AITutorAITutorWiki
🌐
100%
Wiki CatalogDisciplineModule

Computer Science Books/Sem7/Cc

Discipline⏱ 4 Hours Estimated~3 min read

Computer Science Books/Sem7/Cc

– 1 of 487 –

– 2 of 487 –

Published by: Jagannath Kallakurchi Donald J. Houde Dr. Deven Shah & Kogent Learning Solutions Inc. Kailash Jayaswal Black BookTM Cloud Computing

– 3 of 487 –

©Copyright 2014 by Dreamtech Press, 19-A, Ansari Road, Daryaganj, New Delhi-110002 Black Book is a trademark of Paraglyph Press Inc., 2246 E. Myrtle Avenue, Phoenix Arizona 85202, USA exclusively licensed in Indian, Asian and African continent to Dreamtech Press, India. This book may not be duplicated in any way without the express written consent of the publisher, except in the form of brief excerpts or quotations for the purposes of review. The information contained herein is for the personal use of the reader and may not be incorporated in any commercial programs, other books, databases, or any kind of software without written consent of the publisher. Making copies of this book or any portion for any purpose other than your own is a violation of copyright laws. Limits of Liability/disclaimer of Warranty: The author and publisher have used their best efforts in preparing this book. The author make no representation or warranties with respect to the accuracy or completeness of the contents of this book, and specifically disclaim any implied warranties of merchantability or fitness of any particular purpose. There are no warranties which extend beyond the descriptions contained in this paragraph. No warranty may be created or extended by sales representatives or written sales materials. The accuracy and completeness of the information provided herein and the opinions stated herein are not guaranteed or warranted to produce any particulars results, and the advice and strategies contained herein may not be suitable for every individual. Neither Dreamtech Press nor author shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages. Trademarks: All brand names and product names used in this book are trademarks, registered trademarks, or trade names of their respective holders. Dreamtech Press is not associated with any product or vendor mentioned in this book. ISBN: : ISBN ) ebk ( 978-93-5119-394-4 978-93-5119-418-7 Edition: 2014

– 4 of 487 –

About the Author About Kailash Jayaswal Kailash Jayaswal is the Vice President of Technical Services and IT Advisor at Choice Solutions, Ltd. He has completed his B.Tech. in Mechanical Engineering from IIT, New Delhi and M. Tech. from the University of Massachusetts. He has more than 24 years of experience at technical and management levels in various companies such as IBM, Cisco Systems, Roche Bioscience, Siebel (now Oracle), Yahoo, and Caterpillar. He has also provided training to various technical support groups in HP-UX, AIX and Solaris. He has been involved in implementation of several large-scale server and storage consolidations, server virtualization and disaster recovery projects. He is the author of a leading book titled “Administering Datacenters: Servers, Storage and Voice over IP” published in 2005 by John Wiley and Sons, New York. His other published works include articles on Sun Systems Management and Web Administration. He has also been actively involved in teaching courses on IT Deployments to industry professionals and IT application to Undergraduate Engineering Classes at the University of Massachusetts. He has written on IT Products and taught them to Systems Administrators and Sales Engineers at IBM, Cisco and Yahoo. About K V Jagannath Jagannath Kallakurchi Venkobarao, an MSc. in Physics from IIT Roorkee, India, is also one of the co- founders of Choice Solutions Limited. He is the Chief Executive Officer & Managing Director of Choice Solutions Limited, founded in 1991. He was instrumental in setting up of top-class IT infrastructure and IT services at Choice Solutions Limited. An alumni of IIT Roorkee, Venkobarao is now an Honorary Fellow at the same prestigious institution, teaching future professionals the niceties of management. A voracious reader and an avid writer, his need to gain further knowledge led him to enrich himself with degree and certificate courses from various internationally acclaimed institutions. These include an EMBA from Indian School of Business (credits also from Wharton School of Management, Kellogg School of Management and FDC, Brazil) as well as a certificate course from Harvard Business School on Strategy and Implementation. He has also published a paper on management at an International Conference on Innovation and Entrepreneurship.

– 5 of 487 –

About the Author iv Venkobarao has over 28 years of experience in IT field and possesses a rare blend of strong analytical and managerial skills. These have enabled him to deliver in situations that others thought tough. As a strategic thinker who takes inspiration from industry greats like Jack Welch, Venkobarao has a realistic vision that has allowed him to deliver in key situations to meet clients’ needs. A proponent of cloud computing, Venkobarao has been part of several symposiums and gatherings that have delved upon strategies and modalities to boost its adoption across the Indian IT spectrum. He has plans to write more books on management and leadership qualities in the near future. About Donald J. Houde Donald J. Houde is currently serving as the Vice President of Client Implementation Services and Executive Consultant at Choice Solutions, Inc. As a corporate and IT executive, Donald Houde has enjoyed more than 25 years of C-level leadership, IT managerial and solution architecture experience. He has specialized in Applied Physics, Business Operations Financial Management, Real Estate Law, and Information Technology. He is a highly requested advisor on information security, privacy, and confidentiality best practices, as well as a frequent and acclaimed public speaker on education, technology, security, organizational, and leadership topics. About Dr. Deven Shah Currently working as a Professor and Principal in one of the oldest engineering colleges affiliated to the Mumbai University. He is an Open Source Evangelist and pioneered Open Source based content in the engineering studies at the University level. In the year 2009, he created a Private Cloud by using the Open Source Technology in the college to demonstrate how to set up a Virtual Computing Lab. He has received IBM awards for his work on SOA security and the IBM Drona Award (2009). His projects have been selected in the top 20 best projects in the IBM’s Great Mind challenges for four consecutive years. He has authored several books on topics like security, networking, Linux, etc. He is a certified Vulnerability Assessor and has developed various courses by using Open Source Technologies for leading computer institutes in India. He has also carried out various government- funded projects on Security and Cloud Technologies. Acknowledgement We thank the technical and business team at Eucalyptus Systems, Inc. in Goleta California for their generous help with documentation on their cloud product and their permission for us to include the content in this book.

