Showing posts with label AWS. Show all posts
Showing posts with label AWS. Show all posts

Tuesday, December 31, 2019

Looking ahead to 2020, Rackspace CTO Joel Friedman offers his predictions

As the New Year 2020 begins, hybrid and multi-cloud will continue to gain traction, as will software as a service (SaaS). Security remains a tough nut to crack, and edge computing will gain ground, but Joel Friedman, Rackspace CTO, predicts more modestly than the current hype may suggest.


PREDICTION 1: HYBRID/MULTI-CLOUD REMAINS ASCENDANT
Smart organizations have locked onto the benefits of running apps and data in the places that make the most sense, whether that’s public or private cloud, colocation or, most commonly, a bespoke combination of these that can evolve as business needs and resources dictate. However, the complexity of managing multiple clouds across the dimensions of cost, security, governance, identity and DevOps patterns will continue to grow in 2020.


This complexity is related to the forced reliance upon a multitude of platforms, the rate of technological change, disruptions to traditional service delivery models and a real shortage of skill sets required to bring it all together. Due to these factors, it is likely that multi-cloud solutions will prevail, while the search for qualified external help will intensify.

Finding external help may prove difficult, as not only will managed service providers need to maintain a multi- or hybrid cloud instance, but internal and external vendors will need to work together to manage a multitude of issues around cost governance, security and tagging, to name a few. Fortunately, 451 Research has found these growing pains can be alleviated with clear communication and flexibility on each partner’s part.

PREDICTION 2: SAAS = PROBLEM SOLVED
On top of infrastructure, one of the cloud strategies I hear on repeat when working with customers is that “cloud first” starts with SaaS. They don’t want to reinvent the (inferior) wheel by developing applications for ‘solved’ problems. Mature SaaS offerings are a culmination of many iterations of customer mandated features, user experience analysis, and just as important, industry best practices around process workflows.

In many cases, organizations choosing to fit their internal process to best match their SaaS vendor’s implementation – as opposed to always opting for customizing the platform to suit legacy workflows. Furthermore, SaaS has a compounding effect with data; once data is in the system, other ecosystem players can offer turn-key integration and add-on services, further enhancing the value proposition of SaaS. 

While this isn’t necessarily a new trend, Friedman predicts this will be the norm in 2020 and expects to see more and more niche, and vertically-focused applications developing a SaaS model.


PREDICTION 3: SECURITY REMAINS A STRUGGLE
When it comes to security, many organizations remain burdened with legacy systems riddled with technical debt and corresponding security vulnerabilities. They understand the need to harness cloud-compatible security frameworks, operating models and tools to operate securely in cloud-native environments, but it can be slow and rough going.

Most industries simply have not reached the place where mature cloud security practices are being implemented, and this creates fertile ground for breaches. Too many are still attempting to apply traditional security controls and methodologies to cloud-native environments and deployments. 

This generally does not work well; not only is the security implementation likely to be ill fit, it also creates drag on the organization’s desired benefits of agility. This sometimes leads to fragmentation, where business units go around central security and implement on their own shadow security. The risks of this should be obvious.

In 2020, Friedman thinks that the cloud continues to present some growing pains to even the most digital-native and forward-thinking organizations. These organizations understand how the cloud can aid their business in moving fast, but they don’t yet have the maturity to implement real-time or just-in-time posture management and ‘least privilege’ protocols in the ephemeral, complex and constantly changing world of multi-cloud. 

While security teams straddle the old world of insecure legacy applications and platforms (those which cannot or should not be modernized), and the relative newness of cloud operating models, I unfortunately expect to see the breach headlines continue in 2020 along with all of the free credit monitoring can handle.

Even when the security teams agree in concept that it’s possible to be more secure in the cloud, many do not have cloud compatible security frameworks, operating models and tools to aid the business in operating in cloud-native environments securely.


PREDICTION 4: CLOUD CONTROL PLANE WILL BECOME THE NORM
There has been a trend over the past few years in which the management plane has been reversing from the datacenter to the cloud. For early cloud adopters, the datacenter was still the central control point. Organizations burst into the cloud or had back-end projects with no internet accessibility. As cloud grew in popularity, more and more greenfield projects became cloud-native.

Granted, many still integrate with on-premises or hosted private clouds for identity, business intelligence or other data enrichment requirements, but the hyperscalers have now moved past denying that hybrid cloud is real (in attempts to capture all workloads), and pivoted their strategy to capture those datacenter workloads where they stand and bring them into their ecosystem. 

This includes Snowball Edge, AWS RDS of VMware, Azure Stack/Azure Arc and Google Anthos. Expect to see more such services in 2020. And why shouldn’t we? Cloud providers have proven their effectiveness of securely operating at scale, and API-enabling everything.


