Showing posts with label workload. Show all posts
Showing posts with label workload. Show all posts

Tuesday, December 24, 2019

Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

CloudJumper launches distribution agreement with Crayon to improve access to cloud workspace for Azure

CloudJumper announces alliance with Crayon that combines the power of CloudJumper’s Cloud Workspace Management Suite (CWMS) for VDI and RDS workloads with the expertise of Crayon’s managed services and independent 'cloud economics' consulting practice.

CloudJumper and Crayon’s partnership bring new possibilities for customers and MSPs who want the flexibility of choice for management, security options and the ability to build their own value-add services suite leveraging WVD. 


Microsoft’s Windows Virtual Desktop (WVD) brings new choices for customers who want more control of the managed services running on top of desktop and application virtualization solutions. Legacy VDI providers have historically served as a gatekeepers controlling the workstation management plane. CloudJumper brings to Azure WVD what the legacy vendors will not – the flexibility of controlling managed services on top of managed desktops.

The utility of Windows Virtual Desktop (WVD) is further enhanced through CloudJumper's Cloud Workspace Management Suite (CWMS). CWMS is an automation, orchestration workflow and policy solution to deploy, configure and manage WVD in real-time and at cloud scale. CWMS will instantly, and continually, optimize the customer’s Azure investment.


WVD is a complex collection of Azure services. CloudJumper simply funnels the hundreds of WVD setup options into a few key questions and then orchestrates and deploys a customized environment. With CloudJumper, the customer is just minutes away from deploying thousands of new WVD VMs– something that is not available in a native Azure user interface (UI).

To provide additional support for this distribution partnership, CloudJumper's product development team has been working closely with Microsoft's WVD product team for over two years. As a result, CloudJumper is proud to be recognized as a Microsoft Preferred Solution Provider for WVD.

Microsoft Azure WVD provides customers with unique licensing options and operating system flexibility for Windows 10 and Windows 7 desktop virtualization. Windows 7 desktops can now be migrated to Azure WVD and receive up to three years extended security updates at no additional costs. 

New Windows 10 multi-session OS options are only offered in Azure. These OS choices along with the many complementary Azure PaaS management and security offerings can be securely delivered directly into the Azure tenant. Native Azure Management, supported by CWMS, means no redirection and no third party vendor lock-in. This allows customers to leverage current Microsoft licensing instead of buying overlapping third party tools.

The partnership with Crayon combines the strengths and expertise of CloudJumper and Crayon to deliver the next generation of cloud DaaS and WaaS VDI and RDS desktop and application virtualization solutions.


Headquartered in Oslo, Norway, Crayon is in over 35 countries, providing more than 8,000 customers with strategic advice, consulting and managed services, and support with complex IT estates. Crayon has been the preeminent IT infrastructure consulting business in the Nordic region for more than 12 years, and has expanded its footprint in the US in the last two years.

“Crayon’s deep experience in all aspects of the digitalization journey helps ensure the success of the new partnership. We are pleased to combine CloudJumper’s advanced platform with Crayon’s unique SAM to Cloud Consultancy Services as companies take the next step in digital transformation with their move to Windows Virtual Desktop,” said Alex Picchietti, global director of cloud services for Crayon. “The wealth of expertise from both companies will support organizations making this important move to improve productivity and operational efficiency.”

“The advent of WVD and the partnership with a respected industry leader like Crayon extends the reach of our combined solutions globally,” said JD Helms, president of CloudJumper. “Customers are demanding choice and flexibility in their managed workspace providers and CloudJumper is uniquely positioned to do just that.”

Friday, December 20, 2019

Microsoft and Oracle expand interoperability partnership to Canada to help joint customers run their mission-critical workloads

Oracle announced this week continued expansion of its cloud interoperability partnership with Microsoft to help joint customers worldwide run their mission-critical workloads across Oracle Cloud and Microsoft Azure. Its new interconnect location means enterprises can now build workloads that seamlessly interoperate between Microsoft and Oracle cloud regions in Canada. This interconnect builds on an existing partnership announced in June of 2019.

The partnership has received a huge amount of interest, as 80 percent of enterprises use a combination of Microsoft and Oracle software to run their businesses. 


