Wednesday, March 31, 2010

Virtualization and Storage

My storage
As I go through the process of building my virtualized environment, one of my key considerations is storage. We are leaning towards a terabyte SAN storage device to improve the speed of back ups and virtual machines (VMS) can be moved faster.  The ability to quickly deploy  VMS is the key to quick disaster recovery.

System Management
To ease the management of VMS you should create VMS IDs. The use of VMS IDs  allows for control of mobility from server to server and enforce policies automatically. The management tool for Vmware VMS is hypervisor. Management tools become critical because VMS are moved to different servers and taken off line which makes management tricky.

In addition to managing VMS, you must successfully manage all of your licensing. Licensing has been traditionally been tied to per user or per CPU based pricing, but this model does not work with virtual machines. Many vendors must update their licensing models to account for VMS. VMS builds must be accurately tracked to control additional licensing cost associated with OS instances and applications.

Security in a virtual environment is key as the challenges and stakes are high. Any management tools such as hypervisor must be secured properly to protect VMS that ride below. Additionally all your SAN builds become critical as the house all VMS.

Once you have your virtual environment up and running you can decommission servers that have been replaced with VMS. This ultimately saves on power, cooling, and management costs. If you were ever to decommission a virtual server, you would have to find it; and justify the reasoning.

As Virtualization becomes a reality, the key components that need to be monitored are: application availability, resource utilization and allocation, security, storage, and redundancy.  The journey has began and is well worth it.

Monday, March 29, 2010

Virtualization Planning -- disaster recovery and power

I have been reviewing a Virtualization plan for the last 12 - 18 months and I getting close to implementation. The key goals of the Virtualization plan are: consolidation of servers, disaster recovery, reduced power consumption, and fault tolerance.

Virtualization is attractive because it reduces sprawl. The key component of Virtualization is the deployment of virtual machines. Licensing of software running on each virtual machine must be managed and in compliance.As all o the corporate servers become virtualized, down time and disaster recovery become more efficient and cost effective.

Lines of management of virtual servers can become blurred as far as who CIO, CTO, data center, systems manager takes ownership. It seems to be dependent on who is making the decisions regarding deployment.

My current Virtualization plan is as follows: assessment of current resource utilization patterns, security implications, internal and external service requirements, and business disaster recovery plans.

I am in the process of testing Virtualization and determine which technology to use base on cost effectiveness (VMS or Hyper V). Since VMS is the most mature product and easily deployed, I probably will start on this track. When VMware and virtual machines where first deployed there were basic issues with vendors related to licensing, compliance, reliability and performance. During the testing and deployment phase, each of these aspects must be reviewed and responsibility for virtual machines (VMS) must be determined. In some organizations the responsibility for VMS does not fall under I.T., but business managers or some other non-technical discipline.  I am in the process of deploying a test virtual server in my environment. Stay tuned as I update my progress!

Sunday, March 28, 2010

Digital Crime scene forensics and Computer espionage

Computer digital forensics is an emerging field of science to help track and capture cyber criminals. Now that social media sites and the web are a part of our daily life, protecting and securing cyberspace has taken on greater importance.

Computer forensics uses scientific methods to solve questions related to law and computer hacking and possible espionage. Since computer and technology evolves so quickly, it is very difficult for security experts and law enforcement to standarize digital forensic tools and procedures.

All of the computer data and various technologies flow over computer networks which requires network forensics. To improve network security and prevent cyber crime, data and evidence that passes over the network must be analyzed using network forensic tools and procedures.

In the years to come solving computer related crimes will require computer and network forensics and this data will be common component of trail cases. Developing techniques and standards to handle this data is vital to security and fairness of the judicial system.

Network security and cyber crime prevention is tied to collecting and analyzing  network data. This is a difficult task as the data typically resides on internet service providers  servers. In many case you need a sapena  to get access to data.  Many companies are implementing out bound content monitors so they can analyze data that is leaving their network.

In the legal system, the dilemmas revolves around who owns the data, which is  considered evidence.  Creating standards for network forensics and evidence gathering could solve wide ranging legal issues. Currently, security experts and developers are designing software and hardware solutions that will improve overall computer forensic sciences.

Even though a de-facto forensic standard has not been developed, there are some reasonably good  data forensic best practices:
     Best Practice                        Standardization issues

  1. Preservation                       How is the data preserved (media) and by who
  2. Identification                      What tools should be used to identify data (suspicion)
  3. Extraction                          How accurate is the data being extracted (purpose)
  4. Documentation                   How are finding documented and archived (quantity)
  5. Interpretation                    How is the data interpreted and by who (technology)
While researchers and developer create new software solutions, there are no concrete standard to test against. Typically the National Institute of Standards and Technology (NIST) creates standards to test tools used for network forensics, but there has been no clear definition of what forensic tools should do.

As new network forensic tools emerge (commercial and fee) manufacturers and developers should partner with standards organization such as (NIST), to create functional standards for network forensics. Standardized tools and methods will allow researches, security experts, legal professionals to use forensic tools prevent and monitor various security breaches and computer crimes.

Tuesday, March 23, 2010

Health Care Universally Good or Bad, is the hype real

Health Care is both good and bad depending on who you are speaking to or about. I would tend to think, if you currently have health insurance you feel Universal Health Care is bad because the cost of your insurance will increase. If you do not have health insurance or are having a difficult time paying for health insurance, Universal health care is good. I myself fall into the group of people who are concerned that health cost are going to increase.

Knowing some of the facts of the  plan may allow us to determine how the plan may help us. First, I will review the projected cost. As health care is phased in, a surtax will be assessed against the wealthiest Americans making over $500,000 per year. The surtax will be 5.4% income tax for individuals in this tax bracket.  The surtax will be eventually charged to a greater percentage of the American population.

