Skip to content
AL-604 (B) · Information Security & Management/Quick Revision Short Notes

Information Security & Management (AL-604 (B)) - Unit 5 Short Notes

UNIT 5: CLOUD COMPUTING & VIRTUALIZATION


I. FOUNDATIONS & CORE CONCEPTS

A. Definition and Characteristics of Cloud Computing

Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Five Essential Characteristics:

  1. On-demand self-service: Users can provision computing capabilities (e.g., server time, network storage) automatically without human interaction with the service provider.

  2. Broad network access: Capabilities are available over the network and accessed through standard mechanisms (e.g., mobile phones, laptops) using diverse client platforms.

  3. Resource pooling: The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand.

  4. Rapid elasticity: Capabilities can be elastically provisioned and released—often automatically—to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited.

  5. Measured service: Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer.

B. Evolution: Grid Computing vs. Cloud Computing

Comparative Analysis:

Aspect Grid Computing Cloud Computing
Architecture Distributed, heterogeneous, federated Centralized, standardized, large data centers
Resource Mgmt. Collaborative, job scheduling, batch processing Centralized, automated, on-demand provisioning
Ownership Shared resources from multiple organizations/institutions Owned and managed by a single service provider
Scalability Limited by the size of the grid; often static Elastic, dynamic, appears limitless to the user
Business Model Often non-profit, research-oriented; resource sharing Commercial, utility-based (pay-as-you-go)
Use Cases Scientific simulations, large-scale batch jobs Web applications, enterprise services, SaaS

Similarities:

  • Both utilize distributed computing resources.

  • Both aim for resource sharing and increased utilization.

  • Both support parallel and high-throughput processing.

[!TIP]

Common Pitfall: Grid computing focuses on coordinating many disparate resources for a single large task, while cloud computing focuses on providing standardized, on-demand resources for many diverse, independent tasks.

C. Key Paradigms
  • Computing on Demand / Utility Computing: A service model where computing resources (processing, storage, etc.) are provided as a metered service, similar to traditional utilities like electricity or water. It enables dynamic provisioning—resources are automatically allocated and deallocated in real-time based on predefined policies or current demand, without manual intervention.

  • Cloud Computing Reference Model:

    • Defines the fundamental layers and components of a cloud ecosystem.

    • Layers (Service Stack):

      1. Software as a Service (SaaS): End-user applications.

      2. Platform as a Service (PaaS): Development and deployment platforms.

      3. Infrastructure as a Service (IaaS): Virtualized compute, storage, and network.

    • Core Components: Management & Orchestration, Security, Compliance, Billing, and the underlying Physical Infrastructure.

    • Diagram:

      DiagramCANVAS: A three-layer pyramid. Bottom layer: IaaS (VMs, storage, networks). Middle: PaaS (runtime, middleware, DB). Top: SaaS (applications). Surrounding the pyramid: interconnected components for Security, Management, Compliance, and Billing. Arrows show control and usage flows between layers and components.

D. Business and IT Perspectives

Potential Challenges & Risks:

  • Security & Privacy: Data breaches, loss of control, multi-tenancy risks.

  • Compliance & Legal: Data sovereignty, industry-specific regulations (GDPR, HIPAA).

  • Vendor Lock-in: Difficulty migrating data/services between providers due to proprietary APIs.

  • Downtime & Availability: Dependency on provider's infrastructure and internet connectivity.

  • Cost Management: Unexpected costs from egress fees, over-provisioning, or idle resources.

Benefits & Drivers for Adoption:

  • Cost Efficiency: Reduced capital expenditure (CapEx) to operational expenditure (OpEx); pay-per-use model.

  • Scalability & Elasticity: Instant scaling up/down to handle workload spikes.

  • Agility & Speed: Faster deployment of applications and services.

  • Maintenance: Provider handles hardware/software updates and maintenance.

  • Global Reach: Easy deployment in multiple geographic regions.


II. CLOUD SERVICE MODELS (THE CLOUD STACK)

A. Infrastructure as a Service (IaaS)
  • Definition: Provides fundamental computing resources—virtual machines (VMs), raw storage, virtual networks, and sometimes operating systems—over the internet.

