Tuesday, July 20, 2010

UNDERSTAND CLOUD COMPUTING


Making sense out of all of the components of cloud computing confuses even many of the major analysts. It's easy to understand how Google, Amazon, or SalesForce.com fit into the picture. But who is Eucalyptus and what do they do? Does CohesiveFT compete with enStratus or does it complement enStratus? And what is this vCloud thing anyway?

I've identified seven major components to cloud computing that I call "the seven pillars of cloud computing". I call them pillars because, as cloud computing evolves, they will form the foundation of a complete vendor cloud computing strategy. I'm not suggesting that you aren't a real cloud vendor if you lack one of the pillars—in fact, no one currently has a solid strategy for all seven pillars. The companies that end up seeing the most success as vendors in cloud computing, however, will not only develop strategies for all seven pillars, but also a strategy for integrating them into a comprehensive cloud offering.
The Seven Pillars

Seven Pillars of Cloud Computing.
The seven pillars of cloud computing are:

* Virtualization
* Storage
* Cloud Orchestration
* Data Center Systems Management
* Cloud Infrastructure Management
* Hybrid Cloud Integration
* Public Cloud Services

As I mentioned above, there's no company that has offerings in all seven areas. If you are an enterprise looking for the complete cloud solution today, you may have to talk to as many as seven different vendors—though most likely fewer—before you find your answer.

Virtualization

Virtualization is absolutely not a requirement for cloud computing. Google and many others offer cloud services without using virtualization to make it happen.
From the complete cloud solution perspective, however, virtualization absolutely must be a strategic tool in the cloud vendor's arsenal.

Virtualization makes it possible to dedicated the minimum number of resources to a workload as is possible so you can more efficiently share real processing power among different workloads. It thus forms the backbone of many services we think of as cloud services today.

The number of players in this space is quite small. The significant ones are Citrix, KVM (Open Source), Microsoft, Oracle, and VMware.

Storage

From the cloud perspective, storage isn't about making the media on which data is stored. Instead, it's about providing the hardware and software for turning that media into a massive, abstracted storage tier available over a network and impervious to failure.

The current key players in this space are Compellent, EMC, Flexiant, HP, IBM, NetApp, Oracle, ParaScale, and a number of other smaller players.

Cloud Orchestration

There's actually nothing "cloudy" about virtualization. It simply facilitates the programmatic provisioning and de-provisioning of resources necessary for a cloud infrastructure. To make your virtualized infrastructure cloudy, you need an orchestration layer on top of it.

Orchestration layers hide the nuances of the underlying virtualization tier and exposes them to on-demand provisioning through web services APIs.

Companies with a footprint in this space include Amazon, CA (via their 3tera acquisition), Citrix, Enomaly, Eucalyptus, Flexiant, Rackspace, VMOps, and VMware.

Data Center Systems Management

Data center systems management is something most people forget about or ignore today when examining cloud services. It's the main tool a traditional IT operations staff uses to monitor provisioned resources, manage the provisioning, de-provisioning, and other IT workflows, and handle emergency situations.

The traditional data center management offerings are painfully "uncloudy" and the extent of the integration between traditional Data Center Systems Management and the cloud is largely limited to:

* BMC monitoring of RightScale
* enStratus pushing cloud health into Microsoft Systems Center
* IBM's limited support for AWS in Tivoli

Everything else in this space is currently about supporting traditional data center management, provisioning, and monitoring activities.

This space is a well established space with some heavy hitting incumbents: CA, BMC, IBM, EMC, HP, IBM, and Microsoft.

Cloud Infrastructure Management

Cloud infrastructure management is really a specialized version of data center systems management. Cloud infrastructure management tools enable an IT staff to manage, monitor, provision, and de-provision resources in a cloud environment. In a few years, it likely won't be a pillar distinct from data center systems management. I break it out separately because there is almost no overlap between the two pillars today.

Cloud infrastructure management is dominated by start-ups today. The traditional data center systems management tools are poorly suited to the task of managing highly elastic cloud computing infrastructures. This gaping hole has enabled startups to come in and fill the need. On the other hand, there's very little overlap among the different startups in this space.

The cloud infrastructure management space is a very crowded space with a few major players: CA (via Nimsoft), CloudKick, Elastra, enStratus, and RightScale. In addition, CloudSwitch and CohesiveFT have elements of cloud infrastructure management, but generally fit more into the hybrid cloud integration pillar.

