Sunday, October 25, 2009

Amazon Web Services: file this under growing pains...

About a week (~ Oct 14th) Amazon Web Services (AWS) EC2 servers attempting to deliver business-critical emails were blocked or fatally rejected because AWS IP addresses were added to a blacklist by Spamhaus.org. Problem resolved.

Not very pleasant for companies providing business-class mail server hosting on AWS.

Oct 15th AWS worked with Spamhaus to remove all EC2 ranges from their PBLs.

The latest from Amazon Oct 21st:

“It is our intention to make it easy to reliably send email from the EC2 environment. As a result of our experience last week, we have released some changes to improve the ability of valid users to send email from EC2. We have started a new thread with the details of the improvement we have made: http://developer.amazonwebservices.com/connect/thread.jspa?threadID=37650. Please let me know if you have any further issues or questions”

Saturday, October 24, 2009

The workhorse technology behind cloud computing is virtualization. Get to know it well.

The magic pixie dust that makes a cloud a cloud is virtualization technology. The trick is to decouple the physical world of fixed hardware where one computer can behave as though it were many. Where your workspace is in the cloud and all you need is a Netbook (maybe an exaggeration).

One of the more curious aspects of virtualization is the “virtual machine”. It is most affiliated with data-center server virtualization. A virtual machine is nothing more than a file that represents its physical counterparts. No hardware to purchase. No shipping fees. No wires to plug-in. (For those readers that are experts on virtualization, please forgive the oversimplification.)

Hundreds of virtual machines are likely working in earnest inside your own organization. And yes, you are likely your very own cloud provider.

All those virtual machines are important to your business. They can run your email system, your expense reporting application or your customer portal.

So let’s briefly look at some of the ways that the virtual world of servers is vastly different than the physical one.

We are familiar with our laptops going to sleep. (and waking up with a hang-over). How about if 10, 20 or 30 virtual machine go to sleep and wake up at varying times. Will all occurrences of a virus be identified across running, suspended and shutdown virtual machines? Not likely a big deal issue. But its worth thinking about the implications of appropriately configuring the virus scan.

Relocating a physical server is back-breaking work. You pick it up, twist your neck and fall down. A virtual machine (after all it’s a file) can be made to zip across a network. Let’s think about that for a moment. What if it gets intercepted and lands in the wrong hands? A physical machine has to be carried into a facility. Is it easier for a virtual machine file that is not legit to find its way into your network? Not if you have policies in place to have a master or gold copies.

Another interesting property in the virtual world is time. A virtual machine has to keep time, if nothing else than to remind you of mum’s birthday. Time is important. It is used to time-stamp transactions. However timestamps written in log files can also be stomped upon by a perpetrator to mask their activities.

There are plenty of best practices to implement a safe and sound virtual infrastructure. Take a look at your policies and procedures to make certain they are available and executable. Some examples:

· Continue to protect the physical environment.
· Control who creates virtual machines
· Quality control must include real-time configuration management
· Consider encryption as an extra layer of protection for high-risk assets
· Get to know your virtualization technology and how it can be exposed

You can’t get into the virtual world without stepping through the physical world. However, things that happen in the virtual world are not a direct reflection of the physical world. Get savvy.

Wednesday, October 7, 2009

Google Apps: Here I Am

At Tech Labs we are constantly working to get to know all the major Cloud Computing providers and thier virtual wares. Microsoft, Salesforce.com and of course Google.

And Google is well on it’s way to building a reputation and trust that an enterprise can live with. The Google Apps web site already claims more than 1 million businesses running on the platform.

I sat down with one of our consultants to understand some of the details behind Google Apps and what it takes to properly implement the product for an enterprise.

Some of our conversation:

1. What is Google Apps - in your words?
Google Apps is a suite of products. You get Gmail, Talk, Calendar, Docs, and Sites - all of which are part of the $50/user/year licencing fee. Storage allocation is 25GB per user. The first foray for most clients is likely Gmail and Calendar and its not unusual to see "silent rollouts" of Google Docs and Googles Sites as collaboration tools.

2. Security is one of the benefits touted by using Google Apps? Explain.
Gartner estimates over 20,000 to 30,000 samples of potential malware are sent for analysis each day. And more than 5 million U.S. consumers lost money to phishing attacks during the 12 months ending in September 2008, a 39.8% increase over the number of victims a year earlier.

