Welcome!

@CloudExpo Authors: Elizabeth White, Pat Romanski, Liz McMillan, Ed Featherston, Yeshim Deniz

Related Topics: @CloudExpo, Cloud Security, @ThingsExpo

@CloudExpo: Article

Iron-Clad Cloud Networks By @JamesCarlini | @CloudExpo #IoT #Cloud

‘In the Age of Nanokrieg© and cyberattacks, hardening Intelligent Infrastructure and Mission Critical Networks is a must’

Iron-Clad Cloud Networks and Defending Against Nanokrieg©

Today, most enterprises have some type of cloud-based solutions or are looking at cloud-based infrastructure for some of their enterprise applications. What is lacking in many organizations is the strategic design focus and sophisticated implementation for very secure infrastructure which not susceptible to cyberattacks.

Hardening data centers as well as enterprise networks (and clouds) is a critical step to ensure an organization's business continuity. Forget "disaster recovery" as it is a dated term and dated concept. Disaster recovery refers to the organized shutdown of systems and then when the disaster (event) is over, a systematic restart of the total application is initiated.

In today's business environment, many organizations cannot survive if their applications are out-of-service for a couple of days. Business continuity, where enterprise operations continue through the episode of the disaster, is a more robust design approach to system and network resiliency.

Disaster recovery is a dated term like data processing. More resilient systems, which are not susceptible to disasters and outages, are what should be planned and designed, especially for any organization's mission critical applications.

The Internet of Things (IoT) Is Only as Good as the Internet of Reality
I have said this in previous columns, "The Internet of Things is only as good as the Internet of Reality: the Network Infrastructure." Too many IT executives buy off on glossy brochures and catchy buzz-phrases about the "Internet of Things" spun out by the "P.T. Barnum-like", vendor evangelists in their corporate-logo golf shirts.

IT execs, who are not asking hard questions as to the "resiliency and robustness" of some of the inter-workings these cloud products, will be the first ones suffering when their organizations is exposed as having a data leak, a network failure, or a loss of all customer records and credit card information due to a cyberattack. Of course, this also applies to government systems and networks as well.

If the corporate (or government) network infrastructure is not fully protected or resilient from cyberattacks and other threats, the functionality of its cloud will be compromised whether it is a public or private cloud.

Why is this so important? If you are looking at any cloud-based computing, it better be bulletproof especially if it is carrying time-sensitive mission critical applications for your enterprise or information deemed private and confidential (like customer credit card information or health records).

One cloud feature missing in financial networks which I have pointed out in the past is Cloud Transaction Synchronicity ©. Basically, this is the total traffic synchronization of ALL transactions being sent across within a cloud. This should be a traffic monitoring service available in any cloud application.

This would guarantee a much higher and comprehensive level of compliance within the boundaries of the SEC (Securities and Exchange Commission), FINRA (Financial Industry Regulatory Authority) as well as other regulatory bodies within the financial and brokerage area. By having this timing synchronization embedded into the total network infrastructure of a cloud, it would guarantee the ability to re-construct the transaction sequence in any major drop or jump in the velocity and value of transactions processed. It would be able to provide exact sequencing of transactions and where they originated from, which in today's cloud networks is not a functional capability of any network utilizing HFT servers (High Frequency Trading).

Without having this type of diagnostic capability, no cloud network offers what is really needed to be able to re-construct and diagnose the sequence of transactions occurred in a market crash scenario like the one that happened in 2010. (The 1000 Point Drop of the Dow)

Testing the Design for Resiliency: Have You Really Thought It Out?
Many senior executives talk about building network clouds and using them to offer various applications to users in both closed networks (private clouds) and open networks (public clouds).

Have these clouds been thoroughly tested and thought through? One of the major networks being discussed today is the First Responder Network, FirstNet. It is supposed to be a government network that has many capabilities for municipalities. One of its flaws that I see is there is no mention of being EMP-proof throughout the network. They need to incorporate that capability into their RFP and the design spec.

EMP attacks are a real possibility. With the rise in terrorist attacks and a country's national economy viewed as a viable target, it makes sense to harden both data centers and their networks to a standard where EMP attacks are nullified (http://www.thefederalistpapers.org/us/emp-attack-on-us-power-grid-could-kill-9-in-10-americans):

As the Heritage Foundation has reported, an EMP attack with a warhead detonated 25 to 300 miles above the U.S. mainland "would fundamentally change the world:"

"Airplanes would fall from the sky; most cars would be inoperable; electrical devices would fail. Water, sewer and electrical networks would fail simultaneously. Systems of banking, energy, transportation, food production and delivery, water, emergency services and even cyberspace would collapse."

Is your data center susceptible to an EMP attack? (Electro-Mechanical Pulse bomb) Are your network EMP-proof? If you are dealing with a third party supplying a data center capability and/or a private cloud, are they EMP proof?

These are questions to have fully answered before you embark on building out any enterprise or third party-supplied, cloud network or data center supporting any mission critical application.


Carlini's upcoming book on Military Infrastructure, Strategies & Tactics for the War on Terrorism, Nanokrieg Beyond Blitzkrieg, will be out in 2016.

His visionary book, Location Location Connectivity is available on AMAZON.

Follow daily Carlini-isms at www.TWITTER.com/JAMESCARLINI

Copyright 2015 - James Carlini

More Stories By James Carlini

James Carlini, MBA, a certified Infrastructure Consultant, keynote speaker and former award-winning Adjunct Professor at Northwestern University, has advised on mission-critical networks. Clients include the Chicago Mercantile Exchange, GLOBEX, and City of Chicago’s 911 Center. An expert witness in civil and federal courts on network infrastructure, he has worked with AT&T, Sprint and others.