Hybrid Cloud Integration

Another pillar dominated by startups is hybrid cloud integration. Hybrid cloud integration services enable a company to glue together the different kinds of clouds supporting their infrastructure (public and private, multiple public, combined SaaS and Paas) into a single, coherent infrastructure. With hybrid cloud tools, you can manage and automate the movement of workloads among clouds as well as communications between components in different clouds.

This space is the least mature space with a very small set of players: CloudKick, CloudSwitch, CohesiveFT, and enStratus. Among these four players, there's almost no overlap in functionality. CloudKick provides a unified console for managing resources in multiple clouds. CloudSwitch enables you to securely lift your private data center/private cloud enterprise applications and drop them into a public cloud without changing IP addresses. CohesiveFT provides technologies for enabling virtual VPNs among clouds and managing virtual private clouds. enStratus provides governance, provisioning, auto-scaling, and auto-recovery across clouds.

Public Cloud Services

The public cloud services are what most people have in their head when they think "cloud". These are the SaaS, PaaS, and IaaS vendors that leverage the other components of cloud computing to deliver a public cloud offering. As a customer, you procure public cloud services on-demand and stop using them when you no longer need them.

http://www.openworld.co.ke/index.php/openbiz

Thursday, July 8, 2010

SECURING YOUR NETWORK


In computer networks, a DMZ (demilitarized zone) is a computer host or small network inserted as a "neutral zone" between a company's private network and the outside public network. It prevents outside users from getting direct access to a server that has company data. A DMZ is a more secure approach to a firewall and effectively acts as a proxy server as well.

In a typical DMZ configuration for a small company, a separate computer (or host in network terms) receives requests from users within the private network for access to Web sites or other companies accessible on the public network. The DMZ host then initiates sessions for these requests on the public network. However, the DMZ host is not able to initiate a session back into the private network. It can only forward packets that have already been requested.

Users of the public network outside the company can access only the DMZ host. The DMZ may typically also have the company's Web pages so these could be served to the outside world. However, the DMZ provides access to no other company data. In the event that an outside user penetrated the DMZ host's security, the Web pages might be corrupted but no other company information would be exposed. OPENWORLD, the leading company specialized in products designed for setting up a DMZ.

Thursday, June 24, 2010

CYBERCRIME IS AFFECTING YOUR BUSINESS

A new study reveals spam, viruses, phishing and credit-card fraud have become serious issues for small- to medium-sized businesses in Ireland, costing approximately $300 million yearly, according to the Irish Examiner.
After conducting a survey of more than 600 companies, the Irish Small & Medium Enterprises Association concluded cyber crime has become a growing problem. Unless something is done to address the situation, companies will continue seeing a dramatic rise in business costs.
Nearly 70 percent of companies reported being a victim of cyber crime in the last year. Nearly all respondents had been affected by spam, almost half (54 percent) by phishing, 51 percent from virus infection, and 13 percent had experienced credit-card fraud.

Kenya and Africa at large are not far from this. Cybersecurity experts estimate that 80 percent of computers on the African continent are already infected with viruses and other malicious software, according to Foreign Policy. The combination of housing the world’s most vulnerable computers and a majority of a population lacking basic knowledge of IT makes the computers easy targets for skilled botnet operators and hackers.

Also, with the exception of Egypt and South Africa, most African countries lack the legal infrastructure to prosecute, or even stop the rise in cyber crime. Despite commitments made at a Regional Cybersecurity Forum for Africa and Arab states held last year, there is little coordination between countries on how to deal with cybersecurity.

While the continent as a whole is lagging behind in cybersecurity, there are a few countries that have made advancements. Tunisia, for example, has created the first national security institute in Africa, and Nigeria has developed a national cybersecurity initiative aimed at raising awareness and battling online fraud.

It is thus important to boost security in your cyber world using anti-virus software , spam-filtering software and hardware firewalls. It is also important for companies to hire IT professionals for guaranteed security.

Tuesday, June 15, 2010

FIFA WORLD CUP AND CYBERCRIME (BEWARE)

cybercriminals have already started showing their interest in taking advantage of the event, by launching targeted malicious PDFs/malware serving campaigns, blackhat SEO and fraudulent propositions, followed by lottery winning notifications/letters of claim themed scams.

