0% found this document useful (0 votes)
10 views25 pages

Module 5

The document provides an overview of Identity Access Management (IAM) in the cloud, detailing its functions, benefits, challenges, and key components such as authentication, authorization, and identity governance. It emphasizes the importance of IAM for enhancing security, compliance, and operational efficiency while discussing various IAM technologies and tools. Additionally, it highlights the significance of IAM in managing user identities and access across cloud platforms, ensuring secure and efficient resource management.

Uploaded by

1ds23cy018
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views25 pages

Module 5

The document provides an overview of Identity Access Management (IAM) in the cloud, detailing its functions, benefits, challenges, and key components such as authentication, authorization, and identity governance. It emphasizes the importance of IAM for enhancing security, compliance, and operational efficiency while discussing various IAM technologies and tools. Additionally, it highlights the significance of IAM in managing user identities and access across cloud platforms, ensuring secure and efficient resource management.

Uploaded by

1ds23cy018
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MODULE- 5

Identity Access Management in the cloud, Identity and Access Management functions, Identity and Access
Management (IAM) Model, Identity Federation, Authentication for SaaS and Paas customers, Authentication
for IaaS customers, Enterprise Architecture with IDaaS , IDaaS Security Recommendations. Virtualization:
Hardware Virtualization, Software Virtualization, Memory Virtualization, Storage Virtualization, Data
Virtualization, Network Virtualization, Virtualization Security Recommendations.
Identity and Access Management in the cloud
Identity and Access Management (IAM) in the cloud is a critical security practice that controls who can access
cloud resources and what they can do with them. It involves identifying, authenticating, and authorizing users,
groups, and even systems to access cloud services. IAM policies define permissions, roles, and access levels,
ensuring only authorized entities have access to the necessary resources while adhering to principles like "least
privilege" to minimize risks.
Key Aspects of Cloud IAM:
Identification:
Determining who or what is requesting access (users, applications, etc.).
Authentication:
Verifying the identity of the requesting entity (e.g., through username/password, multi-factor authentication).
Authorization:
Determining what permissions the authenticated entity has to access specific resources.
Access Control:
Enforcing policies to restrict access to cloud resources based on roles, permissions, and other factors.
Identity Governance:
Managing the lifecycle of identities, including provisioning, deprovisioning, and access reviews.
Centralized Management:
Providing a single point of control for managing identities and access across different cloud platforms.
Benefits of Cloud IAM:
Enhanced Security:
Controls access to sensitive data and resources, reducing the risk of unauthorized access and breaches.
Improved Compliance:
Ensures adherence to regulatory requirements and industry standards for data protection and access control.
Simplified Management:
Streamlines the process of managing identities and access across the cloud, reducing administrative overhead.
Increased Agility:
Enables organizations to quickly provision and deprovision access as needed, supporting business needs.
Challenges of Cloud IAM:
Complexity:
Managing identities and access across multiple cloud platforms and services can be complex.
Keeping Up with Technology:
The cloud landscape is constantly evolving, requiring ongoing monitoring and adaptation of IAM practices.
Security Risks:
IAM implementations must be robust and secure to prevent unauthorized access and potential breaches.
User Experience:
Ensuring that users can easily access the resources they need while adhering to security policies is a key
challenge.
IAM Identities Classified As
1. IAM Users
2. IAM Groups
3. IAM Roles
Root User: The root user will automatically be created and granted unrestricted rights. We can create an admin user with
fewer powers to control the entire Amazon account.
IAM Users: We can utilize IAM users to access the AWS Console and their administrative permissions differ from those
of the Root user and if we can keep track of their login information.
Example
With the aid of IAM users, we can accomplish our goal of giving a specific person access to every service available in the
Amazon dashboard with only a limited set of permissions, such as read-only access. Let’s say user-1 is a user that I want
to have read-only access to the EC2 instance and no additional permissions, such as create, delete, or update. By creating
an IAM user and attaching user-1 to that IAM user, we may allow the user access to the EC2 instance with the required
permissions.
IAM Groups: A group is a collection of users, and a single person can be a member of several groups. With the aid of
groups, we can manage permissions for many users quickly and efficiently.
IAM Roles
While policies cannot be directly given to any of the services accessible through the Amazon dashboard, IAM roles are
similar to IAM users in that they may be assumed by anybody who requires them. By using roles, we can provide AWS
Services access rights to other AWS Services.
IAM Policies
IAM Policies can manage access for AWS by attaching them to the IAM Identities or resources IAM policies defines
permissions of AWS identities and AWS resources when a user or any resource makes a request to AWS will validate
these policies and confirms whether the request to be allowed or to be denied. AWS policies are stored in the form of
Jason format the number of policies to be attached to particular IAM identities depends upon [Link] permissions required
for one IAM identity. IAM identity can have multiple policies attached to them.
Access Management For AWS Resources Identity Management
• Access management
• Federation
• RBAC/EM
• Multi-Factor authentication
• Access governance
• Customer IAM
• API Security
• IDaaS – Identity as a service
• Granular permissions
• Privileged Identity management – PIM (PAM or PIM is the same)
Figure – Services under IAM
More About the Services: Looking into the services on brief, Identity management is purely responsible for managing
the identity lifecycle. Access management is responsible for the access to the resources, access governance is responsible
