The Virtualization Practice

Cloud Computing

Cloud Computing focuses upon how to construct, secure, manage, monitor and use public IaaS, PaaS, and SaaS clouds. Major areas of focus include barriers to cloud adoption, progress on the part of cloud vendors in removing those barriers, where the line of responsibility is drawn between the cloud vendor and the customer for each of IaaS, PaaS and SaaS clouds, ...
as well as the management tools that are essential to deploy in the cloud, ensure security in the cloud and ensure the performance of applications running in the cloud. Covered vendors include Amazon, VMware, AFORE, CloudSidekick, CloudPhysics, ElasticBox, Hotlink, New Relic, Prelert, Puppet Labs and Virtustream.

CloudComputing

EMC VSPEX is a converged infrastructure offering targeting private clouds offered through EMC and VMware VAR’s. This focus upon the channel makes this the first “private cloud in a box” that is explicitly designed for VAR’s and SI’s to take to their mid-market customers. As such the potential for such an offering is huge. However it is highly likely that the success of VSPEX will be clouded by EMC’s less than stellar track record with the channel, and the complete absence of management software from the offering.

podio

Citrix acquire Podio – Podio’s focus is to provide a platform for small/medium sized organisations to get up and running with standard business function applications offered from Podio’s own App Store. Does this mark the a Citrix foray to better accomodate mobility and consumerisation while stepping outside the microsoft windows desktop delivery environment.

CloudComputing

While at InfoSec World 2012’s summit on Cloud and Virtualization Security, the first talk was on Securing your data. The second was on penetration testing to ensure that data was secure. In essence it has always been about the data but there is a huge difference between what a tenant can do and what the cloud or virtual environment provider can do with respect to data protection and security. This gap is apparently becoming wider instead of smaller as we try to understand tenant vs cloud provider security scopes. There is a lack of transparency with respect to security, but at the same time there are movements to gain that transparency. But secret sauces, scopes, legislation, and lack of knowledge seem to be getting in the way.

CloudComputing

There is a difference between outsourcing layers of your infrastructure and making the organization to whom you have outsourced those layers responsible for them, and losing all rights to change those layers in support of your business and application needs. Careful contract and product decisions need to be made in order to ensure that when you used a managed cloud service, you are not giving up the control you need to be agile and responsive to you business constituents.

CloudComputing

VMware’s Project Octopus and others like ownCloud and Oxygen Cloud have stirred some interesting ideas about Application Security. Those applications that make use of SSL, nearly every web application, can make use of secure data storage for certificate verification means. What makes SSL MiTM attacks possible, is mostly related to poor certificate management. If there was a way to alleviate the need for the user to be involved in this security decision, then SSL MiTM attacks would be significantly reduced.

ApplicationVirtualization

Numecent believe Cloudpaging has the potential to impact all connected devices where software needs to be delivered rapidly and securely. Cloudpaging isn;t just a fancy marketing term for a re-branded application virtualisation. Numecent have delivered a new application delivery technology that is poised to open up a new application delivery mechanism not only for enterprises, but for both ISVs and MSPs.

Speaking-at-RSAC-2012-small

The 3/8 Virtualization Security Podcast held a discussion on the happenings as the 2012 RSA Conference in San Francisco as well as a discussion of the features of Bitdefender’s entry into the virtualization and cloud space with their SVE product. RSA Conference high lights not just those security tools for the virtualization and cloud spaces but the entire industry and each year there is always a common theme. Was there one this year? Was there any surprises at the conference?