| By Jim Liddle | Article Rating: |
|
| September 24, 2009 12:30 PM EDT | Reads: |
1,180 |
Amazon Cloud Journal on Ulitzer
Following on from my last post, Securing Applications on the Amazon Elastic Cloud, One of the biggest questions I often see asked is “Is Amazon EC2 as a platform secure”? This is like saying is my vanilla network secure? As you do to your internal network you can take some steps to make the environment as secure as you can, such as:
- First read the Amazon Security Whitepaper and the Amazon discussion of Security processes
- Ensure the system key is encrypted at start-up
- Ensure you plan for load balancing in case an instance goes down. Ensure you understand all the security implications of this and harden any other instances.
- Test or emulate the performance of applications deployed to the cloud in all geographies where you plan to deploy them. The latency could vary greatly for each.
- Never ever allow password base authentication for shell access.
- Encrypt all network traffic always.
- Always encrypt everything stored on S3
- Encrypt file systems for Block devices
- Open only the minimum required ports
- Include no authentication information in any AMI images
- Think about how your system can be hardened and what is out there such asSELinux, PAX, ExecShield etc
- Don’t allows any decryption keys into the cloud – understand the perils of keys and security
- Install host based intrusion detection system such as OSSEC
- Regularly backup Amazon instances and store them securely.
- Use Security Groups. With EC2 security groups, you can completely isolate every tier, even internally to the EC2 cloud. Multiple security groups can be used to lock down the ports and you can use a special security group to allow in-group communication
- Design in a way you can issue security patches to AMI instances
- If you are using private data off-cloud consider Amazon VPC, OpenVPN, or VPN-Cubed
Syndicated from my Cloud Blog.
Read the original blog entry...
Published September 24, 2009 Reads 1,180
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Jim Liddle
Jim is Managing Director of Jana Technology Services and UK Director of Sales and Operations for GigaSpaces. Jim is a regular blogger at SYS-CON.com, covering mobile, Grid, and Cloud Computing Topics.
- The Top 150 Players in Cloud Computing
- 4th International Cloud Computing Conference & Expo Starts Today
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- Exclusive Q&A with Rich Marcello - Unisys President, Systems & Technology
- The Economics of Cloud Computing Analyzed
- Industry Experts Discuss the State of Cloud Computing
- CIA was Headed to an Enterprise Cloud All Along: Jill Tummler Singer
- Publishing Synergy: Blog, Twitter and Ulitzer
- Akamai Named “Silver Sponsor” of Cloud Computing Expo
- Cloud Computing Expo: Exclusive Q&A with Yahoo! SVP Cloud Computing
- Cloud Computing on Gartner's Top 10 List and SYS-CON Events' 2010 Calendar
- Cloud Expo New York Call for Papers Deadline December 15
- The Top 150 Players in Cloud Computing
- 4th International Cloud Computing Conference & Expo Starts Today
- Cloud CEOs, CTOs & SVPs to Speak at 4th International Cloud Computing Expo
- Yahoo! Named “Platinum Sponsor” of Cloud Computing Expo
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- SYS-CON.TV: Cloud Computing Expo Power Panel
- Exclusive Q&A with Rich Marcello - Unisys President, Systems & Technology
- The Economics of Cloud Computing Analyzed
- Unisys Named “Platinum Sponsor” of Cloud Computing Expo
- 1st Annual GovIT Expo: Letter from the Technical Chair
- Deputy CIO of the CIA to Keynote 1st Annual GovIT Expo
- Industry Experts Discuss the State of Cloud Computing
- Virtualization Conference Keynote Webcast Live on SYS-CON.TV
- The Top 150 Players in Cloud Computing
- SOA 2 Point Oh No!
- The Top 250 Players in the Cloud Computing Ecosystem
- What is Cloud Computing?
- Cloud Computing Expo Europe 2009 in Prague: Themes & Topics
- IBM's Got Its Head in the Clouds
- Cloud Computing Expo 2009 West: Call for Papers Now Closed
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- As Google's SaaS Assault Begins, Move Over Microsoft Office?
- From Enterprise to Cloud, Virtualization Today on SYS-CON.TV
- Twenty-One Experts Define Cloud Computing
