– 6 of 487 –

Contents at a Glance Introduction ……………………………………………………………………………………………………………… xxi Chapter 1: Era of Cloud Computing ………………………………………………………………………………. 1 Chapter 2: Introducing Virtualization …………………………………………………………………………… 27 Chapter 3: Cloud Computing Services …………………………………………………………………………. 55 Chapter 4: Cloud Computing and Business Value ………………………………………………………… 73 Chapter 5: Demystifying Cloud Computing ………………………………………………………………….. 81 Chapter 6: Cloud Types and Models ……………………………………………………………………………. 87 Chapter 7: Open Source Cloud Implementation and Administration……………………………… 113 Chapter 8: Cloud Deployment Techniques …………………………………………………………………. 151 Chapter 9: Recent Trends in Cloud Computing and Standards …………………………………….. 161 Chapter 10: Host Security in the Cloud ………………………………………………………………………. 173 Chapter 11: Data Security in the Cloud ………………………………………………………………………. 179 Chapter 12: Application Architecture for Cloud…………………………………………………………… 201 Chapter 13: Cloud Programming ……………………………………………………………………………….. 219 Chapter 14: Adoption and Use of Cloud by Small and Medium Businesses (SMBs) ………. 237 Chapter 15: Adoption and Use of Cloud by Enterprises ……………………………………………… 253 Chapter 16: Migrating Applications to the Cloud…………………………………………………………. 269 Chapter 17: IT Service Management for Cloud Computing …………………………………………… 277 Chapter 18: SLA with Cloud Service Providers …………………………………………………………… 299 Chapter 19: Risks, Consequences, and Costs for Cloud Computing …………………………….. 317

– 7 of 487 –

Contents at a Glance vi Chapter 20: AAA Administration for Clouds ……………………………………………………………….. 337 Chapter 21: Regulatory and Compliance Requirements for Clouds ………………………………. 351 Chapter 22: Security As A Service …………………………………………………………………………….. 365 Chapter 23: Cloud Certifications and Audits ………………………………………………………………. 379 Chapter 24: Application Development for Cloud …………………………………………………………. 389 Chapter 25: Application Security in the Cloud…………………………………………………………….. 401 Chapter 26: Cloud Computing: The Road Ahead…………………………………………………………. 415 Chapter 27: Mobile Cloud Computing ………………………………………………………………………… 433 Glossary ………………………………………………………………………………………………………………… 447 Index ……………………………………………………………………………………………………………………… 455

– 8 of 487 –

Table of Contents Introduction ………………………………………………………………………………………………….. xxi Chapter 1: Era of Cloud Computing …………………………………………………………………. 1 Getting to Know the Cloud …………………………………………………………………………………………………. 2 Cloud and Other Similar Configurations ……………………………………………………………………………… 3 Peer-To-Peer, Client–Server, and Grid Computing ……………………………………………………………….. 4 Cloud Computing Versus Peer-to-Peer Architecture …………………………………………………………….. 5 Cloud Computing Versus Client–Server Architecture …………………………………………………………… 5 Cloud Computing Versus Grid Computing ………………………………………………………………………….. 6 How We Got to the Cloud …………………………………………………………………………………………………… 6 Concept Phase………………………………………………………………………………………………………………….. 7 Pre-Cloud Phase …………………………………………………………………………………………………………….. 10 Cloud Phase …………………………………………………………………………………………………………………… 11 Server Virtualization Versus Cloud Computing ………………………………………………………………….. 13 Components of Cloud Computing……………………………………………………………………………………… 14 Cloud Types—Private, Public, and Hybrid …………………………………………………………………………. 16 The Public Clouds ………………………………………………………………………………………………………….. 16 The Private Clouds …………………………………………………………………………………………………………. 16 The Community Clouds………………………………………………………………………………………………….. 17 The Hybrid Cloud ………………………………………………………………………………………………………….. 18 Impact of Cloud Computing on Businesses ………………………………………………………………………… 18

– 9 of 487 –

Table of Contents viii Organizations that Could Benefit from Public or Private Clouds………………………………………….. 20 The Cloud is not for Everyone - When you Might not Benefit from the Cloud ……………………… 21 Cloud Computing Service Delivery Models ……………………………………………………………………….. 23 Points to Remember ………………………………………………………………………………………………………….. 25 Chapter 2: Introducing Virtualization ……………………………………………………………… 27 Introducing Virtualization and its Benefits …………………………………………………………………………. 28 Benefits ………………………………………………………………………………………………………………………….. 29 Implementation Levels of Virtualization …………………………………………………………………………….. 30 Comparison between the Implementation Levels of Virtualization ……………………………………. 34 Virtualization Design Requirements ………………………………………………………………………………… 34 Virtualization Providers………………………………………………………………………………………………….. 35 Virtualization at the OS Level ……………………………………………………………………………………………. 37 Virtualization Structure …………………………………………………………………………………………………….. 38 Hosted Structure…………………………………………………………………………………………………………….. 38 Bare-Metal Structure ………………………………………………………………………………………………………. 40 Virtualization Mechanisms………………………………………………………………………………………………… 41 Open Source Virtualization Technology……………………………………………………………………………… 42 KVM versus the Xen Hypervisor …………………………………………………………………………………….. 43 Xen Virtualization Architecture …………………………………………………………………………………………. 43 Binary Translation with Full Virtualization ………………………………………………………………………… 44 Paravirtualization with Compiler Support………………………………………………………………………….. 45 Virtualization of CPU, Memory, and I/O Devices ………………………………………………………………. 46 Hardware Support for Virtualization in Intex x86 Processor………………………………………………… 48 CPU Virtualization …………………………………………………………………………………………………………. 49 Memory Virtualization……………………………………………………………………………………………………. 50 Device and I/O Virtualization…………………………………………………………………………………………. 51 Virtualization in Multicore Processors ……………………………………………………………………………….. 52 Points to Remember ………………………………………………………………………………………………………….. 53 Chapter 3: Cloud Computing Services …………………………………………………………… 55 Infrastructure as a Service (IaaS) ………………………………………………………………………………………… 57 Platform as a Service (PaaS)……………………………………………………………………………………………….. 58