For many people including the wealthy, any new taxes are bad news.  One solution is to get rid of the surtax and find additional ways to fund health care including a carbon tax. A carbon tax is an environmental tax on emissions of CO2.

There has been confusion on how employee base health care would be managed in relation to health care exchanges.  In economic theory,  both employee based health care and exchanges would compete to get insurance coverage, resulting in greater competition; therefore, lowing cost. It is true that both health care coverages are subsidized (employer / government) currently at the tune of 200 billion per year.

Some of the major issues with the health care bill are related to health exchanges. Health exchanges allow for individuals to pool resources to shop for insurance coverage. The exchanges purpose is to make insurance affordable to individuals and small business including a public plan. The regulations related to exchange plans are very strict and limit individual choice. These restrictions seem to benefit the insurance companies in regards to require the purchase of more expensive plans. There should be a push to allow insurers to cut prices if they can offer a more attractive package.

Some forced coverages can have a negative affect on small and medium size businesses. The health care bill required business with payrolls in excess of $500,000 to purchase health insurance for their workers of face a  $2,000 per worker fine. Since most employees have to purchase their own insurance, in most cases with help form their employer, this fine is very steep.

Regardless of what party you belong to,  the plan is workable and helps more than it hinders people.  All of the hysteria in the media and within the GOP is way blown out of proportion. The health care legislation can be used to strengthen the country and the American people as opposed to destroying the country as some have said.

Even some GOP supporters have said, it time for the republicans to get real and move forward. I feell reasonably comfortable the Health Care bill is good for the country!

Monday, March 22, 2010

Perimeter security -- Pearly Gates

The goal of ultimate security is to keep unathorized or intruders outside of a secured area.  Security experts traditionally has focused on perimeter security such as gates, guards, video, firewalls, to prevent undesireable from getting in.

Since security has become more disperse and threats have changed in nature, the focus has become more than just the perimeter.

In todays environment the threat of a security breach is: equally likely from an external or internal source. Typically an internal breach will occur when some one's credentails or idenity is stolen. Organizations and associated facilities must prepare for unauthorize access with in the preimeter security.

To enforce security measures and protect consumers data, federal cybersecurity and senate Judiciary committee has imposed data security programs.  The new security model has evolved into a data centric security or focusing on the value of data and the potential fall out if the data is compromised.

To increase security, the focus becomes who and what process gets access to critical data. The level of protection correlates to quantified risk of breach. The goal of all orgizations is to properly secure sensative data and minimize risk of potential data breach. I will review various technologies that are being used to protect your data in cyberspace. Stay tuned...............

Wednesday, March 17, 2010

Top 25 Technology innovations that have changed our live

11. iPhone / iPod --  The iPhone is considered the catalysis for changing the smartphone market for the better. We can know say we have great mobile devices.
12. Mac OS X -- build on Unix and has raised the bar for innovation in operating systems
13. Multi-core Processors -- The new PC generation is based on multi-core processor for under $1000 comes with tremendous speed and performance. This is a must for next PC purchase.
14. Netbooks -- we finally have a notebook that is small in size, decent capabilities, and low prices.
15.Openoiffice.org -- loosened up the monopoly and opened up document formatting standard
16. POE -- Power over Ethernet,  ability to power VOIP phones, access points, and appliances with out need for wall outlet power.
17.SalesForce.com -- one of the first virtual enterprise customer resource management systems
18. Social Networks "Facebook" has had a profound effect on the way people and businesses connect and communicate.
19. Palm Treo -- for bearer of today's smart phones.
20. Twitter -- changing the way we communicate
21.Red Hat Linux -- stormed business and took hold in the enterprise environment.
22. VMware --  vitualization done in simple terms allowing enterprise class virtula servers running on servers using very little hardware.
23. VOIP Skype, SIP -- Skype allows for cheap voice calls over internet via PC, while SIP signaling allowed for wide spread adoption.
24 Solaris 10 -- leading edge of OS technology including virtualization and 64 bit architecture and  open source strategy.
25 XP --  The desk top operating system of the decade.

Tuesday, March 16, 2010

Technologies that changed the decade and some live

Every decade new technologies have been developed that improve business and quality of life. Over the last decade there have been some great improvements in technology, here is a list of some:
  1. 3G Broadband -- gives us the ability to access the Internet any where in the U.S. and Europe. Carriers use (UMTS / EVDO) standard which allows smartphone, laptops to get internet access any where.
  2. 802.11G wireless networking protocol allows for the transfer of large files to other systems on the same wireless network. If you are installing a wireless network, make sure it is 802.11G.  802.11G has allowed for the spread of WI-FI to most public venues.
  3. AJAX standard scripts for building web appliation technologies. I need to build AJAX to create attractive and interactive web based graphical user interfaces that do no require plug in or extensions that work with most browsers
  4. Amazon EC2 -- rolling out cloud-computing platform, Amazon's Elastic Compute Cloud, business are capable of running their operations on EC2
  5. AMD64 -- AMD builds 64 bit platfrom that has become main stream.
  6. Blackberry -- mobile device build around business, resulting  in the term "Crackberry"
  7. Blade Servers -- rack mount servers consoladating space and cooling.
  8. FireFox -- Mozilla forced browser innovation, resulting in more and better choices
  9. Bluetooth -- wireless innovation allowing us to go hands free.
  10. Google Apps / Gmail  provides features, convience and reliability for many businesses.
Many of us use these technologies in are daily lives to be more productive. Implementing and customizing these technologies can be very benefical for business and their employees.