CLOUD SECURITY SECURITY ASPECTS IN GEOSPATIAL CLOUD. Guided by Prof. S. K. Ghosh Presented by - Soumadip Biswas



Similar documents
Perspectives on Moving to the Cloud Paradigm and the Need for Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Perspectives on Cloud Computing and Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Cloud Courses Description

Security & Trust in the Cloud

Cloud Courses Description

East African Information Conference th August, 2013, Kampala, Uganda. Security and Privacy: Can we trust the cloud?

OWASP Chapter Meeting June Presented by: Brayton Rider, SecureState Chief Architect

Goals. What is Cloud Computing? 11/11/2010. Understand what cloud computing is and how. Understand the challenges and advantages of cloud computing

CHAPTER 8 CLOUD COMPUTING


BUSINESS MANAGEMENT SUPPORT

Cloud Computing: The Next Computing Paradigm

IT Risk and Security Cloud Computing Mike Thomas Erie Insurance May 2011

Cloud Computing; What is it, How long has it been here, and Where is it going?

Security Considerations for Public Mobile Cloud Computing

Cloud Computing for SCADA

Running head: TAKING A DEEPER LOOK AT THE CLOUD: SOLUTION OR 1

Cloud & Security. Dr Debabrata Nayak Debu.nayak@huawei.com

Architecting the Cloud

Cloud Computing Submitted By : Fahim Ilyas ( ) Submitted To : Martin Johnson Submitted On: 31 st May, 2009

Cloud Computing Service Models, Types of Clouds and their Architectures, Challenges.

Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin

Clo l ud d C ompu p tin i g

Cloud Computing An Elephant In The Dark

Cloud Computing, and REST-based Architectures Reid Holmes

ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS

Cloud Security considerations for business adoption. Ricci IEONG CSA-HK&M Chapter

Cloud Computing. What is Cloud Computing?

Deploying ArcGIS for Server using Managed Services

CERTIFICATE PROGRAMME ON CLOUD SPECIALISTS DEVELOPMENT

White Paper on CLOUD COMPUTING

The Magical Cloud. Lennart Franked. Department for Information and Communicationsystems (ICS), Mid Sweden University, Sundsvall.

Deploying a Geospatial Cloud

Architectural Implications of Cloud Computing

Cloud Computing Benefits for Educational Institutions

A.Prof. Dr. Markus Hagenbuchner CSCI319 A Brief Introduction to Cloud Computing. CSCI319 Page: 1

Secure Cloud Computing through IT Auditing

Daren Kinser Auditor, UCSD Jennifer McDonald Auditor, UCSD

OVERVIEW Cloud Deployment Services

Development of Software As a Service Based GIS Cloud for Academic Institutes. Singh, Pushpraj 1 and Gupta, R. D. 2

CLOUD COMPUTING. A Primer

Top 10 Cloud Risks That Will Keep You Awake at Night

The Pivotal Role of Geospatial Information Systems based on Hybrid Cloud Computing for the Health Sector in Egypt

Cloud Computing. Chapter 1 Introducing Cloud Computing

How To Understand Cloud Computing

Cloud Computing Paradigm Shift. Jan Šedivý

Perspectives on Cloud Computing and Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Cloud Computing. Chapter 1 Introducing Cloud Computing

Cloud Computing Flying High (or not) Ben Roper IT Director City of College Station

Cloud Computing and Security Risk Analysis Qing Liu Technology Architect STREAM Technology Lab

Cloud Computing and Disaster Recovery

Oracle Applications and Cloud Computing - Future Direction

Cloud Computing. Course: Designing and Implementing Service Oriented Business Processes

Cloud Computing. What Are We Handing Over? Ganesh Shankar Advanced IT Core Pervasive Technology Institute

TOP 7 THINGS Every Executive Should Know About Cloud Computing EXECUTIVE BRIEF

CLOUD COMPUTING SECURITY ISSUES

A Study on Service Oriented Network Virtualization convergence of Cloud Computing

Mobile Cloud Computing Security Considerations

NCTA Cloud Architecture

INTRODUCING CLOUD POWER

Cloud Services Overview

The Trend and Challenges of Cloud Computing: A Literature Review

Cloud Computing Services and its Application

Cloud Computing in the Enterprise An Overview. For INF 5890 IT & Management Ben Eaton 24/04/2013

How To Compare Cloud Computing To Cloud Platforms And Cloud Computing

Cloud Computing. Karan Saxena * & Kritika Agarwal**

The Hybrid Cloud: Bringing Cloud-Based IT Services to State Government

Cloud Computing: Computing as a Service. Prof. Daivashala Deshmukh Maharashtra Institute of Technology, Aurangabad

INTRODUCTION TO CLOUD COMPUTING CEN483 PARALLEL AND DISTRIBUTED SYSTEMS

ICSA Labs Risk and Privacy Cloud Computing Series Part I : Balancing Risks and Benefits of Public Cloud Services for SMBs

Cloud Computing Phillip Hampton LogicForce Consulting, LLC

Figure 1 Cloud Computing. 1.What is Cloud: Clouds are of specific commercial interest not just on the acquiring tendency to outsource IT

Technology & Business Overview of Cloud Computing

Cloud Computing Technology

Deploying ArcGIS for Server Using Esri Managed Services

What Is It? Business Architecture Research Challenges Bibliography. Cloud Computing. Research Challenges Overview. Carlos Eduardo Moreira dos Santos

Cloud Computing and Government Services August 2013 Serdar Yümlü SAMPAŞ Information & Communication Systems

Cloud Computing. IST 501 Fall Dongwon Lee, Ph.D.

