Although the virtual data center can save costs and improve efficiency, it is estimated that only about 16% of all servers have been virtualized. In addition, many CIOs say they have not moved to virtual or cloud computing models because they are concerned about security issues related to virtualization and cloud computing. This article will discuss the threats to the virtual environment and the Best Practices for solving cloud computing network security problems.
Cloud computing is becoming increasingly popular. A recent survey shows that more than 90% of companies want to use cloud computing in the next three years. However, cloud computing-related security issues are undoubtedly the biggest challenges for the IT department. Mainstream cloud computing business applications (such as Salesforce.com, SharePoint, and SAP) are usually the primary targets of highly-skilled and profitable hacker attacks.
Today's employees are also far beyond the traditional application scope in cloud computing. They often send information through personal email accounts (such as Yahoo or Gmail, use P2P applications (such as LimeWire and BitTorrent) to download files from Web2.0 social networks (such as Facebook and YouTube.
Although these cloud computing-based network applications can create commercial benefits in some situations, however, it may also seize the company's bandwidth, affect production efficiency, and put confidential data in the risk of violation of compliance.
Traditional methods to address network security problems are no longer so effective in the public cloud. WiFi-enabled laptops, third-generation/fourth-generation smartphones, dynamic port selection, and traffic encryption have destroyed application access control over the traditional network based on peripheral defense. Most importantly, it is necessary to optimize and manage the bandwidth of all these applications to ensure the company's network is smooth and the production efficiency of cloud computing five common problems
The rapid development of cloud computing brings many new security problems to the IT department. The following are the five most common problems:
Question 1: P2P Traffic
P2P applications may seize the bandwidth and introduce malware. These applications may be especially difficult to control, because developers often use exchange ports to update new defenses designed to bypass firewall defense.
Question 2: Streaming Media
Streaming Media music and video traffic will impose a heavy burden on network performance and seriously affect traffic of key applications. For example, an IT administrator is confused about why IT takes him an hour and a half to download the patch file, but IT takes only a few minutes to complete. Later, he realized that many employees opened streaming media to watch the competition, resulting in network paralysis and the company's production efficiency was seriously affected.
Question 3: transfer of confidential data
Confidential sensitive information and patent information may be maliciously or unintentionally sent over FTP or via email attachments. A lack of security at work may cause employees to secretly download Customer, order, and payment history records. A survey found that more than half of employees download valuable enterprise data due to rumors of layoffs.
Question 4: third-party email
Third-party email is another channel for potential malware infections and Data leaks. employees and contractors can not only transmit confidential information through enterprise SMTP and POP3 emails, you can also use the web email service, such as Hotmail and Gmail.
Question 5: large file transmission
Without effective control, large file transfers (through FTP or P2P applications) can paralyze network bandwidth. Apply Application Intelligence to cloud computing
To solve these problems in cloud computing, the IT department needs to adopt a new method, that is, Application Intelligence. You can intelligently detect, classify, and control the application bandwidth by using the IP address intercept of the application's smart port and the traditional html "target = _ blank> firewall. By detecting, classifying, and controlling applications, the IT department can block, limit, or optimize any specific application, whether IT is SAP, YouTube, or LimeWire. Then, we can effectively use the Application Intelligence solution to solve the above five problems.
1. Solve P2P Traffic Problems
Because it can detect and classify traffic through a specific application signature rather than a port or address, the application intelligent network is particularly effective in controlling variable port P2P applications. For example, a university IT department will be able to flexibly control the access to LimeWire by students, with a 10% effective bandwidth, so as to ensure that the network bandwidth can prevent non-production activities at the same time.
2. Solve streaming media problems
Application Smart gateway allows IT departments to strictly control streaming media and social network applications. For example, an administrator can allow members of a predefined Active Directory group to access the YouTube website for promotions and other activities, and restrict others' access to YouTube.
3. Solve confidential data transmission problems
The IT department can create and execute application intelligence policies to detect and block email attachments containing watermarks marked with important information or patent information.
4. Solve third-party email Problems
To fill the security gaps in most firewalls and Email Security Solutions, the IT department can use application intelligence to identify, scan, and control any third-party web mail traffic through the gateway (such as Hotmail and Gmail ).
5. solve large-scale file transmission problems
To restrict excessive file transfers, the IT department can develop an application intelligence policy to identify and restrict FTP and P2P file transfers based on predefined size limits.
Application Intelligence and traditional Firewall
Combined with traditional firewall functions, application intelligence can provide more powerful security protection to defend against new threats. For example, an infected Facebook page may suggest "friends" click a link to a YouTube video (actually a link to a malware file ). Because Application Intelligence can detect such links and files from application traffic, it will launch anti-malware and content filtering policies to prevent such malicious files from being downloaded, thus protecting users and enterprise networks.
Conclusion
The growth of cloud computing-based application traffic far exceeds the security functions of traditional firewalls. Fortunately, New Application Intelligence technologies can solve the security problems brought about by these new trends. If IT is effectively deployed on a high-performance platform, application smart Gateway provides IT with effective cloud computing application security.