New services enforce security in the public cloud

Opinion
Feb 11, 20115 mins

In Gartner’s 2011 CIO Agenda survey, 43% of CIOs say that within four years they expect to have the majority of their IT running in the cloud or on SaaS technologies. Before they can put their applications in the cloud, they need to address the issues of security and compliance. Traditional tools don’t migrate well to the public cloud. Now there are new services from startup CloudPassage that get to the heart of security on replicated virtual servers.

In Gartner’s 2011 CIO Agenda survey, just 3% of the CIOs surveyed say the majority of their IT operations are in the cloud today. Looking ahead, 43% say that within four years they expect to have the majority of their IT running in the cloud on Infrastructure-as-a-Service (IaaS) or on Software-as-a-Services (SaaS) technologies. That’s a pretty aggressive adoption rate, largely driven by the need to lower costs and increase agility.

Nevertheless, security and compliance remain major challenges to the adoption of public cloud infrastructure services. In particular, the highly dynamic nature of cloud computing makes it rather difficult to manage virtual servers to assure that they are all properly configured and protected.

In a virtual environment, servers are essentially just another file and set of metadata that can be easily copied, migrated, and stored for use at another time and place.  This elasticity provides organizations with the ability to “cloudburst,” or to expand the number of servers and available compute power within minutes.

However, cloudbursting significantly increases the risk of compromise.  As a virtual server is replicated, any inbred vulnerabilities and exposures, such as misconfigurations, malware and viruses, are also copied onto new server instances.  One improperly configured or infected server could multiply during cloning to become the Typhoid Mary of the cloud farm.

Unfortunately, traditional security tactics don’t migrate well to the public cloud. For example, perimeter security depends heavily on control over the network factors, such as IP addressing, physical topology and routing. Users of IaaS services don’t have the luxury of behind-the-firewall control, and it’s not possible to use network-level IDS or IPS or wire-level UTM mechanisms in these environments. Because the performance implications of each cloud server performing traffic inspection are staggering, IaaS vendors simply don’t allow it.

At the same time, the typical IaaS usage agreement states that the user of the service – not the provider – is responsible for protecting virtual servers, applications and data in the cloud. This essentially includes everything from the virtual machine OS upward in the stack. Clearly there is a need to bridge the gap between traditional perimeter-oriented data center security and the security available today in dynamic cloud environments.

This is the space that newly launched CloudPassage steps into.  (See Security start-up offers free, cloud-based firewall, server-vulnerability services.) CloudPassage offers server security and compliance solutions specifically for the dynamic IaaS cloud operating environment.

The company’s initial functionality offering includes configuration and vulnerability management with its Halo SVM (Server Vulnerability Management) solution and centralized management of host-based firewalls with its Halo Firewall solution. Both of these solutions are themselves cloud based services.

The heart of CloudPassage’s technology is the Halo Daemon and a cloud based analytic control (Halo) Grid.

The eyes and ears of the Halo architecture is the Halo Daemon, which is installed on both the cloud servers and the Halo Grid.  The daemon is a 2MB agent that is the two way communication medium to both the server and the host based firewall.  Further, the daemon performs the server vulnerability assessments and it does so without violating IaaS agreements by silently gathering security and configuration information about the server for secure transfer back to the Halo Grid.

The Halo Grid is the central manager and secure communication pathway for all installed daemons. The grid also performs the heavy compute cycles that are used to continuously monitor and correlate server configurations with security policies and vulnerability assessments.    

The administrator’s interface to the Halo suite is through the Halo Portal, which is a cloud based server farm that manages the both the Halo SVM and Halo Firewall products.

The Halo SVM handles vulnerability scanning, configuration issues, and policy compliance.  It performs the scanning from inside the server using the Halo Daemon so IaaS subscribers don’t have to skirt around the issue of the service provider not permitting remote scans.

The Halo Firewall centrally manages host based firewalls, and handles real-time policy changes, updates, and administrative tasks for large scale IP table management.  Also, when servers are added or moved, Halo Firewall automatically updates the individual host based firewall configurations. This is a nice feature to comply with IaaS vendors’ recommendation to leverage IP tables within the host based firewall.  

The fundamentals of security are critical no matter where a company hosts its IT operations. By implementing this outside-the-firewall security best practice provided by CloudPassage, organizations can extend their traditional behind-the-firewall security and control functionality to cloud hosted applications.  

CloudPassage is offering to let customers try the services for free. Get the details at http://www.cloudpassage.com/try-it.  

Brian Musthaler is a Principal Consultant with Essential Solutions Corporation.  You can write to him at Bmusthaler@essential-iws.com.  

About Essential Solutions:  Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive.  Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.