Gmail is likely to stay more up-to-date with email filters that can spot malicious file attachments and URL filters to inspect for exploits are vital. However even that line-of-defense will suffers from the delay in finding and blocking zero-day attacks. Other cyber security capabilities will be needed.

More than half of employees who left their companies in 2008 took some sensitive corporate data with them. Nearly 80% of these employees said that they knew it was against company policy to take the data, but they did it anyway (source: Ponemon Institute & Symantec). One source of data leakage is email messages that are used to exchange files loaded with hyper-sensitive information.

Google Apps store documents in the 'Cloud' and instead pass around hyperlinks which point to documents that can only be shared with those that you previously granted permissions. Google Message Discovery and Google Message Security offer security and archival features that advance compliance requirements.

Still questions abound such as government and regulatory compliance and service levels

2. Where do you think Google Apps is headed in the enterprise?
Google Apps lineage is of course consumer-focused, however it is evolving rapidly with each major release.

At the sametime it is still not as feature rich as existing offerings by mainstay vendor such as Microsoft.

Microsofts Business Productivity Online Suite (Microsoft BPOS) is appealing because it is available in both a pure SaaS model and a dedicated version. The advantages include custom security, adherance to compliance mandates and the ability to tailor features.

Google Apps is advertised is a SaaS offering ideally to avoid one-off deployments. Users only have the option to get the same release. A pure SaaS offering has to carely balance the desire to quickly mobilize new features and get them safely deployed into production.

Finally a key success factor to the roll out of Google Apps within an enterprise is to have a solid training and communications plan and strategy to allow for a smooth user adoption.

Thanks Jonathan Hsu!

Thursday, September 3, 2009

Cloud: Finding True North

I recently presented a workshop on cloud computing to a fairly large pharmaceutical company.
The discussion rolled and swayed across all ports. IT is still relevant. Cloud computing is a component of the business service management strategy. Virtualization and IT automation are stepping stones. We shared our insights from working with many large enterprises.

Towards the end of the session, you could tell the audience was eager to start searching for their own "true north" when it came to Cloud Computing. What's the best way to oriented with all the pundits, research and facts?

Joe Tobolski (Global Lead of Infrastructure at Accenture Technology Labs) hit the spot with these closing remarks and guiding principles:

  1. Cloud Computing Strategy is one component of your IT’s Business Service Management strategy -- they are not separate and distinct.
  2. There is no single approach to Cloud Computing – the market will remain highly fragmented.
  3. Carefully evaluate candidate applications and IT services that can take advantage of cloud computing. Applications that don’t horizontally scale internally will not give you cost savings if hosted externally on a cloud.
  4. There is an “asymmetrical cost” to go into a cloud and then transition out. Still, carefully plan your exit strategy.
  5. Security and compliance are not portable across clouds and internal IT – but don’t let that slow your approach to Cloud Computing. Pick a suitable application and get going.

Walid

Thursday, August 20, 2009

Hey Cloud - That's Mine, Now Give it Back


The specter of vendor lock-in by cloud service providers is clear as the driven snow: modified programming languages, proprietary API's and non-portable cloud services.


A recent speech by Vinton Cerf:
“…Each cloud is a system unto itself. There is no way to express the idea of exchanging information between distinct computing clouds because there is no way to express the idea of “another cloud.” Nor is there any way to describe the information that is to be exchanged. Moreover, if the information contained in one computing cloud is protected from access by any but authorized users, there is no way to express how that protection is provided and how information about it should be propagated to another cloud when the data is transferred.” – from a recent speech by Vinton Cerf


Cleanly extracting oneself from the clutches of a cloud service provider varies in pain. User lock-in is more of a compelling force as application functionality, code idioms, APIs, and aspects of the information system start to increasingly depend on Cloud provider specific services, such as transaction management , non-standard messaging and proprietary storage data formats.


Exit strategies will depend on the type of cloud service provider, and the underlying technologies used to provide those services. For infrastructure clouds, application code and configurations are self-provided; these applications are the property of the consumer. In some IaaS implementations, virtual machine portability provides migration of running application loads from Cloud provider to internal resources or to another Cloud provider.



