Security from the Cloud vs. Securing The Cloud

Opinion
Dec 10, 20092 mins

Two sides to the story

There are two sides to the cloud security discussion: Securing cloud services and security as a cloud service (SecaaS). SecaaS (like Software as a Service) changes the economics of enterprise security by offering fee-for-service billing and limited or no upfront capital expense (CapEx). Given that 35% of organizations tell us their IT budget is shrinking, anything that reduces CapEx is highly desirable in today’s tight economic climate. SecaaS providers leverage the cloud for three primary purposes: global knowledge, managed security and cloud computing. Global knowledge services aggregate millions of security-relevant data points to deliver reputation-based services such as anti-spam, anti-virus, anti-malware and web browsing protection. Examples include BlueCoat’s WebPulse, Trend Micro’s Smart Protection Network and Websense’s ThreatSeeker network. For managed security we’re seeing traditional on-premise security services such as firewall and IDS moving into the cloud. For example, both AT&T and Savvis offer managed firewalls in the cloud. Compared to on-premise, this type of service provides greater resilience against DDoS and lowers bandwidth requirements. Finally, there are services (for good and bad) emerging that leverage cloud compute services. Just this week WPA Cracker hit the market with a penetration testing service; it runs dictionary attacks against Wi-Fi Protected Access (WPA) Pre-Shared Keys (PSK). The “attack” runs in the cloud in 20 minutes, something that would take five days on a dual-core PC.

The key take-away is regardless of the type of SecaaS, vendors are turning the advantages of the cloud for scale, resilience, and visibility into an attractive economic model.