Welcome!

@CloudExpo Authors: Elizabeth White, Pat Romanski, Liz McMillan, Yeshim Deniz, Aruna Ravichandran

Related Topics: @CloudExpo, Java IoT, Microservices Expo, Microsoft Cloud, Containers Expo Blog, Cloud Security

@CloudExpo: Article

Size Doesn't Matter. Controlling Big Data Through Cloud Security

Beyond the buzzword: It's about complexity, variety, velocity and, yes, volume

There’s data. And then there’s BIG DATA. Many of us have been bombarded with the term in many frameworks. There are some professionals that chalk it up to marketing hype or meaningless buzzword. Personally, I prefer the way Gartner categorizes it. That it is more than size. It is a multi-dimensional model that includes complexity, variety, velocity and, yes, volume.

But the pressing issue with this definition of Big Data is how best to secure something so vast and multifaceted. If you recognize the old concept of a network perimeter is antiquated and dangerously narrow, there should be some concern as to corralling all this data and ensuring its transit and storage is protected. The latter issue speaks directly to compliance needs. Banks and other financial institutions, medical facilities, insurance, retailers and government entities are especially sensitive to the compliance requirements. However, if your business doesn’t fit into these verticals doesn’t mean you can’t directly benefit from cloud computing based security that creates the necessary context. And though your organization is dealing with an incredible mountain of data, you still must do what you can to ensure not only the proprietary intelligence behind your firewalls, but all the data trafficking in, around and through all various endpoints throughout the enterprise.

But again, size should not be the only consideration regarding Big Data. It is the means by which you analyze and apply various processes that allow you to make the best decisions possible about the ongoing security, accessibility and viability of all those many bits and bytes.

If you are looking at scale the McKinsey Global Institute estimates that “enterprises globally stored more than 7 exabytes of new data on disk drives in 2010, One exabyte of data is the equivalent of more than 4,000 times the information stored in the US Library of Congress. That’s a lot of data.

Storing is one thing, but analyzing and managing all the data into useful strategic and tactical outcomes now depends on the other elements of Big Data (complexity, variety, velocity). To do this successfully you have to have a means to put all of it into context. For instance, let’s say an account is accessed. It has the right user name/password credentialing and seeks to export some personal data or transfer funds, or change sensitive account settings. On its face you should allow this action. They have the right name and authentication. But when this is given greater context, there are dynamics from other silos of information that need to be factored. What is the device profile? URL reputation? Is the IP address consistent? When was last log in attempt? What time did this latest transaction occur? So, what seemed to be a reasonable transaction might shows patterns of anomalous behavior.

But here’s the larger issue—all these factors that play into determining true context (which I call situational awareness) may come from different sources and require a bit of juggling and cross-correlating. You have SIEM, Access Management, Log Management, and Identity Management. And they may all live on various servers in various places within the enterprise. So ensuring this process association is doable, but with so many layers and stacks, the results may take too long to take preventative measures. You know what they say about the horse having already left the barn.

By migrating security functions to the cloud (security-as-a-service) you still may run into these same issues unless you find a provider who can combine all the functionality and create the rules for cross-correlation that can normalize and sort through gargantuan amounts of data. A SIEM solution in the cloud is able to take raw data from a variety of sources, normalize it and create and manage the alerts, escalations and prevention protocols. Such a configuration takes the activity from Identity and access management silos, combines them with the silos of general traffic of web traffic, internal access, SaaS solutions and other business/consumer facing applications and generates a flexible and scalable intrusion detection matrix.