The question of application portability becomes murkier as PaaS or SaaS offerings are used. In these cases, the cloud service provides the application’s basic architectural framework, which is usually tightly coupled to the underlying technical and operations infrastructure. De-coupling those applications is a difficult proposition, and may not be possible given intellectual property considerations. Its going to be tough to imagine these vendors agreeing on exposing thier black-box software generator with a standard programming model and interface. It will be important to consider data and process portability when utilizing PaaS and SaaS providers, and to allow for re-platforming or re-hosting if a transition is needed.

The steps to reclaim a system that has been designed, coded, tested and deployed using one or more cloud services will depend on where you plant your system components.

Here are some things to keep in mind as you seek a flexible relationship:

  • Typically, Cloud providers do not own Intellectual Property for artifacts developed or hosted within their IaaS platform; however, clear delineation of ownership is required to avoid potential future litigation.

  • Cloud services, by definition, should be loosely coupled

  • To reduce vendor dependency explore a hybrid approach whereby internal and external resources are implemented to fulfill a business requirement for mission critical or even secondary applications

  • Encapsulate provider specific integration points into core management and provisioning systems to isolate changes introduced by altering the sourcing model

  • Deploy run-time applications in a manner abstracted from underlying infrastructure and machine image

  • Build custom, standards based images capable of running on variety of standard platforms

  • Backups should also be machine independent

  • Carefully design application architecture and development techniques to minimize
  • Compliance to government mandates is not portable and neither are System certifications

  • Promote open standards

  • Put together a transition migration plan and test your cloud migration theories ...


Monday, July 20, 2009

Cloud Computing: The New Normal

Let's get the awkward moment out of the way and define cloud computing for the rest of our time together. Until it changes of course. Here goes. The top 3 cloud styles "of computing that provides on-demand access to a shared set of highly scalable services” (skip the drum roll)...will be:

  • Software-As-A-Service which gives you and I ready-made (fully finished) applications, on-line social networks and unified collaboration tools without the restriction of firewalls. Its what i call Power to the people.
  • Platform-As-A-Service means to shield the developer from installing anything and deploying nothing because the programming platform is out-of-sight and out-of-mind. If you've ever written code then this paradigms mantra is: Power to the developer.
  • Infrastructure-As-A-Service (Infrastructure Cloud) outsources servers, networks and ultimately the data-center and the icing on top is next generation technology for mass-web-application delivery. In other words: Power to the enterprise.
Accenture's point of view of cloud computing adds a fourth and necessary strata that bakes in the billion dollar business of business process outsourcing (BPO) [insert image here]

In this blog entry I wanted to talk a bit about Infrastructure clouds. These providers are at the bottom of the IT rung and have gotten a lot of attention in FY09. A CIO organization that I am intimately familiar with estimates more than $400,000 per year savings if they were to relocate a single seasonal application to an unnamed pay-per-use cloud provider whose name starts with the letter 'a'. Savings were calculated based on the server landscape and servers sizes (development and test, staging and production).

Infrastructure Clouds will happen incrementally and will eventually be the new normal. Dig deeper into the feasibility of moving an infrastructure capability outside of the enterprise and a lot is revealed in terms of pros & cons, pitfalls, issues & considerations. Substantial savings are possible and you can minimize your dependency on a static infrastructure. Amazon Web Services brings with it a pioneering pricing model that flexes with your variable capacity.

However ... opting for such an external Infrastructure Cloud route is more than a mentality - its about a business case and buy-in from stake-holders. Here are the 8 (they were 10 at some-point) issues & considerations list as you explore and assess your infrastructure computing play:

1. Calculating "hosting costs" of infrastructure clouds are the understatement of this year. A detailed cost of ownership is needed and one that honestly reveals the cost-benefit. Switching to anything new introduces complexity. And ongoing run/operational costs don't go away. After all "Linux (or Windows) boxes don't manage themselves". You must break-down the costs bottom-up.

2. Hidden constraints and technical cloud architectures. Memory hogging applications will more than frown upon standard virtual machine settings. Databases may require expensive (effort and cost) "re-partitioning" to fit the cloud providers paradigm. There are new data management formulas in town that maybe better suited. NimbusDB, Hadoop to name a few. To truly and honestly capture the benefits of elasticity (scale-at-will) you will also have to re-architect or "re-factor" your application for parallelism.

