Showing posts with label confucius. Show all posts
Showing posts with label confucius. Show all posts

Monday, October 11, 2010

CloudFucius Closes This Cloud Canon

Konfuzius-1770 Well, this is the 27th entry (26 not counting the intro) in the CloudFucius Series and what an interesting ride!  What started out as a cloud version of the 26 Short Topics about Security series, soon turned into an exploration of the numerous cloud computing surveys, reports, statistics and other feelings about the technology.  I also intended to investigate areas of cloud computing that I was not so familiar with and there were a few areas that I was able to dig further – like Radio and the NFL.  Readers really seemed to like the ‘CloudFucius’ notion and while this is the last of this series, CloudFucius is not retired.  We’ll bring him back from time to time to help decipher some of those cloud surveys.  Another interesting tid-bit is that a few weeks into the series, someone from the Pacific Northwest actually created a twitter handle @cloudfucius.  It wasn’t me but I had great interest in that, as you can imagine.  I tried contacting them several times and then within the last week or so, the account disappeared.  If you are out there, give me a shout!!  Lastly, I included a real Confucius quote in each entry since his words seem to resonate when it comes to cloud computing.

What did I learn?  While I would notice various cloud surveys during my weekly perusal of the internet, I didn’t realize that there are/were so many, so frequently.  Some weeks, literally 4-5 surveys would be released covering some aspect of cloud computing – adoption, budget, compliance, deployment, effectiveness, fears, guests, hijacking, insiders, justification, PKI, litigation, management, networks, open standards, public vs. private, questions, reliability, social media, IPv6, user experience, virtualization, gaming, control, vendors and security just to name 26.  Security is cited as the biggest hurdle in almost 90% of the surveys but I also found that availability, control and a general lack of understanding are also drivers in challenges to cloud adoption.  I also wondered if ‘security’ is the real culprit or are IT professionals just answering with that to keep the assets in-house and under their control.  I bet a little of both.  The ease of shoving stuff to the cloud has made anyone with a office cube an instant IT administrator.  That has brought challenges too.  Those who have touched the clouds, clearly see and recognize the benefits and continue to move more assets to the cloud.  Those who haven’t, are hesitant or risk averse.  And then there’s the group who are either testing or investigating ways to take advantage of the flexibility, scalability, cost savings and agility.

This final entry wouldn’t be complete without some reporting on the most recent cloud surveys.  Hubspan reported that 64% said that 'moving to the cloud for applications, infrastructure, integration and other solutions is a strategic direction for their organization and department.'  Main reasons for not moving to the cloud are lack of understanding the benefits and IT having their own way of doing things.  Finally some honesty.

CA Technologies recently found in their Mainframe - The Ultimate Cloud Platform? survey that '79% of IT organizations consider the mainframe to be an essential component of their cloud computing strategy.'  The kicker is that they are having trouble finding and retaining skilled mainframe professionals.  44% of surveyed companies said they are "grappling" with staffing issues to manage and maintain their production systems.
A new TechTarget survey of more than 800 IT pros found that SMBs are not convinced that Private Clouds are beneficial.  Virtualization Decisions 2010 survey shows that while large organizations might be building and experimenting with cloud technologies, almost two-thirds  said they have no plans to try the private cloud model.  They have enough to do and with smaller budgets, they don’t have the luxury of experimenting with  new technologies.  Also, unlike most surveys, security was not the major barrier.  The number 1 reason was that they really didn't need a couple key components – metered usage and department chargeback – 35% said so.  Complexity and skilled staff also keep them from adopting.

And just to magnify the TechTarget survey, a new Harris Interactive poll of more than 200 IT pros at large enterprises indicates a 'much broader adoption of cloud computing, and shows accelerating momentum behind developing private cloud infrastructures.'  89% said that private clouds are the next logical step for organizations already implementing virtualization.  With this one, we’re also back to citing Security as the main barrier – 91% are concerned about security issues in the public cloud, with 50 percent indicating security as the primary barrier to implementation.

