Pages

Subscribe:

Friday, July 22, 2011

Top 5 Cloud Computing Providers

Here is a list of the Top 5 Cloud Computing providers. The key parameters used for comparing these cloud platforms include when the platforms were introduced, support for various operating systems/languages, current adoption levels of the platforms and the overall potential of the platform. A good understanding of the key cloud computing platforms is critical to understand the current state of cloud computing and the overall direction of the industry. This in turn is very useful while making a choice for an appropriate cloud computing platform. Please read the following article Comparing SaaS, PaaS and IaaS to understand some of the terminology used in this article.

Amazon
Clearly the market leader in Cloud Computing and primarily a IaaS vendor.EC2 and S3 are the two most popular services available as part of Amazon Web Services. They also have the most wide variety of services available as part of their cloud platform.
There are indications that Amazon may have a total of 1.8 million deployed instances and showing 10% overall growth in deployments
Indications are they had a total revenue of 220 million USD revenue from their Cloud business
There are around 100,000 customers using Amazon Web Services



Rackspace

Rackspace which has long been one of the largest players in the managed hosting market quickly transformed itself into a highly successful Cloud Computing provider primarily as an IaaS provider. They have two key services Cloud Servers and Cloud Files which are the equivalent of EC2 and S3 from Amazon.
Indicating 100% growth in Cloud Revenues from 2008 to 2009
Added around 40,000 new customers in the last 4 quarters
Cloud Revenue has been 56 million USD in 2009

Salesforce.com
Salesforce.com was one of the earliest Cloud Computing companies to get setup with a specific focus on CRM and functioned as a SaaS company.Salesforce.com first started in 1999 and has grown significantly from its initial launch with a continuous focus on CRM. Force.com was launched in 2007 as a custom application development platform as an entry into the PaaS market but has not been able to garner a significant market due its proprietary platform. Given the specific nature of the platform Amazon and Rackspace have been ranked higher in this list even though Salesforce has a higher revenue.
Total of 55,000 corporate customers and 1.5 million individual subscribers.
Total revenue of .3 billion for 2009

Google

Google made a late entry into the Cloud Computing business with two services, Google Apps which primarily targets the SaaS space and the Google App Engine which provides a PaaS model for businesses and individuals to deploy their Web Apps. They have quickly made a mark with both the platforms and have made significant growth in the overall cloud computing market.
Google Apps has 1 million customers and an approximate revenue of million
Google App Engine does not have any numbers publicly available, since the paid version launched a year back they may need some more time before we get a sense of the adoption.

Microsoft

Microsoft was the last major player to enter into the market and as expected launched a platform Azure based on their Windows/Azure stack. While they have continued to claim that Azure is not tied to .NET, the expectation is the platform will see most adoption from Microsoft shops with a focus on .NET and Windows based technologies and platforms.
Indications are that around 10,000 customers have moved to Azure
Since the launch has been less than 6 months back its a little early to track adoption.
We rank it high due to the high potential of the platform and tight integration with Microsoft based development platforms.

Conclusion
Amazon and Rackspace continue to be the key players in Cloud Computing with a key focus on IaaS as the core service they offer. Given the core expertise of these companies it is unlikely that they will venture into other aspects of the Cloud and they are unlikely to offer SaaS or PaaS services anytime soon. It is highly likely that all growth in the IaaS segment of Cloud Computing will be distributed between these two companies. Microsoft and Google are likely to be key players in the PaaS space clearly segmented between .NET and Java applications. Salesforce on the other hand is likely to remain a player focused purely on the CRM market and primarily as a SaaS provider.

Thursday, July 14, 2011

Top 7 threats to cloud computing

1 Abuse and nefarious use of cloud computing((IaaS, PaaS) -- 
The easiness of registering for IaaS solutions and the relative anonymity they offer attracts many a cyber criminal. IaaS offerings have been known to host botnets and/or their command and control centers, downloads for exploits, Trojans, etc. There is a myriad of ways in which in-the-cloud capabilities can be misused - possible future uses include launching dynamic attack points, CAPTCHA solving farms, password and key cracking and more
Remediation - 
-Stricter initial registration and validation processes.
-Enhanced credit card fraud monitoring and coordination.
-Comprehensive introspection of customer network traffic.
- Monitoring public blacklists for one’s own network blocks