  • Characteristics: Highest level of control for the user (OS, middleware, runtime, apps). User manages everything above the hypervisor.

  • Examples: Amazon EC2 (VMs), Amazon S3 (storage), Microsoft Azure Virtual Machines, Google Compute Engine.

B. Platform as a Service (PaaS)
  • Definition: Provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the underlying infrastructure (hardware, OS, middleware).

  • Characteristics: User controls deployed applications and configuration settings; provider manages runtime, middleware, OS, servers, storage, networking.

  • Examples: Heroku, Google App Engine, Microsoft Azure App Services, AWS Elastic Beanstalk.

C. Software as a Service (SaaS)
  • Definition: Delivers complete, ready-to-use software applications over the internet, typically on a subscription basis.

  • Characteristics: Lowest control for the user. Provider manages everything—application, data, runtime, middleware, OS, infrastructure. User simply uses the software via a web browser or API.

  • Examples: Gmail, Salesforce CRM, Microsoft 365, Dropbox.

D. Differentiating Service Models

Comparative Analysis:

Model User Control Provider Management Responsibility Customization Level Primary Target User
IaaS High (OS, apps, data) Physical infra, hypervisor, networking Very High IT Admins, DevOps Engineers
PaaS Medium (apps, data) Runtime, middleware, OS, infra Medium Application Developers
SaaS Low (app config, data) Everything (app to infra) Low (config only) End-Users, Business Units

[!TIP]

Memory Aid: "I control Intermediate things (OS) in IaaS; Provider controls Platform in PaaS; Software is all you See in SaaS."

E. Specialized Service Models
  • Storage as a Service / Storage Cloud: Provisioning of storage capacity (block, file, object) on-demand over a network. Examples: Amazon S3 (object), Azure Blob Storage.

  • Data Analytics as a Service (DaaS): Cloud-based platforms for big data processing and analytics. Often includes OLAP (Online Analytical Processing) functionality:

    • OLAP Operations:

      1. Roll-up (Drill-up): Aggregating data by climbing up a concept hierarchy (e.g., city → country).

      2. Drill-down: Reverse of roll-up; navigating from summary to detailed data.

      3. Slice: Selecting one dimension to create a sub-cube (e.g., sales in 2023).

      4. Dice: Selecting on two or more dimensions to create a sub-cube.

      5. Pivot (Rotate): Rotating the cube to change the dimensional orientation of a report.


III. CLOUD DEPLOYMENT MODELS

A. Primary Deployment Models
Model Characteristics Examples Benefits Risks
Public Cloud Owned/operated by third-party providers; multi-tenant; accessible to general public AWS, Azure, Google Cloud Lowest cost, no maintenance, high scalability Least control, security concerns, compliance complexity
Private Cloud Dedicated to a single organization; can be on-premises or hosted; more control VMware on-prem, OpenStack private cloud Highest control, security, customization High CapEx/OpEx, requires in-house expertise
Hybrid Cloud Composition of two or more clouds (private+public) with orchestration between them AWS Outposts + AWS Public Cloud Flexibility, workload optimization, avoids lock-in Complexity in integration, management, security
Community Cloud Shared by several organizations with common concerns (security, compliance, policy) Government cloud, academic consortium Cost-sharing, meets shared compliance needs Limited scalability, potential for internal conflict
B. Deployment Model Selection Framework

Organizations should evaluate based on:

  1. Security & Compliance: Data sensitivity, regulatory requirements (e.g., GDPR, PCI-DSS). Private/Community for high sensitivity.

  2. Cost Constraints: Budget availability (CapEx vs. OpEx). Public cloud for minimal upfront cost.

  3. Control & Customization: Need for deep infrastructure control. Private cloud offers maximum control.

  4. Scalability & Elasticity Needs: Predictable vs. spiky workloads. Public cloud best for elastic demands.

  5. Workload Characteristics: Latency-sensitive apps may need on-prem/private; bursty batch jobs suit public cloud.

  6. Existing IT Investment: Leverage current data centers (private/hybrid) vs. greenfield (public).

[!TIP]

Exam Strategy: For "suitable deployment model" questions, always map requirements (e.g., "strict data sovereignty") to model characteristics (e.g., "private cloud provides dedicated infrastructure").


