ICAC Webinar Series NCJRL
Cloud Computing
ICAC Webinar Series NCJRL
TODAY’S TOPICS
•
What “Cloud Computing” is and
How it Works
•
Security & Privacy Issues
•
Investigative Challenges
WHAT IS CLOUD COMPUTING?
• Cloud computing refers to software or
processes offered over the Internet as
opposed to the user’s computer
• Popular examples:
ICAC Webinar Series NCJRL
WHY “CLOUD COMPUTING”?
The name comes from the use of a
cloud-shaped symbol as an abstract diagram
for the process
http://www.nskinc.com
ICAC Webinar Series NCJRL
WHAT IS NOT CLOUD
COMPUTING?
• Files stored
internally on your
computer
• Accessing a simple
HTML website
CLOUD COMPUTING BENEFITS
• Reduced Cost
ICAC Webinar Series NCJRL
EXAMPLE OF BENEFIT
– If not in the cloud, every business and individual
would have to install their own server software
on their computer
– “Out-sourcing” services like e-mail
•Frees up internal resources
•Cheaper for one company to handle millions
than for each company to do their own
•Allows pooling and sharing of resources –
automatic deployment of new security
techniques
ICAC Webinar Series NCJRL
THE BIG PICTURE
• For many businesses, governments, and
individuals, the use of cloud computing
just makes sense
– AND It is growing in popularity, which
makes it important to learn and understand
• However, a downside exists
– Security and privacy issues
– Data release to a third party
ICAC Webinar Series NCJRL
DEPLOYMENT MODELS
• Many models for the cloud exist
– Public
•Available to general public
•Often free
•Access exclusively via the Internet
– Private
•Solely for one individual organization
•May operate internally or by a third party
•Keeps others out of the system, but lacks the
benefits of shared resources
ICAC Webinar Series NCJRL
DEPLOYMENT MODELS
– Community
•Not open to public, but shared by several related
organizations with common needs
•Costs shared over fewer users than public
clouds, but can be more secure
– Hybrid
•Combine public, community, and/or private
clouds
•Utilizes internal and external resources
ICAC Webinar Series NCJRL
PRIVATE MODEL
ICAC Webinar Series NCJRL
COMMUNITY MODEL
ICAC Webinar Series NCJRL
SERVICE MODELS
• Software as a
Service (SaaS)
– Programs accessed
in the cloud and
maintained there
•Examples: Microsoft
Office 360, Google
Apps, QuickBooks,
E-mail, Games
Cloudtweaks.comICAC Webinar Series NCJRL
SERVICE MODELS
• Platform as a Service (PaaS)
– The cloud provides an environment for an
organization to work
•Examples: Operating Systems, Web Server
SERVICE MODELS
• Infrastructure as a Service (IaaS)
– Enhances security, capacity, memory, or
similar without requiring user to physically
buy newer, larger, more powerful computers
•Examples
– Firewalls
ICAC Webinar Series NCJRL
SERVICE MODELS
• Many newer models, including:
– Storage as a service (STaaS)
– Security as a service (SECaaS)
– Data as a service (DaaS)
– Desktop as a service (DaaS)
– API as a service (APIaaS)
ICAC Webinar Series NCJRL
SERVICE MODELS
ICAC Webinar Series NCJRL
PLATFORM AS A SERVICE
EXAMPLE
Installed on
Microsoft’s
Servers
ICAC Webinar Series NCJRL
INFRASTRUCTURE AS A
SERVICE EXAMPLE
WHO HOSTS THE CLOUD?
• Many companies are competing for your
business in the cloud
• Amazon Web Services was one of the
first on the market (doing so in 2002)
– Hosts everything you’ve seen here and
more
ICAC Webinar Series NCJRL
If a person wants to sign up for a Gmail
account, which model are they using?
A. Hybrid
B. Public
C. Community
D. Private
QUIZ
ICAC Webinar Series NCJRL
Processing power can be acquired through
which cloud service model?
A. Software as a Service
B. Platform as a Service
C. Processing as a Service
D. Infrastructure as a Service
QUIZ
PUBLIC CLOUD SERVICES
• Many public cloud services are available,
often at no cost to the user, including:
ICAC Webinar Series NCJRL
FILE STORAGE
• Box
• Dropbox
• Google Drive
• Backup
– Carbonite
– Mozy
– Norton Online Backup
ICAC Webinar Series NCJRL
FILE STORAGE EXAMPLE:
GOOGLE DRIVE
• Acts like a folder on your computer(s),
and allows file access through your
online account
• 5GB of storage free
– 1 Terabyte (enough for a 3-month long
video) available for $50/month
• Allows file sharing and group editing
ICAC Webinar Series NCJRL
PHOTO SHARING
• Allows user to sync all photos and videos
from their computer and smartphone to
their cloud account
• Files can then be shared with others as
you choose
• Many allow online editing as well,
making them both SaaS and IaaS
ICAC Webinar Series NCJRL
PHOTO SHARING EXAMPLES:
• Flickr
• Picasa Web
Albums
• Photobucket
• Shutterfly
PASSWORD MANAGERS
• Many services allow users to save all of
their passwords in one central account
online
ICAC Webinar Series NCJRL
OPERATING SYSTEMS
• Computers run an entire operating
system from a cloud server
• User never has to install updates
• Makes installing applications easy and
only one copy is needed – saves time
and storage space
• Makes it less likely that a computer will
get a virus or malware
ICAC Webinar Series NCJRL
OPERATING SYSTEMS
EXAMPLE: JOLICLOUD
OPERATING SYSTEMS
EXAMPLE: JOLICLOUD
• Runs entirely within your browser
• Is open source (= free)
ICAC Webinar Series NCJRL
EyeOS
ICAC Webinar Series NCJRL
MOBILE PHONE SYSTEMS
• Many phone developers have created
cloud computing systems for users to
share and sync:
– Contacts
– Files
– Calendar
– Photos and videos
– Applications
– Track devices and remote lock/wipe
ICAC Webinar Series NCJRL
MICROSOFT SKYDRIVE
ICAC Webinar Series NCJRL
ORGANIZATIONS IN THE
CLOUD
• All of the preceding examples have both
individual and organizational uses
• Organizations may choose to utilize a
common cloud service (such as Google
Apps) or may seek to have a service
completely customized for their needs
Which of the following is an example of
how a home user may use cloud
computing?