2 Insecure interfaces and APIs (IaaS, PaaS, SaaS) -
As software interfaces or APIs are what customers use to interact with cloud services, those must have extremely secure authentication, access control, encryption and activity monitoring mechanisms - especially when third parties start to build on them..
Remediation-
-Analyze the security model of cloud provider interfaces.
- Ensure strong authentication and access controls are implemented in concert with encrypted transmission.
- Understand the dependency chain associated with the API

3 Malicious insiders (IaaS, PaaS, SaaS) -
The threat of a malicious insider is well-known to most organizationsThis threat is amplified for consumers of cloud services by the convergence of IT services and customers under a single management domain, combined with a general lack of transparency into provider process and procedure. For example, a provider may not reveal how it grants employees access to physical and virtual assets, how it monitors these employees, or how it analyzes and reports on policy compliance.
Remediation-
-Enforce strict supply chain management and conduct a comprehensive supplier assessment.
-Specify human resource requirements as part of legal contracts.
-Require transparency into overall information security and management practices, as well as compliance reporting.
-Determine security breach notification processes.

4 Shared technology issues (IaaS)-
Sharing infrastructure is a way of life for IaaS providers. Unfortunately, the components on which this infrastructure is based were not designed for that. To ensure that customers don't thread on each other's "territory", monitoring and strong compartmentalization is required, not to mention scanning for and patching of vulnerabilities that might jeopardize this coexistence.
Remediation -
Implement security best practices for installation/configuration.
-Monitor environment for unauthorized changes/activity.
-Promote strong authentication and access control for administrative access and operations. Enforce service -level agreements for patching and vulnerability remediation.
-Conduct vulnerability scanning and configuration audits.

5 Data loss or leakage( IaaS, PaaS, SaaS)-
There are many ways to compromise data. Deletion or alteration of records without a backup of the original content is an obvious example. Unlinking a record from a larger context may render it unrecoverable,
as can storage on unreliable media. Loss of an encoding key may result in effective destruction. Finally, unauthorized parties must be prevented from gaining access to sensitive data. The threat of data compromise  increases in the cloud, due to thenumber of and interactions between risks and challenges which are either unique to cloud, or more dangerous because of the architectural or operational characteristics of the cloud environment.
Remediation - 
-Implement strong API access control.
-Encrypt and protect integrity of data in transit.
-Analyzes data protection at both design and run time. Implement strong key generation, storage and management, and destruction practices. Contractually demand providers wipe persistent media before it
is released into the pool.
-Contractually specify provider backup and retention strategies.

6 Account or service hijacking(IaaS, PaaS, SaaS)  -
Account or service hijacking is not new. Attack methods such as phishing, fraud, and exploitation of software vulnerabilities still achieve results. Credentials and passwords are often reused, which amplifies the impact of such attacks. Cloud solutions add a new threat to the landscape. If an attacker gains access to your credentials, they can eavesdrop on your activities and transactions, manipulate data, return falsified information, and redirect your clients to illegitimate sites. Your account or service instances may
become a new base for the attacker. From here, they may leverage the power of your reputation to launch subsequent attacks.
Remediation - 
-Prohibit the sharing of account credentials between users and services. Leverage strong two-factor authentication techniques where possible.
-Employ proactive monitoring to detect unauthorized activity.
-Understand cloud provider security policies and SLAs

7 Unknown risk profile ( IaaS, PaaS, SaaS) - 
One of the tenets of Cloud Computing is the reduction of hardware and software ownership and maintenance to allow companies to focus on their core business strengths. This has clear financial and operational
benefits, which must be weighed carefully against the contradictory security concerns — complicated by the fact that cloud deployments are driven by anticipated benefits, by groups who may lose track of the
security ramifications. Versions of software, code updates, security practices, vulnerability profiles, intrusion attempts, and security design, are all important factors for estimating your company’s security posture.
Information about who is sharing your infrastructure may be pertinent, in addition to network intrusion logs, redirection attempts and/or successes, and other logs. Security by obscurity may be low effort, but it can result in unknown exposures. It may also impair the in-depth analysis required highly
controlled or regulated operational areas.
Remediation -
-Disclosure of applicable logs and data.
-Partial/full disclosure of infrastructure details (e.g., patch
levels, firewalls, etc.).
-Monitoring and alerting on necessary information

Sunday, June 5, 2011

Cloud computing and Grid computing

Cloud computing is the use of a 3rd party service(Web Services) to perform computing needs. Here Cloud depicts Internet . With cloud computing, companies can scale up to massive capacities in an instant without having to invest in new infrastructure. Cloud computing is benefit to small and medium-sized businesses. Basically consumers use what they need on the Internet and pay only for what they use. Cloud computing incorporates infrastructure as a service (IaaS), platform as a service (PaaS) and software as a service (SaaS) as well as Web 2.0 Cloud computing eliminates the costs and complexity of buying, configuring, and managing the hardware and software needed to build and deploy applications, these applications are delivered as a service over the Internet (the cloud).