for access request grant and audits. PIM or PAM is responsible for managing all the privileged access to the resources.
The remaining services either help these services or help in increasing the productivity of these services.
Market for IAM: Current situation of the market, there are three market leaders (Okta, SailPoint and Cyberark) who
master one of the three domains (Identity Management, Identity Governance and Privilege access management),
according to Gartner and Forrester reports. These companies have developed solutions and are still developing new
solutions that allow an organization to manage identity and its access securely without any hindrances in the workflow.
There are other IAM tools, Beyond Trust, Ping, One login, Centrify, Azure Active Directory, Oracle Identity Cloud
Services and many more.
Benefits of IAM Systems
• Enhanced Security: IAM prevents unauthorized access to sensitive data and systems, thus minimizing the
access of the unauthorized personnel.
• Improved Compliance: It also guarantees that the organization complies with the legal requirements concerning
the access control as well as the tracking of activities performed by the users.
• Increased Productivity: Automates processes of the management of users and access, thus minimizing the
numbers of manual operations and providing faster access to the required resources.
• Reduced Risk: Portfolios reduce internal risks and data losses due to strict access protocols in place.
• Centralized management is capable of consolidating identity and company access control and enforcing the same
across different systems.
Importance of IAM for Organizations
• Security: IAM makes certain that only the right people are given access to core systems and information and
thus safeguards organizations from threats within and outside.
• Regulatory Compliance: IAM aids organizations in compliance with the legal and industry-compliant
requirements based on the accessibility and the log records of the user activities.
• Operational Efficiency: IAM provides means of minimizing workload to IT teams by automating tasks such as
onboarding, offboarding, and shifts in user roles.
• Risk Mitigation: IAM also helps in combating data breaches and cyber attacks since it has strict measures
towards providing access to users.
• User Experience: It provides easier access to the firm’s partners, employees, and customers in interacting with
the systems with increased security, thus enhancing productivity and customer satisfaction.
IAM and Compliance Regulations
• Access Control: IAM helps in authorizing only the right people access to information; this complies with data
protection laws such as GDPR and HIPAA.
• Audit Trails: Saves a rich history of users activities to assist in audits and other reporting requirements.
• Segregation of Duties: Implements strict access control with respect to the roles that inhabitants are to undertake
to avoid breaching conflict of interest rules as provided by SOX and its equivalents.
• Data Protection: Enhances data protection; the program is useful in supporting compliance with Data Security
policies in line with PCI-DSS and other standards.
• User Authentication: Provides multi-factor authentication, thus satisfies security standards for many compliance
programs.
IAM Technologies and Tools
• Single Sign-On (SSO): A choice that lets a user login and use multiple applications at once, as well as give more
security to the services. Example: Its competitors include Okta and Microsoft Azure AD.
• Multi-Factor Authentication (MFA): A second one is that you must verify your account with two or more ways
to boost its security. Example: Some of the examples of Two Factor Authentication applications are Duo Security
and Google Authenticator.
• Role-Based Access Control (RBAC): Secures the system based on employees’ roles, where the user will have
the least privilege to access the system. Example: IBM Security Identity Manager.
• Privileged Access Management (PAM): Performs functions associated with obtaining and maintaining high
levels of accessible (“privileged”) computing resources. Example: CyberArk, BeyondTrust.
Resource Access Control
Identity and access management (IAM) will allows you to manage the permissions to the resources in the AWS cloud like
users who can access particular serivce to which extent and also instead of mantaing the permissions individually you can
manage the permissions to group of users at a time.
1. Managing permissions: For example you want to assign an permission to the user that he/her can only perform
restart the instance task on AWS EC2 instance then you can do using AWS IAM.
2. Implemneting role-based access control(RBAC): Identity and Access Management (IAM) will helps you to
manage the permissions based on roles Roles will helps to assign the the permissions to the resourcesw in the
AWS like which resources can access the another resource according to the requirement.
3. Enabling single sign-on (SSO): Identity and Access Management will helps you to maintain the same password
and user name which will reduce the effort of remembering the different password.
IAM Features
Shared Access to your Account: A team working on a project can easily share resources with the help of the shared
access feature.
1. Free of cost: IAM feature of the AWS account is free to use & charges are added only when you access other
Amazon web services using IAM users.
2. Have Centralized control over your AWS account: Any new creation of users, groups, or any form of
cancellation that takes place in the AWS account is controlled by you, and you have control over what & how
data can be accessed by the user.
3. Grant permission to the user: As the root account holds administrative rights, the user will be granted
permission to access certain services by IAM.
4. Multifactor Authentication: Additional layer of security is implemented on your account by a third party, a six-
digit number that you have to put along with your password when you log into your accounts.
Accessing IAM
1. AWS Console: Access the AWS IAM through the GUI. It is an web application provided by the AWS (Amazon
Web Application) it is an console where users can access the aws console
2. AWS Command Line Tools: Instead of accessing the console you can access y the command line interface
(CLI) to access the AWS web application. You can automate the process by using the Scripts.
3. IAM Query API: Programmatic access to IAM and AWS by allowing you to send HTTPS requests directly to
the service.

