CONTRAIL Security Open Computing Infrastructures for Elastic Services Call FP7-ICT-2009-5 Proposal Number FP7-257438 Dr Jens Jensen jens.jensen.at.stfc.ac.uk.

Slides:



Advertisements
Similar presentations
© 2006 Open Grid Forum Federated Identity in the Cloud OGF 32, Salt Lake City.
Advertisements

© Copyright 2012 Hewlett-Packard Development Company, L.P. Contrail: SLAs for Cloud Federations Lorenzo Blasi, Hewlett Packard 1 contrail.
Canada-EU Future Internet Workshop Waterloo, Canada March 24th, 2011 Ignacio M. Llorente DSA-Research.org Distributed Systems Architecture Research Group.
Contrail and Federated Identity Management
SCD in Horizon 2020 Ian Collier RAL Tier 1 GridPP 33, Ambleside, August 22 nd 2014.
Security Prospects through Cloud Computing by Adopting Multiple Clouds Meiko Jensen, Jorg Schwenk Jens-Matthias Bohli, Nils Gruschka Luigi Lo Iacono Presented.
CLOUD COMPUTING AN OVERVIEW & QUALITY OF SERVICE Hamzeh Khazaei University of Manitoba Department of Computer Science Jan 28, 2010.
FI-WARE – Future Internet Core Platform FI-WARE Cloud Hosting July 2011 High-level description.
Towards Cloud Federations: what we have; what we want OGF 31, Taipei Cloud security session Jens Jensen Science and Technology Facilities Council Rutherford.
Cloud Usability Framework
N. GSU Slide 1 Chapter 04 Cloud Computing Systems N. Xiong Georgia State University.
Cloud Computing Stuart Dillon-Roberts. “In the simplest terms, cloud computing means storing & accessing data & programs over the Internet instead of.
INTRODUCTION TO CLOUD COMPUTING Cs 595 Lecture 5 2/11/2015.
SOFTWARE AS A SERVICE PLATFORM AS A SERVICE INFRASTRUCTURE AS A SERVICE.
Constellation Technologies Providing a support service to commercial users of gLite Nick Trigg.
Cisco and OpenStack Lew Tucker VP/CTO Cloud Computing Cisco Systems,
Cloud Computing in Large Scale Projects George Bourmas Sales Consulting Manager Database & Options.
CLOUD COMPUTING & COST MANAGEMENT S. Gurubalasubramaniyan, MSc IT, MTech Presented by.
Abstract Cloud data center management is a key problem due to the numerous and heterogeneous strategies that can be applied, ranging from the VM placement.
MIGRATING INTO A CLOUD P. Sai Kiran. 2 Cloud Computing Definition “It is a techno-business disruptive model of using distributed large-scale data centers.
Presentation to the Housing Technology Conference Tim Cowland- Senior Consultant 27 th February 2014 The Rise of the Housing Cloud.
© 2013 HP development company L.P. The Contrail Demonstrator and other use cases Christian Temporale, Hewlett Packard 1 contrail.
Opensource for Cloud Deployments – Risk – Reward – Reality
Objective 1.2 Cloud Computing, Internet of Services and Advanced Software Engineering Arian Zwegers European Commission Information Society and Media Directorate.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
An Answer to the EC Expert Group on CLOUD Computing Keith G Jeffery Scientific Coordinator.
Climate Sciences: Use Case and Vision Summary Philip Kershaw CEDA, RAL Space, STFC.
Adaptive software in cloud computing Marin Litoiu York University Canada.
Cloud Computing & Amazon Web Services – EC2 Arpita Patel Software Engineer.
European Grid Initiative Federated Cloud update Peter solagna Pre-GDB Workshop 10/11/
Cloud Use Cases, Required Standards, and Roadmaps Excerpts From Cloud Computing Use Cases White Paper
Grids, Clouds and the Community. Cloud Technology and the NGS Steve Thorn Edinburgh University Matteo Turilli, Oxford University Presented by David Fergusson.
Large Scale Sky Computing Applications with Nimbus Pierre Riteau Université de Rennes 1, IRISA INRIA Rennes – Bretagne Atlantique Rennes, France