A. Backup files
B. Share photos
C. Sync calendar data across devices
D. Save their passwords
E. All of the above
ICAC Webinar Series NCJRL
Security & Privacy Issues
Cloudtweaks.com
ICAC Webinar Series NCJRL
“With the cloud, you don't
own anything. You already
signed it away … the more we
transfer everything onto the
web, onto the cloud, the less
we're going to have control
over it.”
- Steve Wozniak, Apple Co-Founder
THE REAL FEAR
• Theft of confidential or private data
– For example
ICAC Webinar Series NCJRL
ALREADY IN THE CLOUD
• Financial institutions
• Energy
• Military
– Currently moving e-mail to a private cloud
•Projected to reduce cost of e-mail
•May save the Army alone $320 million over a
five-year period
• Nearly every major corporation
ICAC Webinar Series NCJRL
AUTHENTICATION
• There are ways to authenticate a user to
ensure they are who they say they are
• Passwords are used for authentication,
but there are many other means
– Location-based / IP Ranges
– Biometrics
– Card or token
– Digital certificate
ENCRYPTION
• Cloud host may encrypt all data
– May not even have access to the individual
files
ICAC Webinar Series NCJRL
OTHER SECURITY
• Firewalls
• Malware/virus protection
• Log inspection
ICAC Webinar Series NCJRL
UNAUTHORIZED ACCESS
• Hacking
– Cloud may create a larger target while also
offering better security
• Cloud host issues
– Using the cloud often requires relinquishing
physical control over the data – it’s stored
outside of your building
– Gives the host’s employees access to the
data. May require special agreement.
(Gramm-Leach-Bliley Act, HIPAA)
LEGAL ETHICS
• Many states have ethics opinions dealing with
attorneys’ use of cloud computing
– Must take reasonable care to ensure confidentiality
– Evaluate backup strategies
– Vermont – must discuss with client if especially
sensitive
ICAC Webinar Series NCJRL
Which is NOT a form of authentication?
A. Retina scan
B. Firewalls
C. Password
D. Digital certificate
E. IP Ranges
QUIZ
ICAC Webinar Series NCJRL
Investigative Challenges
WHERE IS THE DATA?
ICAC Webinar Series NCJRL
WHERE IS THE DATA?
ICAC Webinar Series NCJRL
INSIDE THE BOX
• Computer’s hard drive
and other memory
– Documents
– Pictures
– Outlook Emails
– Internet Cache
• CD’s and floppy disks
• iPods
• Cell Phones
• External Hard Drives
What the computer owner actually has possession of
INSIDE THE BOX
ICAC Webinar Series NCJRL
OUTSIDE THE BOX
• Online Email Accounts (Gmail and Yahoo)
• Internet Shopping Accounts
• Social Networking Accounts
• Backups of text messages
• Cell Site Location Data
• Subscriber account records
• Contents of Websites
What is not stored on the owner’s computer
ICAC Webinar Series NCJRL
OUTSIDE THE BOX
What is not stored on the owner’s computer
IMPORTANT DISTINCTION
• Inside the box
– Likely Fourth Amendment protection
• Outside the box
– Generally, no reasonable expectation of
privacy
•Fourth Amendment applicability doubtful
•Highly debatable, unsettled question, at best
ICAC Webinar Series NCJRL
DISCOVERY
• Documents under custody, control or
possession (Fed. R. Civ. P. 34)
• Cloud host may or may not have the
ability to preserve and collect data
• Host may keep documents longer than
the company normal retains them
ICAC Webinar Series NCJRL
ENCRYPTION
• Provides security for the creator of the
information but makes an investigation
nearly impossible
– Unless you can compel production of the
password
•Few courts have dealt with the issue, and no
pattern has yet to develop
Where might a person hide an incriminating
file?
A. Smartphone
B. Computer
C. E-mail account
D. Social networking account
E. All of the above
ICAC Webinar Series NCJRL
Which of the following is NOT considered
“outside the box”?
A. Internet cache
B. Cell site location data
C. Online e-mail account
D. Shopping account
E. Contents of websites
QUIZ
ICAC Webinar Series NCJRL