21. 21
NIST對雲端運算的定義
Public Private Hybrid Community
Deployment
Models
Service
Models
Software as a
Service (SaaS)
Platform as a
Service (PaaS)
Infrastucture as a
Service (IaaS)
Essential
Characteristics
On-Demand
Self Service
Broad Network
Access
Resource Pooling
Rapid ElasticityMeasured Service
Visual Model of NIST’s Working Definition of Cloud Computing
http://www.csrc.nist.gov/groups/SNS/cloud-computing/index.html
22. 22
雲端運算的特性
多重租賃/共享資源 (multi tenancy)
Multiple users use the same resource in
network level、host level and application
level
(資料來源:Cloud security and privacy :Tim Mather et al.)
24. 24
雲端運算的特性
彈性(elasticity)
Users can rapidly increase and decrease
their computing resources as they needed,
as well as release resources to other
users when they are no longer required.
(資料來源:Cloud security and privacy :Tim Mather et al.)
25. 25
雲端運算的特性
用多少付多少(pay as you go)
Users pay for only the resource they
actually use.
(資料來源:Cloud security and privacy :Tim Mather et al.)
26. 26
雲端運算的特性
自我調配(self-provisioning)
Users self-provisioning resources, such as
systems( processing capability, software,
storage) and network resources.
(資料來源:Cloud security and privacy :Tim Mather et al.)
84. 84
雲端運算之7大安全威脅
濫用或利用雲端運算進行非法的行為(Abuse and
Nefarious Use of Cloud Computing)
不安全的使用者介面與APIs (Insecure Interface and APIs)
惡意的內部人員(Malicious Insiders)
共享環境所造成的議題(Shared Technology Issues)
資料遺失或外洩(Data Loss or Leakage)
帳號或服務被竊取(Account or Service Hijacking)
未知的風險模型(Unknown Risk Profile)