Identity Access Management Functions:


AM functions are designed to manage digital identities and control access to resources.
1. Authentication: Verify user identities through various methods (e.g., passwords, MFA).
2. Authorization: Grant or deny access to resources based on user roles and permissions.
3. Identity Governance: Manage user identities, roles, and access across systems.
4. Access Control: Enforce policies to restrict or grant access to resources.
5. Provisioning: Automate user account creation, modification, and deletion.
6. De-provisioning: Automate removal of user access when no longer needed.
7. Single Sign-On (SSO): Enable users to access multiple applications with a single set of credentials.
8. Multi-Factor Authentication (MFA): Enhance security with additional verification steps.
9. Auditing and Reporting: Track and analyse access activity to detect potential security issues.
10. Policy Management: Define and enforce access policies across systems.
Architecture Model of IAM

Authentication Management in IAM


Authentication management is a critical component of Identity Access Management (IAM) that verifies user
identities.
1. Multi-Factor Authentication (MFA): Requires multiple verification methods.
2. Single Sign-On (SSO): Allows users to access multiple applications with one set of credentials.
3. Password Management: Manages password policies, reset, and storage.
4. Biometric Authentication: Uses facial recognition, fingerprints, or other biometric data.
Examples:
1. Google Authenticator: MFA app for Google accounts.
2. Microsoft Azure Active Directory (Azure AD): Cloud-based IAM solution with MFA and SSO capabilities.
User Management in IAM
User management is a critical component of Identity Access Management (IAM) that involves managing user
identities, profiles, and access.
1. User Registration: Onboarding new users and creating user accounts.
2. User Profile Management: Managing user attributes, such as name, email, and role.
3. Access Request Management: Managing access requests and approvals.
4. User Lifecycle Management: Managing user account creation, modification, and deletion.
Examples:
1. Okta: Cloud-based IAM solution with user management capabilities.
2. Microsoft Azure Active Directory (Azure AD): Cloud-based IAM solution with user management features.
Authorization Management in IAM
Authorization management is a critical component of Identity Access Management (IAM) that determines what
actions users can perform on resources.
1. Role-Based Access Control (RBAC): Assigns permissions based on user roles.
2. Attribute-Based Access Control (ABAC): Assigns permissions based on user attributes.
3. Policy-Based Access Control: Defines access policies based on organizational requirements.
4. Permission Management: Manages user permissions and access rights.
Examples:
1. AWS IAM: Cloud-based IAM solution with authorization management capabilities.
2. Microsoft Azure Active Directory (Azure AD): Cloud-based IAM solution with authorization management
features.
Monitoring and Auditing Services and Reporting Services in IAM
Monitoring, auditing, and reporting services are essential components of Identity Access Management (IAM)
that provide visibility into user activity and system performance.
Monitoring Services:
1. Real-time Monitoring: Tracks user activity in real-time.
2. Anomaly Detection: Identifies unusual patterns of behavior.
Auditing Services:
1. Log Analysis: Analyzes logs to identify potential security issues.
2. Compliance Auditing: Ensures compliance with regulatory requirements.
Reporting Services:
1. Customizable Reports: Generates reports on user activity, system performance, and security incidents.
2. Dashboards: Provides visual representations of key metrics and trends.
Examples:
1. Splunk: Log management and analysis platform.
2. Tableau: Data visualization and reporting platform.
System and application access management is a critical component of Identity Access Management (IAM) that
controls access to systems and applications.
Key Features:
1. Single Sign-On (SSO): Allows users to access multiple applications with one set of credentials.
2. Multi-Factor Authentication (MFA): Requires additional verification steps for access.
3. Access Control: Grants or denies access to systems and applications based on user roles and permissions.
4. Session Management: Manages user sessions and timeouts.
Examples:
1. Okta: Cloud-based IAM solution with SSO and MFA capabilities.
2. Microsoft Azure Active Directory (Azure AD): Cloud-based IAM solution with SSO and MFA features.
Data Management and Provisioning in IAM
Data management and provisioning are critical components of Identity Access Management (IAM) that ensure
accurate and timely management of user data
Data Management:
1. Data Storage: Securely stores user identity data.
2. Data Synchronization: Ensures consistency of user data across systems.
3. Data Governance: Establishes policies for data management.
Provisioning:
1. User Provisioning: Automates creation, modification, and deletion of user accounts.
2. Role-Based Provisioning: Assigns access based on user roles.
3. Attribute-Based Provisioning: Assigns access based on user attributes
Access Management in IAM
Access management is a critical component of Identity Access Management (IAM) that controls access to
resources based on user identity and permissions.
1. Authentication: Verifying user identities.
2. Authorization: Granting or denying access to resources.
3. Access Control: Managing user permissions and access rights.
Examples:
1. AWS IAM: Cloud-based IAM solution with access management capabilities.
2. Microsoft Azure Active Directory (Azure AD): Cloud-based IAM solution with access management features.
Identity Federation in IAM
Identity federation enables users to access multiple systems or applications using a single identity, without
requiring multiple usernames and passwords.
Key Features:
1. Single Sign-On (SSO): Users can access multiple systems with a single set of credentials.
2. Identity Provider (IdP): Manages user identities and authenticates users.
3. Service Provider (SP): Provides access to systems or applications.
Examples:
1. Google Sign-In: Enables users to access multiple applications using Google credentials.
2. Microsoft Azure Active Directory (Azure AD): Enables identity federation with multiple systems.

Identity Lifecycle Management in IAM


Identity lifecycle management refers to the processes and procedures used to manage user identities throughout their
lifecycle, from creation to deletion.

Stages of Identity Lifecycle:


1. Provisioning: Creating and setting up user accounts.
2. Authentication: Verifying user identities.
3. Authorization: Granting access to resources.
4. Self-Service: Allowing users to manage their own accounts.
5. Password Management: Managing password resets and changes.
6. Complaints and Incident Management: Handling security incidents and user complaints.
7. Deprovisioning: Revoking access and deleting user accounts.
Provisioning:
1. User Onboarding: Creating new user accounts and assigning access.
2. Role-Based Provisioning: Assigning access based on user roles.
3. Attribute-Based Provisioning: Assigning access based on user attributes.
Authentication:
1. Multi-Factor Authentication (MFA): Requiring multiple verification methods.
2. Single Sign-On (SSO): Allowing users to access multiple systems with one set of credentials.

