[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Cloud Security. Tampilkan semua postingan
Tampilkan postingan dengan label Cloud Security. Tampilkan semua postingan

06/10/11

Amazon adds free encryption to storage service

Server Side Encryption protects data stored in Amazon's data center

Using Amazon Web Services' new Server Side Encryption feature, enterprises will at no extra cost be able to encrypt data stored on the company's Simple Storage Service (S3), Amazon said on Tuesday.

The Server Side Encryption feature has been added to simplify the process of protecting data stored on S3. Previously, enterprises had to choose an encryption algorithm, create and store keys, and adapt applications to ensure that all data was encrypted and decrypted for every operation. Now users can leave that to Amazon. The Server Side Encryption feature handles all encryption, decryption, and key management transparently, according to a blog post.

[ Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

The data is encrypted when an extra header is added when writing an object to S3. Each object is encrypted with a unique key. As an additional safeguard, this key itself is encrypted with a regularly rotated master key. The encryption algorithm Amazon uses is AES-256, it said.

Enterprises can start to take advantage of Server Side Encryption using Amazon's Management Console and the S3 API.

That Amazon added encryption on its servers isn't terribly exciting, according to Swedish security expert Jakob Schlyter. The feature would help protect data if someone managed to break into one of Amazon's data centers, and steal a disk that stored company data. That has to be weighed against what would happen if something went wrong with Amazon's key management, and data was lost because of that, Schlyter said, and added that he would still use client-side encryption.

On Tuesday, Amazon also said that the number of objects stored on S3 increased to 566 billion during the third quarter of this year, after reaching 262 billion objects during the last quarter of 2010.

 

Read More...

20/09/11

Cloud Security Needs Continuous Monitoring to Reassure Enterprises, Panel Says

Cloud computingSAN FRANCISCO--A panel of cloud providers and enterprise security professionals said that in order to make enterprise security teams feel more comfortable giving up their data, cloud providers need to be more transparent and open about the security measures and processes they have in place to protect that data. Those assurances , they said, need to go beyond the current point-in-time assessments and move to more meaningful continuous monitoring processes.

Cloud computing is continuing to gain ground in enterprises in many industries, as well as with smaller businesses that are eager to save money and off-load some of their work load to providers who may have more security expertise on staff. However, one of the common complaints among users is that they don't have as much visibility into the way things work at cloud providers as they'd like, not only in terms of their own data, but also in terms of what the providers do to secure their infrastructures.

"Cloud providers are a black box. You can't get visibility. Traditional technology transfer of security into the cloud is one of the gaps we need to focus on," said Rich Tener, director of security at Zynga, during the panel discussion at the United Security Summit here Monday.

"The question is, which black box is more secure than the others?  It's a risk-tolerance game, depending on how secure they are, it's a question of how much risk you can tolerate when you're putting your data in there with them.  We need a way to have a standard, controlled risk view of which providers are riskier than others."

Google, which provides cloud service to millions of consumers as well as large enterprises, through a variety of offerings, spends a lot of time talking to those customers about the security of their data and what steps the company takes to ensure its availability and integrity, said Eran Feigenbaum, director of security for Google Apps. But, he emphasized that there's room for improvement.

"Continuous monitoring is something we can improve on, I'll be very honest," Feigenbaum said. "Every customer deserves the highest level of security. Whether you're a free Gmail user or a large enterprise that's paying us millions of dollars, you get the same level of security. That'show it should be. "

Both Feigenbaum and Tener said that there are circumstances under which public cloud providers can provide a definite security advantage over traditional on-premises security services. But it's not always clear to customers when that's true.

"Cloud can be as secure, if not more secure, than what most organizations do today. The main difference is scale, the scale of doing things right and what happens if something goes wrong, because we have a lot of people's data," Feigenbaum said. "We try to have self-healing systems that don't require human intervention. It's expecting systems to fail and having systems in place to fix and heal those when it happens."

"Public cloud providers can definitely be more secure, but it depends where they are in the security lifecycle," Tener said. "The problem is, it varies. How are they doing security internally? You have to go through that vetting process. I judge the maturity of their security the same way I'd judge mine."

nb : threatpost Read More...

14/09/11

VMware releases free Compliance Checker tool

The tool compares vSphere 4.1 hosts with VMware's Security Hardening Guide

VMware has released a new version of its Compliance Checker tool, which allows IT staff to to test the security of its vSphere 4.1 hosts, the company said in a blog post on Tuesday.

The tool is meant to help users get started on the "trusted cloud," according to George Gerchow, director of VMware's Center for Policy & Compliance.

[ Doing server virtualization right is not so simple. InfoWorld's expert contributors show you how to get it right in this 24-page "Server Virtualization Deep Dive" PDF guide. | Use server virtualization to get highly reliable failover at a fraction of the usual cost. Find out how in InfoWorld's High Availability Virtualization Deep Dive PDF special report. ]

The security assessment done by Compliance Checker is based on a predefined subset of the rules in the vSphere 4.1 Security Hardening Guide, a 113-page document published by VMware in April.

The tool determines if the ESX firewall is correctly configured and if the vSphere Web Access feature has been disabled, for example. The resulting report includes the rules, descriptions of them and the success or failure of each rule, according to the blog post.

To make sure that configuration changes don't open up doors for hackers, the tool can be used over and over again.

The Compliance Checker is based on VMware's vCenter Configuration Manager, which allows enterprises to automate configuration management across virtual as well as physical servers, workstations and desktops.

nb : .infoworld
Read More...