Securing an Open Stack Cloud
February 27, 2012, Cloud Security Alliance Summit, San Francisco—Chris Kemp from Nebula, and former CTO of NASA, talked about the development efforts in creating an open stack for cloud computing through an open source community.
The club platform is defined as an on-demand system that can scale quickly to any demand requirements and can have portions easily commissioned or decommissioned. A native cloud platform is hypervisor agnostic and has network connectivity and storage. Most cloud systems are running some version of Apache 2.0.
Private clouds require internal management and technical knowledge skills, and are tailored to meet current performance requirements. Security for a private cloud is less involved than a public one, because all the data are inside the firewall. A private cloud can be the same as a public one behind firewall, but as more costs and a fixed architecture. A private cloud is more secure than the public would just because it has fewer access points available.
Now there is an effort to create an open stack for public and private cloud developments. Originally started by RackSpace and NASA, the community now numbers over 2300 people and is the basis for many cloud installations. The five main ongoing projects in the community are a dashboard called Horizon, compute engines in a program named Nova, object storage under Swift, image repositories within Glance, and identity under Keystone.
The organization is starting work on test penetration, and a bug test for source code review. Five people are independently looking at security and code as their sole focus along with hundreds of others as part of their submissions. Defense within OpenStack is in-depth and requires changes in operating systems. The keys are prevention, detection, response, and prediction of any intrusion efforts. The foundation of security is governance of all critical focus areas to reduce waivers within system administration. The exception would be a standard-based cloud.
Most of the code for OpenStack is in Python and is designed to be highly scalable. The compute function is much like Amazon EC2 with the hypervisor of your choice the architecture is SQL-based with the ability for parallelized scaling the various components can be viewed and downloaded from the OpenStack website. The framework provides a reference implementation for all aspects of a cloud.
Security is a challenge because the hypervisor security portion is not trivial. This portion requires linking of a database message queue, a filesystem to enable security features, and a hardened daemon to manage and automate functions. The other functions in the reference implementation includes storage in a manner similar to Amazon S3. The management dashboard helps to configure and manage various web applications. The image store uses SQL or metadata and is designed around common open source open stack technologies. It uses the best practices currently available for security.
The ID services have just been rewritten to integrate with existing identification products. As a plug-in structure but is not identification provider. It uses a common security framework through an API. The identity services have been integrated to work with existing tools and processes as well as best practices in order to introduce no new management issues.
Other projects in development are looking at existing technologies and philosophies to enhance existing actresses. All of these functions are made in defensible technologies to address the issues that most security controls are not built-in. By hardening standard tools and technologies they hope to improve overall security and practices. All of the projects have very high granularity to allow for many integration points as well as simulation tools and forensics. The projects are designed to integrate with existing processes and tools and provide links to audits and automation to monitor all the elements of the systems.
The goal of the various projects is to reduce the trade-offs and provide and implemented and tested system. This framework provides capabilities for the development of security as a service. Despite persistant efforts, the bottom line is that policies and practices matter.


