is a good idea. 

Heightened awareness of the evolving business travel risks should be reiterated often to all employees.

And one from Confucius: The superior man, when resting in safety, does not forget that danger may come. When in a state of security he does not forget the possibility of ruin. When all is orderly, he does not forget that disorder may come. Thus his person is not endangered, and his States and all their clans are preserved.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog
twitter: @psilvas
Digg This

Tuesday, June 1, 2010

CloudFucius Shares: Cloud Research and Stats

Konfuzius-1770 Sharing is caring, according to some and with the shortened week, CloudFucius decided to share some resources he’s come across during his Cloud exploration in this abbreviated post.  A few are aged just to give a perspective of what was predicted and written about over time.

Some Interesting Cloud Computing Statistics (2008)

Mobile Cloud Computing Subscribers to Total Nearly One Billion by 2014 (2009)

Server, Desktop Virtualization To Skyrocket By 2013: Report (2009)

Gartner: Brace yourself for cloud computing (2009)

A Berkeley View Of Cloud Computing : An Analysis – the good, the bad and the ugly (2009)

Cloud computing belongs on your three-year roadmap (2009)

Twenty-One Experts Define Cloud Computing (2009)

5 cool cloud computing research projects (2009)

Research Clouds (2010)

Cloud Computing Growth Forecast (2010)

Cloud Computing and Security - Statistics Center (2010)

Cloud Computing Experts Reveal Top 5 Applications for 2010 (2010)

List of Cloud Platforms, Providers, and Enablers 2010 (2010)

The Cloud Computing Opportunity by the Numbers (2010)

Governance grows more integral to managing cloud computing security risks, says survey (2010)

The Cloud Market EC2 Statistics (2010)

Experts believe cloud computing will enhance disaster management (2010)

Cloud Computing Podcast (2010)

Security experts ponder the cost of cloud computing (2010)

Cloud Computing Research from Business Exchange (2010)

Just how green is cloud computing? (2010)

Senior Analyst Guides Investors Through Cloud Computing Sector And Gives His Top Stock Winners (2010)

Towards Understanding Cloud Performance Tradeoffs Using Statistical Workload Analysis and Replay (2010)

…along with F5’s own Lori MacVittie who writes about this stuff daily.

And one from Confucius: Study the past if you would define the future.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Wednesday, May 26, 2010

CloudFucius Listens: F5’s Cloud Computing Solutions

Konfuzius-1770 About a month ago, CloudFucius Hollered about F5’s On-Demand IT solutions which offers a holistic approach to enable a common cloud architectural model—regardless of where IT resources actually reside.  That post contained links to the various whitepapers specifically covering F5’s Cloud Computing Solutions which were designed to unleash the true potential of virtualization and cloud computing.  It’s a comprehensive approach that integrates disparate technologies for application delivery, security, optimization, data management, and infrastructure control—all critical technologies needed to realize the true flexibility and agility of virtualization and cloud computing solutions.  CloudFucius is now excited to announce the availability of those whitepapers in audio format. 

For your listening pleasure:

Audio White Paper - The F5 Powered Cloud - How F5 solutions power a cloud computing architecture capable of delivering highly-available, secure, and optimized on-demand application services.  Read the full pdf of the whitepaper here.

Audio White Paper - The Optimized and Accelerated Cloud - As more organizations begin moving applications into the cloud, congestion will become an increasingly critical issue. F5 offers solutions for optimizing and accelerating applications in the cloud, making them fast and available wherever they reside.  Read the full pdf of the whitepaper here.

Audio White Paper - Securing the Cloud - Cloud computing has become another key resource for IT deployments, but there is still fear of securing applications and data in the cloud. With F5 devices, you can keep your most precious assets safe, no matter where they live.  Read the full pdf of the whitepaper here

Audio White Paper - Cloud Balancing: The Evolution of Global Server Load Balancing - Cloud balancing evolves global server load balancing from traditional routing options based on static data to context aware distribution across cloud-based services.  Read the full pdf of the whitepaper here.

Audio White Paper - Availability and the Cloud - Cloud computing offers IT another tool to deliver applications. While enticing, challenges still exist in making sure the application is always available. F5’s flexible, unified solutions ensure high availability for cloud deployments.  Read the full pdf of the whitepaper here

And one from Confucius: Learning without thought is labor lost; thought without learning is perilous.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Tuesday, May 25, 2010

CloudFucius Combines: Security and Acceleration

Konfuzius-1770 CloudFucius has explored Cloud Security with AAA Important to the Cloud and Hosts in the Cloud along with wanting An Optimized Cloud.  Now he desires the sweet spot of Cloud Application Delivery combining Security and Acceleration.  Few vendors want to admit that adding a web application security solution can also add latency, which can be kryptonite for websites.  No website, cloud or otherwise, wants to add any delay to users’ interaction.  Web application security that also delivers blazing fast websites might sound like an oxymoron, but not to CloudFucius.  And in light of Lori MacVittie’s Get your SaaS off my cloud and the accompanying dramatic reading of, I’m speaking of IaaS and PaaS cloud deployments, where the customer has some control over the applications, software and systems deployed.

It’s like the old Reese’s peanut butter cups commercial, ”You’ve stuck your security in our acceleration.”  “Yeah, well your acceleration has broken our security.”  Securing applications and preventing attacks while simultaneously ensuring consistent, rapid user response, is a basic web application requirement.  Yet web application security traditionally comes at the expense of speed.  This is an especially important issue for online retailers, where slow performance can mean millions of dollars in lost revenue and a security breach can be just as devastating as more than 70 percent of consumers say they would no longer do business with a company that exposed their sensitive information.

