cloudbrokerage.in

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 25 March 2013

CloudCheckr : Amazon Complexity Challenges Many Users

Posted on 09:40 by Unknown
     A recently released infographic from CloudCheckr (http://cloudcheckr.com/) sheds quite a bit of light on the importance of expert advice when an enterprise decides to deploy to the cloud.  When AWS made Trusted Advisor free for the month of March, they took that opportunity to conduct an internal survey of their customers’ usage. CloudCheckr compared the initial scans of 400 users against a list of 125+ best practice checks. The survey was limited to users with over 10 EC2 instances. In aggregate, the users represent a total of just over 16,000 EC2 instances.





     They categorized survey results into 3 main categories: Cost, Availability, and Security; and that over 99% of their users were operating with at least one serious best practice exception. Their primary conclusion was that although cost often grabs the headlines, users suffer from a large number of availability and security issues.

  
     When considering availability, there were numerous serious configuration issues. Users repeatedly failed to optimally configure Auto Scaling and ELB. The failure to create sufficient EBS snapshots was an almost universal issue. When looking at security, they saw a smaller number of issues. However, the ones that did arise were very serious. Specifically, in S3, they saw nearly 1 in 5 users allowed unfettered access to their buckets through “Upload /Delete” or “Edit Permissions” set to everyone. As we explained in an earlier whitepaper, anyone using a simple bucket finder tool could locate and access these buckets.

     In short, typical Amazon Web Services users are not following relatively well know best practices when they deploy to the cloud.  This is not an indictment of the cloud computing model, but rather a realization that most cloud users can benefit greatly from the advice and support of a professional cloud deployment team. 

      Specific conclusion as provided by CloudChekr, are :

  • 96% of all users experienced at least 1 cost related exception(with many experiencing multiple exceptions).  
  • Price optimization remains a large hurdle for AWS users 
  • Nearly 98% suffered from at least 1 availability related exception. 
  • 44% of our users had at least one serious security related exception present  

Additional observations:
COST
  •  Spot instances worry users – there is a general concern of: “what if the price spikes and my instance is terminated?” This fear exists despite the fact that spikes occur very rarely, warnings are available, and proper configuration can significantly mitigate this “surprise termination” risk.
  • It is difficult and time consuming to map the cost scenarios for purchasing reserved instances. The customers who did make this transition had cobbled together home grown spreadsheets as a way of supporting this business decision.
  • The intricacies of matching the configurations between on demand instances and reserved instances while taking into consideration autoscaling and other necessary configurations were daunting. Many felt it was not worth the effort.
  • Amazon's own process for regularly lowering the costs is a deterrent to purchasing RIs. This is especially true for RIs with a 3 year commitment. In fact, within the customers who did purchase RI, none expressed a desire to commit to 3 year commitments. All supported their refusal by referencing the regular AWS price drops and the fact that they could not accurately predict their business requirements 3 years out.
 
 AVAILABILITY

  • Users were generally surprised with the exceptions. They believed that they “had done everything right” but then realized that they underestimated the complexity of AWS.
  • Users were often unsure of exactly why something needed to be remedied. The underlying architecture of AWS continues to unfold and users are not always familiar with the latest AWS twist.
  • AWS dynamism played a large role in the number of exceptions. Users commented that they often fixed exceptions and, after a week of usage, found new exceptions had arisen.
  • Users remained very happy with the overall level of service from AWS. Despite the exceptions which diminish overall functionality, the users still found that AWS offered tremendous functionality advantages.
SECURITY

  • The AWS management console offered little functionality for helping with S3 security. It does not present a useful means of monitoring and controlling S3 inventory and usage. In fact, we found that most of our users were surprised when the inventory was reported. They often had 300-500% more buckets, objects and storage than they expected.
  • S3 is often an afterthought for users. EC2 commands more user attention. Users often failed to create and implement formal policies.
  • S3 cost was contributing to factor to the problems. Given the low cost, team members throw up objects and buckets at will while secure in the knowledge that they can store huge amounts of data at a minimal cost. Similarly, the low costdisincentives users to perform inventories from each region and perform an audit of objects and policies/configurations.  Since users did not know what they had stored, they could not determine the level of security.