3. Cloudy Performance. Testing and benchmarking is needed to validate that your applications will run without loss of characteristics and won't drift into no-mans-land overtime. We have conducted internal evaluations of elastic load-balancing capabilities and I will share the results in a separate blog entry.

4. Understand liability of outsourcing the handling and processing of data. Uncertainty, fear and the veritable "not-invented here syndrome" can very swiftly put a wrench in any public cloud adventure. Early input from the security teams and legal organizations is a must. Do you know what your requirements are in the first place. Maybe its something from NIST or an ISO Standard. Does your risk & security models fit in a virtual, multi-tenant and massively scalable setting. If not a net-new risk assessment is the only sure-fire method to reveal show-stoppers and understand strategies to overcome concerns of storing and handling Personally Identifiable Information, your compliance obligations and on-going status. Lots more here in another blog post.

5. Bridge over troubled waters. Sorting out your options to talking back to the enterprise is dizzying. Licencing issues do not vanish with a public cloud. Appliance-based Virtual Private Network, software based virtual private clouds and other secure or dedicated network solutions are viable options. In another blog I will address some of the findings and observations vis-a-vis software and hardware Cloud VPNs.

6. In Cloud provider we "maybe" trust. One quickly realizes that a short duration, non-sensitive application won't get anybody fired it its loaded up on an infrastructure cloud. Start-up companies are running thier business on clouds every day. But not every organization is in risk-averse start-up mode, and most likely you author/owner, controllor or processor of intellectual property or private customer data. In any relationship one will have to determine what is gained and what is lost. Trust is about confidence on either side of that equation. You form and determine your degree of trust in a variety of ways including: credentials or identify of the provider, behaviour (e.g. transparency, qualifications) reputation in the market-place, history and track-record in the business, binding commitments in Service Level Agreement & terms of use.

7. Control & Governance . Sand-boxes, code promotion, deployment, service provisioning, service commissioning/De-Commissioning, service monitoring, backup, Disaster Recovery, charge backs. Just a smattering of the capabilities, services and tasks - in no particular order.

8. Security, Privacy and Compliance. Suffice to say, security will have a strong voice of its own in the decision to move to a Cloud. Willingness to trust the vendor is will get you to the starting gate. Standards and requirements will factor into both your risk tolerance and dictate if safeguards limit your exposure. New cyber-threats see an larger attack surface (lots of computers in one place). The attacks themselves are more sophisticated and looking into rear-view mirror is not sufficient. You will have to more like the new E-Class - anticipatory to the situation at hand. Cloud computing is neither brand new, nor a leap of faith.

Accenture believes the future IT infrastructure will be a combination of traditionally managed infrastructure and services sourced from IaaS, Platform as a Service (PaaS), and Software as a Service (SaaS) cloud providers. Bridging the gap between existing environments and operating models and differing Cloud offerings will require the enterprise to support highly virtual, dynamic environment conducive to cloud computing, while enabling automated provisioning and orchestration. An internal Cloud is not imaginary (more on that later) and the benefits but can be extended to external Cloud providers to obtain capacity, services, and data to reduce cost, increase speed to market, address capacity demands.

Our experience shows embracing a cloud model is substantially different than executing traditional Data Center models, from planning and acquisition through management and operations. It is generally counterproductive to re-engineer cloud infrastructure models to directly mirror traditional Data Center structures. While executing and integrating traditional management elements is essential, sourcing an external cloud computing model means ceding some architecture and infrastructure control. However, significant financial and flexibility benefits can be achieved by effectively harnessing and integrating the strongest aspects of traditional and cloud operation models.

Until we meet again....Walid Negm

Tuesday, July 14, 2009

A Social and Technical Phenomenon

Cloud computing is collaboration without the constraint of the firewall. It’s frictionless communication ala Twitter. Cloud computing is start-up experimentation at extremely low cost. First and fore-most an organization will need to determine the degree of trust it wants to place on a cloud provider. Will the cloud provider run the latest anti-virus software definitions? Do their routers and firewalls stand up to an onslaught of denial of service attack and network intrusions. Are the personnel given just the right administrative privileges and actions logged and audited?

CIO and CISO’s will have to grapple with the age old dilemma of access versus accessibility.