Application Security
7/23/2013
02:52 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Cloud Storage Improves

Three new features make Google's cloud storage service more useful for developers and businesses.

8 Great Cloud Storage Services
8 Great Cloud Storage Services
(click image for larger view and for slideshow)
Continuing its effort to make its infrastructure-as-a-service (IaaS) business more competitive with Amazon Web Services, Google on Monday added three significant features to its Cloud Storage service.

Google Cloud Storage, launched in 2010, provides online storage as a Web service. Though there is some functional overlap with the company's consumer-oriented storage service Google Drive — both have APIs that support programmatic data access — Cloud Storage provides a more robust level of service and capabilities for desktop, mobile and Web applications.

Cloud Storage competes with Amazon S3, Windows Azure Storage and Rackspace Cloud Block Storage, among others. Though Google entered the IaaS business long after Amazon did, it is catching up in terms of capabilities, thanks to the introduction of Object Lifecycle Management, Regional Buckets and Automatic Parallel Composite Uploads.

[ Is Google pushing the boundaries of acceptable ad placement? Read Google Gmail Ads Appear Within Inbox. ]

Object Lifecycle Management suggests tedious technobabble, but the term nonetheless succinctly describes a critical storage function: the ability to delete files programmatically. As Google developer programs engineer Brian Dorsey explains in a blog post, this feature allows developers to configure a storage bucket to keep files for a specified period of time before getting rid of them.

Object Lifecycle Management can also be used in conjunction with Object Versioning to keep, say, only the three most recent versions of files. It is an essential way to manage storage usage and costs.

Regional Buckets provide a way to specify where Durable Reduced Availability data — a form of storage that reduces cost at the expense of availability — is stored, so it can be served from the same network fabric as Google Compute Engine instances. This reduces network latency and increases bandwidth to virtual machines, which may be advantageous when running data-intensive code.

Automatic Parallel Composite Uploads is a new feature in the 'gsutil' app, a Python application that lets users interact with Cloud Storage from the command line. It allows large objects to be uploaded in parallel, a potential time savings.

Google only really committed to the IaaS market in May when it made Compute Engine available to the public and received ISO 27001:2005 international security certifications for its Cloud Platform. Launched last year as an invitation-only service, Compute Engine began admitting Google Cloud Platform Gold Support customers in April.

Google in May also made its platform-as-a-service offering, App Engine, more appealing by adding support for the popular PHP programming language.

Research firm IDC last week said that cloud computing has become "business as usual" for enterprises, rather than a service restricted to IT infrastructure.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
7/24/2013 | 8:27:30 PM
re: Google Cloud Storage Improves
Tom, with Object Lifecycle Management, does Google guarantee that the files are fully deleted, including any backups, such that it could be used by companies with policies to destroy certain data after say three years? Right now, maybe they do that by wiping out encryption keys, so that an e-discovery request can be answered with an assurance that the data is gone. If so, that seems like a compelling selling point.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-2086
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.

CVE-2015-2087
Published: 2015-02-26
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.

CVE-2015-2088
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2015-2089
Published: 2015-02-26
Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (...

CVE-2015-2090
Published: 2015-02-26
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.