– 10 of 487 –

Table of Contents ix Leveraging PaaS for Productivity ………………………………………………………………………………………. 61 Guidelines for Selecting a PaaS Provider …………………………………………………………………………….. 63 Concerns with PaaS…………………………………………………………………………………………………………… 63 Language and PaaS …………………………………………………………………………………………………………… 64 Software as a Service (SaaS)……………………………………………………………………………………………….. 64 Database as a Service (DBaaS) ……………………………………………………………………………………………. 70 Specialized Cloud Services ………………………………………………………………………………………………… 71 Points to Remember ………………………………………………………………………………………………………….. 72 Chapter 4: Cloud Computing and Business Value ………………………………………….. 73 Key Drivers for Cloud Computing …………………………………………………………………………………….. 74 Cloud Computing and Outsourcing …………………………………………………………………………………… 75 Types of Scalability …………………………………………………………………………………………………………… 77 Use of Load Balancers to Enhance Scalability ……………………………………………………………………… 77 Variable Operating Costs Using Cloud Computing ………………………………………………………….. 78 Time-to-market Benefits of Cloud Computing …………………………………………………………………. 78 Distribution Over the Internet……………………………………………………………………………………………. 79 Levels of Business Value from Cloud Computing ……………………………………………………………….. 79 Points to Remember ………………………………………………………………………………………………………….. 80 Chapter 5: Demystifying Cloud Computing ……………………………………………………. 81 Myths and Truths ……………………………………………………………………………………………………………… 82 Points to Remember ………………………………………………………………………………………………………….. 86 Chapter 6: Cloud Types and Models ………………………………………………………………. 87 Private Cloud……………………………………………………………………………………………………………………. 88 Components of a Private Cloud ………………………………………………………………………………………. 90 Implementation Phases of a Private Cloud……………………………………………………………………….. 91 Hardening a Private Cloud ……………………………………………………………………………………………… 93 What is Not a Private Cloud ……………………………………………………………………………………………. 94 Use Cases of a Private Cloud …………………………………………………………………………………………… 95 Case Study: Private Cloud for Central and State Governments ………………………………………….. 96 Case Study: Private Cloud for College to Create a Virtual Computing Lab…………………………. 97

– 11 of 487 –

Table of Contents x Community Cloud ……………………………………………………………………………………………………………. 98 Public Cloud …………………………………………………………………………………………………………………….. 99 When to Avoid Public Clouds ……………………………………………………………………………………….. 102 Public Versus Community Cloud…………………………………………………………………………………… 104 Cloud APIs…………………………………………………………………………………………………………………… 105 Case Study: Weather Forecasting Using a Public Cloud ………………………………………………….. 107 Case Study: Software Development and Testing in a Public Cloud ………………………………….. 107 Hybrid Clouds………………………………………………………………………………………………………………… 109 Private Versus Hybrid Cloud ………………………………………………………………………………………… 110 Points to Remember ………………………………………………………………………………………………………… 111 Chapter 7: Open Source Cloud Implementation and Administration …………….. 113 Open-Source Eucalyptus Cloud Architecture ……………………………………………………………………. 114 Features of Eucalyptus ………………………………………………………………………………………………….. 114 Components of Eucalyptus……………………………………………………………………………………………. 116 Modes of Operation………………………………………………………………………………………………………. 118 Installation and Configuration Process …………………………………………………………………………… 121 Open-Source OpenStack Cloud Architecture…………………………………………………………………….. 129 Features of OpenStack…………………………………………………………………………………………………… 131 Components of OpenStack ……………………………………………………………………………………………. 132 Modes of Operation………………………………………………………………………………………………………. 136 Installation and Configuration Process …………………………………………………………………………… 136 Cloud Administration and Management ………………………………………………………………………….. 141 OpenStack Web-Based Interface Dashboard …………………………………………………………………… 141 Eucalyptus Web-Based Interface ……………………………………………………………………………………. 143 Starting and Shutting Down the Cloud Controller and Cluster Controller ……………………….. 145 Bundling or Uploading Virtual Machine Images on the Cloud Controller…………………………… 146 Bundling and Uploading Bootable Image File ………………………………………………………………… 146 Bundling and Uploading the Kernel, initrd, and root Partition Separately ……………………….. 146 Launching Instances through PHP-Based Web Interface …………………………………………………. 148 Connecting to the Instances through PHP-Based Web Interface ………………………………………. 148 GUI Access to VM Instances over SSH ……………………………………………………………………………… 148 Points to Remember ………………………………………………………………………………………………………… 149

– 12 of 487 –

Table of Contents xi Chapter 8: Cloud Deployment Techniques …………………………………………………… 151 Potential Network Problems and their Mitigation……………………………………………………………… 153 Cloud Network Topologies ……………………………………………………………………………………………… 153 Automation for Cloud Deployments ………………………………………………………………………………… 154 Self-Service Features in a Cloud Deployment ……………………………………………………………………. 155 Federated Cloud Deployments ………………………………………………………………………………………… 156 Cloud Performance …………………………………………………………………………………………………………. 156 Cloud Performance Monitoring and Tuning……………………………………………………………………… 157 Impact of Memory on Cloud Performance………………………………………………………………………… 157 Improving Cloud Database Performance ………………………………………………………………………….. 158 Cloud Services Brokerage (CSB) ………………………………………………………………………………………. 158 Points to Remember ………………………………………………………………………………………………………… 159 Chapter 9: Recent Trends in Cloud Computing and Standards …………………….. 161 Recent Trends: Conflict of Interest for Public Cloud and IT Product Providers…………………… 162 Recent Trends in Cloud Compliance ………………………………………………………………………………… 163 Recent Trends in Security: BYOD and Encryption Exposures …………………………………………….. 163 Recent Trends in Cloud Standards …………………………………………………………………………………… 164 Approaches to Implement Interoperability between Clouds ………………………………………………. 167 Recent Changes in Professional Certifications …………………………………………………………………… 168 Cloud Ratings …………………………………………………………………………………………………………………. 169 Cloud Computing Trends that are Accelerating Adoption …………………………………………………. 170 Points to Remember ………………………………………………………………………………………………………… 171 Chapter 10: Host Security in the Cloud ………………………………………………………… 173 Security for the Virtualization Product ……………………………………………………………………………… 174 Host Security for SaaS ……………………………………………………………………………………………………… 175 Host Security for PaaS……………………………………………………………………………………………………… 176 Host Security for IaaS………………………………………………………………………………………………………. 177 Points to Remember ………………………………………………………………………………………………………… 178