Authorization:
1. Role-Based Access Control (RBAC): Assigning access based on user roles.
2. Attribute-Based Access Control (ABAC): Assigning access based on user attributes.
Self-Service:
1. User Profile Management: Allowing users to update their own profiles.
2. Password Reset: Allowing users to reset their own passwords.
Password Management:
1. Password Policies: Establishing rules for password creation and management.
2. Password Reset: Managing password reset processes.
Complaints and Incident Management:
1. Security Incident Response: Responding to security incidents.
2. User Complaint Management: Handling user complaints and issues.
Deprovisioning:
1. User Offboarding: Revoking access and deleting user accounts.
2. Role-Based Deprovisioning: Revoking access based on user roles.
By implementing effective identity lifecycle management, organizations can enhance security, streamline access, and
improve user experience.
Authentication for SaaS, PaaS, and IaaS Customers
Authentication is a critical component of cloud security that ensures only authorized users can access cloud resources.
SaaS (Software as a Service) Authentication:
1. Single Sign-On (SSO): Enables users to access SaaS applications with a single set of credentials.
2. Multi-Factor Authentication (MFA): Requires additional verification methods for access.
3. Identity Federation: Enables SSO between SaaS applications and identity providers.
PaaS (Platform as a Service) Authentication:
1. API Keys: Used to authenticate API requests.
2. OAuth: Enables delegated access to PaaS resources.
3. Role-Based Access Control (RBAC): Assigns access based on user roles.
IaaS (Infrastructure as a Service) Authentication:
1. SSH Keys: Used to authenticate access to IaaS resources.
2. API Keys: Used to authenticate API requests.
3. Identity and Access Management (IAM): Manages access to IaaS resources.

Identity-as-a-Service (IDaaS) refers identity and access management services provided through the cloud on a
subscription basis. Identity-as-a-Service is typically fully on-premises and provided via set of software and hardware
means. An identity service stores the information linked with a digital entity in a form which can be managed and queried
for further utilization in electronic transactions. Major core functions of Identity Services are:
1. A data stores.
2. Query Engine.
3. Policy Engine.
Some Distributed transaction systems like cloud computing systems and internetworks magnify the problems tackled by
identity management systems by revealing a larger attack surface to an intruder than a private network does. Whether it is
network congestion protection, privileged component access, or any other defined right or privilege, As the central tenet
of secure network schema leads to the base of validation authorization of object on its identity. Hence, establishing
identity is the key to get trust and to anything that an object seems to claim possession of. Services which provide digital
identity management as a service are classification of internetworked systems. IDaaS – Identity-as-a-Service is a of the
month, which is applied to many services that are already exist. Servers that run the numerous internet domains (.COM,
.ORG, .EDU, .MIL, .RU, .TV etc.) are IDaaS servers. DNS configures the identity of a domain as belonging to a group of
assigned networks, linked with an owner and his information, and so forth. If the identity is configured in the form of IP
number, then the metadata is another property.
Definition of an Identity – An identity refers to a set of attributes or characteristics which make something recognizable
or known. It is digital identity of an individual that is mostly concerned in computer network systems. An attribute and
metadata of any object related to another object that enables an object to be identifiable is termed as Digital Identity. An
identity can belong to an individual and may consist of the following:
1. Things you are: Biological characteristics like gender, age etc.
2. Things you know: Personal data like social security PINs etc.
3. Things you have: Your fingerprint, bank account which you can access etc.
4. Things you relate to: Your family and friends, beliefs and values etc.
To establish an identity, an individual might be demanded to provide a name and password, that is termed as single-factor
authentication method. More secure authentication needs the use of minimum two-factor authentication. To get a multi-
factor authentication, an individual might have a system which checks a biometric factor like fingerprint pattern which is
