CloudPassage launches new security product for public clouds
The company's Halo NetSec product tackles the tough problem of securing servers in the cloud
IDG News Service - CloudPassage is launching a new security product for virtual servers in public clouds such as Amazon Web Services that it says takes care of the all-important need for security when using services from infrastructure providers.
The product, called Halo NetSec, offers a firewall, two-factor authentication in order to access virtual servers, as well as intrusion-detection capabilities. It allows administrators to set up a so-called "perimeter" defense without needing access to the actual network, which they don't have when using cloud-based services, said Rand Wacker, vice president of product at CloudPassage.
"What we've done is create a cloud-ready platform that handles automatically all management and policy controls with a combination of a lightweight host-based agent and software-as-a-service grid," Wacker said.
Halo NetSec runs a small, 3MB daemon on a virtual server, which is responsible for executing commands and communicating with CloudPassage's computing grid. The small footprint means customers do not end up paying more to their provider for computing services, Wacker said.
CloudPassage has developed technology to be able to deploy the firewall as administrators fire up new virtual servers such as databases or Web applications, the firewall and its rules are applied.
"We never considered in the old days of firewall management the idea of a server dynamically appearing, disappearing and changing IPs," Wacker said.
Halo NetSec also has two-factor authentication for administrators when accessing their servers. An administrator goes to CloudPassage's Web portal and uses a USB key to generate a one-time passcode, and then access is granted to their servers, Wacker said.
The product also does not need access to the hypervisor since it runs within the operating system of the virtual server, Wacker said. Other types of security software need access to the hypervisor, but infrastructure providers such as Amazon Web Services and Rackspace do not allow it.
"Amazon has no issue with where our software is installed," Wacker said.
Halo NetSec is a lighter version of its Halo Professional package. For example, administrators can do a daily intrusion-detection scan and store the log for one day. With a Professional subscription, administrators can run a scan once an hour and store the results for two years, Wacker said. CloudPassage also has a free basic version of Halo.
The goal with Halo NetSec was to create a "mid-range" package that was "very easy to get a basic set of security capabilities," Wacker said.
Halo NetSec costs 3.5 cents per server per hour, although volume discounts apply and other discounts are available with a monthly minimum usage commitment.
Send news tips and comments to jeremy_kirk@idg.com



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Utility Storage - The Ideal Platform for Virtual and Cloud Computing
- Server virtualization has transformed corporate IT -- companies have enjoyed major cost savings and have gained flexibility and efficiency. But this has also...
- Forrester on the Converged Infrastructure
- To understand infrastructure and operations (I&O) perceptions of converged infrastructure (CI), Forrester Consulting surveyed 200 I&O decision-makers from six different countries. Decision-makers were...
- IDC white paper: Delivering an Integrated Infrastructure for the Cloud
- In an IDC White Paper sponsored by HP, IDC covers how cloud computing is one of the prevailing IT trends today and how...
- HP Cloud Service Automation: Intelligent Automation for Building, Managing, and Securing Cloud Services
- Many lines of business are now procuring cloud services on their own because cloud computing professes to do what IT has long promised:...
- Benefits of Private Cloud and Infrastructure as a Service
- This solution brief will help you understand the benefits of the HP CloudSystem Matrix which provides a unified solotion for physical and virtual... All Cloud Computing White Papers
- Live Webcast
Integrated IT Operations Management in the Cloud - Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and...
- Live Webcast
The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard - Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
- Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- De-risk Deploying Business Critical Apps in Your Private Cloud
- Architect your private clouds to ensure that application requirements for performance & availability are achieved with minimal risk to the business.
- Navigating the Public Cloud
- InfoWorld contributing editor and consultant David Linthicum offers expert advice about choosing services to outsource to the public cloud providers, cloud data security... All Cloud Computing Webcasts
By Jean-Marc Seguin
Before you start making changes in the organization steam rolling toward the goal of a private cloud, it's important that you understand where you are today so that you can plot the right trajectory, and as you progress toward your goal, make course corrections as needed. more