A fully-realized cloud-based SIEM deployment (which is much less expensive in the cloud, yet just as powerful as any on premise solution) can prevent an IP address in China from spoofing your customers account and create intelligence that deflects and notes if a Flame virus is being lobbed at your network. But a true cloud-based security partner worth their salt will also provide the raw data for post-capture analysis. This way you can analyze new traffic patterns, but more important create the baseline to make intelligent decisions for the long term security of your network or immediate recognitions of anomalous behavior. But all that raw data…that’s where the cloud gets you, right? You get penalized for having bigger and bigger data sets. Not if you have the right vendor. I personally know where you can get storage space for as little as $1 per gB per month. You can scale the amount and the type of data you wish to keep in the cloud. You control when it gets destroyed according to various compliance requirements. I also have some thoughts about vendors who provide the services, but require you to buy some appliance that you install and maintain on your network…but that’s a whole other blog.

The bottom line is Big Data can be managed given the right tools. And those tools do exist in the cloud and can be managed through the same. And when you have the right rules, passing though an integrated suite of security solutions you’ll begin to see that size doesn’t matter. What matters is creating a situational awareness that provides you a platform to make better decisions. And if that place is in the cloud…all the better.

More Stories By Kevin Nikkhoo

With more than 32 years of experience in information technology, and an extensive and successful entrepreneurial background, Kevin Nikkhoo is the CEO of the dynamic security-as-a-service startup Cloud Access. CloudAccess is at the forefront of the latest evolution of IT asset protection--the cloud.

Kevin holds a Bachelor of Science in Computer Engineering from McGill University, Master of Computer Engineering at California State University, Los Angeles, and an MBA from the University of Southern California with emphasis in entrepreneurial studies.