unique. Multi-factor authentication needs the use of a network security or reliable services which is in the deployment of
reliable services that most common IDaaS applications are employed in the cloud computing. A lot of things has digital
identity. Machine accounts and user, devices, and many other objects configure their identity in various methods. In this,
identities are created and stored in the database of security domains that are the basis of any domain of network. Network
interfaces which are recognized uniquely by Media Access Control (MAC) addresses, that are referred to as Ethernet
Hardware Access (EHA). Network identity assign specific MAC address that enables system to be uniquely found on the
network. The manner in which a Windows provider validates installation of windows on the system of the user is known
as Windows Product Activation and it establish an identification index or profile of the system, which is instructive.
During activation, the following unique data components are fetched:
1. PC manufacturer
2. CPU type and its serial number
3. BIOS checksum
4. Display adapter
5. RAM amount
6. A 25-character software product key and product ID
7. The uniquely assigned Global Unique Identifier or GUID
8. Network address and its MAC address
9. SCSCI and IDE adapters
10. Hard drive and volume serial number
11. Optical drive
12. Region and language settings
Each of the above uniquely identified hardware characteristics is assigned a factor such that an overall sum can be
remunerated.
Advantages of IDaaS
• Reduced costs: IDaaS eliminates the need for organizations to invest in on-premises hardware and software to
manage user identities and access. This can result in significant cost savings in terms of hardware, software, and
maintenance expenses.
• Improved security: IDaaS provides a more secure environment for managing user identities and access. It offers
advanced authentication methods, such as multi-factor authentication, which can enhance security and reduce the
risk of data breaches.
• Scalability: IDaaS is designed to scale easily and can accommodate a large number of users and resources. This
makes it easier to manage user identities and access as organizations grow and expand.
• Flexibility: IDaaS offers a flexible solution that can be customized to meet the specific needs of an organization.
This includes options for integrating with other cloud-based services and on-premises applications.
• Simplified management: IDaaS provides a centralized management interface that enables organizations to
manage user identities and access from a single location. This simplifies the management of user identities and
access across different applications and services.
• Improved user experience: IDaaS offers a seamless user experience across different applications and devices.
This makes it easier for users to access resources and applications, which can improve productivity and user
satisfaction.
Disadvantages of IDaaS
• Dependence on internet connectivity: IDaaS relies on internet connectivity, which means that organizations
may experience disruptions in service if there are issues with the internet connection or if the service provider
experiences downtime.
• Limited customization: While IDaaS offers some flexibility, it may not be as customizable as an on-premises
solution. This may limit an organization’s ability to configure the service to meet specific needs or integrate with
certain applications.
• Security concerns: IDaaS involves transferring sensitive user identity and access information to a third-party
service provider. This raises concerns about data security and privacy, as the service provider may be a target for
cyber attacks or may not be as stringent in its security practices as the organization itself.
• Regulatory compliance: Organizations may face regulatory compliance issues when using IDaaS, particularly if
they operate in industries with strict data privacy regulations. The use of third-party service providers may
require additional compliance measures to be put in place to ensure the security and privacy of sensitive
information.
• Integration challenges: Integrating IDaaS with existing systems and applications may be challenging,
particularly if those systems and applications were not designed with cloud-based identity and access
management in mind.
Virtualization is used to create a virtual version of an underlying service With the help of Virtualization,
multiple operating systems and applications can run on the same machine and its same hardware at the same
time, increasing the utilization and flexibility of hardware. It was initially developed during the mainframe era.

