2009年10月7日水曜日

DDoS attack rains down on Amazon cloud

Amazon Web Servicesで大掛かりなDDOS攻撃があり、サービスが19時間も停止した、という事件が発生し、顧客である、BitBucket社が大きな影響を受けた、という話。 
 
興味深いのは、障害が起きている間、AWSの競合ホスティング事業者からサービス乗り換えの営業売込みが入ってきている、という事。 

Updated Web-based code hosting service Bitbucket experienced more than 19 hours of downtime over the weekend after an apparent DDoS attack on the sky-high compute infrastructure it rents from Amazon.com.

This in turn left many developers without access to code projects hosted on Bitbucket, a GitHub-like service based on the Mercurial version control system.

"Looks like all (my and a large number of fellow nerds) bitbucket projects have evaporated in a temporary, cloudy way. This is a major pissoff," said one Reg reader and Bitbucket user, as others vented via Twitter.

But on another level, the news is sure to fuel fears over the security of Amazon's Elastic Compute Cloud (EC2) and similar "infrastructure clouds," online services that provide grid-like access to scalable processing, storage, and networking resources.

"The lesson here is: 'Don't bet the farm on a single cloud provider,'" says Craig Balding, founder of cloudsecurity.org and a security practitioner at a Fortune 500 company. "It's common sense really. But people get lulled into thinking they site is always going to be available [when they host with a single provider]."

According to a blog post from Jesper Nøhr, the Danish developer who runs Bitbucket.org, the site's Amazon-hosted network storage became "virtually unavailable" beginning Friday evening, and the outage persisted well into Saturday before Amazon pinpointed the problem.

Nøhr says Amazon advised him not to divulge the cause of the outage. But he divulged anyway. "We were attacked. Bigtime. We had a massive flood of UDP [User Datagram Protocol] packets coming in to our IP, basically eating away all bandwidth to the box," he wrote. "So, basically a massive-scale DDOS. That's nice."

Speaking with The Reg, Nøhr said that Amazon urged him not to reveal the attack because it might help attackers develop new ways of DDoSing the site.

After uncovering the problem - at least 16 hours after it was first reported - Amazon blocked the offending traffic, and service returned to normal. But by the next morning (Sunday), the problem returned, and another two hours passed before this second outage was reversed. According to Nøhr, Amazon told him the second attack used a flood of TCP SYN connection requests, rather than UDP packets.

Then, it seems, a third attack arrived. Nøhr tells The Reg that an attack on an Amazon edge router took out service for some but not all Bitbucket customers for close to one and a half hours earlier today.

For Nøhr and other Bitbucket devotees, it seems odd that traffic from the net at large could bring down what should be "internal" storage resources. Nøhr speculates that Bitbucket's storage sits on the same network interface that connects the site to the outside world. He asks why the storage isn't on a separate channel - and why Amazon doesn't have methods in place to rapidly detect and combat such DDoS attacks.

"I do think they could've taken precautions to at least be warned if one of their routers started pumping through millions of bogus UDP packets to one IP," he wrote, "and I also think that 16+ hours is too long to discover the root of the problem."

Cloudsecurity.org's Balding is equally surprised that an outside attack could somehow "get between" EC2 and EBS. But since Amazon treats its service as a black box, he says, it's difficult to tell what actually occurred. He says it's possible that the attack came from inside EC2 - i.e. from another EC2 customer - but this is unlikely. "You'd think that Amazon could have shut down that sort of thing pretty quickly," he tells The Reg.

Amazon did not immediately respond to a request for comment, but we made contact before Pacific Coast office hours. We will update this story when the company responds.

In a security white paper (pdf) dated September 2008, the company says it uses standard DDoS-fighting techniques such as syn cookies and connection limits. It also says: "To further mitigate the effect of potential DDoS attacks, Amazon maintains internal bandwidth which exceeds its provider-supplied Internet bandwidth."

Bitbucket runs its entire site on Amazon's Elastic Compute Cloud, using the company's Elastic Block Store (EBS) for storing its database, log files, user data, and more. EBS provides persistent storage for EC2 server instances.

On Friday evening, Jesper Nøhr and Bitbucket told Amazon that there appeared to be a serious slowdown in the transfer of data to and from its Elastic Block Store. Nøhr said the site was "getting less throughput than you can pull off of a 1.44MB floppy".

But when Nøhr first reported the problem, an Amazon support rep blamed it on that fact that EBS is a shared resource, saying that performance could vary. But after Nøhr made another call, a second rep acknowledged that the problem went beyond the usual performance hiccups.

"We had been extremely frustrated up until this point, because 1) we couldn't actually *do* anything about it, and 2) we were being told that everything should be fine," Nøhr wrote. "It felt like there was an elephant right in front of us, and a person next to us was insisting that there wasn't."

Eventually, Nøhr said, Amazon gave the problem the attention it deserved. "After a bit of stalling with their first rep, our case received absolutely stellar attention. They were very professional in their correspondence, and in communicating things to us along the way."