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud F2F Security Issues in the cloud Introduction Linda Cornwall,
JASMIN and CEMS: The Need for Secure Data Access in a Virtual Environment Cloud Workshop 23 July 2013 Philip Kershaw Centre for Environmental Data Archival.
What is the cloud ? IT as a service Cloud allows access to services without user technical knowledge or control of supporting infrastructure Best described.
The Helix Nebula Marketplace HNX The European cloud marketplace for scientists, researchers, developers & public organisations Marc-Elian Bégin, CEO, Co-founder,
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
1 European e-Infrastructure experiences gained and way ahead OGF 20 / EGEE User’s Forum 9 th May 2007 Mário Campolargo European Commission - DG INFSO Head.
Ruth Pordes November 2004TeraGrid GIG Site Review1 TeraGrid and Open Science Grid Ruth Pordes, Fermilab representing the Open Science.
Windows Azure for scalable compute and storage SQL Azure for relational storage for the cloud AppFabric infrastructure to connect the cloud.
HUSKY CONSULTANTS FRANKLIN VALENCIA WIOLETA MILCZAREK ANTHONY GAGLIARDI JR. BRIAN CONNERY.
Cloud Service Provisioning Jens Jensen (STFC), Piyush Harsh (INRIA) et al contrail is co-funded by the EC 7th Framework Programme under Grant Agreement.
CISC 849 : Applications in Fintech Namami Shukla Dept of Computer & Information Sciences University of Delaware A Cloud Computing Methodology Study of.
1 - Genias and Contrail - WP14 Communication and Dissemination Ad Emmen, Genias Benelux bv contrail is co-funded by the EC 7th Framework Programme under.
European Middleware Initiative (EMI) Alberto Di Meglio (CERN) Project Director.
Cloud Architecture. SPI Model Cloud Computing Classification Model – SPI Cloud Computing Classification Model – SPI - SaaS: (Software as a Service) -
CLOUD COMPUTING WHAT IS CLOUD COMPUTING?  Cloud Computing, also known as ‘on-demand computing’, is a kind of Internet-based computing,
Directions in eScience Interoperability and Science Clouds June Interoperability in Action – Standards Implementation.
Ian Collier, STFC, Romain Wartel, CERN Maintaining Traceability in an Evolving Distributed Computing Environment Introduction Security.
INTRODUCTION TO GRID & CLOUD COMPUTING U. Jhashuva 1 Asst. Professor Dept. of CSE.
European Grid Initiative The EGI Federated Cloud as Educational and Training Infrastructure for Data Science Tiziana Ferrari/ EGI.eu.
EGI-InSPIRE EGI-InSPIRE RI The European Grid Infrastructure Steven Newhouse Director, EGI.eu Project Director, EGI-InSPIRE 29/06/2016CoreGrid.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI A pan-European Research Infrastructure supporting the digital European Research.
EGI-InSPIRE RI EGI Compute and Data Services for Open Access in H2020 Tiziana Ferrari Technical Director, EGI.eu
EGI-InSPIRE RI An Introduction to European Grid Infrastructure (EGI) March An Introduction to the European Grid Infrastructure.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Developing Horizon 2020 projects January 2014 EGI FedCloud F2F, Oxford.
Clouding with Microsoft Azure
StratusLab First Periodic Review
Federated Cloud Computing
FedCloud Blueprint Update
StratusLab Final Periodic Review
StratusLab Final Periodic Review
Linked Challenges Virtualisation has a key role to play….
EGI-Engage Engaging the EGI Community towards an Open Science Commons
Introduction to Cloud Computing
Cloud Computing: Concepts
Fundamental Concepts and Models
Computer Science and Engineering
Presentation transcript:

