Cloud computing has emerged as a popular paradigm and an attractive model for providing a reliable distributed computing model.it is increasing attracting huge attention both in academic research and industrial initiatives. Cloud deployments are paramount for institution and organizations of all scales. The availability of a flexible, free open source cloud platform designed with no propriety software and the ability of its integration with legacy systems and third-party applications are fundamental. Open stack is a free and opensource software released under the terms of Apache license with a fragmented and distributed architecture making it highly flexible. This project was initiated and aimed at designing a secured cloud infrastructure called BradStack, which is built on OpenStack in the Computing Laboratory at the University of Bradford. In this report, we present and discuss the steps required in deploying a secured BradStack Multi-node cloud infrastructure and conducting Penetration testing on OpenStack Services to validate the effectiveness of the security controls on the BradStack platform. This report serves as a practical guideline, focusing on security and practical infrastructure related issues. It also serves as a reference for institutions looking at the possibilities of implementing a secured cloud solution.
翻译:云计算已经成为一个流行的范例和提供可靠分布式计算模型的吸引模式。 它正在学术研究和工业倡议中引起极大关注。 云的部署对于各种机构和组织都至关重要。 提供一个灵活、自由的开放源云平台,其设计没有适当的软件,而且能够与遗留系统和第三方应用整合。 开放堆放是一种自由开放源软件,根据阿帕奇许可证发放,其结构支离破碎且分布非常灵活。 这个项目启动并旨在设计一个称为布拉德斯塔克的安全云库基础设施,它建在布拉德福德大学计算机实验室的OpenStack上。我们在本报告中介绍并讨论部署一个安全的布拉德斯塔克多点云基础设施以及进行对OpenStack服务进行穿透测试以验证布拉德斯塔克平台安全控制有效性所需的必要步骤。该报告是一个实用指南,侧重于安全和实际基础设施相关问题。它还作为各机构研究实施安全云解决方案的可能性的参考。