• It is one of the main cost-effective, hardware-reducing, and energy-saving techniques used by cloud
providers. Virtualization allows sharing of a single physical instance of a resource or an application
among multiple customers and organizations at one time. It does this by assigning a logical name to
physical storage and providing a pointer to that physical resource on demand.

The term virtualization is often synonymous with hardware virtualization, which plays a fundamental
role in efficiently delivering Infrastructure-as-a-Service (IaaS) solutions for cloud computing.
Moreover, virtualization technologies provide a virtual environment for not only executing
applications but also for storage, memory, and networking

• Host Machine: The machine on which the virtual machine is going to be built is known as Host
Machine.

• Guest Machine: The virtual machine is referred to as a Guest Machine.

Working of Virtualization in Cloud Computing

• Virtualization has a prominent impact on Cloud Computing. In the case of cloud computing, users
store data in the cloud, but with the help of Virtualization, users have the extra benefit of sharing the
infrastructure.
• Cloud Vendors take care of the required physical resources, but these cloud providers charge a huge
amount for these services which impacts every user or organization. Virtualization helps Users or
Organisations in maintaining those services which are required by a company through external (third-
party) people, which helps in reducing costs to the company. This is the way through which
Virtualization works in Cloud Computing.

Benefits of Virtualization

Here are some of the benefits of using Virtualization in Cloud Computing –

• More flexible and efficient allocation of resources.

• Enhance development productivity.

• It lowers the cost of IT infrastructure.

• Remote access and rapid scalability.

• High availability and disaster recovery.

• Pay peruse of the IT infrastructure on demand.

• Enables running multiple operating systems.

Drawback of Virtualization

• High Initial Investment: Clouds have a very high initial investment, but it is also true that it will
help in reducing the cost of companies.

• Learning New Infrastructure: As the companies shifted from Servers to Cloud, it requires highly
skilled staff who have skills to work with the cloud easily and for this, you have to hire new staff or
provide training to current staff.

• Risk of Data: Hosting data on third-party resources can lead to putting the data at risk, it has the
chance of getting attacked by any hacker or cracker very easily.

Characteristics of Virtualization

• Increased Security: The ability to control the execution of a guest program in a completely
transparent manner opens new possibilities for delivering a secure, controlled execution environment.
All the operations of the guest programs are generally performed against the virtual machine, which
then translates and applies them to the host programs.