Follow daily Carlini-isms at www.twitter.com/JAMESCARLINI

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
Today most companies are adopting or evaluating container technology - Docker in particular - to speed up application deployment, drive down cost, ease management and make application delivery more flexible overall. As with most new architectures, this dream takes significant work to become a reality. Even when you do get your application componentized enough and packaged properly, there are still challenges for DevOps teams to making the shift to continuous delivery and achieving that reducti...
SYS-CON Events announced today that Interface Corporation will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Interface Corporation is a company developing, manufacturing and marketing high quality and wide variety of industrial computers and interface modules such as PCIs and PCI express. For more information, visit http://www.i...
SYS-CON Events announced today that mruby Forum will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. mruby is the lightweight implementation of the Ruby language. We introduce mruby and the mruby IoT framework that enhances development productivity. For more information, visit http://forum.mruby.org/.
In his session at @ThingsExpo, Greg Gorman is the Director, IoT Developer Ecosystem, Watson IoT, will provide a short tutorial on Node-RED, a Node.js-based programming tool for wiring together hardware devices, APIs and online services in new and interesting ways. It provides a browser-based editor that makes it easy to wire together flows using a wide range of nodes in the palette that can be deployed to its runtime in a single-click. There is a large library of contributed nodes that help so...
What is the best strategy for selecting the right offshore company for your business? In his session at 21st Cloud Expo, Alan Winters, U.S. Head of Business Development at MobiDev, will discuss the things to look for - positive and negative - in evaluating your options. He will also discuss how to maximize productivity with your offshore developers. Before you start your search, clearly understand your business needs and how that impacts software choices.
IBM helps FinTechs and financial services companies build and monetize cognitive-enabled financial services apps quickly and at scale. Hosted on IBM Bluemix, IBM’s platform builds in customer insights, regulatory compliance analytics and security to help reduce development time and testing. In his session at 21st Cloud Expo, Lennart Frantzell, a Developer Advocate with IBM, will discuss how these tools simplify the time-consuming tasks of selection, mapping and data integration, allowing devel...
SYS-CON Events announced today that Cedexis will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Cedexis is the leader in data-driven enterprise global traffic management. Whether optimizing traffic through datacenters, clouds, CDNs, or any combination, Cedexis solutions drive quality and cost-effectiveness.
SYS-CON Events announced today that Mobile Create USA will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Mobile Create USA Inc. is an MVNO-based business model that uses portable communication devices and cellular-based infrastructure in the development, sales, operation and mobile communications systems incorporating GPS capabi...
While some developers care passionately about how data centers and clouds are architected, for most, it is only the end result that matters. To the majority of companies, technology exists to solve a business problem, and only delivers value when it is solving that problem. 2017 brings the mainstream adoption of containers for production workloads. In his session at 21st Cloud Expo, Ben McCormack, VP of Operations at Evernote, will discuss how data centers of the future will be managed, how th...
Why Federal cloud? What is in Federal Clouds and integrations? This session will identify the process and the FedRAMP initiative. But is it sufficient? What is the remedy for keeping abreast of cutting-edge technology? In his session at 21st Cloud Expo, Rasananda Behera will examine the proposed solutions: Private or public or hybrid cloud Responsible governing bodies How can we accomplish?
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
SYS-CON Events announced today that Keisoku Research Consultant Co. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Keisoku Research Consultant, Co. offers research and consulting in a wide range of civil engineering-related fields from information construction to preservation of cultural properties. For more information, vi...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
Most of the time there is a lot of work involved to move to the cloud, and most of that isn't really related to AWS or Azure or Google Cloud. Before we talk about public cloud vendors and DevOps tools, there are usually several technical and non-technical challenges that are connected to it and that every company needs to solve to move to the cloud. In his session at 21st Cloud Expo, Stefano Bellasio, CEO and founder of Cloud Academy Inc., will discuss what the tools, disciplines, and cultural...
SYS-CON Events announced today that Enroute Lab will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enroute Lab is an industrial design, research and development company of unmanned robotic vehicle system. For more information, please visit http://elab.co.jp/.
SYS-CON Events announced today that Ryobi Systems will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Ryobi Systems Co., Ltd., as an information service company, specialized in business support for local governments and medical industry. We are challenging to achive the precision farming with AI. For more information, visit http:...
Today traditional IT approaches leverage well-architected compute/networking domains to control what applications can access what data, and how. DevOps includes rapid application development/deployment leveraging concepts like containerization, third-party sourced applications and databases. Such applications need access to production data for its test and iteration cycles. Data Security? That sounds like a roadblock to DevOps vs. protecting the crown jewels to those in IT.
21st International Cloud Expo, taking place October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Me...
SYS-CON Events announced today that Fusic will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Fusic Co. provides mocks as virtual IoT devices. You can customize mocks, and get any amount of data at any time in your test. For more information, visit https://fusic.co.jp/english/.
The “Digital Era” is forcing us to engage with new methods to build, operate and maintain applications. This transformation also implies an evolution to more and more intelligent applications to better engage with the customers, while creating significant market differentiators. In both cases, the cloud has become a key enabler to embrace this digital revolution. So, moving to the cloud is no longer the question; the new questions are HOW and WHEN. To make this equation even more complex, most ...