PREDICTION 5: EDGE WILL GAIN MODERATE GROUND
Edge computing is a new frontier — no player is currently dominating this space, as it is a naturally fragmented market. When choosing locations over platforms to address local markets, data sovereignty, and other use case specific needs, I believe organizations may want to align in a technology-neutral and consistent manner. And based on the trends over the past year, containers and serverless seem like a natural beneficiary for edge.

As Kubernetes dominates in the container orchestration arena, serverless is another story in which, as of yet, there are no victors. AWS, Azure and Google Cloud Platform all have their own flavors of Function-as-a-Service (FaaS), which are embedded within their respective cloud ecosystems. Will OpenFaaS with kNative gain some ground based on open standards, addressing the often spoken lock-in avoidance and mobility potential? We shall see. 

Either way, Friedman predicts that 2020 will see lots of innovation and exploration in the edge space, but he suspects this is the year of gaining momentum and the floodgates won’t open until 2021.

Friday, December 20, 2019

Commvault data protection software now fully tested and validated to support AWS Outposts

Commvault announced on Thursday that Commvault software has been tested and validated to support AWS Outposts, which is a new, fully-managed service that extends Amazon Web Services (AWS) infrastructure, services, APIs and tools to virtually any data center, co-location space, or on-premises facility for a truly consistent hybrid cloud experience.

Many customers need to keep certain workloads on-premises while managing other workloads in the cloud. Commvault has robust and expansive support for the ever-growing number of diverse workloads rapidly migrating to AWS from other platforms and delivers the same look, feel and performance for data protection and management on-premises as it does in the cloud. 


As a complement to AWS Outposts, Commvault’s software provides a true single solution, not just a single interface, which creates cost efficiencies, provides simplicity and reduces risk.

Commvault is an Advanced Technology Partner in the AWS Partner Network (APN) and holds AWS Storage Competency status. Working with the AWS engineering team allows Commvault to offer integrated cloud storage solutions and support, giving customers the ability to migrate, backup and store data in the cloud. The depth and breadth of Commvault’s software with the wide array of storage services available from AWS allows customers to rest assured that their data is secure and available in the cloud. 


“Our tested and validated support for AWS Outposts allows our customers to leverage Commvault’s powerful cloud data protection and management capabilities on AWS,” said Karen Falcone, Vice President of Worldwide Cloud GTM, Commvault. “With the growth of cloud services and so many Commvault customers moving into AWS, we are helping organizations achieve the same level of data protection in the cloud as they did on-premises without the complexity and costs of installing and managing infrastructure.”


In October, Commvault announced product and experience enhancements to Commvault Activate, its data insights and governance solution that gives users greater visibility into their data, identifies opportunities for storage efficiencies and manages risk. Enhancements include the addition of file access controls for file storage optimization and new redaction functions with sensitive data governance. 

Thursday, December 12, 2019

Amazon SageMaker Ground Truth enables auto-segmenting of objects when performing semantic segmentation labeling

Amazon Web Services announced Wednesday that its Amazon SageMaker Ground Truth helps build highly accurate training datasets for machine learning (ML) quickly. Ground Truth offers easy access to third-party and own human labelers, and provides them with built-in workflows and interfaces for common labeling tasks. 

Additionally, Ground Truth can lower labeling costs by up to 70 percent using automatic labeling, which works by training Ground Truth from data humans have labeled so that the service learns to label data independently. 

Amazon SageMaker Ground Truth helps users build highly accurate training datasets for machine learning quickly. SageMaker Ground Truth offers easy access to public and private human labelers and provides them with built-in workflows and interfaces for common labeling tasks. Additionally, SageMaker Ground Truth can lower labeling costs by up to 70 percent using automatic labeling, which works by training Ground Truth from data labeled by humans so that the service learns to label data independently.



Successful machine learning models are built on the shoulders of large volumes of high-quality training data. But, the process to create the training data necessary to build these models is often expensive, complicated, and time-consuming. The majority of models created today require a human to manually label data in a way that allows the model to learn how to make correct decisions. 

For example, building a computer vision system that is reliable enough to identify objects - such as traffic lights, stop signs, and pedestrians - requires thousands of hours of video recordings that consist of hundreds of millions of video frames. Each one of these frames needs all of the important elements like the road, other cars, and signage to be labeled by a human before any work can begin on the model that the user wants to develop.

Amazon SageMaker Ground Truth reduces the time and effort required to create datasets for training to reduce costs. These savings are achieved by using machine learning to automatically label data. The model is able to get progressively better over time by continuously learning from labels created by human labelers.