As cloud computing becomes ubiquitous, and businesses rely on multiple cloud providers, the partnership makes managing companies’ most important cloud workloads significantly easier. These workloads include financial planning, inventory, sales applications – and their underlying databases.

The expansion will give more customers direct, fast and highly reliable network connectivity between Microsoft Azure and Oracle Cloud, while providing first-class customer service and support that enterprises have come to expect from the two companies. This multi-cloud solution delivers the performance, easy integration, rigorous service level agreements, and collaborative enterprise support that they need to simplify their operations. 


Simply put, the Oracle-Microsoft partnership means cloud services run by the two providers will interoperate as if they were part of a single cloud, making it easier for customers to run their mission-critical workloads across the two clouds.

“The global demand for running applications and databases in multi-cloud environments continues to accelerate,” said Clay Magouyrk, senior vice president of engineering, Oracle Cloud Infrastructure.  “With the new interconnect, our Canadian customers can now take advantage of a nearly seamless cloud integration between the world's largest enterprise cloud providers, Microsoft and Oracle.”


The two companies are putting customers first by enabling them to run full-stack applications side-by-side across clouds, or one part of a workload within Azure and another part of the same workload within Oracle Cloud. 

For example, using the interconnect makes it possible to connect Azure services like analytics and AI to Oracle Cloud services like Autonomous Database. Together, Azure and Oracle Cloud offer customers a one-stop shop for all the cloud services and applications they need to run their entire business.

From a technical perspective, the interconnect means less latency or delay, which enables better data transfer and application interaction between clouds. It also supports a broader spectrum of workloads, using resources available on both sides. Accenture recently performed testing on the performance of the interconnect and confirmed that the solution offers customers low latency and high ease of use.

Microsoft and Oracle plan to make the direct interconnect available in additional regions, including on the US West Coast, in a US Government specific region, in Asia, and in the European Union. Earlier this year, Oracle and Microsoft created an interconnect in Ashburn (North America), Azure US East, and in London (United Kingdom).

Tuesday, December 10, 2019

McAfee aligns with Amazon Web Services to bring MVISION Cloud support to Amazon Detective

McAfee has announced that McAfee MVISION Cloud for Amazon Web Services (AWS) now includes support for Amazon Detective, providing customers with seamless incident detection and remediation. Through the integration of MVISION Cloud with Amazon Detective, customers have the ability to react to security issues quickly and confidently while leveraging the appropriate tools for incident investigation. 


Amazon Detective is a security service that is designed to easily analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. Amazon Detective automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to help customers visualize and conduct faster and more efficient security investigations. 

With McAfee MVISION Cloud, AWS customers can leverage a trusted cloud platform that has achieved AWS Security Competency status as well as AWS Well-Architected Partner designation for its Cloud Access Security Broker (CASB) technology to help locate issues and threats, and move without friction into the analysis phase to resolve the risk.


The capabilities in McAfee MVISION Cloud for AWS include integration with Amazon Detective to detect configuration issues or other cloud risks using McAfee MVISION Cloud and move seamlessly into the investigation phase with Amazon Detective.


The offering comes with architectural freedom of choice that includes Configuration Audit / Cloud Security Posture Management (CSPM) for diverse cloud workloads. Incidents can be detected for a wide array of virtual machine (Amazon Elastic Compute Cloud (Amazon EC2)) or container-based workloads (Amazon Elastic Container Service (Amazon ECS), and Amazon Elastic Kubernetes Service (Amazon EKS) including storage services needed to support the target applications.

Its rich, multifaceted incident data provides integrated CASB-derived functionality such as DLP / Malware detection and user behavior and threat analytics that go beyond detecting basic configuration issues. Identify threats and prioritize remediation, for a frictionless move into Amazon Detective to resolve risks quickly and efficiently.

“We worked closely with AWS to integrate a solution that our mutual customers can use to get total visibility and control over their applications and workloads on AWS,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Amazon Detective’s capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to seamlessly enforce data loss prevention, avoid unauthorized sharing of data, address threats from insiders and compromised accounts, prevent misconfiguration drift, audit all user activity and secure corporate data as organizations leverage the cloud to accelerate their business.”


“McAfee’s market-leading Cloud Security Platform provides a uniform approach to protecting data and stopping threats in the cloud through comprehensive and consistent policies,” said Nemi George, vice president, information security officer, Pacific Dental Services. “The new Amazon Detective integration will give us the added investigation capabilities to improve our compliance and reduce the risk within our cloud infrastructure.”