– 13 of 487 –

Table of Contents xii Chapter 11: Data Security in the Cloud…………………………………………………………. 179 Challenges with Cloud Data…………………………………………………………………………………………….. 181 Challenges with Data Redundancy ………………………………………………………………………………… 181 Challenges with Disaster Recovery ………………………………………………………………………………… 181 Challenges with Data Backup………………………………………………………………………………………… 182 Challenges with Data Replication ………………………………………………………………………………….. 182 Challenges with Data Residency or Location ………………………………………………………………….. 182 Challenges with Data Reliability ……………………………………………………………………………………. 183 Challenges with Data Fragmentation……………………………………………………………………………… 183 Challenges with Data Integration…………………………………………………………………………………… 183 Challenges with Data Transformation ……………………………………………………………………………. 184 Challenges with Data Migration ……………………………………………………………………………………. 184 Challenges with Data Security …………………………………………………………………………………………. 184 Data Confidentiality and Encryption………………………………………………………………………………… 186 Key Protection ……………………………………………………………………………………………………………… 187 Key Length …………………………………………………………………………………………………………………… 189 Backup Data …………………………………………………………………………………………………………………. 190 Data Availability …………………………………………………………………………………………………………….. 191 Data Integrity………………………………………………………………………………………………………………….. 193 Cloud Data Management Interface …………………………………………………………………………………… 194 Cloud Storage Gateways (CSGs) ………………………………………………………………………………………. 195 Advantages of Using a CSG…………………………………………………………………………………………… 197 Cloud Firewall ………………………………………………………………………………………………………………… 198 Virtual Firewall ………………………………………………………………………………………………………………. 198 Points to Remember ………………………………………………………………………………………………………… 198 Chapter 12: Application Architecture for Cloud ……………………………………………. 201 Cloud Application Requirements …………………………………………………………………………………….. 202 Architecture for Traditional Versus Cloud Applications ……………………………………………………. 204 Assumptions for Traditional and Cloud Applications ……………………………………………………….. 204 Recommendations for Cloud Application Architecture ……………………………………………………… 205 Fundamental Requirements for Cloud Application Architecture ……………………………………….. 207

– 14 of 487 –

Table of Contents xiii Relevance and Use of Client-server Architecture for Cloud Applications ……………………………. 210 Addressing Cloud Application Performance and Scalability ……………………………………………… 211 Service-Oriented Architecture (SOA) for Cloud Applications …………………………………………….. 212 Parallelization within Cloud Applications ………………………………………………………………………… 215 Leveraging In-memory Operations for Cloud Applications ……………………………………………….. 216 Points to Remember ………………………………………………………………………………………………………… 216 Chapter 13: Cloud Programming ………………………………………………………………….. 219 Programming Support for Google Apps Engine ……………………………………………………………….. 220 Google File System ……………………………………………………………………………………………………….. 221 BigTable as Google’s NoSQL System ……………………………………………………………………………… 223 Chubby as Google Distributed Lock Service …………………………………………………………………… 226 Programming Support for Amazon EC2 …………………………………………………………………………… 229 Amazon S3 …………………………………………………………………………………………………………………… 229 Elastic Block Store (ESB) ……………………………………………………………………………………………….. 231 Amazon SimpleDB ……………………………………………………………………………………………………….. 233 Points to Remember ………………………………………………………………………………………………………… 235 Chapter 14: Adoption and Use of Cloud by Small and Medium Businesses (SMBs) ……………………………………………………… 237 Pace of Adoption of Public Cloud by SMBs ………………………………………………………………………. 238 Public Cloud Benefits for SMBs………………………………………………………………………………………… 239 Public Cloud Adoption Phases for SMBs ………………………………………………………………………….. 241 Cloud Vendor Roles and Responsibilities Towards SMBs ………………………………………………….. 243 Vendor Selection Phases ………………………………………………………………………………………………….. 244 Cloud Provider Liability ………………………………………………………………………………………………….. 245 Cloud Provider Capabilities …………………………………………………………………………………………….. 245 Infrastructure Management Capabilities ………………………………………………………………………… 245 Service Management Capabilities ………………………………………………………………………………….. 246 Financial Management Capabilities ……………………………………………………………………………….. 246 Risk Management Capabilities ………………………………………………………………………………………. 247 Success Factors for Cloud Consumers ………………………………………………………………………………. 248

– 15 of 487 –

Table of Contents xiv Issues with SMBs Using Public Cloud Services …………………………………………………………………. 251 Points to Remember ………………………………………………………………………………………………………… 251 Chapter 15: Adoption and Use of Cloud by Enterprises ………………………………. 253 Questions that Enterprises Must Ask Cloud Vendors ………………………………………………………… 255 Points to Remember ………………………………………………………………………………………………………… 268 Chapter 16: Migrating Applications to the Cloud ………………………………………….. 269 Key Aspects That Will Migrate Users to Cloud Applications ……………………………………………… 270 Cloud Migration Techniques……………………………………………………………………………………………. 270 Phases During the Migration of an Application to the Cloud……………………………………………… 273 Cloud Emulators and Its Use for Application Testing and Migration …………………………………. 275 Points to Remember ………………………………………………………………………………………………………… 275 Chapter 17: IT Service Management for Cloud Computing ……………………………. 277 ITIL-Based Service Management………………………………………………………………………………………. 278 Service Strategy ………………………………………………………………………………………………………………. 280 Strategy Management for IT Services …………………………………………………………………………….. 280 Service Portfolio Management……………………………………………………………………………………….. 281 Financial Management of IT Services……………………………………………………………………………… 281 Demand Management…………………………………………………………………………………………………… 282 Business Relationship Management……………………………………………………………………………….. 282 Service Design ………………………………………………………………………………………………………………… 282 Design Coordination …………………………………………………………………………………………………….. 283 Service Catalog …………………………………………………………………………………………………………….. 283 Service Level Management ……………………………………………………………………………………………. 284 Availability Management ……………………………………………………………………………………………… 284 Capacity Management ………………………………………………………………………………………………….. 284 IT Service Continuity Management (ITSCM) ………………………………………………………………….. 285 Information Security Management System (ISMS) ………………………………………………………….. 286 Supplier Management …………………………………………………………………………………………………… 286