Testing as a Service on Cloud: A Review

Managing Cloud Computing Risk

Improving IT Service Management Architecture in Cloud Environment on Top of Current Frameworks

Fundamental Concepts and Models

A Study on Analysis and Implementation of a Cloud Computing Framework for Multimedia Convergence Services

Cloud Computing Cluster Introduction to Cloud Computing. Rick Martin, Co-chair, Cloud Computing Cluster August 26, 2013

WHAT DOES IT SERVICE MANAGEMENT LOOK LIKE IN THE CLOUD? An ITIL based approach

Clinical Trials in the Cloud: A New Paradigm?

See Appendix A for the complete definition which includes the five essential characteristics, three service models, and four deployment models.

Digital Forensics. Lab 10: Cloud Computing & the Future of Digital Forensics

Cloud Based E-Government: Benefits and Challenges

A Strawman Model. NIST Cloud Computing Reference Architecture and Taxonomy Working Group. January 3, 2011

Future of Cloud Computing in India

The NIST Definition of Cloud Computing (Draft)

Cloud Computing and its Security in Higher Education

What Cloud computing means in real life

FEDERATED CLOUD: A DEVELOPMENT IN CLOUD COMPUTING AND A SOLUTION TO EDUCATIONAL NEEDS

Objectives. To understand Cloud Computing Issues. Foundational Elements of Cloud Computing Security & Privacy Cloud Migration Paths Risks in Cloud

Cloud Computing For Distributed University Campus: A Prototype Suggestion

Transcription:

CLOUD SECURITY SECURITY ASPECTS IN GEOSPATIAL CLOUD Guided by Prof. S. K. Ghosh Presented by - Soumadip Biswas

PART 1 A brief Concept of cloud Issues in cloud Security Issues

A BRIEF The Evolution Super computing Cluster computing Utility computing Grid computing Service Oriented Architecture: SOA Service Service-orientation

CONCEPT : SOA The storing and accessing of applications and computer data often through a Web browser rather than running installed software on your personal computer or office server Internet-based computing whereby information, IT resources, and software applications are provided to computers and mobile devices on-demand Using the Internet to access web-based applications, web services

THE BIG PICTURE : CLOUD Security Scalability Availability Performance Cost-effective Resilient computing Release resources when no longer needed Pay for what you use Leverage others core competencies Turn fixed cost into variable cost

COMPONENTS Basic Concept Characteristics On-demand self service Broad network access Resource pooling location independence Rapid elasticity Measured service Cloud Service Models Cloud Deployment Models

SERVICE MODELS Software as a Service (SaaS) Platform as a Service (PaaS) Infrastructure as a Service (IaaS) A Cousin model Data as a Service (DaaS)

DEPLOYMENT MODELS Public Cloud Enterprise owned or leased Private Cloud Shared infrastructure for specific community Community Cloud Sold to the public, mega-scale infrastructure Hybrid Cloud Composition of two or more clouds

CLOUD ATTACK INCIDENTS Google Docs found the flaw in March 2009 that inadvertently shares users docs. Salesforce.com employee fell victim to a phishing attack and leaked customer list in October 2009 Epic.com logged a complaint against Google for its privacy practices in March 2009. Steven Warshak stops govt. repeated searches of his e-mail using SCA in July 2007. Outage of big bucket deployment in amazons in Feb 2008 where for a period of several hours there was Denial of Service attack.

A SURVEY Security Availability Performance On-demand paym t model may cost more Lack of interoperability standards Bringing back in-house may be difficult Hard to integrate with in-house IT Not enough ability to customize 87.5% 83.3% 82.9% 81.0% 80.2% 79.8% 76.8% 76.0% 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% A rating of many different issues in cloud computing, Ref: Cloud Computing 2010, An IDC Update, IDC Executive Telebriefing, 29 September 2009

ISSUES Privacy issues Lack of user control Unauthorized secondary usage Trust issues Weak Trust Relationship Lack Of Customer Trust Security issues Legal issues Legal framework Transferring of data Outsourcing Issue

SECURITY ISSUES Authentication and identity management Access Availability and backup Control over Data lifecycle Lack of standardization Multi-tenancy Audit

SECURITY ASPECTS Server access security Internet access security Database access security Data privacy security Program access security

SECURITY RELEVANT CLOUD COMPONENTS Cloud Provisioning Services Cloud Data Storage Services Cloud Processing Infrastructure Cloud Support Services Cloud Network and Perimeter Security Elastic Elements: Storage, Processing, and Virtual Networks