IV. ENABLING TECHNOLOGIES: VIRTUALIZATION & STORAGE

A. Virtualization Fundamentals
  • Concept: Creation of a virtual (rather than actual) version of something, including virtual computer hardware platforms, storage devices, and network resources. It abstracts physical hardware from the operating system and applications.

  • Role in Efficiency: Allows multiple virtual machines (VMs) or containers to run on a single physical server, dramatically improving hardware utilization (from ~15% to 60-80%), reducing power, cooling, and footprint costs.

B. Hypervisors (Virtual Machine Monitors)
  • Functions: Creates and manages VMs; allocates physical resources (CPU, memory, storage, network) to VMs; provides isolation between VMs; presents virtual hardware to guest OSes.

  • Types:

    • Type 1 (Native/Bare-metal): Runs directly on the host's hardware. Examples: VMware ESXi, Microsoft Hyper-V, Xen. Primary use: Server virtualization, data centers.

    • Type 2 (Hosted): Runs on a conventional operating system as a software layer. Examples: Oracle VirtualBox, VMware Workstation. Primary use: Desktop virtualization, testing.

  • Hardware Virtual Machine (HVM): A virtualization technique that uses hardware extensions (Intel VT-x, AMD-V) in the CPU to run unmodified guest operating systems with near-native performance. The hypervisor leverages these extensions for efficient CPU virtualization.

C. Advanced Virtualization Techniques
  • Logical Partitioning (LPAR):

    • Concept & Architecture: A technique (commonly in IBM POWER, mainframes) to divide a single physical server into multiple isolated logical partitions, each with its own dedicated resources (CPU, memory, I/O). Managed by a hypervisor (e.g., PowerVM, z/VM).

    • Advantages:

      • Improved Resource Allocation: Fine-grained, dynamic sharing and assignment of resources.

      • Strong Isolation: Partitions are completely isolated; a failure in one does not affect others.

      • Security: High level of separation suitable for consolidating workloads with different security levels.

    • Disadvantages:

      • Overhead: Hypervisor and partitioning management consume some resources.

      • Complexity: Requires skilled administration; not as flexible as full virtualization for OS diversity.

  • Virtualized Data Center:

    • Architecture: Integrates virtualized servers (with hypervisors), virtualized storage (SAN/NAS), and virtualized networking (software-defined networking - SDN) into a unified, software-defined pool of resources.

    • Components:

      1. Virtualized Servers: Physical servers running hypervisors hosting multiple VMs.

      2. Virtualized Storage: Storage Area Network (SAN) or Network-Attached Storage (NAS) presented as a single logical pool.

      3. Virtualized Networking: Virtual switches (vSwitch), virtual LANs (VLAN), SDN controllers managing logical network topologies.

      4. Management Layer: Centralized console (e.g., vCenter, OpenStack Horizon) for provisioning, monitoring, and orchestration.

    • Diagram:

      DiagramCANVAS: A rack of physical servers, each with a hypervisor layer showing multiple VMs. All servers connect to a virtual switch (vSwitch). The vSwitch connects to a virtual network (VLAN) and a shared storage array (SAN). A central management server has a console overseeing all hypervisors, VMs, storage, and network configurations.

D. Virtualization Platform Requirements
  • Hardware:

    • CPU: 64-bit architecture with hardware virtualization support (Intel VT-x / AMD-V). Multiple cores for concurrent VM execution.

    • Memory (RAM): Sufficient capacity to host multiple VMs plus hypervisor overhead (typically 10-20% extra).

    • Storage: Fast disks (SSD/NVMe recommended) with enough capacity for VM images and data. RAID for redundancy.

    • Network: Multiple network interfaces (NICs) for management, VM traffic, and storage traffic separation.

  • Software:

    • Hypervisor: Type 1 for production servers, Type 2 for desktops.

    • Management Tools: For provisioning, monitoring, and lifecycle management (e.g., vCenter, System Center VMM, OpenStack Nova).