– 16 of 487 –

Table of Contents xv Service Transition ……………………………………………………………………………………………………………. 287 Transition Planning and Support (or Project Management Phase) ……………………………………. 288 Change Management ……………………………………………………………………………………………………. 288 Service Asset and Configuration Management (SACM) ………………………………………………….. 289 Release and Deployment Management ………………………………………………………………………….. 290 Service Validation and Testing ………………………………………………………………………………………. 290 Change Evaluation ……………………………………………………………………………………………………….. 290 Knowledge Management ………………………………………………………………………………………………. 291 Service Operations ………………………………………………………………………………………………………….. 291 IT Operations Management …………………………………………………………………………………………… 292 Service Helpdesk ………………………………………………………………………………………………………….. 292 Event Management……………………………………………………………………………………………………….. 292 Incident Management …………………………………………………………………………………………………… 293 Request Fulfillment ………………………………………………………………………………………………………. 293 Problem Management …………………………………………………………………………………………………… 294 Access Management ……………………………………………………………………………………………………… 294 Technical Management …………………………………………………………………………………………………. 295 Application Management ……………………………………………………………………………………………… 295 Continual Service Improvement ………………………………………………………………………………………. 295 Points to Remember ………………………………………………………………………………………………………… 297 Chapter 18: SLA with Cloud Service Providers …………………………………………….. 299 The Concept of an SLA ……………………………………………………………………………………………………. 301 SLA Aspects and Requirements ……………………………………………………………………………………….. 302 Service Availability …………………………………………………………………………………………………………. 305 Cloud Outages………………………………………………………………………………………………………………… 305 Credit Calculation for SLA Breaches ………………………………………………………………………………… 306 Sample SLA 1: Amazon S3 SLA ……………………………………………………………………………………….. 306 Sample SLA 2: The Rackspace Cloud Server SLA………………………………………………………………. 309 Sample SLA 3: Google Apps SLA …………………………………………………………………………………….. 311 Sample SLA 4: HP Cloud Compute SLA …………………………………………………………………………… 312 Points to Remember ………………………………………………………………………………………………………… 315

– 17 of 487 –

Table of Contents xvi Chapter 19: Risks, Consequences, and Costs for Cloud Computing…………….. 317 Introducing Risks in Cloud Computing ……………………………………………………………………………. 318 Risk Assessment and Management…………………………………………………………………………………… 320 Risk of Vendor Lock-in ……………………………………………………………………………………………………. 320 Risk of Loss of Control …………………………………………………………………………………………………….. 321 Risk of Not Meeting Regulatory Compliances …………………………………………………………………… 321 Risk of Resource Scarcity or Poor Provisioning …………………………………………………………………. 321 Risk in a Multi-Tenant Environment ………………………………………………………………………………… 322 Risk of Failure…………………………………………………………………………………………………………………. 322 Risk of Failure of Supply Chain ……………………………………………………………………………………….. 322 Risk of Inadequate SLA …………………………………………………………………………………………………… 323 Risks of Malware and Internet Attacks……………………………………………………………………………… 323 Risk of Management of Cloud Resources ………………………………………………………………………….. 323 Risk of Network Outages…………………………………………………………………………………………………. 324 Risks in the Physical Infrastructure ………………………………………………………………………………….. 324 Legal Risk Due to Legislation …………………………………………………………………………………………… 324 Risks with Software and Application Licensing ………………………………………………………………… 325 Security and Compliance Requirements in a Public Cloud ………………………………………………… 326 Calculating Total Cost of Ownership (TCO) for Cloud Computing…………………………………….. 327 Direct and Indirect Cloud Costs……………………………………………………………………………………….. 327 Costs Allocations in a Cloud ……………………………………………………………………………………………. 328 Chargeback Models for Allocation of Direct and Indirect Cost …………………………………………… 329 Chargeback Methodology ……………………………………………………………………………………………….. 330 Cost……………………………………………………………………………………………………………………………… 331 Billable Items ………………………………………………………………………………………………………………….. 331 Atomic Units ………………………………………………………………………………………………………………… 332 Pricing Model ………………………………………………………………………………………………………………. 332 Chargeback Tools and Solution ……………………………………………………………………………………… 333 Maintaining Strategic Flexibility in a Cloud………………………………………………………………………. 334 Points to Remember ………………………………………………………………………………………………………… 335 Chapter 20: AAA Administration for Clouds …………………………………………………. 337 The AAA Model ……………………………………………………………………………………………………………… 338 Authentication ……………………………………………………………………………………………………………… 338

– 18 of 487 –

Table of Contents xvii Authorization……………………………………………………………………………………………………………….. 338 Accounting of Cloud Resource Utilization ……………………………………………………………………… 339 Single Sign-On for Clouds ……………………………………………………………………………………………….. 340 Case Study: Secure SSO for Migration to the Cloud for Southern Shipyards ………………………. 342 Industry Implementations for AAA …………………………………………………………………………………. 343 Authentication Management in the Cloud ………………………………………………………………………… 344 Standards for Controlling Access …………………………………………………………………………………… 345 SAML …………………………………………………………………………………………………………………………….. 346 Authorization Management in the Cloud …………………………………………………………………………. 349 Accounting for Resource Utilization…………………………………………………………………………………. 350 Points to Remember ………………………………………………………………………………………………………… 350 Chapter 21: Regulatory and Compliance Requirements for Clouds………………. 351 Regulations for Clouds ……………………………………………………………………………………………………. 352 GLBA …………………………………………………………………………………………………………………………… 355 HIPAA: Health Insurance Portability and Accountability Act of 1996………………………………. 356 HITECH: Health Information Technology for Economic and Clinical Health Act ……………… 357 PCI-DSS: Payment Card Industry-Data Security Standards …………………………………………….. 358 SOX: Sarbanes–Oxley Act ……………………………………………………………………………………………… 359 ECPA: Electronics Communication Privacy Act ……………………………………………………………… 360 How to Evaluate Compliance within a Cloud …………………………………………………………………… 361 Understand Compliance Requirements and Work with Your Cloud Service Provider ………. 361 Select a Cloud Provider with a History of Transparency in Security and Policies ……………… 362 Separate Your and Your Cloud Provider’s Responsibilities ……………………………………………… 362 Understand Your Application and Data Requirements……………………………………………………. 363 Know About the Certifications and Compliance of Your Cloud Provider …………………………. 363 Points to Remember ………………………………………………………………………………………………………… 363 Chapter 22: Security As A Service ……………………………………………………………….. 365 What Can Security-as-a-Service Offer? ……………………………………………………………………………… 366 Benefits of Security-as-a-Service……………………………………………………………………………………….. 368 Concerns with Security-as-a-Service…………………………………………………………………………………. 370 Security Service Providers ……………………………………………………………………………………………….. 371