Where the labeling model has high confidence in its results based on what it has learned so far, it will automatically apply labels to the raw data. Where the labeling model has lower confidence in its results, it will pass the data to humans to do the labeling. 

The human-generated labels are provided back to the labeling model for it to learn from and improve. Over time, SageMaker Ground Truth can label more and more data automatically and substantially speed up the creation of training datasets. 


Semantic segmentation is a computer vision ML technique that involves assigning class labels to individual pixels in an image. For example, in video frames captured by a moving vehicle, class labels can include vehicles, pedestrians, roads, traffic signals, buildings, or backgrounds. It provides a high-precision understanding of the locations of different objects in the image and is often used to build perception systems for autonomous vehicles or robotics. 

To build an ML model for semantic segmentation, it is first necessary to label a large volume of data at the pixel level. This labeling process is complex. It requires skilled labelers and significant time—some images can take up to two hours to label accurately.

To increase labeling throughput, improve accuracy, and mitigate labeler fatigue, Ground Truth added the auto-segment feature to the semantic segmentation labeling user interface. The auto-segment tool simplifies the task by automatically labeling areas of interest in an image with only minimal input. 

Users can accept, undo, or correct the resulting output from auto-segment. The screenshot highlights the auto-segmenting feature in the toolbar, and shows that it captured the dog in the image as an object. 

With this new feature, users can work up to ten times faster on semantic segmentation tasks. Instead of drawing a tightly fitting polygon or using the brush tool to capture an object in an image, users draw four points: one at the top-most, bottom-most, left-most, and right-most points of the object. Ground Truth takes these four points as input and uses the Deep Extreme Cut (DEXTR) algorithm to produce a tightly fitting mask around the object. 

Tuesday, December 10, 2019

McAfee aligns with Amazon Web Services to bring MVISION Cloud support to Amazon Detective

McAfee has announced that McAfee MVISION Cloud for Amazon Web Services (AWS) now includes support for Amazon Detective, providing customers with seamless incident detection and remediation. Through the integration of MVISION Cloud with Amazon Detective, customers have the ability to react to security issues quickly and confidently while leveraging the appropriate tools for incident investigation. 


Amazon Detective is a security service that is designed to easily analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. Amazon Detective automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to help customers visualize and conduct faster and more efficient security investigations. 

With McAfee MVISION Cloud, AWS customers can leverage a trusted cloud platform that has achieved AWS Security Competency status as well as AWS Well-Architected Partner designation for its Cloud Access Security Broker (CASB) technology to help locate issues and threats, and move without friction into the analysis phase to resolve the risk.


The capabilities in McAfee MVISION Cloud for AWS include integration with Amazon Detective to detect configuration issues or other cloud risks using McAfee MVISION Cloud and move seamlessly into the investigation phase with Amazon Detective.


The offering comes with architectural freedom of choice that includes Configuration Audit / Cloud Security Posture Management (CSPM) for diverse cloud workloads. Incidents can be detected for a wide array of virtual machine (Amazon Elastic Compute Cloud (Amazon EC2)) or container-based workloads (Amazon Elastic Container Service (Amazon ECS), and Amazon Elastic Kubernetes Service (Amazon EKS) including storage services needed to support the target applications.

Its rich, multifaceted incident data provides integrated CASB-derived functionality such as DLP / Malware detection and user behavior and threat analytics that go beyond detecting basic configuration issues. Identify threats and prioritize remediation, for a frictionless move into Amazon Detective to resolve risks quickly and efficiently.

“We worked closely with AWS to integrate a solution that our mutual customers can use to get total visibility and control over their applications and workloads on AWS,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Amazon Detective’s capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to seamlessly enforce data loss prevention, avoid unauthorized sharing of data, address threats from insiders and compromised accounts, prevent misconfiguration drift, audit all user activity and secure corporate data as organizations leverage the cloud to accelerate their business.”


“McAfee’s market-leading Cloud Security Platform provides a uniform approach to protecting data and stopping threats in the cloud through comprehensive and consistent policies,” said Nemi George, vice president, information security officer, Pacific Dental Services. “The new Amazon Detective integration will give us the added investigation capabilities to improve our compliance and reduce the risk within our cloud infrastructure.”

“We’re delighted that McAfee MVISON Cloud on AWS now supports Amazon Detective, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Dan Plastina, vice president of ESS Security Services, Amazon Web Services. “Customers using Amazon Detective will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

Sunday, December 8, 2019

Amazon VPC Ingress Routing and Trend Micro help simplify network security

Amazon Web Services (AWS) announced availability of Amazon Virtual Private Cloud (Amazon VPC) Ingress Routing service. As a Launch Partner for Amazon VPC Ingress Routing, Trend Micro continues to innovate alongside AWS to provide solutions to customers—enabling new approaches to network security. 

