securing a public cloud infrastructure : windows azure

38

Upload: vivekbhat

Post on 02-Nov-2014

1.014 views

Category:

Technology


1 download

DESCRIPTION

Securing a public cloud infrastructure: Windows Azure

TRANSCRIPT

Page 1: Securing a public cloud infrastructure : Windows Azure
Page 2: Securing a public cloud infrastructure : Windows Azure
Page 3: Securing a public cloud infrastructure : Windows Azure
Page 4: Securing a public cloud infrastructure : Windows Azure
Page 5: Securing a public cloud infrastructure : Windows Azure
Page 6: Securing a public cloud infrastructure : Windows Azure

Source: Saugatuck Technology Inc., 2009 Cloud Infrastructure Survey (Julne09), WW N=670

Saugatuck Insight:

Saugatuck believes

that many users will

find that changes

required in internal

organization and

politics for moving

from dedicated to

shared resources

pose significant

challenges to the

adoption of Cloud

Computing.

Page 7: Securing a public cloud infrastructure : Windows Azure

Security Privacy

Reliability Business Practice

Questions

Is your service secure?

Are you ISO 27001

certified?

Jurisdiction?

Have you ever had a

service outage?

Do you have performance

SLA?

Do you have an incident response plan?

Do you have SAS Type II Report?

Do you provide 24*7 support?

Are you HIPAA compliant?

How do you ensure data

isolation?

Data retention?

Page 8: Securing a public cloud infrastructure : Windows Azure

location ownership control

Page 9: Securing a public cloud infrastructure : Windows Azure
Page 10: Securing a public cloud infrastructure : Windows Azure

10

Page 11: Securing a public cloud infrastructure : Windows Azure

Hybrid Public Private

SaaS Software as a Service

PaaS Platform as a Service

IaaS Infrastructure as a Service

Page 12: Securing a public cloud infrastructure : Windows Azure

Spoofing Tampering &

Disclosure

Port Scanning/

Service

Enumeration

Elevation of

Privilege

Load-balanced

Infrastructure

Network

bandwidth

throttling

Configurable

scale-out

Denial of

Service

Service Definition

file, Windows

Firewall, VM switch

packet filtering

VM switch

hardening

Certificate

Services

Shared-Access

Signatures

HTTPS

Sidechannel

protections

VLANs

Top of Rack

Switches

Custom packet

filtering

Partial Trust

Runtime

Hypervisor

custom

sandboxing

Virtual Service

Accounts

Page 13: Securing a public cloud infrastructure : Windows Azure
Page 14: Securing a public cloud infrastructure : Windows Azure
Page 15: Securing a public cloud infrastructure : Windows Azure
Page 16: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Customer Admin Users

External Web Site

Physical Attacks

On Servers Central Admin

Page 17: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Customer Admin Users

Physical Attacks On Servers

Page 18: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Central Admin

Page 19: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Customer Admin Users

Page 20: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Users

Page 21: Securing a public cloud infrastructure : Windows Azure

Windows Azure

Customer Tenant

Customer Admin

Page 22: Securing a public cloud infrastructure : Windows Azure

Managed Code

Access Security:

partial trust

Windows Account:

running with least

privileges

Windows FW (VM):

rules based on service

model

Virtual Machine: fixed

CPU, memory, disk

resources Root Partition Packet

Filter: defense in

depth against VM

“jailbreaking”

Network ACLs: dedicated VLANS for tenant nodes

22

Page 23: Securing a public cloud infrastructure : Windows Azure
Page 24: Securing a public cloud infrastructure : Windows Azure
Page 25: Securing a public cloud infrastructure : Windows Azure

Hypervisor

Network/Disk

R

o

o

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

G

u

e

s

t

V

M

Page 26: Securing a public cloud infrastructure : Windows Azure
Page 27: Securing a public cloud infrastructure : Windows Azure
Page 28: Securing a public cloud infrastructure : Windows Azure
Page 29: Securing a public cloud infrastructure : Windows Azure
Page 30: Securing a public cloud infrastructure : Windows Azure
Page 31: Securing a public cloud infrastructure : Windows Azure
Page 32: Securing a public cloud infrastructure : Windows Azure
Page 33: Securing a public cloud infrastructure : Windows Azure
Page 34: Securing a public cloud infrastructure : Windows Azure
Page 35: Securing a public cloud infrastructure : Windows Azure

Service security starts with the data center

Data center within a data center

Motion sensors

24×7 secured access

Biometric controlled access systems

Video camera surveillance

Security breach alarms

World-Class Security

Page 36: Securing a public cloud infrastructure : Windows Azure
Page 37: Securing a public cloud infrastructure : Windows Azure

1 .Windows Azure Security Overview

2. TechNet Webcast - Windows Azure Security - A

Peek Under the Hood (Level 100)

3. MSDN Webcast - Security Talk - Using Windows

Azure Storage Securely (Level 200)

4. Securing Microsoft's Cloud Infrastructure

Page 38: Securing a public cloud infrastructure : Windows Azure