– 19 of 487 –

Table of Contents xviii Identity Management as a Service (IdMaaS) ……………………………………………………………………… 373 Attributes of IdMaaS Providers………………………………………………………………………………………… 376 Leading IdMaaS Providers ………………………………………………………………………………………………. 377 Points to Remember ………………………………………………………………………………………………………… 377 Chapter 23: Cloud Certifications and Audits ………………………………………………… 379 Certifications…………………………………………………………………………………………………………………… 380 ISO 9000 Family of Certifications …………………………………………………………………………………… 380 ISO 27000 and ISMS Family of Certifications ………………………………………………………………….. 380 CMMI Certifications……………………………………………………………………………………………………… 381 Cloud Audit Framework …………………………………………………………………………………………………. 383 SysTrust……………………………………………………………………………………………………………………….. 383 WebTrust……………………………………………………………………………………………………………………… 384 SAS 70………………………………………………………………………………………………………………………….. 385 Cloud Auditing Requirements …………………………………………………………………………………………. 386 Internal Audit Requirements …………………………………………………………………………………………. 386 Customer Audit Requirements………………………………………………………………………………………. 386 Government Audit Requirements ………………………………………………………………………………….. 387 Points to Remember ………………………………………………………………………………………………………… 387 Chapter 24: Application Development for Cloud …………………………………………… 389 Developing On-Premise Versus Cloud Applications …………………………………………………………. 390 Modifying Traditional Applications for Deployment in the Cloud……………………………………… 391 Stages During the Development Process of Cloud Application ………………………………………….. 392 Managing a Cloud Application ………………………………………………………………………………………… 393 Using Agile Software Development for Cloud Applications ………………………………………………. 394 Cloud Applications: What NOT To Do …………………………………………………………………………….. 396 Static Code Analysis for Cloud Applications …………………………………………………………………….. 396 Developing Synchronous and Asynchronous Cloud Applications ……………………………………… 397 Case Study: Software Product Development and Testing in a Public Cloud……………………….. 397 The ISV selects two cloud providers ………………………………………………………………………………. 398 Points to Remember ………………………………………………………………………………………………………… 399

– 20 of 487 –

Table of Contents xix Chapter 25: Application Security in the Cloud ……………………………………………… 401 Cloud Application Software Development Lifecycle (SDLC) ……………………………………………… 403 Cloud Service Reports by Providers …………………………………………………………………………………. 404 Application Security in an IaaS Environment ……………………………………………………………………. 405 Application Security in a PaaS Environment …………………………………………………………………….. 408 Security Challenges in a PaaS ………………………………………………………………………………………… 409 Protecting a PaaS ………………………………………………………………………………………………………….. 410 Application Security in a SaaS Environment……………………………………………………………………… 411 Points to Remember ………………………………………………………………………………………………………… 413 Chapter 26: Cloud Computing: The Road Ahead ………………………………………….. 415 The Road Ahead for Revenue for Cloud Providers ……………………………………………………………. 416 The Road Ahead for Enterprise Customers……………………………………………………………………….. 417 The Road Ahead for Corporate IT Administrators …………………………………………………………….. 417 The Road Ahead for Corporate IT Departments………………………………………………………………… 418 Change in IT Team Structure …………………………………………………………………………………………. 418 Lower Operational Expenses …………………………………………………………………………………………. 419 Open Systems ………………………………………………………………………………………………………………. 419 The Road Ahead for Cloud Developers…………………………………………………………………………….. 419 The Road Ahead for Standards ………………………………………………………………………………………… 420 The Road Ahead for System Integrators and Managed Service Providers ………………………….. 421 The Road Ahead for Cloud Service Brokerages …………………………………………………………………. 423 iPaaS - “Embedded” Feature of Cloud Services…………………………………………………………………. 424 The Road Ahead for Cloud Security …………………………………………………………………………………. 426 The Road Ahead for Cloud SLAs ……………………………………………………………………………………… 428 The Road Ahead for Identity Management……………………………………………………………………….. 428 The Road Ahead for Cloud Consumers…………………………………………………………………………….. 429 Points to Remember ………………………………………………………………………………………………………… 431 Chapter 27: Mobile Cloud Computing …………………………………………………………… 433 Definition of Mobile Cloud Computing ……………………………………………………………………………. 434 Architecture of Mobile Cloud Computing ………………………………………………………………………… 436 Benefits of Mobile Cloud Computing ……………………………………………………………………………….. 438

– 21 of 487 –

Table of Contents xx Extended Lifetime of the Battery ……………………………………………………………………………………. 439 Improved Data Storage Capacity and Processing Power …………………………………………………. 439 Improved Reliability …………………………………………………………………………………………………….. 440 Mobile Cloud Computing Challenges ………………………………………………………………………………. 440 Challenges at Cloud End ………………………………………………………………………………………………. 442 Points to Remember ………………………………………………………………………………………………………… 445 Glossary ……………………………………………………………………………………………………… 447 Index …………………………………………………………………………………………………………… 455

– 22 of 487 –

Introduction Congratulations on buying Cloud Computing Black Book! This book is designed to provide a one- stop reference for your entire cloud computing needs, starting from understanding the basics of cloud computing; virtualization; cloud computing services; cloud computing and business value; myths and facts about cloud computing; cloud types and models; open source cloud implementation and administration; cloud deployment techniques; recent trends in cloud computing and standards; host security in the cloud; data security in the cloud; application architecture for cloud; cloud programming; adoption and use of small as well as medium businesses; adoption and use of cloud by enterprises; migration of applications to the cloud; IT service management for cloud computing; SLA with cloud providers; risks, consequences, and costs for cloud computing; AAA administration for clouds; regulatory and compliance requirements for clouds; security as a service; cloud certifications and audits; application development for cloud; application security in cloud; future of cloud computing; and mobile cloud computing. Presently most companies use the cloud computing model to access secure and scalable service offerings for infrastructure, data, applications, and email—anytime, anywhere, and from any device. The Audience This book caters to the needs of a vast range of audience such as system architects and practitioners, researchers, and system developers. The book also targets professional computer science developers and graduate students especially at the Masters level. This book is equally beneficial for people who want to learn cloud computing from scratch, or who want to migrate their data on cloud. Cloud Computing Black Book serves as an excellent guide to learn cloud computing—covering all its basic as well as advanced level concepts in detail.