·      
Bookmark and Share  



Cloud Musings on Forbes

( Thank you. If you enjoyed this article, get free updates by email or RSS - © Copyright Kevin L. Jackson 2012)




Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Government still wary of cloud computing
    Federal News Radio interviewed Ron Markezich, a corporate vice president of Microsoft, Mike Bradshaw, president of Google federal, and Mich...
  • NRRC Video Series - Video 5 : Boeing Ozone Dashboards for Emergency Management
    In September, the NCOIC delivered the Geospatial Community Cloud (GCC) demonstration . Sponsored by the National Geospatial-Intelligence Ag...
  • So what kind of consultant are you?
    Yesterday over lunch, a good friend of mine from the Limelight Marketing Group and I started talking about my recent transition. As you can...
  • Cloud Computing as a Strategic Asset
    For some reason, this week seems to have more in it than most. While the steady stream of briefing request seem to be increasing, the post b...
  • Iranian Protests Showcase Twitter, Facebook, YouTube (and Cloud Computing) !
    In covering unfolding events in Iran, the world's most powerful news outlets have been entirely dependent on the Twitter-provided flow o...
  • Vivek Kundra Nominated for Federal CIO
    Mr. Kundra's quote from the Wall Street Journal says it all: “I’m a big believer in disruptive technology. If I went to the coffee shop,...
  • MIT Survey: What A Response !!
    We've been quite surprised by the number of survey responses we've received.  THANK YOU !!   That subset of the cloud computing comm...
  • Robert Duffner Interviews Chris Kemp, NASA, and Kevin Jackson, NJVC, on GovCloud
    Recently, I had the pleasure of being interviewed by Mr. Robert Duffner , director of Product Management for Windows Azure , as part of his ...
  • BISNOW Data Center Event Highlight's Cloud
    A big thank you to BISNOW and my fellow panel members for an outstanding discussion and very informative event, last week's Data Center ...
  • CSC and Terremark target US Government with Cloud Computing
    Today's announcement by CSC reinforced the strong wave of cloud computing towards the Federal space. Ranked by Washington Technology Ma...

