How Data Security Can Vaporize in the Cloud

While cloud computing services offer a way to lower costs and offload basic server and storage maintenance to companies that purport to have expertise, it also presents dramatic security and legal challenges that should be considered before signing up.

By Lucas Mearian

Thu, October 15, 2009Computerworld PHOENIX -- While hosted cloud computing may be all the rage for reducing cost of ownership and management, IT managers say hosted storage services present dramatic security challenges and legal implications that need to be considered.

Cloud Security: Danger (and Opportunity) Ahead
Cloud Computing Definitions and Solutions

Arthur Lessard, chief information security officer at toy manufacturer Mattel Inc., in El Segundo, Calif., said during a presentation at Storage Networking World on Wednesday that cloud computing is appealing, even if many end users don't know what the word "cloud" means. For example, many confuse cloud computing with pure server and storage virtualization or simply backing up data to a remote site.

True cloud services should be characterized by grid-architected hosts with central management, applications that can be ported seamlessly from system to system, capacity that is easily provisioned and significant data redundancy, he said.

"We're talking software as a service," Lessard said.

When storage is hosted offsite in a virtualized server and disk array environment, cloud computing presents real limitations around authentication, and auditing - especially auditing of logging. The lack of auditing capabilities may affect the ability to record user logins, administrative actions and data writes, Lessard said.

"What I can't find out is who has been reading the data files, and ... depending on what business you're in, that might be important," he said.

There is also not usually any indication of login anomalies, such as repetitive attempts to log into your site under an incorrect name and password. That information is kept by the vendor and is usually part of a contract negotiation process. With respect to authentication, or who sets up the accounts and what control you have over accounts and how they're provisioned, most vendors offer self-registration into your applications, "and that can have holes," Lessard said.

"Most authentication in a cloud environment is done through user name and password only, so if I had a nifty two-factor authentication set up or biometrics, it's no longer offered," he said.

Most service provider also have restrictions against penetration testing of the cloud by their customers.

"To be honest, I can't blame the vendor because by doing penetration testing against their environment for your applications, it could impact someone else's applications," he said. "Remember, it's a cloud, and you don't have a lot of control over where my stuff is running or where it sits."

Hackers can also exploit security holds associated with hardware and software cloning in virtual server environments. Most operating systems have unique or personalized components when they're installed on hardware, and the OSes rely on the hardware to generate random numbers for public and private encryption key pairs and user IDs, even when they're being cloned onto new systems.

Microsoft

Loading...
Data Center MarketSpace
Addressing Log Management Shortfalls
High performance, affordable log and security event management technology is rapidly evolving. Learn more »
Maximize PC Energy & Cost Savings in a Windows 7 World
This desktop upgrade presents organizations with a unique opportunity to reduce energy waste. Learn more »
Respond to changing business challenges faster with SOA
This white paper shows how a service oriented architecture (SOA) helps align the infrastructure with business needs in order to achieve maximum flexibility. Learn more »
 
SPONSORED LINKS
 

Consolidate data centers and lower IT service costs. Learn How.

State of the Data Integration Market

Take the Netezza TwinFin TestDrive!

Best Practices to Reduce IT Operational Costs

Maximizing efficiencies with unified communications.

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Does your IDS really work? Find out with a free Endace Audit

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

Trend Micro ranked #1 against real-world malware. Read more.

AT&T Application Management & Hosting. Let us help you STRETCH

Microsofts new client operating system helped Pella reduce power consumption.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

WAN optimization techniques significantly improve application performance. Read More.

What's Next for Enterprise Resource Planning?

Gartner Magic Quadrant, Application Delivery Controllers 2009

Adobe® LiveCycle® solutions for business process automation

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

Enhance Customer Loyalty through Higher Responsiveness

Cloud Computing: The Impact CIOs See

Verint Systems. Discover the Power of Intelligence in Action"

Let Progress Software help your business make progress.

Efficiency goes up. Costs come down.

Global Research: CIOs Weigh In On Virtualization

Taking the Service Desk to the Next Level

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

See why ShoreTel is named best overall VoIP provider by Nemertes Research

Real-world testing ranks Trend Micro #1 against malware. See results.

Forrester: The real-world financial impact of Windows 7

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Stay informed with custom newsletters from Tech Dispenser

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Ensure cost effective application delivery. Learn More.

The Revolution and Evolution of Private Cloud Computing

ROI of Application Delivery Controllers

Enterprise Capture: Your Onramp to Business Process Automation

Adobe® LiveCycle®solutions for intuitive user experience

Unlocking the Mainframe: Modernizing Legacy System to SOA

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

 
 
RESOURCE CENTER