– 23 of 487 –

Introduction xxii About this Book Cloud Computing Black Book explains the usage of different types of clouds according to the users’ needs. This book mainly covers the following:  Introduction to cloud computing and its comparison with peer-to-peer architecture, client-server architecture, and grid computing  Virtualization, its benefits, structure, and mechanism. The book also explores the Xen virtualization architecture, binary translation with full virtualization, paravirtualization with compiler support, and hardware support for virtualization in Intex x86 processor  Cloud computing services comprising Infrastructure as a Service (IaaS), Platform as a service (PaaS), Software as a service (SaaS), and Database as a service (DBaaS)  Types of scalability, cloud computing and outsourcing, key drivers of cloud computing, and levels of business value from cloud computing  Myths and facts related to cloud computing  Types of clouds such as private cloud, community cloud, public cloud, and hybrid cloud  Open-source Eucalyptus cloud architecture and cloud administration as well as management  Potential network problems and their mitigation, cloud network topologies, automation for cloud deployments, self-service feature in a cloud deployment, federated cloud deployments, cloud performance monitoring as well as tuning, impact of memory on cloud performance, and cloud services brokerage  Recent trends of cloud such as trends in cloud compliance, trends in security, trends in cloud standards, trends in conflicts of interest for public cloud and IT product providers. Apart from these, the book focuses on cloud ratings, recent changes in professional certifications, and cloud computing trends that are accelerating the adoption of cloud  Host security in the cloud for SaaS, PaaS, and IaaS  Challenges with cloud data, challenges with data security, data confidentiality and encryption, data availability, data integrity, cloud data management interface, cloud storage gateways, cloud firewalls, and virtual firewalls  Cloud application requirements, comparison between the traditional architecture and cloud application architecture, recommendations for cloud application architecture, addressing cloud application performance and scalability, Service-Oriented Architecture (SOA) for cloud applications, and leveraging In-memory operations for cloud applications  Programming support for Google Apps Engine and Amazon EC2

– 24 of 487 –

Introduction xxiii  Pace of adoption of public cloud by small and medium businesses (SMBs), public cloud benefits for SMBs, public cloud adoption phases by SMBs, vendor selection phases, cloud provider liability, cloud provider capabilities, success factors for cloud consumers, and issues with SMBs using public cloud services  Questions that enterprises should ask cloud vendors  Key aspects in migrating data to cloud applications, cloud migration techniques, migration phases , cloud emulators and their use for application testing and migration  IT service management for cloud computing, service strategy, service design, service transition, service operations, and continual service improvement  Concept of Service Level Agreement (SLA), aspects and requirements, service availability, cloud outages, credit calculations of SLA breaches, and sample SLAs for various vendors such as Amazon S3 SLA, Google Apps SLA, HP Cloud Compute SLA, and Rackspace Cloud server SLA  Risks for cloud computing such as risk of vendor lock-in, risk of loss of control, risk of not meeting regulatory compliances, risk of resource scarcity or poor provisioning, risk in a multi- tenant environment, risk of failure, risk of failure of supply chain, risk of inadequate SLA, risk of malware and Internet attacks, risk of management of cloud resources, risk of network outrages, risk in the physical infrastructure, legal risk due to legislation, risk with software and application licensing, and security as well as compliance requirements in a public cloud  The AAA model, single sign-on for clouds, industry implementations for AAA, authorization management in a cloud, and accounting for resource utilization  Regulatory and compliance requirements for clouds  Security as a service, its benefits, and concerns  Cloud certifications and audits, cloud audit framework, and cloud auditing requirements  Application development on clouds, comparison between development on-premise versus cloud applications, modifying traditional applications for deployment in the cloud, stages during the development process of cloud application, managing a cloud application, using Agile software development for cloud applications, static code analysis for cloud applications, and developing synchronous as well as asynchronous cloud applications  Application security in clouds, cloud application software development lifecycle, cloud service reports by providers, application security in an IaaS environment, application security in PaaS environment, and application security in a SaaS environment  Future for enterprise customers, corporate IT administrators, corporate IT departments, cloud developers, system integrators as well as managed service providers, cloud service brokerages, cloud security, cloud SLAs, and identity management, and cloud consumers  Mobile cloud computing, its architecture, benefits, and challenges Enjoy reading!

– 25 of 487 –

Introduction xxiv Conventions We have used some standard conventions throughout this book. This section acquaints you with these conventions. After you have been introduced to virtualization and its benefits, let us take a look at implementation levels of virtualization. The additional, but crucial, information for readers regarding the concepts explained in chapters is given as Exam Prism. For a consumer organization, selecting a cloud provider with the right resources, capacity, and business continuity setup is important. The examples related to the cloud computing concepts, which the readers’ should remember are given as Snapshots in the chapters. These notes are written by experienced authors who have analyzed what you, as a reader, are looking for. Clouds with massive compute resources will be used for colossal computations for mechanical and thermal analysis, weather forecasting, DNA and genome sequencing, etc. The important terms are written in a different font to make them appear distinct from the overall text. Each figure has a caption to help you understand it better. There are several phases involved in deployment of a private cloud, as shown in Figure 1: Case Study 1: E-mail Archiving and Data Storage In general, workers of a company spend up to 90 minutes or more in managing personal data and archiving e-mails, which can be up to or even more than 5TB in size. Backing up and maintaining that data periodically and their recovery for operational purposes may consume more than 8 hours and 16 hours, respectively. This can be optimized by using virtualized data storage, which works in manner similar to a bank, as shown in the following points:  The client data is stored in a cloud, for which the services are provided by a technology company.  The client data taken by the service provider company is optimized and merged back.  A single e-mail or the Internet request file provides the entire data on requirements.  A turn-key operation created automatically keeps the information current by periodic archiving of data for process streamlining.