Web application performance in the cloud is also critical for corporate operations, particularly for remote workers, where slow access to enterprise applications can destroy productivity.  As more applications are being delivered through a standard browser from the cloud, the challenge of accelerating web applications without compromising security grows.  This has usually required multiple dedicated units either from the customer or provider, along with staff to properly configure and manage them.  Because each of these “extra” devices has its own way of proxying transactions, packets can slow to a crawl due to the extra overhead of TCP and application processing.  Fast and secure in a single, individually wrapped unit does seem like two contrary goals.

The Security Half
As the cloud has evolved, so have security issues.  And as more companies become comfortable deploying critical systems in the cloud, solutions like web application firewalls are a requirement, particularly for regulatory compliance situations.  Plus, as the workforce becomes more mobile, applications need to be available in more places and on more devices, adding to the complexity of enforcing security without impacting productivity.  Consider that a few years back, the browser’s main purpose was to surf the net.  Today, browser usage is a daily tool for both personal and professional needs.  In addition to the usual web application activities like ordering supplies, checking traffic, and booking travel, we also submit more private data like health details and payroll information.  The browser acts as a secret confidant in many areas of our lives since it transmits highly sensitive data in both our work and social spheres.  And it goes both ways; while other people, providers, sites, and systems have our sensitive data, we may also be carrying someone else’s sensitive data on our own machines.  Today, the Could and really the Internet at large is more than a function of paying bills or getting our jobs done—it holds our digital identity for both work and play.  And once a digital identity is out there, there’s no retracting it.  We just hope there are proper controls in place to keep it secret and safe.

The Acceleration Half
For retail web applications and search engines, downtime or poor performance can mean lost revenue along with significant, tangible costs.  A couple years ago, the Warwick Business School published research that showed it can be more than $500,000 in lost revenue for an unplanned outage lasting just an hour.  For financial institutions, the loss can be in the several million dollar range.  And downtime costs more than just lost revenue.  Not adhering to a service level agreement can incur remediation costs or penalties and non-compliance with certain regulatory laws can result in fines.  Additionally, the damage to a company’s brand reputation—whether it’s from an outage, poor performance, or breach—can have long-lasting, detrimental effects to the company.

These days, many people now have high-speed connections to the home accessing applications in the cloud.  But applications have matured and now offer users pipe-clogging rich data like video and other multi-media.  If the website is slow, users will probably go somewhere else.  It happens all the time.  You type in a URL only to watch the browser icon spin and spin. You might try to reload or retype, but more often, you simply type a different URL to a similar site.  With an e-commerce site, poor performance usually means a lost sale because you probably won’t wait around if your cart doesn’t load quickly or stalls during the secure check-out process.  If it’s a business application and you’re stuck with a sluggish site, then that’s lost productivity, a frustrated user and can result in a time-consuming trouble ticket for IT.  When application performance suffers, the business suffers.

What’s the big deal?
Typically, securing an application can come at the cost of end-user productivity because of deployment complexity.  Implementing website security—like a web application firewall—adds yet another mediation point where the traffic between the client and the application is examined and processed.   This naturally increases the latency of the application especially in the cloud, since the traffic might have to make multiple trips.  This can become painfully apparent with globally disbursed users or metered bandwidth agreements but the solution is not always simple. Web application performance and security administration can cross organizational structures within companies, making ownership splintered and ambiguous.  Add a cloud provider to the mix and the finger pointing can look like Harry Nilsson's The Point! (Oh how I love pulling out obscure childhood references in my blogs!!)

The Sweet Spot
Fortunately, you can integrate security and acceleration into a single device with BIG-IP Local Traffic Manager (LTM) and the BIG-IP LTM Virtual Edition (VE).  By adding the BIG-IP Application Security Manager (ASM) module and the BIG-IP WebAccelerator module to BIG-IP LTM, not only are you able to deliver web application security and acceleration, but the combination provides faster cloud deployment and simplifies the process of managing and deploying web applications in the cloud.  This is a true, internal system integration and not just co-deployment of multiple proxies on the same device.  These integrated components provide the means to both secure and accelerate your web applications with ease.  The unified security and web application acceleration takes a single platform approach that receives, examines, and acts upon application traffic as a single operation, in the shortest possible time and with the least complexity. The management GUI allows varying levels of access to system administrators according to their roles.  This ensures that administrators have appropriate management access without granting them access to restricted, role-specific management functions.  Cloud providers can segment customers, customers can segment departments.

The single-platform integration of these functions means that BIG-IP can share context between security and acceleration—something you don’t get with multiple units and enables both the security side and the acceleration side to make intelligent, real-time decisions for delivering applications from your cloud infrastructure.  You can deploy and manage a highly available, very secure, and incredibly fast cloud infrastructure all from the same unified platform that minimizes WAN bandwidth utilization, safeguards web applications, and prevents data leakage, all while directing traffic to the application server best able to service a request.  Using the unified web application security and acceleration solution, a single proxy secures, accelerates, optimizes, and ensures application availability for all your cloud applications.

And one from Confucius: He who will not economize will have to agonize.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6

Related:
Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog, law
twitter: @psilvas
Digg This