Commentary

Charles Babcock
InformationWeek  

Amazon's Private Cloud: Virtually Private Or Maybe Private?

Amazon, purveyor of the EC2 public cloud, suddenly announced Aug. 26 it's a private cloud supplier. Isn't there something wrong with a multi-tenant, shared resource provider transforming itself into a private cloud service? I'm not sure Amazon can offer a private cloud --yet. Then again, I see no reason why it couldn't sometime in the future.

Amazon, purveyor of the EC2 public cloud, suddenly announced Aug. 26 it's a private cloud supplier. Isn't there something wrong with a multi-tenant, shared resource provider transforming itself into a private cloud service? I'm not sure Amazon can offer a private cloud --yet. Then again, I see no reason why it couldn't sometime in the future.Amazon announced Wednesday that it's offering an enterprise service oriented toward private cloud use, the Virtual Private Cloud. That means it will make facilities and services available that can be accessed solely by the subscriber over a VPN. No snooping eyes or devices on the network are going to see your private data.

Werner Vogels, in his blog on the subject, says: Amazon Virtual Private Cloud customers will be able to "seamlessly extend their IT infrastructure into the cloud while maintaining the levels of isolation required for their enterprise management tools to do their work."


More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Companies making use of Amazon to establish their external "private cloud" will access resources over their own routers, which will be configured to go only to IP addresses in a particular company-owned address block. Amazon will set up a Virtual Private Cloud that serves that address block, Vogels explained.

"These resources are fully isolated and can only communicate with other resources in the same Virtual Private Cloud…" he continued.

That may be true, in one sense. But I'm wondering if "isolation" as Vogels uses it means the physical server resources being used are dedicated to the customer's Virtual Private Cloud, or just the network access is isolated by the VPN. Amazon might answer that the isolation provided by the VPN is enough. There may be additional Amazon measures that try to insure that it is enough. But he's going a long ways down the "private" descriptive path if these resources are multi-tenant, perhaps even existing EC2 servers that have been co-assigned the task of supplying the Virtual Private Cloud.

Werners notes in the blog, it's already spent "$2 billion in developing technologies that could deliver security, reliability and performance at tremendous scale and at low cost."

Fair enough. But does that mean if an intruder succeeded somehow in getting into my Virtual Private Cloud, my data would still be protected, highly sensitive virtual machine operations would be shielded from less sensitive virtual machine operations, and suspicious activity, such as an irregular fund transfer, would stand out as an exception and be reported swiftly by the Virtual Private Cloud's monitoring service?

If the answer is, "If you configure your end right, then no intruder can get in," that's a red flag. To keep my data secure, Virtual Private Cloud security is going to have to amount to more than network isolation. There will need to be intruder protection and virtual firewalls built into each virtual machine that isolates it from traffic with other virtual machines; in some cases, isolated it from other VMs even though they are inside the same Virtual Private Cloud. More detail needs to emerge on this offering. But I think what we have in Amazon's latest service is not a private cloud as I understand it but a "virtual" private cloud, a private cloud, maybe, a private cloud that mostly secures the data but can't do everything the typical chief security officer does inside the data center.

My questions: Will I remain in full compliance if I mingle use of my most secure, private data between the data center and the Virtual Private Cloud? Where has the security boundary moved to? It used to be at the perimeter of the data center. Is it still there or did it move into the cloud, with the data? Who's now responsible for that boundary, Amazon or me?


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links