Study on the Security of Cloud Computing
February 26, 2010Not only does cloud computing help to save money, it also helps to increase IT security: Small and medium sized companies especially can profit from special cloud security solutions and the knowledge advantage of experienced providers. Large companies, however, should check thoroughly whether the terms of contract offer adequate security guarantees for the respective case, because failures and disruptions are not uncommon in cloud computing. These findings were the result from a study exploring the security risks of cloud computing carried out by the Fraunhofer Institute for Secure Information Technology (Germany).
The study provides an overview of prices and functions offered by the most important cloud providers and detailed risk assessments for various use cases.
The number of companies using cloud computing continues to increase and they are shifting their data, applications and business processes to server farms from providers such as Amazon, Google, IBM or Microsoft. Benefit: The companies do not have to purchase servers and software solutions themselves, but lease the necessary capacities for data, processing power and applications from professional providers. This saves money and effort and, furthermore, provides for high flexibility, because the activity of the leased service can be adjusted according to the customers needs.
But what happens in the case of a service failure? Who guarantees that the company secrets are secure on the external servers? Which security risks evolve when a cloud service subcontractor accesses the cloud systems? Is the data destroyed after deletion? These and similar questions should be resolved before a company decides if and what cloud service to use. The strategy of outsourcing into the cloud on the one hand allows the companies to concentrate on their core competencies and to develop new business opportunities. But on the other hand the dependency on external IT systems is increasing, and a failure of these systems due to technical failures, malware or hacker attacks may not only cripple communication but can disrupt even whole business or production processes.
"Almost every large cloud service provider had an incident in the past in the areas of availability or security“, reports Dr. Werner Streitberger, one of the study's authors. "The current offerings in cloud services show that especially in the area of infrastructure a number of security technologies have been applied already. The cloud providers have not yet advanced the support of security technologies as much in the areas of architecture, management and compliance.“
The SIT study showed that small and medium sized companies would be able to increase their security by using cloud services despite certain risks. "They can obtain security solutions as a service from a specialised provider and thus benefit from the provider's experience in the implementation and running of secure services“, explains Streitberger.
Large companies, however, should review a cloud provider's security functions individually and decide also on an individual basis, whether the supplied security mechanisms are sufficient for the specific requirement of the company. "The current cloud service offerings show that a number of security technologies are already in use at infrastructure level, but in the areas of application and platform, management and compliance, the cloud providers have not yet fully achieved the required protection targets“, Streitberger criticizes. The responsibility for the data usually remains with the cloud user, so he needs to define exact requirements how and which data may be stored and processed in a cloud service, and what security functions have to be in place.
The Service Level Agreement (SLA), i. e. the agreement about the rights and duties between the cloud user and the cloud provider, represent another weak point. The current customary agreements only provide minimal warranty for the quality of service for the cloud. Security guarantees exist rudimentarily and the functions necessary for the guarantees are insufficiently documented by the cloud provider. "Quite often security plays a secondary role in the offered service. We therefore recommend requesting detailed information about the cloud service from the various providers. A proof of concept may be a valuable option before using a cloud service in a production environment“, says Streitberger.
More information: The study can be ordered via the Internet at http://www.sit.fra … oud-security
-
Cisco offering computing cloud protection
Apr 21, 2009 |
not rated yet |
0
-
Sun Microsystems to offer 'public cloud' service
Mar 18, 2009 |
not rated yet |
0
-
IBM to Build First Cloud Computing Center in China
Feb 01, 2008 |
not rated yet |
0
-
IBM Unveils Industry's First Public Desktop Cloud
Aug 31, 2009 |
not rated yet |
0
-
US government takes leap into the Internet 'cloud'
Sep 15, 2009 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (30) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Calling function with no input argument
1 hour ago
-
Force free body diagram problem on gym equipment
2 hours ago
-
Empirical data regarding shower heads and water
10 hours ago
-
feed hold button on CNC lathe
Feb 09, 2012
-
RFAC in Fortran
Feb 09, 2012
-
dynamics 2/32
Feb 08, 2012
- More from Physics Forums - General Engineering
More news stories
Zuckerberg's focus drives Facebook's ascent
When Mark Zuckerberg showed up to rent Judy Fusco's Los Altos, Calif., house in the fall of 2004, soon after he'd arrived in Silicon Valley, the landlord was immediately struck by his confidence.
36 minutes ago |
1 / 5 (1) |
0
Netflix light on flicks as viewers soak up TV shows
Like most fresh faces that arrive in Hollywood, Netflix wanted to be a movie star. But now it's learning what many in Tinseltown have known for decades: Movies are sexy, but the real money is in television.
1 hour ago |
not rated yet |
1
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
4 hours ago |
5 / 5 (3) |
2
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
4 hours ago |
5 / 5 (6) |
10
|
Sony's Hirai refuses to abandon dire TV business
Struggling Japanese entertainment giant Sony will not abandon its cash-bleeding television business, its incoming CEO says, but he acknowledges tough decisions lie ahead including over redundancies.
2 hours ago |
not rated yet |
0
New understanding of DNA repair could eventually lead to cancer therapy
A research group in the Faculty of Medicine & Dentistry at the University of Alberta is hoping its latest discovery could one day be used to develop new therapies that target certain types of cancers.
Antidepressants and pregnancy: Women must consider the impact of drugs on baby, and of depression on baby, themselves
Upon learning they are pregnant, most women dutifully nix the alcohol, sushi and caffeine. But what about antidepressants?
Both maternal and paternal age linked to autism
Older maternal and paternal age are jointly associated with having a child with autism, according to a recently published study led by researchers at The University of Texas Health Science Center at Houston (UTHealth).
Night, weekend delivery OK for babies with birth defects
Weekday delivery is no better than night or weekend delivery for infants with birth defects, according to a new study presented today at The Pregnancy Meeting, the Society for Maternal-Fetal Medicine's annual conference. ...
Sonic Cradle lands spot in TED exhibition
A Simon Fraser University graduate student project that melds music, meditation and modern technology has landed a rare spot as an exhibit at TEDActive 2012 in Palm Springs, California this month.
From virginity to Viagra
Americans will spend more than $17 billion on Valentine's Day, but far less on programs like sex education for adolescents. The editors of the new book, Sex for Life, From Virginity to Viagra, How Sexuality Changes Throughout ...