CLOUD SECURITY Timothy Brown Director, Security & Virtualization

Slides:



Advertisements
Similar presentations
1 NETE4631 Cloud deployment models and migration Lecture Notes #4.
Advertisements

Infrastructure as a Service (IaaS) Amazon EC2
Unified Logs and Reporting for Hybrid Centralized Management
MyCloudIT Removes the Complexity of Moving Cloud Customers’ Entire IT Infrastructures to Microsoft Azure – Including the Desktop MICROSOFT AZURE ISV: MYCLOUDIT.
With the Help of the Microsoft Azure Platform, Devbridge Group Provides Powerful, Flexible, and Scalable Responsive Web Solutions MICROSOFT AZURE ISV PROFILE:
A Brief Overview by Aditya Dutt March 18 th ’ Aditya Inc.
© Asite Solutions Ltd Cloud Computing World Forum A Global Software as a Service Platform for Supply Chain Collaboration Tony Ryan CEOwww.asite.com.
Introducing Microsoft Azure Government Steve Read Barbara Brucker.
== Enovatio Delivers a Scalable Project Management Solution Minus Large Upfront Infrastructure Costs, Thanks to the Powerful Microsoft Azure Platform MICROSOFT.
Cloud Computing is a Nebulous Subject Or how I learned to love VDF on Amazon.
GOOGLE APP ENGINE By Muktadiur Rahman. Contents  Cloud Computing  What is App Engine  Why App Engine  Development with App Engine  Quote & Pricing.
+ Logentries Is a Real-Time Log Analytics Service for Aggregating, Analyzing, and Alerting on Log Data from Microsoft Azure Apps and Systems MICROSOFT.
Cloud Architecture. SPI Model Cloud Computing Classification Model – SPI Cloud Computing Classification Model – SPI - SaaS: (Software as a Service) -
Copyright © New Signature Who we are: Focused on consistently delivering great customer experiences. What we do: We help you transform your business.
Alfresco on Azure Shah Rahman Founder and CEO, CloudlyIO.
Snip2Code: Search, Share and Collect Code Snippets Faster, Easier, Efficiently with Power of Microsoft Azure Platform MICROSOFT AZURE ISV PROFILE: SNIP2CODE.
Deploying Docker Datacenter on AWS © 2016, Amazon Web Services, Inc. or its affiliates. All rights reserved.
CS 6027 Advanced Networking FINAL PROJECT ​. Cloud Computing KRANTHI ​ CHENNUPATI PRANEETHA VARIGONDA ​ SANGEETHA LAXMAN ​ VARUN ​ DENDUKURI.
Clouding with Microsoft Azure
Unit 3 Virtualization.
Connected Infrastructure
AWS Simple Icons v AWS Simple Icons: Usage Guidelines
AuraPortal Cloud Helps Empower Organizations to Organize and Control Their Business Processes via Applications on the Microsoft Azure Cloud Platform MICROSOFT.
MICROSOFT AZURE ISV PROFILE: BMC SOFTWARE
Avenues International Inc.
Security Virtualization
Azure Infrastructure for SAP®
100% Exam Passing Guarantee & Money Back Assurance
DocFusion 365 Intelligent Template Designer and Document Generation Engine on Azure Enables Your Team to Increase Productivity MICROSOFT AZURE APP BUILDER.
Barracuda Networks Creates Next-Generation Security Solutions That Enable Customers to Accelerate Their Adoption of Microsoft Azure MICROSOFT AZURE APP.
Hybrid Management and Security
Trial.iO Makes it Easy to Provision Software Trials, Demos and Training Environments in the Azure Cloud in One Click, Without Any IT Involvement MICROSOFT.
Introduction to Amazon Web Services Overview of AWS Services
Azure-Powered Augmented Reality Storytelling Platform for Kids Makes Learning Adaptive, Fun “Azure and its associated storage, content delivery, and virtual.
Connected Infrastructure
Stylelabs Develops the Marketing Content Hub to Offer Enterprises a High-End Marketing Content Management Platform Based on Microsoft Azure MICROSOFT AZURE.
Cloud Security.
Zero-Code Solution on Azure Helps Businesses Optimize Processes with Automation and Agility “Implementing Azure has empowered us to help our customers.
Chapter 21: Cloud Computing and Related Security Issues
Chapter 22: Cloud Computing Technology and Security
Acutelearn Amazon Web Services Training Classroom Training Instructor led trainings at Acutelearn premises Corporate Training Custom tailored trainings.
AWS. Introduction AWS launched in 2006 from the internal infrastructure that Amazon.com built to handle its online retail operations. AWS was one of the.
OpenNebula Offers an Enterprise-Ready, Fully Open Management Solution for Private and Public Clouds – Try It Easily with an Azure Marketplace Sandbox MICROSOFT.
Built on the Powerful Microsoft Azure Platform, Lievestro Delivers Care Information, Capacity Management Solutions to Hospitals, Medical Field MICROSOFT.
Your Business Opportunity
Cloud Computing Security: Mapping Concepts to Practical Techniques
VMware NSX and Micro-Segmentation
Microsoft Azure Platform Powers New Elements Constellation Software Suite to Deliver Invaluable Insights From Your Data for Marketing and Sales MICROSOFT.
Interlake Hybrid Cloud Management Suite
Be Better: Achieve Customer Service Excellence and Create a Lean RMA and Returns Process with Renewity RMA and the Power of Microsoft Azure MICROSOFT AZURE.
Utilizing the Capabilities of Microsoft Azure, Skipper Offers a Results-Based Platform That Helps Digital Advertisers with the Marketing of Their Mobile.
PowerHub on Microsoft Azure Enables Renewable Energy Professionals to Track and Manage Projects from a Centralized Platform Accessible Anywhere MICROSOFT.
The Only Digital Asset Management System on Microsoft Azure, MediaValet Is Uniquely Equipped to Meet Any Company’s Needs MICROSOFT AZURE ISV PROFILE: MEDIAVALET.
AWS Boulder - Denver Meetup – January 2017
Automating Security in the Cloud
AdQ is Azure-Powered Pre-Roll Ad Management Software That Improves Pre-Roll Ad Performance, Increases Profits, and Optimizes User Experience MICROSOFT.
Abiquo’s Hybrid Cloud Management Solution Helps Enterprises Maximise the Full Potential of the Microsoft Azure Platform MICROSOFT AZURE ISV PROFILE: ABIQUO.
Defending high value targets in the cloud using IP Reputation
Why Amazon Web Services
MS AZURE By Sauras Pandey.
Agenda Need of Cloud Computing What is Cloud Computing
Cloud Security AWS as an example.
A - E Cloud Enterprise Symbols
Cloud Security AWS as an example.
Route web traffic using Azure CLI
COMPANY PROFILE: REELWAY
Setting up PostgreSQL for Production in AWS
Procurement & Contract Management Solution on Azure Helps to Boost Business Performance “Microsoft Azure gives us the cloud infrastructure to quickly and.
OU BATTLECARD: Oracle Identity Management Training
Cloud Computing for Wireless Networks
Presentation transcript:

