The Definition of Cloud Computing

What is the cloud and why should I go there?
The transition to cloud services offers major opportunities for your organisation. Significant scalability, flexibility and cost-efficiency can all be achieved through the adoption of cloud-based solutions. Migrating to the cloud can be a scary prospect for many organizations. In fact, the question is often asked: What actually is cloud computing, and why do I need to go there? Drawing on our consultants’ wealth of knowledge, we have put together a comprehensive definition of cloud computing, outlining how to get the best out of this new technology.

Cloud Computing Defined
On Demand Self Service
At the touch of a button your cloud environment should be there for you. For example, if your IT team were to come under pressure to add or change software, platforms or infrastructure and make them available to your users, they should be able to make these additions instantly. It’s an instant access environment provision.

Ubiquitous Network Access
This is the beauty of cloud – you can access it from anywhere via the Internet. You don’t need any specialized ingress point into your environment; it’s readily accessible for anyone with Internet access. You can access it anytime, from anywhere. This benefit is crucial to all aspects of your organization. All your team needs is an Internet connection and they can log in and use all their enterprise applications and systems, including all their data and resources from any location. This can be vital for remote workers, such as salespeople on the road who are trying to close that quarter-defining sale.

There are risks with this of course; companies need to keep control of who has access to the cloud and what data they are able to access. The benefits that come from having ease of access also create risks. Our experts regularly work with organizations to define the criticality of their data and then categorize it, based on their requirements. It’s important to apply controls to your environment to ensure the right people are accessing the right data.

Location Transparent Resource Pooling
The cloud allows you to pool your resources, so an organization can exploit its assets 24 hours a day. By pooling your resources in a cloud you can utilize your software, platforms and infrastructure through shared services, allowing your users to get the most out of your assets. Pooling strategies include the likes of data storage services, processing services and bandwidth provision services. This provides huge economies of scale for organisations and provides the means to really embrace the global office. As your workforce shuts down for the day on one side of the world, your team on the other side can get up and continue working from the same platforms, applications and infrastructure. The cloud allows you to sweat your assets from anywhere.

Rapid Elasticity
The beauty of being in the cloud is the ability to scale up and scale down your infrastructure at a moment’s notice. The ability to auto-scale in the cloud eliminates much of the risk associated with scoping requirements for technology projects. With traditional environments on premise, if you under-scope the design for an environment and the demands on it prove higher than expected, you lose revenue. Conversely, if you over-scope and sales are lower than expected, you increase costs unnecessarily. The ability to scale your infrastructure at will allows you to design environments with a degree of confidence not available with traditional models.

Once again, this benefit comes with its own risks. It’s imperative that this is monitored on a regular basis. The ease of scaling up and down environments brings financial rewards but also heightens the risk. If an environment is scaled up to meet peak demand and left as such when it’s not needed, this can have negative implications.

Proper, consistent management of this service is the key to success.

Measured Pay Per Use
When in the cloud, you only pay for what you use. This means you can offset your operational savings against your capital expenditure and truly reap the financial benefits. Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service. In addition, this allows for a much more predictable and closely-controlled method of financial accounting, moving from Cap-Ex to Op-Ex budgeting.

Ross Spelman, Group Technical Services Manager, Espion

[Cloud Security Alliance Blog]

Let’s Not Pit Broader Privacy Concerns Against Security in the EU

In an age where information is power, crowdsourcing threat data is a powerful tool to inhibit the attackers’ opportunity. The quicker we uncover and understand attacks and how they work, the faster we can prevent them.

Yet, at present, much broader privacy concerns can be an inhibitor that could keep us behind the pace of the attacker. All too often, I see people start to look at their feet as privacy in the EU overrides thought processes.  Ironic that, by not collaborating, potentially we leave ourselves more exposed to attackers, who all too often aim to steal private information.  When we get into “the why, the what, and the how” of threat information gathering and collaboration, perceptions typically change. My challenge to each of you is to understand the details and not let broader privacy debates unduly influence your perspective on the value of cyberthreat information collaboration. 

To want to share, we need to recognize the value sharing brings, which is to identify new attacks faster and be better enabled to prevent impact to users’ systems and personal information. It’s important to remember that cybersecurity is developed to protect you and your information.

So, what data is required to discover threats? When I started in the industry, customers would send threat samples to us via courier.  With the increasing speed and volume of attacks, we have been driven to automate the process. The Internet provided the mechanism to shorten submission times and leverages CPU scale to reduce the time to analyze, thereby increasing the volume of samples that can be processed.