“We’re delighted that McAfee MVISON Cloud on AWS now supports Amazon Detective, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Dan Plastina, vice president of ESS Security Services, Amazon Web Services. “Customers using Amazon Detective will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

Monday, December 9, 2019

Diamanti joins AI/ML sector with its GPU platform that supports containerized workloads on Kubernetes

Diamanti announced availability of its enterprise platform with GPU support for running containerized workloads under Kubernetes, ideal for the demanding requirements of emerging artificial intelligence (AI) and machine learning (ML) applications. 

In conjunction with its recent announcement of Diamanti Spektra, customers can now provide to their end users GPU capacity in cloud clusters for scaling AI/ML workloads on premises out to public clouds to accelerate model development and training.


Diamanti recently announced the close of a $35 million Series C funding round that the company plans to use to ramp global go-to-market initiatives, along with increased investment in engineering resources to drive the roadmap for Diamanti Spektra, as well as new software, SaaS, and hardware solutions for emerging AI and ML workloads.

“AI is quickly proving to be the most disruptive set of new technologies in decades thanks to breathtaking advances in computing power, volume, velocity and variety of data,” said Tom Barton, CEO of Diamanti. “Our platform offers unmatched extensibility and flexibility for containerized workloads and now our customers can add GPU support for a heterogeneous environment under the same Kubernetes umbrella to help with even the most demanding AI/ML requirements.”


The Diamanti platform for AI/ML workloads fully supports Nvidia’s NVLink cross connect GPU card technology for higher performing workloads, as well as Kubeflow, a machine learning framework for Kubernetes that provides highly-available Jupyter notebooks and ML pipelines.

“Cloud-native methodology and software are crossing over with AI and machine learning, with Kubernetes an increasingly attractive option for data scientists to orchestrate the distributed architecture required to run multiple machine learning libraries and frameworks in production at scale,” said Matt Aslett, research vice president, 451 Research. “One key use case across several verticals involves infrastructure that can be quickly spun up or down to support massive simulations.”

Early access Diamanti customers are already benefiting from the new platform support for GPUs in industries as varied as financial services, energy and travel, among others.


For AI/ML applications requiring GPUs, the new Diamanti Spektra solution can also now manage the full lifecycle of containerized workloads across on-premises and public clouds, moving applications and data between Kubernetes clusters as necessary. 

Diamanti Spektra combines the power of Diamanti’s hardware-boosted x86 platform along with cloud-based infrastructure to provide Kubernetes-as-a-Service. Diamanti Spektra is in technology preview.

Wednesday, December 4, 2019

AWS releases slew of security offerings to help enterprises build and operate

Amazon Web Services Inc. (AWS), an Amazon.com company, announced Tuesday three new services and capabilities that make it easier for customers to build and operate securely.


Amazon Detective is a new security service that makes it easy for customers to conduct faster and more efficient investigations into security issues across their workloads (available in preview).


AWS IAM Access Analyzer is a new AWS Identity and Access Management (IAM) capability that makes it simple for security teams and administrators to audit resource policies for unintended access, currently available.



AWS Nitro Enclaves is a new Amazon EC2 capability that makes it easy for customers to process highly sensitive data by partitioning compute and memory resources within an instance to create an isolated compute environment, set to be available in preview early next year.


AWS is architected to deliver secure and flexible cloud computing environment. Many of security-minded organizations trust AWS with their sensitive workloads, which in turn means that all AWS customers benefit from rapidly evolving infrastructure and services designed to meet the most exacting standards for security and compliance. 


AWS has taken away much of the undifferentiated heavy lifting associated with enterprise computing, and customers have asked for similar efficiencies in how they go about building and operating securely in the cloud. 


AWS has continuously introduced new capabilities that help customers achieve greater security, including services like Amazon GuardDuty (which continuously monitors for threats to a customer’s accounts and workloads), Amazon Inspector (which assesses application hosts for vulnerabilities and deviations from best practices), Amazon Macie (which uses machine learning to discover, classify, and protect sensitive data), and AWS Security Hub (a unified security and compliance center). 