Categories

  • 3Tera
  • 451
  • A. K. Cebrowski
  • ACT
  • ACT-IAC
  • adhoc information system
  • Air Force Maj. Gen. David Edgington
  • ajax
  • Akamai
  • Akamai Boeing Company
  • All Things Considered
  • amazon
  • Amazon Web Services
  • Amazon.
  • ambient awareness
  • American Council for Technology
  • Andres Seabrook
  • Andrew McLaughlin
  • Animoto
  • Appirio
  • Appistry
  • AppJet
  • AppLogic
  • Apptis
  • Army
  • ASD NII
  • Assistant Secretary of Defense
  • ATT
  • auto-scaling
  • Avner Algom
  • Azure
  • BAE Systems
  • BAH
  • Ballmer
  • Balmer
  • bandwidth auction
  • bandwidth cloud
  • bandwidth-on-demand
  • barack obama
  • Battle for Clicks
  • battlegroup cloud
  • Berkely Cloud Computing
  • BerkelyDB
  • Bigtable
  • bill clinton
  • Bill Gerety
  • blue business platform
  • BMC
  • Bob Gourley
  • Bob Lozano
  • Bob Marcus
  • Boeing
  • Booz Allen Hamilton
  • Brand Niemann
  • budgeting process
  • CANES
  • capital expenditures
  • carl ichan
  • CDC
  • Center for Strategic and International Studies
  • Centers for Disease Control and Prevention
  • child development group of mississippi
  • children's defense fund
  • China
  • Chirag Mehta
  • Chris Capossela
  • chris kemp
  • Chris Pearson
  • Christian Science Monitor
  • Christophe Bisciglia
  • Chrome
  • chuck mehle
  • CIA
  • Cinematic Artificial Intelligence
  • cio 2.0
  • CIO Survey
  • Cisco
  • cloud broker
  • cloud broker; cloud computing
  • cloud computing
  • cloud computing benefits
  • Cloud Computing Center
  • cloud computing concerns
  • Cloud Computing Decision
  • cloud computing dictionary
  • cloud computing events
  • Cloud Computing Expo
  • cloud computing group
  • Cloud Computing Guides
  • Cloud computing journal
  • Cloud Computing Marketplace
  • Cloud computing offerings
  • cloud computing portal
  • cloud computing research
  • cloud computing security
  • cloud computing survey
  • cloud computing taxonomy
  • Cloud Computing Twiki
  • Cloud computing use
  • Cloud computing value
  • Cloud Computing War Game
  • Cloud Computing Wargame
  • Cloud Economic Models
  • cloud interoperability
  • cloud rating
  • cloud redundancy
  • cloud reliability
  • Cloud Security
  • cloud services
  • cloud spectator
  • cloud standards
  • cloud vendors
  • CloudCamp
  • CloudCamp Federal
  • CloudCamp: Federal
  • Cloudera
  • CloudExpo
  • CloudNow
  • CNBC
  • CNET
  • Cohesiveft
  • Col. Vincent Valdespino
  • Colin McNamara
  • Collabnet
  • Controlled Unclassified Information
  • COOP
  • correlative analysis
  • Cryptographic data splitting
  • CSC
  • cubit
  • CUI
  • Customs and Border Patrol
  • Cybersecurity
  • Daoli
  • Dark Cloud
  • data center
  • Dataline
  • Dave Douglas
  • Dave Stegon
  • David Douglas
  • David Lindquist
  • David Mihelcic
  • David Ryan
  • Dawn Leaf
  • DDOS
  • defense
  • Defense Intelligence Agency CTO
  • definition operations
  • Dell
  • Department of Interior
  • DHS
  • Diane Bryant
  • DICOM
  • Dion Hinchcliffe
  • DISA
  • DISA CTO
  • Dissemination
  • DoD
  • DoD Cloud Computing
  • Dr. Brand Niemann
  • EAGLE
  • Earth Builder
  • Earthbuilder
  • ebook
  • EC2
  • Elastic Block Store
  • Elastra
  • EMC
  • Enomaly
  • Enomoly
  • enStratus
  • eric schmidt
  • Eurocloud
  • European Defense Agency
  • eweek
  • Exchange
  • Explaining Cloud Computingchristopher Barnatt
  • Exploitation
  • FBI
  • fccI
  • Fedcloud
  • Federal
  • Federal CIO
  • Federal Cloud Computing Wiki
  • Federal News Radio
  • Federal SOA Community of Practice
  • FedRAMP
  • FIPS
  • FirstChoice
  • FISMA
  • Forrester
  • FOSE 2009
  • gaming cloud
  • gartner
  • GEOINT
  • george bush
  • george mason university
  • George Reese
  • George W. Casey
  • Georgia
  • Geva Perry
  • Glenn Dasmalchi
  • Global Content Delivery Service
  • Go Grid
  • Golden Phoenix
  • Goldman
  • Google
  • Google Docs
  • google mindshare
  • google trends
  • GovCloud
  • Government
  • government cloud computing
  • Gravitant
  • green cloud computing
  • Greg Boss
  • grid computing
  • GSA
  • GSA FedRAMP Apps.gov
  • GSAW
  • HaaS
  • Hadoop
  • Harrison Donnelly
  • Henry Sienkiewcz
  • Hewlett Packard
  • high performance computing
  • hillary clinton
  • HL7
  • home depot
  • homeland security
  • HP
  • hype cycle
  • IaaS
  • IAC
  • IBM
  • IGT
  • Implemetation of Network-Centric Warfare
  • Industry Advisory Council
  • information
  • information operations
  • Information Sharing
  • Information Sharing Environment
  • Information Week
  • Inforworld
  • inmobile
  • intel
  • intelligence community
  • intelligence support
  • intelligence support information operations
  • intellipedia
  • Irving Wladasky-Berger
  • Israel
  • IT budget
  • Japan
  • Jason Miller
  • java
  • Jeff Barr
  • Jeffrey A. Sorenson
  • Jeremy Geelan
  • Jill Singer
  • Joe McKendrick
  • John Dvorak
  • John Foley
  • John Garing
  • John Grimes
  • john mccain
  • joint forces command
  • joint intelligence laboratory
  • Joint Warfighting Conference 08 (JWC 08)
  • jott
  • Juniper Networks
  • JWICS
  • Katie Lewin
  • Kevin Jackson
  • KMI Media
  • LANDWARNET
  • Larry Ellison
  • latency
  • Lauren States
  • law enforcement
  • Leslie Lenert
  • Letitia long
  • library of national intelligence
  • LinkedIn Answers
  • location based services
  • MaaS
  • maneuver warfare
  • marian wright edelman
  • MashupOS
  • McKinsey
  • MEDWEB
  • mentat
  • Michael Farber
  • Michael Vizard
  • microsoft
  • Midori
  • Mike Bradshaw
  • Mike Cameron
  • Mike Krieger
  • Military information technology
  • military secure mobile communications
  • MIT
  • MIT Survey
  • mobile
  • MobileMe
  • Mongo
  • National Defense University. IRM College
  • National Office for Cyberspace
  • National Public Radio
  • National Science Foundation
  • national security
  • NATO
  • NATO Communications and Information Systems Services Agency
  • Navy
  • Navy CIO Robert Carey
  • Navy Marine Corps Intranet
  • Navy Next Generation Enterprise Network
  • NC3
  • NCES
  • NCIC
  • NCOIC
  • NCOIC Plenary Session
  • NCSA
  • net-centric warfare
  • Netcentric Corporation
  • Network Centic Operations Industry Consortium
  • Network Centric Operations Industry Consortium
  • Networx
  • NextGen
  • Nexus
  • NGA
  • NGEN
  • Nicholas Carr
  • NIPRNet
  • NIST
  • NJVC
  • NLETS
  • NMCI
  • North Carolina
  • Northrop Grumman
  • Northrop Grumman Mission Systems
  • NPR
  • NRO
  • NSA
  • NSG
  • NVTC
  • O'Reilly Media
  • Office Commuincations
  • Office of Force Transformation
  • OMB
  • On The Frontlines
  • ontology
  • operational expenditures
  • Oracle
  • Oracle On Demand
  • oral history
  • OSD Cloud ComputingD
  • PaaS
  • Parabon
  • Parker Harris
  • Paul Strassmann
  • Pauline Healy
  • PED
  • Peter Coffee
  • Peter Nickolov
  • Petra Mayer
  • platform-as-a-service
  • plenary
  • PlugIntoTheCloud.com
  • PostPath
  • private clouds
  • Processing
  • project hydrazine
  • public - private clouds
  • Q-layer
  • RACE
  • Rackspace
  • RAID
  • Ramat Gan
  • Randall Stross
  • Red Herring
  • relational databases
  • Republican National Convention
  • Reuven Cohen
  • Richard Martin
  • RightScale
  • RNC
  • Rob Vietmeyer
  • robert brewin
  • Robert Carey
  • robert duffner
  • Rod Fontecilla
  • Roger Baker
  • Ron Markezich
  • Russia
  • SaaS
  • Sachs
  • SAIC
  • salesforce.com
  • SAP
  • scalability computing
  • Scott Lowe
  • secure cloud computing
  • security
  • security risk
  • Sensitive But Unclassified
  • Servervault
  • service level agreements
  • shane robinson
  • SharePoint
  • SinpleDB
  • SIPRNet
  • SISO
  • situational awareness
  • six degrees of separation
  • SLA
  • SOA
  • SOA Predictions
  • SOA-R
  • SOA-R Interactive Network Group
  • solar powered mobile communications
  • Soraya Correa
  • sourceforge
  • space situational awareness
  • speech
  • stateless computing
  • Steam Cloud
  • Steve Mills
  • steve stroh
  • Steven L Armentrout
  • Stevie Clifton
  • sun
  • Susanne Balle
  • SYS-CON
  • tactical cloud
  • tactical simulations
  • TECH Bisnow Washington
  • technology
  • TechWeb
  • Terremark
  • Terremark Worldwide
  • Terry Morgan
  • The Big Switch
  • The Economist
  • TIC
  • Tim May
  • Tivoli
  • Todd Wiseman
  • TPM
  • trademark
  • Traditional vs. Cloud
  • transcloud
  • Transition Study Group
  • Trezz Media
  • Tsinghua University
  • Twitter
  • UAV
  • USJFCOM
  • USPTO
  • utility computing
  • Valiant Angel
  • Valve
  • VanRoekel
  • VDC-OS
  • Verizon
  • Veteran's Administration
  • Virtual Network Link
  • virtualization
  • Virtustream
  • Vista
  • Vivek Kundra
  • Vivwk Kundra
  • VMware
  • voiceinteraction
  • Wall Street Journal
  • Walt Mossberg
  • web2.0
  • Werner Vogels
  • White House
  • William Forrest
  • wireless
  • Wohl Centre
  • World Summit of Cloud Computing
  • XCalibre
  • XEN
  • yahoo
  • ZeroNines