• Managed Execution: In particular, sharing, aggregation, emulation, and isolation are the most
relevant features.

• Sharing: Virtualization allows the creation of a separate computing environment within the same
host.

Aggregation: It is possible to share physical resources among several guests, but virtualization also allows
aggregation, which is the opposite process.
LAYERS OF VIRTUALIZATION

Instruction Set Architecture (ISA) Level Layer.

The Instruction Set Architecture (ISA) level layer refers to the interface between software and hardware that
defines the set of instructions a processor can execute.

Types of ISAs:

1. CISC (Complex Instruction Set Computing): ISAs with complex instructions that can perform multiple
operations.

2. RISC (Reduced Instruction Set Computing): ISAs with simple instructions that can be combined to
perform complex operations.

How it works:

1. Processor Design: ISAs are used to design and implement processors.

2. Compiler Development: Compilers use ISAs to generate machine code.

3. Embedded Systems: ISAs are used in embedded systems, such as microcontrollers.


Examples:

1. x86: A CISC ISA used in Intel and AMD processors.

2. ARM: A RISC ISA used in mobile and embedded systems.

3. PowerPC: A RISC ISA used in various applications.

Hardware Abstraction Level Layer

Hardware abstraction level virtualization involves abstracting the physical hardware resources of a system,
creating a virtualized environment that can run multiple operating systems or applications.

How it Works:

1. Hypervisor Installation: The hypervisor is installed on the host machine.

2. Virtual Machine Creation: Virtual machines are created on top of the hypervisor.

3. Resource Allocation: Resources are allocated to each virtual machine.

4. Virtual Machine Management: Virtual machines are managed using management tools.

Examples:

1. VMware ESXi: Type 1 hypervisor for server virtualization.

2. Microsoft Hyper-V: Type 1 hypervisor for server virtualization.

3. VirtualBox: Type 2 hypervisor for desktop virtualization.

Operating System Level Layer

Operating system-level virtualization involves creating multiple virtual environments (containers) on a single
host operating system, each with its own isolated environment.

How it Works:

1. Container Creation: Containers are created on top of the host operating system.

2. Resource Allocation: Resources are allocated to each container.

3. Application Deployment: Applications are deployed inside containers.

4. Container Management: Containers are managed using container orchestration tools.

Examples:

1. Docker: Containerization platform for building, shipping, and running containers.


2. Kubernetes: Container orchestration platform for managing containerized applications.

3. OpenVZ: Container-based virtualization platform for Linux.

Library Level Layer

Library-level virtualization involves providing a compatibility layer for applications to run on a different
platform by emulating the required libraries and APIs.

How it Works:

1. Library Emulation: The library-level virtualization layer emulates the required libraries and APIs.

2. API Translation: The virtualization layer translates API calls from the application to the native platform
APIs.

3. Application Execution: The application runs on the non-native platform using the emulated libraries and
APIs.

Examples:

1. Wine: Runs Windows applications on Linux and macOS by emulating Windows APIs.

2. Cygwin: Provides Unix-like environment on Windows by emulating Unix APIs.

3. Darling: Runs macOS applications on Linux by emulating macOS APIs.

Application Level Layer

Application-level virtualization involves encapsulating an application and its dependencies into a single
package, allowing it to run on any platform without modification.

How it Works:

1. Application Packaging: The application and its dependencies are packaged into a single unit.

2. Virtualization Layer: A virtualization layer is installed on the client device.

3. Application Execution: The packaged application is executed on the client device, using the virtualization
layer.

Examples:

1. Java Virtual Machine (JVM): Runs Java bytecode on any platform.

2. Microsoft App-V: Virtualizes Windows applications, allowing them to run on any Windows device.

3. Citrix XenApp: Virtualizes Windows applications, allowing them to run on any device with a Citrix client.
Types of Virtualization

1. Application Virtualization

2. Network Virtualization

3. Desktop Virtualization

4. Storage Virtualization

5. Server Virtualization

6. Data virtualization
[Link] Virtualization: This lets you use an application on your local device while it’s actually hosted
on a remote server. Your personal data and the app’s settings are stored on the server, but you can still run it
locally via the internet. It’s useful if you need to work with multiple versions of the same software. Common
examples include hosted or packaged apps.