CLOUD SECURITY Timothy Brown Director, Security & Virtualization Network Utility Force

About Your Presenter Walker and Associates has been around for more than 40 years, handling the needs of communications carriers and the Federal Government as a Value Added Distributor (Warehousing, Networking, Design Services, Reselling) Network Utility Force is a consulting company focused on network and security infrastructure. We enable companies to make the most of their infrastructure. Our team collectively has over 100 years of service provider and enterprise engineering experience. I (Tim Brown) am ex-OEM, ex-service provider, ex-VAR and have been involved in network engineering since 1995.

Today’s Presentation Fundamental questions (but there are many others): Is being in the cloud less secure than having gear at my facility? What new threats do I face by moving to the cloud? How can all this “as-a-service” stuff help me do my job?

How do you normally protect an asset? Infrastructure security (power, cooling, entrance points, …) Physical security Network security Systems security Application security Data security (storage, databases)

Cloud has us think of things a little differently Generate revenue from “functions” Decompose the true cost/effort of delivering a given function, make that something we can sell (“de”-commoditize) The security needs of DoD are fundamentally different from a web hosting provider Move to automation, immutability Services don’t prevent you from rolling your own (and in DoD case, you use SCCA)

Looking at five options today Amazon’s AWS Google Cloud Microsoft Azure Virtualized security within your existing facilities Carriers/Hosting

One axis: How “automatable” is the solution With cloud computing and virtualization, world is moving to a more “repeatable, immutable” model Applications no longer monolithic Systems are heading to a distributed world We could evaluate these items on many axes. But some of the more important things that differentiate clouds

Cloud Platforms and Security Features

All clouds offer some high level segmentation and network virtualization “Buckets” of resources Projects, VPCs, granularity Whitebox or software switches, special hypervisor features MAC learning, custom drivers Custom firewalls/packet processors

Network Features Amazon AWS Custom route tables DHCP Options Elastic IPs Flexible NAT Cloud Firewall Peering Flow Monitoring Google Cloud Cloud Load Balancing Cloud CDN Cloud InterconnectMicrosoft Azure ExpressRoute Load Balancing/Application Gateway Network Watcher

Logging and Monitoring Amazon AWS CloudTrail CloudWatch Log Aggregation Google Cloud Stackdriver (AWS+GCP) – Error reporting, trace, debugger, API frontends Microsoft Azure Azure Monitoring Application Insights Log Analytics System Center Operations Manager

Access Control Amazon AWS IAM MFA Directory Service Google Cloud Cloud IAM Cloud IAP Cloud DLP Key Vaults Microsoft Azure Key Vault Active Directory

Border Protection Approach

Historical approach to security: protect the border

Segmentation Approach

Segmentation approach

Microsegmentation Approach

Microsegmentation

Typical Architectures

AWS

Some terminology changes

AWS Architecture Example

AWS Architecture

AWS Compliance GovCloud has achieved FedRAMP High Provisional authorizations for IL4 and soon IL5 (unclassified, IL5 includes unclassified National Security Systems) See https://s3.amazonaws.com/quickstart-reference/enterprise- accelerator/nist/latest/assets/NIST-800-53-Security-Controls- Mapping.xlsx

Google

Google Cloud Architecture

Compliance Has FedRAMP ATO No SRG compliance as far as I know of

Azure

Microsoft Azure Architecture

Azure Compliance DoD IL5, 4 Compliant

You Host It

Comes back to our two views: Segmentation and microsegmentation

Where the security industry is headed

Zero Trust Model

Summary

Thanks