Considering that, these threats and exploitation tactics are prone to intensify throughout the entire event, let’s review some of the most commonly used attack vectors, and discuss the risk mitigation strategies for each and every one of them.

The threats and the fraudulent schemes

The following list doesn’t aims to achieve conclusiveness, instead it would discuss the most prevalent threats based on the historical “performance” of malicious attackers, and scammers in general.
Targeted malware attacks serving client-side exploits -The combination of a recently announced zero day flaw affecting Adobe’s most popular products, and the global proportions of the FIFA World Cup, clearly offer a malicious attacker the opportunity to capitalize on the event. According to Symantec, based on the campaigns analyzed since April, malicious PDFs continue representing the highest percentage of malicious attachments - .pdf 41%.exe 18%.doc 14%.xls 7%.scr 4%.ppt 1%. Their findings confirm the findings from a related report, indicating that outdated Adobe flaws for which patches are available, represented 80% of all exploits for 2009. What’s driving the success of these malicious campaigns? With or without the recent Adobe zero day, the malicious attackers have realized that just because a patch is available, it doesn’t necessarily mean that hundreds of thousands of Internet users are patching themselves. And they should.
419/Lottery Scams - According to the 2009’s IC3 Internet Crime Report, advance fee fraud represented 9.8% of all complaints. The percentage is naturally much higher due to the unknown number of people that didn’t report the fraud. Largely underestimated as a serious threat, lottery scams usually cost a small fortune to the affected victim. And due to their targeted nature — the majority are sent manually and usually originate from Africa based IPs — the scammers often succeed in tricking the gullible user. Once the user, now victim, is hooked, the “Winning Notification” slowly transforms into a advance fee based fraud, where in order to obtain the millions that you never really won, you would need to send back a decent amount of money. Don’t.
Blackhat SEO (Search Engine Optimization) campaigns serving scareware - Blackhat SEO, involves the process of on purposely hijacking trending buzz story across the web, in order to capitalize on the hijacked traffic by serving client-side exploits, or most commonly scareware. There’s a common misunderstanding regarding blackhat SEO campaigns these days, with a large number of users thinking that a cybercriminal is manually monitoring these trending topics in order to hijack them. Which is not true, since the process is semi-automatic, in fact on the majority of occasions they aren’t even aware that they’re targeting a particular topic.
Spamvertised fraudulent offers, phishing attempts - According to the 2009’s IC3 Internet Crime Report, non-delivery of merchandise and/or payment represented 11.9% of all the complaints. Moreover, the scammers are also well known for keeping track of different promotions, which they can easily brandjack and attempt to obtain sensitive data from the affected users. One of these examples is Visa’s “Go Fans” campaign - “Phishing samples spammers are targeting the Visa brand, which is one of the six global FIFA partners. Visa announced a “Go Fans” promotion offer in which card holders get the chance to win a trip to South Africa to experience the 2010 World Cup matches. Aware of the fan frenzy involved with watching live World Cup games, phishers are in the right (albeit criminal) business of trying to make money out if it.“

Risk mitigation strategies
Targeted malware attacks serving client-side exploits - With malicious PDFs representing such a high percentage of the exploits used, perhaps an alternative PDF reader such as the Foxit Reader, is worth considering. As well as: taking care of outdated third-party applications in combination with NoScript and least privilege accounts, or complete sandboxing/isolated web browsing, in order to ensure that what happens in the sandbox, stays in the sandbox.
419/Lottery Scams - Although the professional layout of these messages is improving, perhaps the single most important mitigation strategy, one that no software vendor can provide you with, is the lack of gullibility when someone tells you that you’ve just won 1 million dollars. Don’t be naive, and once you spot the scam, consider reporting it.
Blackhat SEO (Search Engine Optimization) campaigns serving scareware - The protection tips for mitigating client-side exploits serving campaigns, fully apply to the scareware threat. For additional information on what exactly scareware/rogue security software is, and how to protect from it, consider going through the “The ultimate guide to scareware protection“.
Spamvertised fraudulent offers, phishing attempts - despite the fact that millions of people admit they click and interact with spam/phishing emails, these emails are not longer 100% fraud oriented, but often as the first touch point for a targeted client-side exploits serving campaign. Therefore, avoiding any interaction with them, next to reporting them as spam, is highly recommended.