News
8/1/2011
10:38 AM
George Crump
George Crump
Commentary
50%
50%

How to Choose A Cloud Storage Provider: Availability

Access varies across cloud storage providers. Here's how to make sure you get what you need, when you need it.

In a recent entry we discussed what security capabilities you should look for in a cloud storage provider. While security is important, being able to get to your data is equally imperative. To make matters worse, many cloud storage providers are somewhat sketchy in what level of availability they will commit to. Knowing what you can expect from your provider--and how you have to augment that--is critical.

Understanding the availability you need is important because in most cases the level of availability you get directly impacts the price you pay. Typically, the more copies of data that you store in different parts of the cloud, the more it's going to cost.

To a large extent, how available you need cloud storage to be depends on how you are going to use it. If you're using cloud storage as an offsite vault for your backups and you are also keeping some or most of your backups onsite, then 100% availability may not be that big of a concern. If you're using cloud storage as the primary destination for your backups, even with a local cache of some sort, then access to that data for recovery may be critical.

If you're going to use cloud storage for primary storage, then availability is more important, especially with block-based storage solutions. NAS or file-based solutions tend to keep the most recently accessed files in a local, on-premises cache. That means that if the cache is of adequate size you can still get to your most recently accessed files until the cloud service is backed up. Block is more random in nature, so it's harder to predict exactly where the next access will be and, if an old block of data can't be accessed, the application may crash.

The two situations where availability is critical are probably going to be: when you're counting on cloud storage as your primary backup storage area and when you're using cloud storage to store primary block-based storage. Cloud storage as a NAS storage area could be a close third.

Increased availability can come in two forms. The first can be to use the basic services from two different cloud suppliers. This gives you redundancy, not only in a cloud storage failure, but also protects you in case one of the organizations goes out of business. This means your cloud storage software or application needs to be able to support writing to two clouds simultaneously. For most organizations, though, the cost is not going to be practical to have two cloud storage providers.

The next option is to invest in a cloud storage provider that can provide some level of redundancy. This is not limited to just redundant copies of storage spread around the Internet, but also a redundant means of accessing that data. As stated above, extra copies will typically mean extra money. The pricing for these extra copies can vary greatly, so check out the details.

Many providers can deliver a multi-copy level of redundancy, but the key is to make sure that they will provide a service level agreement to stand behind that commitment. Beyond the SLA, make sure that the organization has the capabilities to fulfill the commitments in that SLA, otherwise they are just words on a page. Look to make sure they have quality storage systems, quality data centers, and quality network connections--and of course the financial wherewithal to stand behind all that.

Also understand exactly what is being committed to. Some providers offer a complete, full-service responsibility; others still put much of the burden on you. Several cloud vendors are now providing a turnkey service where they will manage the redundancy and connectivity for you. Of course there is a fee for this service, but it may be well worth it, especially if your IT resources are already stretched thin.

The final step in availability is to know what you will do when a failure occurs. Don't wait for a network or cloud storage failure to figure out your strategy. Plan for it. Make sure that you know how you will connect to the redundant copies or how you will switch to a local copy if you decide to go that route.

Follow Storage Switzerland on Twitter

George Crump is lead analyst of Storage Switzerland, an IT analyst firm focused on the storage and virtualization segments. Storage Switzerland's disclosure statement.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AJ12345
50%
50%
AJ12345,
User Rank: Apprentice
12/4/2011 | 12:23:50 AM
re: How to Choose A Cloud Storage Provider: Availability
Cloud technology has come a long way! I think the most important things are

1. Security
2. Ease of use and integration
3. Cost savings potential

Here's a company doing it really well: bit.ly/cloudforhotels
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2208
Published: 2014-12-28
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

CVE-2014-2209
Published: 2014-12-28
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory.

CVE-2014-5386
Published: 2014-12-28
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initial...

CVE-2014-6228
Published: 2014-12-28
Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split ...

CVE-2014-6229
Published: 2014-12-28
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by leveraging read access beyond the end of the string,...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.