So the survey results are in and more will arrive this week, next week, next month and into the foreseeable future as long as there are questions surrounding the cloud.  I do think I covered a good portion of the survey data available over the last couple months so if you need to research cloud statistics or if you missed any CloudFucius columns, here they are in order:

The CloudFucius Series
And one from Confucius: The superior man, when resting in safety, does not forget that danger may come. When in a state of security he does not forget the possibility of ruin. When all is orderly, he does not forget that disorder may come. Thus his person is not endangered, and his States and all their clans are preserved.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25

Resources:
Technorati Tags: F5, infrastructure 2.0, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, infrastructure 2.0, web, internet
twitter: @psilvas
Digg This

Wednesday, May 26, 2010

CloudFucius Listens: F5’s Cloud Computing Solutions

Konfuzius-1770 About a month ago, CloudFucius Hollered about F5’s On-Demand IT solutions which offers a holistic approach to enable a common cloud architectural model—regardless of where IT resources actually reside.  That post contained links to the various whitepapers specifically covering F5’s Cloud Computing Solutions which were designed to unleash the true potential of virtualization and cloud computing.  It’s a comprehensive approach that integrates disparate technologies for application delivery, security, optimization, data management, and infrastructure control—all critical technologies needed to realize the true flexibility and agility of virtualization and cloud computing solutions.  CloudFucius is now excited to announce the availability of those whitepapers in audio format. 

For your listening pleasure:

Audio White Paper - The F5 Powered Cloud - How F5 solutions power a cloud computing architecture capable of delivering highly-available, secure, and optimized on-demand application services.  Read the full pdf of the whitepaper here.

Audio White Paper - The Optimized and Accelerated Cloud - As more organizations begin moving applications into the cloud, congestion will become an increasingly critical issue. F5 offers solutions for optimizing and accelerating applications in the cloud, making them fast and available wherever they reside.  Read the full pdf of the whitepaper here.

Audio White Paper - Securing the Cloud - Cloud computing has become another key resource for IT deployments, but there is still fear of securing applications and data in the cloud. With F5 devices, you can keep your most precious assets safe, no matter where they live.  Read the full pdf of the whitepaper here

Audio White Paper - Cloud Balancing: The Evolution of Global Server Load Balancing - Cloud balancing evolves global server load balancing from traditional routing options based on static data to context aware distribution across cloud-based services.  Read the full pdf of the whitepaper here.

Audio White Paper - Availability and the Cloud - Cloud computing offers IT another tool to deliver applications. While enticing, challenges still exist in making sure the application is always available. F5’s flexible, unified solutions ensure high availability for cloud deployments.  Read the full pdf of the whitepaper here

And one from Confucius: Learning without thought is labor lost; thought without learning is perilous.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Wednesday, May 5, 2010

CloudFucius Ponders: High-Availability in the Cloud

Konfuzius-1770 According to Gartner, “By 2012, 20 percent of businesses will own no IT assets.”  While the need for hardware will not disappear completely, hardware ownership is going through a transition: Virtualization, total cost of ownership (TCO) benefits, an openness to allow users run their personal machines on corporate networks, and the advent of cloud computing are all driving the movement to reduce hardware assets.  Cloud computing offers the ability to deliver critical business applications, systems, and services around the world with a high degree of availability, which enables a more productive workforce.  No matter which cloud service — IaaS, PaaS, or SaaS (or combination thereof) — a customer or service provider chooses, the availability of that service to users is paramount, especially if service level agreements (SLAs) are part of the contract.  Even with a huge cost savings, there is no benefit for either the user or business if an application or infrastructure component is unavailable or slow.

As hype about the cloud has turned into the opportunity for cost savings, operational efficiency, and IT agility, organizations are discussing, testing, and deploying some form of cloud computing.  Many IT departments initially moved to the cloud with non-critical applications and, after experiencing positive results and watching cloud computing quickly mature, are starting to move their business critical applications, enabling business units and IT departments to focus on the services and workflows that best serve the business.  Since the driver for any cloud deployment, regardless of model or location, is to deliver applications in the most efficient, agile, and secure way possible, the dynamic control plane of cloud architecture requires the capability to intercept, interpret, and instruct where the data must go and must have the necessary infrastructure, at strategic points of control, to enable quick, intelligent decisions and ensure consistent availability.

The on-demand, elastic, scalable, and customizable nature of the cloud must be considered when deploying cloud architectures.  Many different customers might be accessing the same back-end applications, but each customer has the expectation that only their application will be properly delivered to users.  Making sure that multiple instances of the same application are delivered in a scalable manner requires both load balancing and some form of server virtualization. An Application Delivery Controller (ADC) can virtualize back-end systems and can integrate deeply with the network and application servers to ensure the highest availability of a requested resource.  Each request is inspected using any number of metrics and then routed to the best available server.  Knowing how an ADC can enhance your application delivery architecture is essential prior to deployment. Many applications have stellar performance during the testing phase, only to fall apart when they are live. By adding a Virtual ADC to your development infrastructure, you can build, test and deploy your code with ADC enhancements from the start.