– 26 of 487 –

Introduction xxv Figure 1: Phases in a Private Cloud Deployment and Go-live Notes are given in the following format: The I/O requests must pass through the host OS to obtain the pass-through facilities in the hosted structure. Table 1 lists the components of OpenStack software with their code names: Table 1 lists the components of OpenStack software with their code names Component Code Name Compute Nova Object Storage Swift Block Storage Cinder Networking Neutron

– 27 of 487 –

Introduction xxvi Table 1 lists the components of OpenStack software with their code names Component Code Name Dashboard Horizon Identity Service Keystone Image Service Glance Other Resources To know more about cloud computing, refer to:  IBM Cloud Computing, http://www.ibm.com/cloud-computing/in/en/  Rackspace Cloud computing, http://www.rackspace.com/cloud/what_is_cloud_computing/  Dell Cloud Computing, http://www.dell.com/learn/us/en/555/dell-cloud-computing The Black Book Philosophy “Complexity kills. It sucks the life out of developers, it makes products difficult to plan, build and test, it introduces security challenges, and it causes end-user and administrator frustration.” Ray Ozzie – Chief Software Architect at Microsoft Corporation Whichever language or platform you might be learning or working on, being a prolific programmer and administrator is fraught with challenges, complications, complexities, and frustrations. We, at Kogent Learning Solutions Inc. and Dreamtech Press, realize this veracity seamlessly; and ensure that our Black Book series comes as an accomplished and dexterous solution to these complexities. The unique structure of Black Books ensures that complex topics are chunked into appropriate sections and presented in a more comprehensible manner, employing diagrams, code, and real-life examples for further simplicity. In addition, Black Books ensure a learning path replete with adequate practice avenues of the concepts learned by means of code examples, listings, executable programs and applications. Each Black Book is designed to grow with its readers, providing all the guidance and reference material they need as they move towards software proficiency. In summation, the Black Book philosophy extends beyond simple pedagogy; and seeks to decipher the practical challenges imbibed in the professional roles of its readers, whether students or professionals – that is why we call it a “Comprehensive Problem Solver”!

– 28 of 487 –

1 Era of Cloud Computing If you need an information on: See page: Getting to Know the Cloud 2 Cloud and Other Similar Configurations 3 Peer-To-Peer, Client–Server, and Grid Computing 4 Cloud Computing Versus Peer-to-Peer Architecture 5 Cloud Computing Versus Client–Server Architecture 5 Cloud Computing Versus Grid Computing 6 How We Got to the Cloud 6 Server Virtualization Versus Cloud Computing 13 Components of Cloud Computing 14 Cloud Types—Private, Public, and Hybrid 16 Impact of Cloud Computing on Businesses 18 Organizations that Could Benefit from Public or Private Clouds 20 The Cloud is not for Everyone - When you Might not Benefit from the Cloud 21 Cloud Computing Service Delivery Models 23 “Nature is a mutable cloud which is always and never the same.” Ralph Waldo Emerson, American essayist and poet (May 1803 – April 1882)

– 29 of 487 –

Chapter 1 2 The two most common IT-related terms currently in use are Internet and Cloud Computing. If you go back a hundred years, the word Industrial Revolution had become a common term. Each of these terms had an immense impact on how business was conducted. While none of them created an overnight change in the way companies steered their businesses; the change came in a series of waves, spread over decades. The coming of Internet and Cloud Computing have spawned startups in various new industry verticals, forcing the existing conglomerates to acclimatize and adapt quickly to survive in the innovative environment. A lot has been written on Cloud Computing on billboards, newspapers, and non-IT and IT magazines. There are many who are sure that cloud computing is just a temporary fad and businesses are pretending to use it for saving expenses. Several existing enterprises and startups want to go the cloud way to just get on the train and not miss out on competitive benefits. Before we discuss the effects of cloud computing on businesses, let us make sense of what it is and other IT services (started as far back as 1960s) that it bears semblance with. Getting to Know the Cloud Cloud is a model where users have a convenient, on-demand access to a shared pool of resources, such as servers, storage, and applications, over the Internet. Users don’t have a control of underlying hardware infrastructure that is owned and managed by the provider. They access the services or allocated resources by using a Web browser. The most common definition in use is the one by the National Institute of Standards and Technology (NIST), USA, in their Special Publication 800-145, which states, “Cloud Computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.” Cloud Computing has several definitions. According to NIST, the five salient features of a cloud are:  On-Demand Self-Service—A consumer can set up computing capabilities, such as server time and network storage, as needed, automatically without having any direct communication with each service provider.  Broad Network Access—Capabilities are available over the network and accessed through normal mechanisms that are used by various devices, such as mobile phones, tablets, laptops, or workstations.  Resource Pooling—The provider’s computing resources, such as storage, processing, memory, and network bandwidth, are pooled to serve multiple consumers by using a multi-tenant model. Further, on the basis of the consumer’s demand, various physical and virtual resources are systematically assigned and re-assigned. There is a sense of location independence, in that the customer generally has no control or knowledge over the exact location of the provided resources but may well be able to specify the location at a higher level of abstraction, for example country, state, or datacenter.

– 30 of 487 –

Era of Cloud Computing 3  Rapid Elasticity—Cloud computing capabilities can be systematically provisioned to meet demand and load requirements. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at any time.  Measured Service—Cloud systems can automatically control and optimize the use of resources by leveraging a metering capability at some level of abstraction that is appropriate for the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and the consumer. Cloud and Other Similar Configurations There are several multi-tenant implementations that are similar to cloud computing. The models are similar and for once, can confuse the related concepts. A clear understanding of the following terms will help you in distinguishing these from Cloud Computing (See Figure 1 on next page).  Application Service Provider (ASP) —Jostein Eikeland, the founder of Tele-computing, coined the term ASP in 1996. An ASP was defined as an organization that hosts and manag

[…content truncated for processing]