AWS has also delivered a slew of native features like Amazon S3 Block Public Access that help customers use core services more securely, and technological innovations like the AWS Nitro System that enhance the inherent security of customer instances by moving virtualization and security functions to dedicated hardware and software. 


Amazon Detective, IAM Access Analyzer, and AWS Nitro Enclaves will help in reducing the amount of custom engineering required to meet security and compliance needs, allow security teams to be more efficient and confident when responding to issues, and make it easier for customers to manage access to AWS resources.

“Amazon S3 is one of the most popular cloud storage solutions, but because of human error it’s historically been a bit of a security liability,” said Sean Roberts, general manager of public cloud at Ensono, a hybrid IT services provider. "Over the last few years, hundreds of well-known organizations have suffered data breaches as a direct result of an incorrect S3 configuration – where buckets have been set to public when they should have been private.” 

“When sensitive data is unintentionally exposed online, it can damage an organization’s reputation and lead to serious financial implications. In real terms, this sensitive data is often usernames and passwords, compromising not only the business but its customers too,” Roberts added. “Access Analyzer will be a welcome addition to S3, and will help businesses all over the world audit their storage for misconfigurations and leaky buckets.”

F5 enters into alliance with AWS to enable users to innovate faster in the cloud

F5 Networks announced a multi-year global Strategic Collaboration Agreement (SCA) with Amazon Web Services (AWS) to allow customers to use F5 for new cloud-native application workloads and extend their existing F5 investments on AWS.


F5’s application services ensure the performance and security of millions of applications for global enterprises. The SCA will enhance companies’ ability to leverage the full suite of F5 Software-as-a-Service (SaaS) and cloud-native application services to migrate, build, secure, and operate their applications on AWS. 


The structured framework of this engagement will allow customers to have a consistent and scalable operating model for their application assets on AWS, while exploring future innovations that enhance migration and operation of applications to the cloud. 


Customers can use advanced F5 solutions to standardize, scale, and optimize application services for AWS environments, from lift-and-shift and re-platforming, to full application development and modernization.

“F5 has collaborated closely with AWS for years, most recently on our SaaS offering, F5 Cloud Services. Together with AWS, we are providing a set of solutions that help enterprises deploy apps quickly and securely, while ensuring they are performant and comply with policy,” said Chad Whalen, Executive Vice President, Worldwide Sales at F5. “This aligns with our strategy of supporting modern DevOps practices and serving engineering teams with capabilities that create the most efficient path from code to customer.”


Enterprises are adopting the cloud to speed innovation cycles and create efficiencies, but today many companies must maintain separate data center and cloud environments, which drive up their operational costs, add complexity, and increase risk. These customers need a hybrid cloud solution that allows their applications to run with consistent performance and security regardless of the location. 

The work F5 and AWS do together addresses this need, allowing organizations to use F5 application services across all environments. Additionally, F5 solutions will make it easier for DevOps teams and application developers to provision, configure, and manage services via APIs or the web portal, without the need for deep networking or security expertise.

“The ability to deploy and run applications on AWS using F5 services is an important requirement for many customers that have standardized on F5 for application delivery and security,” said Mike Clayville, vice president, worldwide commercial sales and business development at AWS. “This Strategic Collaboration Agreement elevates our historic relationship with F5 to a higher level. It will be a great asset for customers as they build new cloud-native applications on AWS and move an increasing number of mission-critical workloads such as SAP and Windows to AWS.”

As part of the collaboration, F5 and AWS will work to allow customers to upgrade to F5’s application services, including F5 Cloud Services using cloud-native, SaaS-based application performance and security services; BIG-IP Virtual Edition with software-based, full-featured Layer 4–7 application delivery and security services; NGINX is a lightweight, highly scalable, and highly performant API management, and full-service proxy software built atop the open source web server; Silverline, its cloud-based managed services platform for application threat protection; and Aspen Mesh, an enterprise-ready, fully supported service mesh built on Istio.

“StockCharts.com is benefiting tremendously from the close collaboration between F5 and AWS,” said Chip Anderson, Founder and President of StockCharts.com. “By leveraging F5’s cloud solutions on AWS, our new cloud strategy is allowing us to provide our customers with a faster, more reliable, secure, and scalable set of web applications. We are now providing more insight and data, faster than ever before.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...