Once installed and configured, administrators are able to apply firewall rules and policies to any connection that can access public, private or hybrid cloud services. A small (3MB) security daemon works with CloudPassage’s computing grid to enforce rules, policy and monitor for intrusions.
CloudPassage also has added a physical aspect to cloud security such as a USB key that creates a one-time password for each session. This also may become a trend as time goes on.
Tighter security like this is becoming mandatory, with all the system break-ins that seem to be happening more frequently around the world.
“When people look at adding security to a cloud system, they generally think they’re buying a slice of something,””CloudPassage founder and CEO Carson Sweet told eWEEK. “So now we’re doing full-blown dynamic firewall management, multi-cloud. We’re going to cross-cloud (systems) now, so we can have servers in EC2 (Amazon’s Elastic Compute Cloud), in Rackspace and in Terremark with one policy over all of them. The most interesting aspect of all of this continues to be that it all just works in the cloud.”
Security doesn’t work the same way in public and private cloud environments as it does in on-site data centres.
“When individual servers, especially in a cloud system, become vulnerable, you can clone those things so fast. And when you clone one of those servers, you’re also cloning every vulnerability,” Sweet said. “Pretty soon, a big cloud server farm can begin to look like a chunk of Swiss cheese. You replicate the problems along with the actual server.”
As an example, Sweet told of one legendary cloud server he knew about “that was just plopped out there. We called it Typhoid Mary because when that started to get replicated, it was really bad news.” He wasn’t at liberty to tell exactly which system was affected, but it was a large one—and it became a huge mess, he said.
“The interesting thing is that we have gotten away with this in the data centre for years, because of the firewalls and other security on the hardware devices,” Sweet said. “But you can’t do that in the cloud.”
Crypto free for all? US Justice Department is disbanding team of prosecutors who targetted cryptocurrency…
US-sanctioned YMTC publishes nearly 20 memory patent applications, showcasing innovations in efficiency and chip construction
Battery giant CATL reportedly in talks to buy controlling stake in unit of EV maker…
Chinese EV giant BYD launches high-end Denza brand in Europe to compete with Mercedes, BMW…
US power companies say in some cases data centre requests exceed their peak demand or…
Some 2,000 support staff reportedly laid off as Microsoft ends China outsourcing deal with its…