With an ADC, load balancing is just the foundation of what can be accomplished.  In application delivery architectures, additional elements such as caching, compression, rate shaping, authentication, and other customizable functionality, can be combined to provide a rich, agile, secure and highly available cloud infrastructure.  Scalability is also important in the cloud and being able to bring up or take down application instances seamlessly — as needed and without IT intervention — helps to prevent unnecessary costs if you’ve contracted a “pay as you go” cloud model.  An ADC can also isolate management and configuration functions to control cloud infrastructure access and keep network traffic separate to ensure segregation of customer environments and the security of the information.  The ability of an ADC to recognize network and application conditions contextually in real-time, as well as its ability to determine the best resource to deliver the request, ensures the availability of applications delivered from the cloud.

Availability is crucial; however, unless applications in the cloud are delivered without delay, especially when traveling over latency-sensitive connections, users will be frustrated waiting for “available” resources.  Additional cloud deployment scenarios like disaster recovery or seasonal web traffic surges might require a global server load balancer added to the architecture.  A Global ADC uses application awareness, geolocation, and network condition information to route requests to the cloud infrastructure that will respond best and using the geolocation of users based on IP address, you can route the user to the closest cloud or data center.  In extreme situations, such as a data center outage, a Global ADC will already know if a user’s primary location is unavailable and it will automatically route the user to the responding location.

Cloud computing, while still evolving in all its iterations, can offer IT a powerful alternative for efficient application, infrastructure, and platform delivery.  As businesses continue to embrace the cloud as an advantageous application delivery option, the basics are still the same: scalability, flexibility, and availability to enable a more agile infrastructure, faster time-to-market, a more productive workforce, and a lower TCO along with happier users.

And one from Confucius: The man of virtue makes the difficulty to be overcome his first business, and success only a subsequent consideration.

ps

The CloudFucius Series: Intro, 1, 2, 3

Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

twitter: @psilvas

Digg This

Tuesday, April 27, 2010

CloudFucius Hollers: Read All About, F5’s On-Demand IT

Yesterday F5 announced a holistic approach to enable a common cloud architectural model—regardless of where IT resources actually reside.  Unifying Application Delivery, Access Control and Optimization to the cloud along with ongoing collaboration with technology partners like Microsoft, VMware, and Gomez, enables enterprises and service providers to realize the potential of ‘On-Demand IT’ through a dynamic services model.  There is a lot of information on this and wanted to share some of the technical whitepapers available for this solution.
The F5 Powered Cloud
How F5 solutions power a cloud computing architecture capable of delivering highly-available, secure, and optimized on-demand application services.
The Optimized and Accelerated Cloud
As more organizations begin moving applications into the cloud, congestion will become an increasingly critical issue. F5 offers solutions for optimizing and accelerating applications in the cloud, making them fast and available wherever they reside.
Availability and the Cloud
Cloud computing offers IT another tool to deliver applications. While enticing, challenges still exist in making sure the application is always available. F5’s flexible, unified solutions ensure high availability for cloud deployments.
Securing the Cloud
Cloud computing has become another key resource for IT deployments, but there is still fear of securing applications and data in the cloud. With F5 devices, you can keep your most precious assets safe, no matter where they live.
Cloud Balancing: The Evolution of Global Server Load Balancing
Cloud balancing evolves global server load balancing from traditional routing options based on static data to context aware distribution across cloud-based services.

F5 Cloud Computing Solutions

And one from Confucius himself: Go before the people with your example, and be laborious in their affairs.

The CloudFucius Series: Intro, 1, 2
ps
Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog
Digg This

Wednesday, April 21, 2010

CloudFucius Wonders: Can Cloud, Confidentiality and The Constitution Coexist?

This question has been puzzling a few folks of late, not just CloudFucius.  The Judicial/legal side of the internet seems to have gotten some attention lately even though courts have been trying to make sense and catch up with technology for some time, probably since the Electronic Communications Privacy Act of 1986.  There are many issues involved here but a couple stand out for CloudFucius.