Trend Micro TippingPoint and Trend Micro Cloud One integrate with Amazon VPC Ingress Routing deliver network security that allows customers to obtain compliance by inspecting both ingress and egress traffic, thereby providing user with a deployment experience designed to eliminate any disruption in the business.


Amazon VPC Ingress Routing is a service that helps customers simplify the integration of network and security appliances within their network topology. With Amazon VPC Ingress Routing, customers can define routing rules at the Internet Gateway (IGW) and Virtual Private Gateway (VGW) to redirect ingress traffic to third-party appliances, before it reaches the final destination. This makes it easier for customers to deploy production-grade applications with the networking and security services they require within their Amazon VPC.

By enabling customers to redirect their north-south traffic flowing in and out of a VPC through internet gateway and virtual private gateway to the Trend Micro cloud network security solution. Not only does this enable customers to screen all external traffic before it reaches the subnet, but it also allows for the interception of traffic flowing into different subnets, using different instances of the Trend Micro solution.


Trend Micro customers now have the ability to have cloud network layer security in AWS leveraging Amazon VPC Ingress Routing. With this enhancement, customers can deploy in any VPC, without any disruptive re-architecture and without introducing any additional routing or proxies. Deploying directly inline is the ideal solution and enables simplified network security without disruption in the cloud.

A defense-in-depth or layered security approach is important to organizations, especially at the cloud network layer. That being said, customers need to be able to deploy a solution without re-architecting or slowing down their business, the problem is, previous solutions in the marketplace couldn’t meet both requirements.

So, when customers wanted TippingPoint intrusion prevention system (IPS) capabilities to be brought to the cloud, Trend Micro responded with a solution. Backed by research from Trend Micro Research, including the Zero Day Initiative, Trend Micro created a solution that includes cloud network IPS capabilities, incorporating detection, protection and threat disruption—without any disruption to the network.


At AWS re:Invent 2018, AWS announced the launch of Amazon Transit Gateway. This architecture enables customers to route traffic through a hub and spoke topology, and leverage this as a primary deployment model in the Cloud Network Protection, powered by TippingPoint, cloud IPS solution, announced in July this year. This enabled customers to gain broad security and compliance, without re-architecting, and the company will soon add a flexible deployment model.

Saturday, December 7, 2019

Rackspace strengthens professional and managed services to boost user cloud adoption with AWS

Rackspace accelerates its growth as a full stack service provider by expanding its portfolio of Rackspace Service Blocks and its position in providing professional and managed services for Amazon Web Services (AWS). With the expansion of the Service Blocks portfolio, Rackspace further empowers customers to keep pace with innovation and capitalize on new services and features like Artificial Intelligence (AI), Machine Learning (ML), Internet of Things (IoT), and Serverless Computing. 


Rackspace Service Blocks is the modular cloud services portfolio comprised of discrete, customizable services provided on a flexible consumption model, which allows customers to only pay for the cloud services they need, optimizing IT economics.  

The Rackspace Service Block patterns are designed to streamline the adoption of AWS by consolidating broad expertise across infrastructure, applications, data, strategy and integration. 


This capability is distilled into solution roadmaps designed to help customers deploy three key types of solutions. A combination of professional services, managed cloud and advanced Kubernetes management service blocks, this offering helps customers outline their container strategy, build containerized applications and transition them into ongoing management.


It delivers a grouping of managed and professional services designed to provide customers with the tools and expertise needed to make a smooth transition to hybrid cloud with VMware Cloud on AWS. This configuration helps customers streamline analytics processes, uncover deficiencies within processes and derive meaning from data to enable better data-driven business decisions and serve their customers with accurate and timely data. 


“Our customers need deep AWS expertise that helps them develop, deploy, and integrate the latest applications, improve and secure their infrastructure, and ultimately make the most of what AWS has to offer so that they can move their businesses forward,” said Matt Stoyka, chief relationship officer, Rackspace. “Our enhancement of Rackspace Service Blocks bridges the skills gap faced by customers who are quickly maturing on AWS.” 

“For 15 years, we’ve trusted Rackspace to hear and understand our challenges, diagnose our problems, and quickly develop solutions that fit our evolving needs as a company,” said Bill Dalton, vice president of Firefly Digital. “Today, bringing their expertise to manage our entire container services journey, Rackspace ensures we’re getting the most from AWS so we can focus on innovating and staying competitive.” 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...