Sign in with
Sign up | Sign in

Application Protection

How Secure Is The Cloud?
By

How well are Web applications protected?

Certainly, the least secure aspect of any cloud deployment is in its Web applications and how they are connected to the rest of the cloud-based infrastructure. The challenge is to virtualize as many of the protective devices/applications as are available on on-premises servers, such as load balancers, intrusion prevention appliances, and firewalls. The major cloud providers are beginning to add these tools to their list of services so that IT developers can migrate their applications to the cloud and still maintain the level of security that they have come to expect with the ones running inside their own data centers.

For example, Amazon's cloud-based servers can't send spoofed network traffic, no matter which operating system they are running. The Amazon firewalls will only allow traffic using its own source IP or MAC network address, which is a nice safeguard.

The CTO of Town and Country, Missouri-based cloud hosting provider Savvis, Bryan Doerr, talks about how automation can play a critical role in cloud security."We can automatically provision stuff quickly, but what we can't do is make decisions quickly. How long it will take me to add capacity to this app? How long to recognize a failure and respond? Now that we have all this infrastructure virtualized, and [have] automated these changes, we need to automate the decision making too. We need to close the loop from sense to decision. Virtualization has freed us from manually patching cables and setting up racks of equipment. We have to make these decisions in advance, define them in terms of policy, and then express those in terms of guides for our provisioning systems. The trick is to figure out how to help customers get down the road." Products such as Racemi's DynaCenter are just one of the many automation tools available for these sorts of tasks.

Finally, no matter what you do, don't be afraid to kick the actual tires and make a site visit to vet your vendor. "We made a personal visit to our cloud provider's location and saw what their UPS looks like and how they are managing their data center," says the USGA's Jessica Carroll. "That made us more comfortable with selecting them as our provider."

As you can see, there are a number of best practices and other steps cloud computing users can take to secure their operations. Security expert Bruce Schneier says, "You have to get smarter about negotiating your contracts for security services. We are going to see a lot more ways to connect untrusted devices to a trusted network," and cloud computing is just one of them.

Display all 14 comments.
This thread is closed for comments
  • 1 Hide
    fstrthnu , December 22, 2010 8:34 PM
    Answer: It's safe IF you play your cards right, but almost all of the time you can forget about decent security
  • 2 Hide
    Anonymous , December 23, 2010 7:22 PM
    You haven't really addressed many of the security concerns IT pros have about "the cloud". Who potentially has access to my data, what controls are in place to keep that data safe (ie could a rouge employee rip backup of my DB and take it home)? How are other legal situations handled, such as warrants/requests for data from law enforcement, will the customer be notified, will the vendor simply comply, etc? What happens *IF* the cloud vendor goes out of business one day, where is my data (one would assume there would be warning signs before this happens, but stranger things have happened)? There are tons of questions with not many good answers out there.
  • 0 Hide
    babachoo , December 26, 2010 1:16 AM
    This article has been brought to you by domestic datamining organizations and the people they have in their pockets.
  • 0 Hide
    gonebamboo , December 26, 2010 5:13 PM

    Check out this cloud-based (Software as a Service) platform and its security architecture.

    http://www.otakhi.com
    http://www.otakhi.com/pages/security.html
  • 0 Hide
    ludikraut , December 27, 2010 2:09 AM
    This article barely scratches the surface of security issues surrounding cloud computing. It reads more like an executive summary than something I would expect to see on Tomshardware - very disappointing.
  • 0 Hide
    Anonymous , December 27, 2010 3:03 AM
    Cloud computing is overrated. Your data will never be secure in someone else's hands. Any encryption can be broken with time.
  • 0 Hide
    Anonymous , December 28, 2010 8:24 PM
    I didn't really see any mention of on-site encryption in this article, only transport encryption. Also, who assures us that claims made regarding security are entirely true instead of being marketing word-play which seems so popular these days. Only when a cloud service publishes results done by a third party auditor that I trust will I use them.
  • 0 Hide
    gtaker , January 4, 2011 2:59 PM
    If you are in the external cloud with your company your data will be compromise.. I'm 100% sure of that... we look at this cloud stuff 8 years ago and came to that conclusion if you need to do it, do it inside your company not outside...
  • 0 Hide
    sadams04 , January 10, 2011 12:54 PM
    Security is always a concern, but my main concern with the cloud is around someone else being responsible for up-time / availability. Those priorities rarely line up across multiple companies. While you may recover lost revenue through a breach in service level agreements, you can't recover customer perceptions and experiences in the same way.
  • 0 Hide
    perrakis , July 16, 2012 6:59 PM
    There's an updated version of the Ponemon Cloud Security Study available from the report's sponsor, Dome9: http://www.dome9.com/resources/ponemon-cloud-security-study.

    Incidentally, Dome9 offers free cloud security for an unlimited number of servers. You can check them out at http://www.dome9.com. Essentially, their value prop is the ability to close administrative ports on a remote cloud server and make access available on demand. This is important in the cloud where your servers operate outside your traditional network, and leaving ports open exposes them to hackers, brute force attacks, and exploits.
  • 0 Hide
    Scanlia , September 5, 2012 12:41 PM
    http://www.wcbk.info/2012/05/cloud-price-comparison.html
  • 0 Hide
    Scanlia , September 5, 2012 12:43 PM
    I found a really helpful article on cloud computing prices, and comparing all the different companies.

  • 0 Hide
    ken66_31 , December 6, 2012 7:24 AM
    Cloud computing can be so secure if you work with the right tools: http://www.drive-maxx.com/Pages/Product-information_3. Your data will be encrypted on your computer.
  • 0 Hide
    Xalman Xhan , June 5, 2013 3:47 PM
    There are actually two fears about cloud computing that deal with security – data security and job security. Organizations might get comfortable with data security but their IT side of the house doesn’t feel comfortable with job security. The cloud was supposed to be this evil thing that was going to eliminate jobs for local IT departments, but truth of the matter is that job elimination hasn’t actually happened. IT managers and professionals are working with increasingly restrained resources under impossible deadlines, but that has always been the case.

    http://www.dincloud.com/blog/security-in-the-cloud

    This is another interesting article that discusses Cloud security in detail.