Grid computing is a form of distributed computing whereby resources of many computers in a network is used at the same time, to solve a single problem. Grid systems are designed for collaborative sharing of resources. It can also be thought of as distributed and large-scale cluster computing Grid computing is making big contributions to scientific research, helping scientists around the world to analyze and store massive amounts of data by sharing computing resources 

Cloud   — Full private cluster is provisioned
— Individual user can only get a tiny fraction of the total resource pool
— No support for cloud federation except through the client interface
— Opaque with respect to resources
•Grid
— Built so that individual users can get most, if not all of the resources in a single request
— Middleware approach takes federation as a first principle
— Resources are exposed, often as bare metal
 
 

Wednesday, May 25, 2011

Types of Virtualization

Operating System Virtualization -
 The use of OS-level virtualization or partitioning (such as LPARs, VPARs, NPARs,Dynamic System Domains, and so on) in cloud architectures can help solve some of the core security, privacy, and regulatory issues that could otherwise hinder the adoption of cloud computing.For example, OS virtualization such as that provided by Solaris. Containers makes it possible to maintain a one-application-per-server deployment model while simultaneously sharing hardware resources. Solaris Containers isolate software applications and services using software-defined boundaries and allow many private execution environments to be created within a single instance of the Solaris OS. Each environment has its own identity, separate from the underlying hardware, so it behaves as if it’s running on its own system, making consolidation simple, safe, and secure. This makes it possible to reduce the administrative overhead and complexity of managing multiple operating systems and improve utilization at the same time.

Platform Virtualization -
 Platform virtualization allows arbitrary operating systems and resulting application environments to run on a given system. There are two basic models for this system virtualization: full virtualization, or a complete simulation of underlying hardware, and paravirtualization, which offers a “mostly similar” model of the underlying hardware. These are implemented as Type 1 hypervisors, which run directly on hardware, and Type 2 hypervisors, which run on top of a traditional operating system. Each of the top virtualization vendors offers variations of both models. It’s important to realize that there are design and performance trade-offs for any model of system virtualization.Generally, the more abstract the OS is made  from the underlying hardware, the less hardware-specific features can be accessed. Increased OS abstraction can also increase the potential for performance reduction and limitations.

Network Virtualization -
 Load-balancing techniques have been a hot topic in cloud computing because, as the physical and virtual systems within the cloud scale up, so does the complexity of managing the workload that’s performed to deliver the service. Load balancers group multiple servers and services behind virtual IP addresses. They provide resource-based scheduling of service requests and automatic failover when a node fails. While hardware balancers may outperform software-based balancers, their flexibility is always limited. Engineers end up either writing software that interacts with hardware via a suboptimal user interface or using a large number of computers to solve the problem. A significant challenge in cloud computing networking is not just the provisioning of individual virtual network interfaces to a given virtual environment, but also the increasing need of cloud infrastructures to offer a more complicated virtual private datacenter, which provisions a set of different system roles and the logical interconnections between those roles.

Application Virtualization- 
There is also a software angle to “containers” within the cloud. The Web container technology implemented in the cloud greatly impacts developer productivity and flexibility.The Web container is the part of the application server that manages servlets, JavaServerTM Page (JSP) files, and other Web-tier components. But not all Web container technologies are created equal. Apache Tomcat, for example, is a popular open-source Web container technology, but it has limitations for developers who want to go beyond Web-tier applications. If an application needs to use persistence, clustering, failover, messaging, or Enterprise Java Beans (EJBTM), these capabilities have to be added to Tomcat one by one, whereas the GlassFish™ Project provides an integrated collection of Java EE containers that delivers all of these capabilities. Today, most cloud computing offerings concentrate on platform virtualization, and the developer chooses the OS and development platform. But increasingly public clouds and certainly private clouds will offer higher-level development environment programming abstractions. Over time, we might expect the level of abstraction that the developer interfaces with to move gradually upward as more functionality percolates down into the platform.