Blog Archive

  • ▼  2013 (39)
    • ►  December (7)
    • ►  November (7)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (3)
    • ►  June (2)
    • ►  May (3)
    • ►  April (4)
    • ▼  March (3)
      • How Cloud Brokerage Enables a Practical Path to Cl...
      • NJVC Cloudcuity Management Portal to Provide Secur...
      • CloudCheckr : Amazon Complexity Challenges Many Users
    • ►  February (3)
  • ►  2012 (27)
    • ►  December (2)
    • ►  November (4)
    • ►  October (4)
    • ►  September (2)
    • ►  August (3)
    • ►  July (3)
    • ►  May (2)
    • ►  April (1)
    • ►  March (4)
    • ►  February (1)
    • ►  January (1)
  • ►  2011 (32)
    • ►  December (1)
    • ►  November (2)
    • ►  October (6)
    • ►  September (4)
    • ►  August (1)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (4)
    • ►  March (3)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (54)
    • ►  December (4)
    • ►  November (3)
    • ►  October (4)
    • ►  September (3)
    • ►  August (5)
    • ►  July (3)
    • ►  June (5)
    • ►  May (4)
    • ►  April (3)
    • ►  March (5)
    • ►  February (5)
    • ►  January (10)
  • ►  2009 (115)
    • ►  December (1)
    • ►  November (6)
    • ►  October (6)
    • ►  September (7)
    • ►  August (10)
    • ►  July (13)
    • ►  June (10)
    • ►  May (8)
    • ►  April (11)
    • ►  March (13)
    • ►  February (14)
    • ►  January (16)
  • ►  2008 (200)
    • ►  December (19)
    • ►  November (22)
    • ►  October (23)
    • ►  September (23)
    • ►  August (23)
    • ►  July (30)
    • ►  June (26)
    • ►  May (34)
Powered by Blogger.

About Me

Unknown
View my complete profile