Components:

1. Physical Hardware: The underlying hardware that runs the virtualization infrastructure.

2. Operating System: The host operating system that manages the hardware resources.

3. Virtualization Layer: The software layer that enables application virtualization.

4. Applications: The virtualized applications that run on top of the virtualization layer.

5. Presentation Layer: The layer that manages the user interface and presentation of the virtualized
applications.

6. Desktop: The user's desktop environment that accesses the virtualized applications.
Architecture Model:

The application virtualization architecture model consists of the following layers:

1. Hardware Layer: The physical hardware that runs the virtualization infrastructure.

2. OS Layer: The host operating system that manages the hardware resources.

3. Virtualization Layer: The software layer that enables application virtualization.

4. Application Layer: The virtualized applications that run on top of the virtualization layer.

5. Presentation Layer: The layer that manages the user interface and presentation of the virtualized
applications.

How it Works:

1. Application Virtualization: The virtualization layer captures the application's dependencies and
configurations.

2. Application Streaming: The virtualized application is streamed to the user's desktop.

3. Presentation Virtualization: The presentation layer manages the user interface and presentation of the
virtualized application.

2. Network Virtualization: This allows multiple virtual networks to run on the same physical network, each
operating independently. You can quickly set up virtual switches, routers, firewalls, and VPNs, making
network management more flexible and efficient.

3. Desktop Virtualization: With desktop virtualization, your operating system is stored on a server and can
be accessed from anywhere on any device. It’s great for users who need flexibility, as it simplifies software
updates and provides portability.
4. Storage Virtualization: This combines storage from different servers into a single system, making it
easier to manage. It ensures smooth performance and efficient operations even when the underlying hardware
changes or fails.

5. Server Virtualization: This splits a physical server into multiple virtual servers, each functioning
independently. It helps improve performance, cut costs and makes tasks like server migration and energy
management easier.

6. Data Virtualization: This brings data from different sources together in one place without needing to
know where or how it’s stored. It creates a unified view of the data, which can be accessed remotely via
cloud services. Companies like Oracle and IBM offer solutions for this.

Virtualization vs Containerization

Below is a comparison table between Virtualization and Containerization:

Aspect Virtualization Containerization

Architecture Full OS per VM Shared host OS

Resource Usage High Low

Performance Slightly slower due to overhead Faster due to lightweight design

Scalability Limited by heavier VMs Highly scalable


Aspect Virtualization Containerization

Portability Moderate Very high

Use Case Running multiple OS types Rapid deployment of apps

Uses of Virtualization

• Resource Optimization: Maximizes hardware utilization by running multiple virtual machines on a


single server.

• Cost Reduction: Reduces hardware and maintenance costs by consolidating servers.

• Scalability: Enables quick scaling of resources based on demand.

• Flexibility: Dynamically allocates resources to applications as needed.

• Disaster Recovery: Simplifies backup and recovery by easily restoring virtual machines.

• Multi-Tenancy: Supports multiple users on a single server securely and efficiently.

• Testing Environments: Provides isolated virtual environments for development and testing.

• Efficient Deployment: Speeds up application deployment with pre-configured virtual environments.

• Security Isolation: Keeps applications secure by isolating them in separate virtual machines.

• Energy Efficiency: Reduces power consumption by running fewer physical servers

Virtualisation Security Recommendation

1. Understand the Shared Responsibility Model: Recognize the division of security responsibilities
between the provider and the customer for each service model.
2. Implement Strong Access Controls: Use multi-factor authentication (MFA) and the principle of
least privilege to limit access to sensitive data and resources.
3. Encrypt Data: Ensure data is encrypted both at rest and in transit to protect against unauthorized
access.
4. Regularly Update and Patch: Keep all software and systems updated to mitigate vulnerabilities.
5. Monitor and Audit: Continuously monitor for suspicious activities and conduct regular security
audits to identify and address potential risks.

SINGLE SIGN OPN SERVICE


Single Sign-On (SSO) is a service that allows users to access multiple applications or systems with a single
set of login credentials.

How SSO Works:

1. User Authentication: User logs in with credentials.

2. Token Generation: SSO service generates a token or session.

3. Application Access: Token is used to access multiple applications.

• Logs into the authentication server.


• It returns the user’s ticket
• User send the ticket in intranet server
• Intranet server sends the ticket to the authentication server.
• Authentication server sends the user’s security credentials for that server back to the intranet server.

You might also like