63
How to Move Your Data Center To A Cloud Infrastructure January 22, 2014 Chris Brenton Director of Security

How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

  • View
    480

  • Download
    0

Embed Size (px)

DESCRIPTION

Dyn Director of Security Chris Brenton prepared these slides as part of a webinar on how to move your data center to the cloud.

Citation preview

Page 1: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

How to Move Your Data CenterTo A Cloud InfrastructureJanuary 22, 2014

Chris BrentonDirector of Security

Page 2: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 2 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Your Presenter

Chris Brenton - Director of Security@Chris_Brenton

[email protected]

Page 3: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 3 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What We’ll Cover

• Background on industry trends

• Strengths and weaknesses of each cloud

service and deployment model

• Security options

Page 4: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 4 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

New Era of Computing

• Mainframe/mini = Generation 1

• PC client/server = Generation 2

• Hybrid cloud = Generation 3– No single deployment model– Hit its stride in 2010

Page 5: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 5 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

An Automotive Analogy• The 1960s:

o Easy to work ono Extremely inefficient (poor power and mileage)

Page 6: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 6 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

An Automotive Analogy• The 1980’s:

o Change fluids and that’s about ito 50% improvement in power and

mileage

Page 7: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 7 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

An Automotive Analogy• The 2000s:

o Outsource just about everything to specialists

o 200%+ improvement in power and mileage

Page 8: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 8 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Private or Public Cloud Infrastructure?

• Private -- Do it all yourself

o You maintain control and all responsibility

o You need to staff accordinglyo Greater flexibility

Page 9: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 9 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Private or Public Cloud Infrastructure?

• Public -- Outsource to specialists

o Easier to focus on core product(s)o Less staffing concernso Speed of scale

Page 10: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 10 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Definitions: Tenant and Provider

• Tenanto Entity consuming the resource(s)o This could be your customerso This could be other internal workgroups

Page 11: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 11 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Definitions: Tenant and Provider

• Providero Entity managing the resource(s)o This could be your Operations

groupo This could be a 3rd party company

Page 12: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 12 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Gen2 Computing

Page 13: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 13 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Gen3 Computing

Page 14: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 14 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Gen3 Computing SMB

Page 15: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 15 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Déjà vu – Laptops As A Model• We’ve dealt with mobile workloads in the past

Page 16: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 16 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Déjà vu – Laptops As A Model• We’ve dealt with mobile workloads in the past

• Workstations used to only reside on desks

Page 17: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 17 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Déjà vu – Laptops As A Model• We’ve dealt with mobile workloads in the past

• Workstations used to only reside on desks• Laptops opened up the possibility of working

from anywhere

Page 18: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 18 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Déjà vu – Laptops As A Model• Security needed to change from being network

based to host based

Page 19: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 19 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Déjà vu – Laptops As A Model• Security needed to change from being network

based to host based

• Expect similar to occur with mobile workloads– Shared resources means host based

technology must be reworked prior to use

Page 20: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 20 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Models

• Infrastructure as a Service (IaaS)o Provider supplies platformo Tenant loads OS and all apps

Page 21: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 21 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Models

• Platform as a Service (PaaS)o Provider supplies platform and stacko Tenant provides custom apps

Page 22: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 22 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Models

• Software as a Service (SaaS)o Provider supplies OS, stack and appso Tenant hits the ground running

Page 23: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 23 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Model Examples• IaaS

o Amazon Web Services (AWS)o Rackspace Cloud Hosting

Page 24: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 24 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Model Examples• IaaS

o Amazon Web Services (AWS)o Rackspace Cloud Hosting

• PaaSo Original Microsoft Azureo VMware Cloud Foundry

Page 25: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 25 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Cloud Model Examples• SaaS

o Dyno Salesforce

Page 26: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 26 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Deployment Model Tradeoffs

• IaaSo Provider generates the lowest level

environmento More work for tenant to deploy appo More tenant control to implement

security

Page 27: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 27 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Deployment Model Tradeoffs• SaaS

o Nearly turnkey solution for app deploymento Least amount of tenant control and

flexibility

Page 28: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 28 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Deployment Model Tradeoffs• PaaS

o Sits in the middle

Page 29: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 29 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Delineation of Responsibility

Page 30: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 30 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What Are My Security Options?