@CloudExpo Stories
The session is centered around the tracing of systems on cloud using technologies like ebpf. The goal is to talk about what this technology is all about and what purpose it serves. In his session at 21st Cloud Expo, Shashank Jain, Development Architect at SAP, will touch upon concepts of observability in the cloud and also some of the challenges we have. Generally most cloud-based monitoring tools capture details at a very granular level. To troubleshoot problems this might not be good enough.
The dynamic nature of the cloud means that change is a constant when it comes to modern cloud-based infrastructure. Delivering modern applications to end users, therefore, is a constantly shifting challenge. Delivery automation helps IT Ops teams ensure that apps are providing an optimal end user experience over hybrid-cloud and multi-cloud environments, no matter what the current state of the infrastructure is. To employ a delivery automation strategy that reflects your business rules, making r...
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software. They hope to capture value from emerging technologies such as IoT, SDN, and AI. Ultimately, irrespective of the vertical, it is about deriving value from independent software applications participating in an ecosystem as one comprehensive solution. In his session at @ThingsExpo, Kausik Sridhar, founder and CTO of Pulzze Systems, will discuss how given the magnitude of today's applicati...
Smart cities have the potential to change our lives at so many levels for citizens: less pollution, reduced parking obstacles, better health, education and more energy savings. Real-time data streaming and the Internet of Things (IoT) possess the power to turn this vision into a reality. However, most organizations today are building their data infrastructure to focus solely on addressing immediate business needs vs. a platform capable of quickly adapting emerging technologies to address future ...
Data scientists must access high-performance computing resources across a wide-area network. To achieve cloud-based HPC visualization, researchers must transfer datasets and visualization results efficiently. HPC clusters now compute GPU-accelerated visualization in the cloud cluster. To efficiently display results remotely, a high-performance, low-latency protocol transfers the display from the cluster to a remote desktop. Further, tools to easily mount remote datasets and efficiently transfer...
In a recent survey, Sumo Logic surveyed 1,500 customers who employ cloud services such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). According to the survey, a quarter of the respondents have already deployed Docker containers and nearly as many (23 percent) are employing the AWS Lambda serverless computing framework. It’s clear: serverless is here to stay. The adoption does come with some needed changes, within both application development and operations. Tha...
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, will lead you through the exciting evolution of the cloud. He'll look at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering ...
Companies are harnessing data in ways we once associated with science fiction. Analysts have access to a plethora of visualization and reporting tools, but considering the vast amount of data businesses collect and limitations of CPUs, end users are forced to design their structures and systems with limitations. Until now. As the cloud toolkit to analyze data has evolved, GPUs have stepped in to massively parallel SQL, visualization and machine learning.
We all know that end users experience the Internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices – not doing so will be a path to eventual b...
Enterprises are adopting Kubernetes to accelerate the development and the delivery of cloud-native applications. However, sharing a Kubernetes cluster between members of the same team can be challenging. And, sharing clusters across multiple teams is even harder. Kubernetes offers several constructs to help implement segmentation and isolation. However, these primitives can be complex to understand and apply. As a result, it’s becoming common for enterprises to end up with several clusters. Thi...
SYS-CON Events announced today that Taica will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TAZMO technology and development capabilities in the semiconductor and LCD-related manufacturing fields are among the best worldwide. For more information, visit https://www.tazmo.co.jp/en/.
SYS-CON Events announced today that TidalScale will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. TidalScale is the leading provider of Software-Defined Servers that bring flexibility to modern data centers by right-sizing servers on the fly to fit any data set or workload. TidalScale’s award-winning inverse hypervisor technology combines multiple commodity servers (including their ass...
SYS-CON Events announced today that Avere Systems, a leading provider of hybrid cloud enablement solutions, will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Avere Systems was created by file systems experts determined to reinvent storage by changing the way enterprises thought about and bought storage resources. With decades of experience behind the company’s founders, Avere got its ...
Microsoft Azure Container Services can be used for container deployment in a variety of ways including support for Orchestrators like Kubernetes, Docker Swarm and Mesos. However, the abstraction for app development that support application self-healing, scaling and so on may not be at the right level. Helm and Draft makes this a lot easier. In this primarily demo-driven session at @DevOpsSummit at 21st Cloud Expo, Raghavan "Rags" Srinivas, a Cloud Solutions Architect/Evangelist at Microsoft, wi...
The next XaaS is CICDaaS. Why? Because CICD saves developers a huge amount of time. CD is an especially great option for projects that require multiple and frequent contributions to be integrated. But… securing CICD best practices is an emerging, essential, yet little understood practice for DevOps teams and their Cloud Service Providers. The only way to get CICD to work in a highly secure environment takes collaboration, patience and persistence. Building CICD in the cloud requires rigorous ar...
Containers are rapidly finding their way into enterprise data centers, but change is difficult. How do enterprises transform their architecture with technologies like containers without losing the reliable components of their current solutions? In his session at @DevOpsSummit at 21st Cloud Expo, Tony Campbell, Director, Educational Services at CoreOS, will explore the challenges organizations are facing today as they move to containers and go over how Kubernetes applications can deploy with lega...
In his session at 21st Cloud Expo, Raju Shreewastava, founder of Big Data Trunk, will provide a fun and simple way to introduce Machine Leaning to anyone and everyone. Together we will solve a machine learning problem and find an easy way to be able to do machine learning without even coding. Raju Shreewastava is the founder of Big Data Trunk (www.BigDataTrunk.com), a Big Data Training and consulting firm with offices in the United States. He previously led the data warehouse/business intellige...
Today most companies are adopting or evaluating container technology - Docker in particular - to speed up application deployment, drive down cost, ease management and make application delivery more flexible overall. As with most new architectures, this dream takes significant work to become a reality. Even when you do get your application componentized enough and packaged properly, there are still challenges for DevOps teams to making the shift to continuous delivery and achieving that reducti...
As hybrid cloud becomes the de-facto standard mode of operation for most enterprises, new challenges arise on how to efficiently and economically share data across environments. In his session at 21st Cloud Expo, Dr. Allon Cohen, VP of Product at Elastifile, will explore new techniques and best practices that help enterprise IT benefit from the advantages of hybrid cloud environments by enabling data availability for both legacy enterprise and cloud-native mission critical applications. By rev...
SYS-CON Events announced today that Ryobi Systems will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Ryobi Systems Co., Ltd., as an information service company, specialized in business support for local governments and medical industry. We are challenging to achive the precision farming with AI. For more information, visit http:...