As attacks have become increasingly unique and complex, what’s needed to analyze an attack now is often more than just a singular file; it often requires knowledge of environmental specifics and commonly may need to maintain communication with the attack source to function.  What we should recognize is that, typically, attacks are external connections into the business.

Today, good security vendors provide choices as to whether you do the initial threat analysis on your own premises or leverage the CPU capacity of the cloud. Ideally, either way, the intelligence gathered on the attack needs to be passed back to allow other customers to be able to detect the attack as well. How would you feel knowing that a breach could have been stopped, but those who knew about it chose not to share their insight? The more attack intelligence we build, the more we can quickly and accurately detect the next iteration that we know will come down the road.

Now, imagine the insights available if all of the key vendors were to collaborate at a technology level. This is exactly what responsible cyberthreat information sharing does today – between customers and security vendors, among security vendors.  Take, for example, the Cyber Threat Alliance (CTA), instigated between key security vendors at a technology level. This group was formed with the aim of sharing threat intelligence for the purpose of improving defenses against advanced cyber adversaries across member organizations and their customers. Its goal is to gain broader insight into attacks more rapidly, so prevention controls can be applied faster. Effectively, we can outpower the attackers, making the cost of success much harder. No longer would a quick recompile of the attack binary or new phishing subject line succeed. The entire lifecycle of the attack would need to be genuinely unique for the attributes (Indicators of Compromise) not to be recognized. We would effectively be crowdsourcing at a technology level the ability to discover and, therefore, prevent attacks.

In Europe, data privacy is a contentious topic. We are in danger of becoming nations of skeptics that see it as easier not to share than to trust. Yet the EU Network Information Security directive includes a requirement for national cooperation plans around threat intelligence, so there is a clear recognition at a nation level to collaborate to better prevent cyberattacks. Both are important topics for society, yet we are in danger of the emotional aspects of the privacy debate overshadowing our need to collaborate.

Here are three of the questions I am frequently asked and my perspective on them (and I challenge you to reflect on these and build your own views):

1. Do you understand what threat information your security solutions are capturing in order to understand and qualify if there is a privacy concern?

Take as the example the attack binary – its external code – so there shouldn’t be privacy concerns there. The cynical retort, however, would be that the attacker may embed this in an internal document to increase the likelihood of users opening it. I would challenge that, if the attacker can do this, the data in question is no longer private.

Session information is also extremely valuable for identifying and understanding the attack.  Considering the attacker is typically external, this data is typically being passed over the Internet, as the attack communicates with the victim, and, as such, is not private data.  The key point here is to challenge your vendor to share exactly what data is passed back to the cloud. Most are increasingly giving very granular policy control on just what you choose to share. In my experience, all are open to disclosing this and have technical documentation to validate it.

2. Where does threat information and the intelligence go?

Typically, many want to ensure cloud data resides in the EU to reduce regulatory complications.  As such, security companies are now building on-premises filter points to complete the initial localized analysis and clouds in the EU to help with this requirement. However we should recognize that most attackers do not work within limitations of geographic boundaries, so, to be effective, even though the raw information is gathered and analyzed within the EU, the intelligence from it (the detection capabilities generated from the analysis) must be shared globally to succeed. How frustrated would you be if the response was “we knew about that attack but couldn’t share the data, as we didn’t trust your country”?

3. How can I trust my security company?

It seems people want to be skeptical about security providers. The topic used to be whether vendors write the attacks; now, it’s whether they are spying on their customers.  You could ask the same of your postal or courier service – how do you know that they don’t open all of your parcels and letters?  The short answer is that we must have some level of trust in their ability to deliver on the services they each provide. The same goes for the security industry. Being transparent with each other on what, how and why threat information is gathered, but also allowing each customer flexibility in how they contribute, is a core component in maintaining that trust.

In a world where new threats appear every second but the rudimentary techniques used change very slowly, attackers succeed by making their attacks chameleon-like. If we simply look for the color of the skin, we fail. Yet, if we can go beneath the skin, the characteristics are more detailed and consistent.

To beat the attacker, we have to get under the skin of the attack, and through crowdsourced cloud collaboration, we have the CPU power to achieve this and outperform them.  The UK Cyber Information Sharing Partnership (CISP.org), which I’m proud to be a part of, has shown clear value in sharing threat information between like organizations.

To collaborate, we need to ensure we understand the specific requirements and the value we receive from being part of the security threat intelligence community.  We need to be pragmatic and not let the current emotional responses around broader privacy concerns unduly influence our decision to beat the attacker and so assure our information.

[Palo Alto Networks Blog]

English
Exit mobile version