Security for Private Cloud
Environments
John Fitzgerald
(john.fitzgerald@internet.de)
1
IaaS ist Grundlage für Cloud
Management
Computing
Networking
Storage
IaaS Zonen IaaS Cloud
(vereinfacht)
Keine Notwendigkeit, den Ort eines Dienstes im
Detail zu kennen -> alle Dienste in der „Cloud“
Systemaufbau
Host OS
z.B.
Centos
Debian
Fedora
Interactive Cloud OS
RedHat
SUSE
Ubuntu
[…]
Hypervisor
z.B.
KVM
Xen
Hyper-V*
VMWare*
[…]
Storage
z.B.
Cinder
Ceph
DRDB
Gluster FS
Hadoop
NFS
[…]
Network
z.B.
GRE
IP-IP
IS-IS
Open vSwitch
VirtIO
VXLan
VLAN
[…]
Mgmt.
z.B.
Horizon
Sunstone
[…]
Gast OS
z.B.
Centos
Debian
Fedora
RedHat
SUSE
Ubuntu
Windows
[…]
Add-On
(Optional) z.B.
Dokker
Seafile
Owncloud
[…]
Server
Hardware
Storage NetworkCPU RAM
Gast OS Gast OSGast OS
Add-
On
Add-
On
Management GUI
Gast OS Gast OS
Add-
On
Hypervisor
Host Betriebssystem (OS)
* = nicht quelloffen
Einzelkomponenten (weitere Informationen: www.opencloud.eurocloud.de)
(vereinfacht)
Verwundbarkeit
Neighbor Attack
Host OS Attack
Internet
• Whiteboard
Ausfall ARD
https://www.ard.de heruntergeladen am 10.9.2019 um 11:58 CEST
John Fitzgerald
(john.fitzgerald@internet.de)
6
Best Practice
Compute Nodes
Office
DMZ
DMZ 2 Controller
One
firewalls
VMs
Internet
ssh /xml <oneway>
Management via
VPN / Tunnel
Retrieve
information
configure
oobm <one-way>
VM Management
Serverzyklus(exemplarisch)
KUNDEN-
APPLIKATION

Weitere ähnliche Inhalte

PDF
ZFS unter Linux
PDF
SuperSUSE – die Lösung für dynamisch wachsenden Speicher
PDF
Infracoders Graz, smartOS - vom Netzwerk in der Box - zum Software Cloud Stack
PDF
Private Cloud mit Open Source
PDF
Ceph Introduction @GPN15
PDF
Schweben auf Wolke7
PDF
OSMC 2011 | Collectd in der großen weiten Welt - Anbindung des Datensammlers ...
PDF
LinuxTag 2008 - Virtuelle Cold-Standby Server mit Linux
ZFS unter Linux
SuperSUSE – die Lösung für dynamisch wachsenden Speicher
Infracoders Graz, smartOS - vom Netzwerk in der Box - zum Software Cloud Stack
Private Cloud mit Open Source
Ceph Introduction @GPN15
Schweben auf Wolke7
OSMC 2011 | Collectd in der großen weiten Welt - Anbindung des Datensammlers ...
LinuxTag 2008 - Virtuelle Cold-Standby Server mit Linux

Mehr von OpenNebula Project (20)

PDF
OpenNebulaConf2019 - Welcome and Project Update - Ignacio M. Llorente, Rubén ...
PDF
OpenNebulaConf2019 - Building Virtual Environments for Security Analyses of C...
PDF
OpenNebulaConf2019 - CORD and Edge computing with OpenNebula - Alfonso Aureli...
PDF
OpenNebulaConf2019 - 6 years (+) OpenNebula - Lessons learned - Sebastian Man...
PDF
OpenNebulaConf2019 - Performant and Resilient Storage the Open Source & Linux...
PDF
OpenNebulaConf2019 - Image Backups in OpenNebula - Momčilo Medić - ITAF
PDF
OpenNebulaConf2019 - How We Use GOCA to Manage our OpenNebula Cloud - Jean-Ph...
PDF
OpenNebulaConf2019 - Crytek: A Video gaming Edge Implementation "on the shoul...
PDF
Replacing vCloud with OpenNebula
PDF
NTS: What We Do With OpenNebula - and Why We Do It
PDF
OpenNebula from the Perspective of an ISP
PDF
NTS CAPTAIN / OpenNebula at Julius Blum GmbH
PDF
Performant and Resilient Storage: The Open Source & Linux Way
PDF
NetApp Hybrid Cloud with OpenNebula
PPTX
NSX with OpenNebula - upcoming 5.10
PDF
CheckPoint R80.30 Installation on OpenNebula
PDF
DE-CIX: CloudConnectivity
PDF
PDF
Cloud Disaggregation with OpenNebula
PDF
OpenNebula and StorPool: Building Powerful Clouds
OpenNebulaConf2019 - Welcome and Project Update - Ignacio M. Llorente, Rubén ...
OpenNebulaConf2019 - Building Virtual Environments for Security Analyses of C...
OpenNebulaConf2019 - CORD and Edge computing with OpenNebula - Alfonso Aureli...
OpenNebulaConf2019 - 6 years (+) OpenNebula - Lessons learned - Sebastian Man...
OpenNebulaConf2019 - Performant and Resilient Storage the Open Source & Linux...
OpenNebulaConf2019 - Image Backups in OpenNebula - Momčilo Medić - ITAF
OpenNebulaConf2019 - How We Use GOCA to Manage our OpenNebula Cloud - Jean-Ph...
OpenNebulaConf2019 - Crytek: A Video gaming Edge Implementation "on the shoul...
Replacing vCloud with OpenNebula
NTS: What We Do With OpenNebula - and Why We Do It
OpenNebula from the Perspective of an ISP
NTS CAPTAIN / OpenNebula at Julius Blum GmbH
Performant and Resilient Storage: The Open Source & Linux Way
NetApp Hybrid Cloud with OpenNebula
NSX with OpenNebula - upcoming 5.10
CheckPoint R80.30 Installation on OpenNebula
DE-CIX: CloudConnectivity
Cloud Disaggregation with OpenNebula
OpenNebula and StorPool: Building Powerful Clouds
Anzeige

Security for Private Cloud Environments