Page 31: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 31 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Extending The LAN Into The Cloud

Page 32: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 32 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

LAN Extended Challenges• Increases load on corporate link

o Today we’re mobileo Limits public cloud scaling

• Increase load on perimeter infrastructure

Page 33: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 33 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

LAN Extended Challenges• Negates network benefits

o Provider load balancingo Multi-peer pointso Geo-location DNS o Higher latency

• No protection within virtual infrastructure

Page 34: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 34 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Virtual Appliance Management

Page 35: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 35 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Virtual Appliance Architecture

Page 36: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 36 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What About Introspection?

• Hypervisor based securityo Has visibility into all VMs

Page 37: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 37 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What About Introspection?

• Hypervisor based securityo Has visibility into all VMs

• Single point of managemento For a specific hypervisor deployment

Page 38: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 38 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What About Introspection?

• Do you want other tenants to have access to your hypervisor?

Page 39: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 39 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

What About Introspection?

• Do you want other tenants to have access to your hypervisor?

• Do you want your provider to have non-auditable access to your VMs?o Can break segregation of duties

Page 40: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 40 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Host-Based Architecture

Consistent architecture (and risk abatement) regardless of deployment

Page 41: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 41 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Why Host Based Firewalls?

• Tenant controlled– Provider gains no additional access

Page 42: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 42 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Why Host Based Firewalls?

• Tenant controlled– Provider gains no additional access

• Supported across all cloud infrastructures

Page 43: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 43 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Why Host Based Firewalls?

• Tenant controlled– Provider gains no additional access

• Supported across all cloud infrastructures• Consistent management across all cloud

deployments

Page 44: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 44 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Why Host Based Firewalls?

• Tenant controlled– Provider gains no additional access

• Supported across all cloud infrastructures• Consistent management across all cloud

deployments• Security is portable with the VM

Page 45: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 45 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Why Host Based Firewalls?

• Tenant controlled– Provider gains no additional access

• Supported across all cloud infrastructures• Consistent management across all cloud

deployments• Security is portable with the VM• Mitigate potential risks from vswitch or VLANs

Page 46: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 46 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Consistency is Key to Security• Customization is common in small

business

Page 47: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 47 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Consistency is Key to Security• Customization is common in small business

• Focus is on getting the product to market– “We’ll worry about maintaining it later”

Page 48: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 48 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Consistency is Key to Security• Enterprise needs to play “the long game”

Page 49: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 49 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Consistency is Key to Security• Enterprise needs to play “the long game”

• “Snowflakes” can be an inhibitoro Reduces available resources for

innovationo Can easily stunt an organizations

ability to scale

Page 50: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 50 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

One Off Server Deployment

Page 51: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 51 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

VM Cloning

Page 52: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 52 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Clones Should All Have• Patches to the same level

Page 53: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 53 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Clones Should All Have• Patches to the same level

• Identical configuration settings

Page 54: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 54 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Clones Should All Have• Patches to the same level

• Identical configuration settings• Same system accounts

Page 55: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 55 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Clones Should All Have• Patches to the same level

• Identical configuration settings• Same system accounts• The same processes running in

memory

Page 56: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 56 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Clones Should All Have• Patches to the same level

• Identical configuration settings• Same system accounts• The same processes running in

memory• Usually no reason to logon– Update master and re-clone

Page 57: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 57 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

VM Clone Security = Spot The Difference Game

Page 58: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 58 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Spot The Difference

GoldMaster

Has an additionallistening port open

Page 59: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 59 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

GoldMaster

1 login successfulon first try

Spot The Difference

Page 60: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 60 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Spot The Difference

GoldMaster

Missing 3 patches Missing 3 patches

Missing 3 patches

Page 61: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 61 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

VM Clone Security

• Can identify positive exceptions, not just negative ones

oSuccessful logino Increased patch level

Page 62: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 62 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

VM Clone Security

• Can simplify server securityo No more one off auditing!o Far easier to ID variations that matter

Page 63: How To Move Your Data Center To The Cloud - Chris Brenton of Dyn

Pg. 63 How to Move Your Data Center to a Cloud Infrastructure @chris_brenton

Questions?

Chris Brenton - Director of Security@Chris_Brenton

[email protected]