GENERAL SECURITY ADVANTAGES Shifting public data to a external cloud reduces the exposure of the internal sensitive data Cloud homogeneity makes security auditing/testing simpler Clouds enable automated security management Redundancy / Disaster Recovery

PART 2 Get domain specific Geospatial Cloud Issues in Geospatial cloud Examples

DOMAIN : GIS Geographical Information System Captures, stores, analyzes, manages, and presents data with reference to geographic location data Uses Earth surface based scientific investigations Resource, asset management Infrastructure assessment and development Reference, location planning Statistical analysis, criminology Warfare assessments LOT MORE

GIS SERVICES Web feature service Retrieves heterogeneous data Web mapping service Creates maps with customization Web processing service Processes user requests Web Coverage Service Describes objects in spatial data and provides coverage

A SCENARIO Ref: Geospatial Service-Oriented Architecture (SOA) An ESRI White Paper, page 65

A SOA APPROACH: CLOUDY Ref: Geospatial Service-Oriented Architecture (SOA) An ESRI White Paper, page 73

LETS COMBINE THEM GIS in Cloud Many different services offered by GIS Cloud can be a great option to integrate with GIS Enhance the Storage Capacity and Security of Spatial Data, Provide Strong Support of Mass Data Storage for GIS Enhance the Efficient Processing Capabilities of Spatial Analysis and Facilitate Decision-Making Support by Combining Cloud Computing and Spatial Analysis Have a Great Impact on Software Development and Product Models of GIS

DATA AS A SERVICE (DAAS) Multi-tenancy, system configuration to be a pooled and shared resource by many institutions and governments enhancing the ability to discover and share data Ability to access this storage intensive ( raster ) data quickly and given the low cost the ability to store more time dependant/historical data Pay as you go for data access may provide promise for a business model that in the long-term could support the financing of the NSDI

SECURITY ISSUES Access control Use RBAC Security and Confidentiality of Spatial data Protect sensitive data Other Issues SLA violation Supervision issue Regulation establishing

EXAMPLE : GEOIQ Geographical information system Organize and Share GIS Projects Create and Edit Spatial and Non-Spatial Data Import and Interoperability Styling GIS Attributes Information Export Spatial Data Publish and Share WMS and TMS Server Publish GIS Projects on Google Maps GIS Support for Mobile Devices

BASIC WORKING Ref: www.geoiq.com

SOME MORE EXAMPLES IBM cloud offering RMSC and ESRI Collaborate on GIS Cloud RMSC is providing all the compute horsepower and ESRI is providing their ArcGIS software package Microsoft Azure is working Google Maps NSDI takes initiative

A NEWS NGAC GeoCloud Game March 23, 2010 Geospatial Cloud Computing Workshop designed to increase awareness and understanding of cloud computing issues Features a war-game Result at a glance Deigned for members of the NGAC, FGDC Executive Committee, and geospatial professionals within the Govt. common language around the challenges involved in migrating to cloud computing technology and the risks and rewards associated with this migration. Reveals the importance of having this GeoCloud as Collaboration and sharing Experience varying fidelity of spatial data and their interdependencies Complex organizational issues role-playing Guiding policies facilitate process between and among govt. agencies Much work needs to be done on DaaS and Pay-as-you-go Model

CONCLUSION AND REMARKS We have seen that cloud have many of its own kind of challenges and advantages as well Geospatial Cloud, would be a real deal when implemented Lack of the examples about cloud techniques applying in GIS, thus it s a really novice All new works needs to be done, much care is required

REFERENCES 1) Yang Jinnan; Wu Sheng;, "Studies on application of cloud computing techniques in GIS," Geoscience and Remote Sensing (IITA-GRS), 2010 Second IITA International Conference on, vol.1, no., pp.492-495, 28-31 Aug. 2010 2) Bian Wu; Xincai Wu; Jian Huang;, "Geospatial data services within Cloud computing environment," Audio Language and Image Processing (ICALIP), 2010 International Conference on, vol., no., pp.1577-1584, 23-25 Nov. 2010 3) Geospatial Service-Oriented Architecture (SOA) An Esri White Paper 4) Definitions of SOA, ver. 1.1, the Open Group. 5) Cloud Computing Defined 17 July 2010. 6) Cloud Software Service: Concepts, Technology, Economics, Harry Katzan, Jr. Savannah State University, Service Science 1(4), pp. 256-269, 2009 SSG 7) Privacy in the Clouds, Ann Cavoukian 2000, p. 4. 8) Effectively and Securely Using the Cloud Computing Paradigm, Peter Mell, Tim Grance, NIST, Information Technology Laboratory, 10-29-2009 9) Cloud Computing 2010, An IDC Update, IDC Executive Telebriefing, 29 September 2009 10) www.geoiq.com 11) geocommons.com/help/ 12) Security in cloud computing, Vaibhav Vikas Neharkar, sit,iitkgp