    • Guest Operating Systems: Supported OSes for VMs (Windows, Linux variants).

E. Storage Technologies
  • Storage Area Network (SAN) vs. Network-Attached Storage (NAS):
Feature SAN NAS
Access Level Block-level (raw disks/LUNs) File-level (NFS, SMB/CIFS)
Protocol Fibre Channel (FC), iSCSI, FCoE NFS, SMB/CIFS, HTTP
Network Dedicated high-speed network (often FC) Standard IP/Ethernet network
Performance Very high, low latency Good, but higher latency than SAN
Management Complex, requires specialized skills Simpler, like managing a file server
Use Case Databases, high-transaction apps, VMs (boot) File sharing, home directories, backups
  • Storage Virtualization: The process of abstracting physical storage resources from their underlying physical platforms and presenting them as a single, logical, pooled storage entity. It enables features like thin provisioning, data migration, and storage tiering without disrupting hosts.

  • Storage Cloud (Storage as a Service): A cloud service model where storage capacity is provided over the internet on a pay-per-use basis. It is typically object-based (e.g., Amazon S3) and offers high durability, scalability, and global accessibility.


V. CLOUD SECURITY (CRITICAL EXAM FOCUS)

A. Importance and Unique Challenges
  • Importance: Cloud environments host sensitive data and critical applications. A breach can lead to massive data loss, financial damage, and reputational harm. Security is fundamental to trust and adoption.

  • Unique Challenges:

    • Shared Responsibility Model: Security is a joint duty; confusion over provider vs. user responsibilities creates gaps.

    • Multi-tenancy: Multiple customers' data and applications reside on the same physical infrastructure, increasing attack surface and risk of data leakage.

    • Loss of Direct Control: Customers have limited visibility and control over the underlying infrastructure.

    • Dynamic Provisioning & Elasticity: Resources scale automatically, making traditional security perimeters and asset tracking difficult.

    • API Vulnerabilities: Cloud services are accessed via APIs; insecure APIs are a major attack vector.

    • Compliance Complexity: Data location and handling must comply with varying regional laws.

B. Cloud Security Domains
  1. Data Security: Encryption (at rest, in transit), data integrity checks, data loss prevention (DLP), secure deletion, and lifecycle management.

  2. Network Security: Virtual network segmentation (VLANs, VXLANs), virtual firewalls, intrusion detection/prevention systems (IDS/IPS), DDoS mitigation, secure VPNs.

  3. Identity and Access Management (IAM): Strong authentication (MFA), fine-grained authorization (RBAC), least privilege principle, federation, and single sign-on (SSO).

  4. Compliance and Governance: Audit logging, monitoring, reporting, adherence to standards (ISO 27001, SOC 2), and contractual SLAs.

C. Secure Cloud Architecture & Communications
  • Secure Execution Environments: Use of Trusted Platform Module (TPM) and trusted execution environments (e.g., Intel SGX, AMD SEV) to ensure platform integrity and protect code/data during processing.

  • Encryption Mechanisms:

    • Data-at-Rest: Encrypt data stored on disks or in object storage (e.g., AES-256). Use provider-managed keys or customer-managed keys (CMK) for higher control.

    • Data-in-Transit: Encrypt data moving over networks using TLS/SSL, IPsec VPNs.

  • Secure Communication Protocols: HTTPS (HTTP over TLS), SSH for secure shell access, SFTP/FTPS for file transfers.

  • Secure Bootstrapping Mechanisms: Secure initial setup and configuration of cloud resources, including validated images, immutable infrastructure patterns, and automated, auditable provisioning.

D. Virtual Machine (VM) Security
  • VM-Specific Security Risks:

    • Hypervisor Attacks: Compromising the hypervisor ("host") gives control over all hosted VMs.

    • VM Escape: A malicious VM breaking out of its isolated environment to access the host or other VMs.

    • VM Image Tampering: Malicious code or backdoors inserted into VM templates or snapshots.

    • Inter-VM Traffic Monitoring: Sniffing traffic between VMs on the same physical host if virtual switches are misconfigured.

