Application Security
7/23/2013
02:52 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Google Cloud Storage Improves

Three new features make Google's cloud storage service more useful for developers and businesses.

8 Great Cloud Storage Services
8 Great Cloud Storage Services
(click image for larger view and for slideshow)
Continuing its effort to make its infrastructure-as-a-service (IaaS) business more competitive with Amazon Web Services, Google on Monday added three significant features to its Cloud Storage service.

Google Cloud Storage, launched in 2010, provides online storage as a Web service. Though there is some functional overlap with the company's consumer-oriented storage service Google Drive — both have APIs that support programmatic data access — Cloud Storage provides a more robust level of service and capabilities for desktop, mobile and Web applications.

Cloud Storage competes with Amazon S3, Windows Azure Storage and Rackspace Cloud Block Storage, among others. Though Google entered the IaaS business long after Amazon did, it is catching up in terms of capabilities, thanks to the introduction of Object Lifecycle Management, Regional Buckets and Automatic Parallel Composite Uploads.

[ Is Google pushing the boundaries of acceptable ad placement? Read Google Gmail Ads Appear Within Inbox. ]

Object Lifecycle Management suggests tedious technobabble, but the term nonetheless succinctly describes a critical storage function: the ability to delete files programmatically. As Google developer programs engineer Brian Dorsey explains in a blog post, this feature allows developers to configure a storage bucket to keep files for a specified period of time before getting rid of them.

Object Lifecycle Management can also be used in conjunction with Object Versioning to keep, say, only the three most recent versions of files. It is an essential way to manage storage usage and costs.

Regional Buckets provide a way to specify where Durable Reduced Availability data — a form of storage that reduces cost at the expense of availability — is stored, so it can be served from the same network fabric as Google Compute Engine instances. This reduces network latency and increases bandwidth to virtual machines, which may be advantageous when running data-intensive code.

Automatic Parallel Composite Uploads is a new feature in the 'gsutil' app, a Python application that lets users interact with Cloud Storage from the command line. It allows large objects to be uploaded in parallel, a potential time savings.

Google only really committed to the IaaS market in May when it made Compute Engine available to the public and received ISO 27001:2005 international security certifications for its Cloud Platform. Launched last year as an invitation-only service, Compute Engine began admitting Google Cloud Platform Gold Support customers in April.

Google in May also made its platform-as-a-service offering, App Engine, more appealing by adding support for the popular PHP programming language.

Research firm IDC last week said that cloud computing has become "business as usual" for enterprises, rather than a service restricted to IT infrastructure.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
7/24/2013 | 8:27:30 PM
re: Google Cloud Storage Improves
Tom, with Object Lifecycle Management, does Google guarantee that the files are fully deleted, including any backups, such that it could be used by companies with policies to destroy certain data after say three years? Right now, maybe they do that by wiping out encryption keys, so that an e-discovery request can be answered with an assurance that the data is gone. If so, that seems like a compelling selling point.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.