CONTRAIL Security Open Computing Infrastructures for Elastic Services Call FP7-ICT Proposal Number FP Dr Jens Jensen jens.jensen.at.stfc.ac.uk STFC e-Science Centre, Oct 2010

contrail-project.eu CONTRAIL project - background EU funded “Internet of Services” programme Three year project Started 01 Oct 2010 Goals: Open Source PaaS and IaaS Workflow, MapReduce, Federation: flexible provider/consumer boundaries 2

contrail-project.eu CONTRAIL partners France: INRIA – Lead Edge-IT Germany ZIB Italy CNR HP Italy Tiscali 3 Netherlands Genias VUA Slovenia XLAB UK Constellation Tech STFC

contrail-project.eu 4  Enhanced platform scalability, performance and security  Complete software stack for IaaS  Scalable fault-tolerant storage for Clouds  Self-optimizing, self-healing properties  Secure private network  QoS integrated within infrastructure (storage, network, VMs)  Efficiency through vertical integration of PaaS and IaaS  e.g. Map/Reduce on GAFS file system  Seamless integration of (external) user resources  European, Open approach to Cloud Federation  Federations as an evolving market for IaaS  Contribute to the standardization process Main Innovations and Contributions

CONTRAIL Subprojects and Partners 5 INRIA XLAB STFC ZIB VUA TISC INRIA CNR VUA STFC GENIAS ZIB HP-IIC CONST CNRTISC HP-IICTISC STFC EDGE

contrail-project.eu Contrail Output: IaaS Cloud Buzzword: PaaS, IaaS, (DaaS) Network: VIN – Virtual Infrastructure Networks Virtualisation: Hardware (Xen, KVM,…) Process (OpenVZ, chroot) – sort of like pilot jobs Booting images Storage: Global Autonomous File System (GAFS) Built on XtreemFS “Open Source cloud storage not cloudy” – lack elasticity 6

contrail-project.eu Contrail Output: PaaS Structured data services Eg databases Distributed Key/Value store Runtime environments MapReduce Dynamic allocation of resources “Independent services scale differently” “Tightly coupled stack” “Increase performance and integration” 7

contrail-project.eu CONTRAIL Security Security Work package Lead: STFC Main collaborators: INRIA, XLAB, CNR Minor collaborators: Tiscali, HP, EDGE-IT Use of formal methods verify architecture and implementation Cf. B, Z, Event-B Learning from other EU-funded projects such as DEPLOY Accounting SLAs QoS – Quality of Service QoP – Quality of Protection 8

contrail-project.eu CONTRAIL – Security Loose Ends Role of security in federation Managing policies and resource sharing Authentication Planned to use XtreemOS (X.509 sans GSI) Also compare RESERVOIR (also X.509 but non-IGTF currently) QoS is also security Eg availability QoP is security Eg integrity Securing (virtual) networks Securing VM images 9

contrail-project.eu CONTRAIL – Security Loose Ends Does “traditional” security apply to clouds Understand and mitigate risks Users and trust Cf CSA threats Moving data outside trusted boundary Legal issues with moving data Security of VM images Cf. current work from HEPiX, JSPG, JSPG++ 10

contrail-project.eu Service Provider – DDoS RESERVOIR: “DDoS is greatest risk” Methods for dealing with attack Compare scaling existing services “Cloud bursting” Risk of billing user However, most “attacks” we see are “unintentional” Neither malicious, nor needing scaling Dodgy scientist code Users who don’t understand pitfalls of dist’d comp 11

contrail-project.eu CONTRAIL - Standards Recognise OCCI as the “most promising” Did not consider CDMI (not available when proposal was written) Commitment to standardisation Not clear what, yet Need to aim up-front, though Need to liaise/collaborate with EGI and EMI? SLAs from and others Not standardised “Can standardise underlying model” “Concertation”proposed standards bodies ETSI, W3C, OASIS, OGF, OMG 12

contrail-project.eu CONTRAIL – Use Cases 1.Distributed Provision of Geo-Referenced Data o Tourist data on digital globe 2.Multimedia Processing Service Marketplace o Content provider, licences 3.Clouds for High Performance Real-Time Data Analysis o Analysis of beamline data, fitting models 4.Large Scale Code Analysis o doc4.mandriva.org 5.High Throughput Electronic Drug Discovery o Pharma use cases, genomics, NGS 13

contrail-project.eu More information jens.jensen.at.stfc.ac.uk