Monday, February 7, 2011

Key Technology- Virtualisation

Virtualization forms a solid foundation for all cloud architectures. It enables the abstraction and aggregation of all data center resources, thereby creating a unified resource that can be shared by all application loads. Hardware such as servers, storage devices, and other components are treated as a pool of resources rather than a discrete system, thereby allowing the allocation of resources on demand. By decoupling the physical IT infrastructure from the applications and services being hosted, virtualization allows greater efficiency and flexibility, without any effect on system administration productivity or tools and processes . By separating the workload from the underlying OS and hardware, virtualization allows extreme portability.
Figure shows an example of vitrualisation: in non  cloud computing there is a need for three servers; in cloud computing two servers are used.

Vitrual Workspaces:
- An abstraction of an executing environment that can be made dynamically available to authorised to clients    by using well defined protocols
- Resource quota(e.g. CPU, memory share)
- Software configuration(e.g O/S, provided services)
- Implement on Virtual Machines:
- Abstraction of a physical host machine
- Hypervisor intercepts and emulates instructions from VMs, and allow management of VMs

VM technology allows multiple virtual machines to run on a single physical  machine.






Wednesday, January 12, 2011

Benefits of Cloud computing

Reduced Costs- Cloud technology is paid incrementally, saving organizations money. The cloud promises to reduce the cost of acquiring, delivering, and maintaining computing power, a benefit of particular importance in times of fiscal uncertainty. By enabling agencies to purchase only the computing services needed, instead of investing in complex and expensive IT infrastructures,agencies can drive down the costs of developing, testing, and maintaining new and existing systems.

Access-  The cloud promises universal access to high-powered computing and storage resources for anyone with a network access device.Employees can access information wherever they are, rather than having to remain at their desks. By providing such capabilities, cloud computing helps to facilitate telework initiatives, as well as bolster an agency’s continuity of operations (COOP) demands.



Scalability and Capacity- No longer do IT personnel need to worry about keeping software up to date.The cloud is an always-on computing resource that enables users to tailor consumption to their specific needs. Infinitely scalable, cloud computing allows IT infrastructures to be expanded efficiently and expediently without the necessity of making major capital investments. Capacity can be added as resources are needed and completed in a very short period of time.Thus, agencies can avoid the latency,expense, and risk of purchasing hardware and software that takes up data center space -- and can reduce the traditional time required to scale up an application in support of the mission. Cloud computing allows agencies to easily move in the other direction as well, removing capacity, and thus expenses, as needed.

Resource Maximization- Organizations can store more data than on private computer systems. Cloud computing eases the burden on IT resource already stretched thin, particularly important for agencies facing shortages of qualified IT professionals.

Collaboration- The cloud presents an environment where users can develop software-based services that enhances collaboration and fosters greater information sharing, not only within the agency, but also among other government and private entities.

Customization-  Cloud computing offers a platform of tremendous potential for creating and amending applications to address a diversity of tasks and challenges. Its inherent agility means that specific processes can be easily altered to meet shifting agency needs, since those processes are typically changeable by making a configuration change,and not by driving redevelopment fromt he back-end systems.

Thursday, December 30, 2010

Deployment Models

Deploying cloud computing can differ depending on requirements, and the following four deployment models have been identified, each with specific characteristics that support the needs of the services and users of the clouds in particular ways .


• Private Cloud — The cloud infrastructure has been deployed, and is maintained and operated for a specific organization. The operation may be in-house or with a third party on the premises.
• Community Cloud — The cloud infrastructure is shared among a number of organizations with similar interests and requirements. This may help limit the capital expenditure costs for its establishment as the costs are shared among the organizations. The operation may be in-house or with a third party on the premises.
• Public Cloud — The cloud infrastructure is available to the public on a commercial basis by a cloud service provider. This enables a consumer to develop and deploy a service in the cloud with very little financial outlay compared to the capital expenditure requirements normally associated with other deployment options.
• Hybrid Cloud — The cloud infrastructure consists of a number of clouds of any type, but the clouds have the ability through their interfaces to allow data and/or applications to be moved from one cloud to another. This can be a combination of private and public clouds that support the requirement to retain some data in an organization, and also the need to offer services in the cloud.