    • Resource Exhaustion: One VM consuming excessive host resources (CPU, memory, disk I/O) to impact others ("noisy neighbor").

  • Benefits of Virtualization Security:

    • Isolation: VMs are strongly isolated from each other at the hardware level (via hypervisor), containing breaches.

    • Encapsulation: A VM is a single set of files (disk image, config). This allows for easy backup, snapshotting, restoration, and forensic analysis.

  • Securing VMs - Recommendations:

    • Use Hardened Images: Start with minimal, security-hardened OS images (e.g., CIS Benchmarks) and patch regularly.

    • Implement Network Segmentation: Use virtual networks (VLANs, security groups) to isolate VMs by function (e.g., web tier, app tier, DB tier).

    • Monitor VM Activity: Enable host-based intrusion detection (HIDS), collect and analyze VM logs centrally.

    • Patch Management: Keep guest OS and applications within VMs updated. Use automated patching tools.

    • Secure VM Lifecycle: Scan VM images for malware before deployment; securely decommission VMs (wipe storage).

E. Access Control Models
  • Role-Based Access Control (RBAC):

    • Principles: Permissions are assigned to roles (e.g., Admin, Developer, ReadOnlyUser), not directly to individuals. Users are assigned to roles, inheriting the role's permissions. Follows the principle of least privilege.

    • Application in Cloud IAM: Cloud providers implement RBAC as the core IAM model.

      • Define Roles: Create roles with specific sets of permissions (e.g., EC2:StartInstances, S3:GetObject).

      • Assign Roles: Attach roles to users, groups, or services (e.g., an EC2 instance role).

      • Policy-Based: Permissions are defined in JSON/YAML policy documents attached to roles.

    • Benefit: Simplifies administration, ensures consistency, and scales well in dynamic cloud environments with many users and resources.


VI. CLOUD MANAGEMENT, INTEGRATION & QUALITY

A. Service-Oriented Architecture (SOA) in Cloud
  • SOA as a Design Principle: SOA structures an application as a collection of loosely coupled, interoperable services that communicate over a network (typically via web services - SOAP/REST).

  • Facilitating Interoperability & Integration:

    • Standardized Interfaces: Services expose well-defined, platform-independent APIs (e.g., RESTful APIs), allowing diverse cloud-based services and applications to communicate regardless of underlying technology.

    • Loose Coupling: Services are independent; one service can be updated or replaced without breaking others that consume it.

    • Reusability: Services can be reused across different applications and business processes.

    • Composition: Complex workflows and applications can be built by orchestrating existing cloud services (e.g., using AWS Step Functions, Azure Logic Apps).

    • Example: A cloud-based e-commerce app might integrate a SaaS CRM (Salesforce), a PaaS payment gateway (Stripe), and a custom IaaS-hosted inventory service via their REST APIs.

B. Quality of Service (QoS)
  • Definition: The overall performance and reliability of a cloud service, as experienced by the user. It is defined by a set of measurable service attributes.

  • Key Metrics:

    • Availability: Uptime percentage (e.g., 99.9% "three nines"). Often defined in Service Level Agreements (SLAs).

    • Performance: Response time, throughput (requests/sec), latency.

    • Reliability: Mean Time Between Failures (MTBF), failure rate.

    • Scalability: Ability to handle increased load.

    • Security: As covered in Section V.

  • Issues & Challenges in Ensuring QoS:

    • Multi-tenancy & "Noisy Neighbor": One tenant's resource-intensive VM can degrade performance for others on the same host.

    • Dynamic Resource Allocation: Automatic scaling can introduce variability in performance if not managed properly.

    • Network Variability: Performance depends on internet connectivity and provider's network backbone.

    • Measuring End-to-End QoS: Difficulty in measuring performance across distributed components (client, internet, cloud provider network, internal cloud).

    • SLAs and Penalties: Defining fair and measurable QoS metrics in SLAs, and enforcing penalties for breaches, is complex.

C. Cloud Ecosystem & Stakeholders
  • Role of Independent Software Vendors (ISVs):

    • Develop commercial software applications that run on cloud platforms.

