Wednesday 15 October 2014

Day2-Research on hybrid cloud/cloud security

Started research on hybrid cloud and cloud security.

Some useful papers:

Hybrid cloud storage
http://www.storsimple.com/Portals/65157/docs/ESG-White-Paper-Microsoft-HCS-Nov-2013.pdf

Hybrid cloud security - VMware
www.frost.com/prod/servlet/cpo/272112250

Research on public cloud provider - openstack
https://openstack.cloudenci.ie/horizon

The vCloud Cloudburst Architecture Model:

ref: http://download3.vmware.com/vcat/documentation-center/Cloud%20Bursting/7%20Cloud%20Bursting.pdf



This picture accurately represents the cloudburst monitoring model which we are trying to achieve.


The security model:


1. use the security model (CSA 3.0)
2. Put port rules in place (firewalls)
3. Secure the site(s) - Certs/https
4. Encrypt relevant data (in the db) with certs
5. Run a pentest/hacking test


Next Steps:

Brief - All

circulate before the weekend - Ying
complete

Research

Compliance

1. Security - Jeff - ongoing
2. Infrastructure (Arch) - Ying - ongoing
3. Options for Private/Public - Richie - Confirmed - AWS to Azure

Tech

1. Orchestrator - Jeff - going (autoscaling between the 2 clouds)
2. Load Balancer - Richie/Jeff - AWS Load balancer
3. Firewall - Ying - hold off
4. Alerting system - Ying - aws alerting system
5. App - Richie - figure out how to get the app up. 
6. Connectors - Jeff - vpn - needs more


Azure
1. Orchestrator - Ying 
2. Load Balancer - Richie/Jeff - AWS Load balancer - investigate
3. Firewall - Ying - hold off
4. Alerting system - Ying - aws alerting system/azure alerting systems.
5. App - Richie - figure out how to get the app up. - Richie
6. Connectors - richie/jeff/ying - vpn - need more - need to do it.


New tasks
1. Investigate monitoring
2. Automatically deploy to the cloud
3.



Others
Running eucalyptus locally - jeff
vmware - richie





Project compliance:
Design - 15%

Tasks - write the arguments for each of the 2 private cloud models
1. Capacity (new vm requested) Richie
2. Load (auto scale) Ying/Jeff

Implementation of private cloud
Provision of public cloud
Implementation and documentation of private could
Demonstration of private cloud

Security
Approach and project planning
Selection of tools/methodologies/frameworks/benchmarking
technical testing approach
findings and risk rating
challenges and limitations

No comments:

Post a Comment