First, there is the ‘Privacy vs. Convenience’ dilemma.  Many love and often need the GPS Navigators whether it be a permanent unit in the vehicle or right from our handheld device to get where we need to go.  These services are most beneficial when searching for a destination but it is also a ‘tracking bug’ in that, it records every movement we make.  This has certainly been beneficial in many industries like trucking, delivery, automotive, retail and many others, even with some legal issues.  It has helped locate people during emergencies and disasters.  It has also helped in geo-tagging photographs.  But, we do give up a lot of privacy, secrecy and confidentiality when using many of the technologies designed to make our lives ‘easier.’ 
Americans have a rather tortured relationship with privacy. They often say one thing ("Privacy is important to me") but do another ("Sure, thanks for the coupon, here's my Social Security Number") noted Lee Rainie, head of the Pew Internet and American Life Project. From: The Constitutional issues of cloud computing
You might not want anyone knowing where you are going but by simply using a navigation system to get to your undisclosed location, someone can track you down.  Often, you don’t even need to be in navigation mode to be tracked – just having GPS enabled can leave breadcrumbs.  Don’t forget, even the most miniscule trips to the gas station can still contain valuable data….to someone.  How do you know if your milk runs to the 7-Eleven aren’t being gathered and analyzed?  At the same, where is that data stored, who has access and how is it being used?  I use GPS when I need it and I’m not suggesting dumping it, just wondering.  Found a story where Mobile Coupons are being offered to your phone.  Depending on your GPS location, they can send you a coupon for a nearby merchant along with this one about Location-Based strategies.

Second, is the Fourth Amendment in the digital age.  In the United States, the 4th Amendment protects against unreasonable searches and seizures.  Law enforcement needs to convince a judge that a serious crime has/is occurring to obtain a warrant prior to taking evidence from a physical location, like your home.  It focuses on physical possessions and space.  For instance, if you are committing crimes, you can place your devious plans in a safe hidden in your bedroom and law enforcement needs to present a search warrant before searching your home for such documents.  But what happens if you decide to store your ‘Get rich quick scheme’ planning document in the cloud?  Are you still protected?  Can you expect certain procedures to be followed before that document is accessed?  The Computer Crime & Intellectual Property Section of the US Dept of Justice site states:
To determine whether an individual has a reasonable expectation of privacy in information stored in a computer, it helps to treat the computer like a closed container such as a briefcase or file cabinet. The Fourth Amendment generally prohibits law enforcement from accessing and viewing information stored in a computer if it would be prohibited from opening a closed container and examining its contents in the same situation….Although courts have generally agreed that electronic storage devices can be analogized to closed containers, they have reached differing conclusions about whether a computer or other storage device should be classified as a single closed container or whether each individual file stored within a computer or storage device should be treated as a separate closed container.
But, you might lose that Fourth Amendment right when you give control to a third party, such as a cloud provider.  Imagine you wrote a play about terrorism and used a cloud service to store your document.  Maybe there were some ‘surveillance’ keywords or triggers used as character lines.  Maybe there is scene at a transportation hub (train, airport, etc) and characters themselves say things that could be taken as domestic threats – out of context of course.  You should have some expectation that your literary work is kept just as safe/secure while in the cloud as it is on your powered down hard drive or stack of papers on your desk.  And we haven’t even touched on compliance, records retention, computer forensics, data recovery and many other litigating issues.  The cases continue to play out and this blog entry only covers a couple of the challenges associated with Cloud Computing and the Law, but CloudFucius will keep an eye on it for ya.
Many of the articles found while researching this topic:
Finally, you might be wondering why CloudFucius went from A to C in his series.  Well, this time we decided to jump around but still cover 26 interesting topics.
And one from Confucius himself: I am not one who was born in the possession of knowledge; I am one who is fond of antiquity, and earnest in seeking it there.

ps

The CloudFucius Series: Intro, 1
Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog, law

twitter: @psilvas

Tuesday, April 13, 2010

CloudFucius Says: AAA Important to Cloud

Konfuzius-1770 While companies certainly see a business benefit to a pay-as-you-go model for computing resources, security concerns seem always to appear at the top of surveys regarding cloud computing. These concerns include authentication, authorization, accounting (AAA) services; encryption; storage; security breaches; regulatory compliance; location of data and users; and other risks associated with isolating sensitive corporate data.  Add to this array of concerns the potential loss of control over your data, and the cloud model starts to get a little scary.  No matter where your applications live in the cloud or how they are being served, one theme is consistent: You are hosting and delivering your critical data at a third-party location, not within your four walls, and keeping that data safe is a top priority.