    • "Build vs. Buy": They build applications that enterprises can "buy" as SaaS (e.g., Salesforce, Workday) or as software to deploy on IaaS/PaaS.

    • Platform Optimization: ISVs optimize their applications for specific cloud platforms (e.g., using AWS RDS, Azure SQL Database) to leverage managed services and improve performance.

    • Marketplace Distribution: Distribute applications through cloud provider marketplaces (AWS Marketplace, Azure Marketplace), simplifying procurement and deployment for customers.

    • Drivers for Cloud Adoption: ISVs are key drivers, as their cloud-native applications encourage enterprises to adopt the underlying cloud infrastructure.

D. Cloud Management & Benchmarks
  • Cloud Infrastructure Benchmarks:

    • Purpose: To objectively measure and compare the performance, cost-efficiency, and scalability of different cloud providers or configurations. Helps in capacity planning, cost optimization, and vendor selection.

    • Common Metrics:

      • Compute: CPU performance (e.g., SPECint), VM boot time.

      • Storage: IOPS (Input/Output Operations Per Second), throughput (MB/s), latency.

      • Network: Bandwidth, latency, jitter, packet loss.

      • Cost: Cost per VM-hour, cost per GB storage, network egress cost.

  • Cloud Stack Management Layers & Tools Overview:

    • Infrastructure Layer: Tools for managing physical/virtual servers, storage, networks (e.g., VMware vSphere, OpenStack Nova, Cinder, Neutron).

    • Platform Layer: Tools for deploying and managing applications (e.g., Kubernetes for containers, Cloud Foundry, AWS Elastic Beanstalk).

    • Application/Service Layer: Monitoring, logging, and APM (Application Performance Monitoring) tools (e.g., Datadog, New Relic, CloudWatch).

    • Orchestration & Automation: Tools to automate provisioning and workflows (e.g., Terraform, AWS CloudFormation, Ansible).


VII. CLOUD PLATFORMS & IMPLEMENTATION TOOLS (SPECIFIC CASE STUDIES)

A. Open-Source Cloud Platforms
  • OpenNebula:

    • Architecture: A flexible, modular system. Core components include:

      • Front-end (Controller): The management node running the OpenNebula services (scheduler, accounting, etc.).

      • Cluster Nodes: Physical/virtual servers running the hypervisor (KVM, LXC, VMware) and the OpenNebula node agent.

      • Storage & Networking: Integrates with existing storage (NFS, iSCSI, Ceph) and networking (Open vSwitch, 802.1Q VLANs).

    • Features: VM lifecycle management, hybrid cloud support (can manage private data center and public cloud resources like AWS EC2), multi-tenant isolation, customizable scheduling.

    • Use in Cloud Computing: Primarily used to build and manage private and hybrid clouds. Valued for its simplicity, stability, and focus on enterprise data center integration rather than being a full PaaS/SaaS suite.

  • Nimbus:

    • Architecture: A toolkit focused on Infrastructure as a Service (IaaS). Key components:

      • Nimbus Context Broker: The core service that handles VM lifecycle requests (create, destroy, deploy).

      • Cloud Services: A set of services (e.g., workspace control, image management) that implement the IaaS interfaces (often EC2-compatible).

      • Backend: Pluggable drivers for different hypervisors (Xen, KVM), schedulers, and storage systems.

    • Features: Lightweight, EC2/WSDL-compatible APIs, strong support for scientific computing and high-performance computing (HPC) workloads, secure context-based delegation.

    • Use in Cloud Computing: Widely adopted in research and scientific communities (e.g., for grid/cloud testbeds like FutureGrid) where custom, controllable IaaS clouds are needed for running large-scale computational jobs.

B. Other Notable Platforms (Contextual Awareness)
  • Eucalyptus: An open-source platform for constructing AWS-compatible private clouds. Its architecture mirrors AWS (EC2, S3, IAM interfaces), allowing easy migration and hybrid cloud setups with AWS.

  • OpenStack: A massive, modular, open-source IaaS cloud operating system. Components (Nova for compute, Neutron for networking, Cinder for block storage, Swift for object storage, Keystone for identity) provide a comprehensive alternative to public clouds. Used for building both private and public clouds.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in