Most early adopters began to test hosting in the cloud using non-critical data.  Performance, scalability, and shared resources were the primary focus of initial cloud offerings. While this is still a major attraction, cloud computing has matured and established itself as yet another option for IT.  More data—including sensitive data—is making its way to the cloud.  The problem is that you really don’t know where in the cloud the data is at any given moment.  IT departments are already anxious about the confidentiality and integrity of sensitive data; hosting this data in the cloud highlights not only concerns about protecting critical data in a third-party location but also role-based access control to that data for normal business functions.

Organizations are beginning to realize that the cloud does not lend itself to static security controls.  Like all other elements within cloud architecture, security must be integrated into a centralized, dynamic control plane.  In the cloud, security solutions must have the capability to intercept all data traffic, interpret its context, and then make appropriate decisions about that traffic, including instructing other cloud elements how to handle it.  The cloud requires the ability to apply global policies and tools that can migrate with, and control access to, the applications and data as they move from data center to cloud—and as they travel to other points in the cloud.

One of the biggest areas of concern for both cloud vendors and customers alike is strong authentication, authorization, and encryption of data to and from the cloud.  Users and administrators alike need to be authenticated—with strong or two-factor authentication—to ensure that only authorized personnel are able to access data.  And, the data itself needs to be segmented to ensure there is no leakage to other users or systems.  Most experts agree that AAA services along with secure, encrypted tunnels to manage your cloud infrastructure should be at the top of the basic cloud services offered by vendors.  Since data can be housed at a distant location where you have less physical control, logical control becomes paramount, and enforcing strict access to raw data and protecting data in transit (such as uploading new data) becomes critical to the business.  Lost, leaked, or tampered data can have devastating consequences.

Secure services based on SSL VPN offer endpoint security, giving IT administrators the ability to see who is accessing the organization and what the endpoint device’s posture is to validate against the corporate access policy. Strong AAA services, L4 and L7 user Access Control Lists, and integrated application security help protect corporate assets and maintain regulatory compliance.

Cloud computing, while quickly evolving, can offer IT departments a powerful alternative for delivering applications. Cloud computing promises scalable, on-demand resources; flexible, self-serve deployment; lower TCO; faster time to market; and a multitude of service options that can host your entire infrastructure, be a part of your infrastructure, or simply serve a single application.

And one from Confucius himself: I hear and I forget. I see and I remember. I do and I understand.

ps

Related:

Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

Follow: @psilvas

Digg This

Wednesday, April 7, 2010

CloudFucius Says: Blog Series, Good Idea

Konfuzius-1770 Last year I wrote a blog series called, ‘26 Short Topics About Security’ covering an alphabet soup of stories.   It seemed to be well received and this year I’ve decided to do another – this time focused on Cloud Computing with ‘CloudFucius’ as my guide.  Confucius, of course, was a Chinese philosopher who focused on personal growth, morals, good judgment, ethics and many other life enlightening behaviors.  He lived around 500BC and is credited with, ‘Do not impose on others what you yourself do not desire,’ and many other gems like, ‘Choose a job you love, and you will never have to work a day in your life.

First, I want to stake a claim here that CloudFucius (TM) is mine and I have started the copyright process.  :-)  I googled and did a copyright search for 'Cloudfucius' and absolutely nothing gets returned, which actually surprised me.  'Cloud-fucius' returns a bunch of 'fucius' stuff so I figured it’s good to take.  If you do have any rights, speak up now.  While I am well versed with the security stories, I can admit I'm no cloud super-expert; knowledgeable but certainly not to the level of MacVittie, Ness and the rest.  While weaving in what I do know, I was thinking of investigating a bunch of cloud topics that I’m not an expert on, learn along the way and report on it.  Education for all and playing off the fact that Confucius=wisdom.  Hopefully CloudFucius will teach us something along the way.  He’ll start next week with some easy doctrines like, CloudFucius Says: AAA Important to Cloud and in later weeks move into other areas like, CloudFucius Says: Secure Cloud is Possible.  I’m looking forward to what we uncover and CloudFucius is excited to spread some cloud knowledge to the masses and someday getting a Hasbro toy and game named after him.

下 周 见 - 下 for Next; 周 for week; 见 for see/meet.

ps

Technorati Tags: MacVittie, F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, greg Ness, context-aware, infrastructure 2.0, automation, web, internet, blog

Digg This