Nøhr says that Amazon wants to work with him to ensure this sort of attack doesn't happen in the future, but he's now considering a switch to another hosting provider.

"We're seriously considering moving to a different setup now," he said. "Not because Amazon isn't providing us with decent service, which they are, most of the time. While we were down, several large hosting companies took direct contact with us, pitching their solutions. I won't mention names, but some of the offerings are quite tempting, and have several advantages over what we get with Amazon.

"One thing's for sure, we're investing a lot of man-hours into making sure this won't happen again. If this means moving to a different host, so be it. We haven't decided yet."

According to Nøhr, the DDoS traffic was spoofed, so it's unclear where it originated. Nøhr speculates that attackers were targeting a Bitbucket-hosted project "related to" World of Warcraft, but he declined to name the service.

2009年10月6日火曜日

Adopting a Single-View Management Infrastructure

Cloud Computing環境のリソース管理のツールについての記事

The beauty of both cloud computing and virtualization is that it lets you convert your data center from a collection of discrete components into a flexible, scalable pool of resources.


Well, yes, but that's not the whole story.


You see, once your server, storage and networking capabilities are available at large, you'll need a way to manage them so they can be used in tandem, without leading to virtual sprawl that ties things up with idle pursuits nor producing data bottlenecks because applications in one environment can't find the resources it needs in another.


That's why many of the latest enterprise management suites are aiming for what is called a single-view approach to the enterprise -- that is, taking stock of all available resources and plugging the gaps that prevent them from being used as a cohesive whole.


One of these is the new ManageEngine IT 360 from, naturally, ManageEngine. The company has compiled a variety of networking, systems and applications management modules into a single user interface called the Business Dashboard. The interface can be customized for any number of users, from a lowly admin to the CIO, and can extend across multiple environments, such as Windows, Linux and UNIX file servers, app servers, mail systems and even WAN components. It also provides an integrated ITIL-ready Service Desk with tools like automated trouble ticketing, change management modules and a knowledge base.


EMC is heading in a similar direction with the Ionix software line. The latest component is the Data Center Insight Manager designed to act as a common interface for all manner of enterprise software. The company is looking to overcome the problem of multiple departments using their own naming conventions and other markers in the configuration management database, which ends up confusing applications because individual components often get tagged with multiple names -- say, one for DNS and another for Windows. And the problem is compounded whenever an infrastructure change is made.


Improving the CMBD is also the goal at Intelliden, which recently unveiled the NetNovo automation system. It essentially acts as a "network CMBD" in that it provides a repository for all network management data, with a full set of APIs for queries and publishing information. In this way, it can provide automated updates on network configuration changes to the enterprise CMBD, so network views and policies can be updated accordingly. The company says this approach allows it to accommodate multiple management modes to suit various admin skill levels, support numerous regulatory, security and engineering mandates and standards, and enable rapid integration with third-party applications.


Managing a single data center is one thing, but the rise of the cloud means that vital resources may soon be spread around the world. A California company called Chatsworth Products Inc. (CPI) says it is kicking management up to a global scale with its Enterprise Infrastructure Solutions. The package offers the ability to monitor and control systems wherever they happen to reside, with modules covering everything from asset management to power and thermal control. The system is built around the Scalable Enterprise Management Application (SEMA), which acts as the central storehouse for devices across the network.


There's no question that resource management in the age of the cloud will be a challenge, and it is still very likely that admins will have their hands full once users grow accustomed to provisioning their own resources as they need them. That's why it's crucial at this point to bring as much management capability under one roof as possible, so at least you have a chance of keeping things under control when the world of finite resources gives way to a world of infinite ones.

Exclusive: IBM’s Test Cloud Opens to Public Beta

IBMが自社のクラウドインフラ、Test Cloudを一般に公開する、との予定。

Exclusive: IBM’s Test Cloud Opens to Public Beta

IBM tomorrow is expected to open its test and development cloud to a public beta after serving about 600 customers in a private beta. Some in the cloud community were disappointed when Big Blue announced plans for the test and development cloud in June but provided no time table for the public beta and the general availability of the product. But now we know that the public beta of IBM’s Smart Business Develop and Test Cloud, which uses tools from its Rational software, will open Thursday at 2 p.m. PDT, allowing anyone to take those virtual machines for a spin for free.  The general availability will be sometime early next year.

That’s promising news as the company inches to the cloud, and better news is on the way. In a conversation this week with Maria Azua, VP, Cloud Computing Enablement, Enterprise Initiatives at IBM, I learned that the company plans to eventually launch a secure private cloud offering similar to those already offered by Savvis or Amazon’s Web Services. Big Blue also affirmed its plans to release special-purpose clouds for certain workloads built on specialized hardware, as well as platforms built on DB2 and WebSphere.

Azua told me that IBM learned some valuable lessons as it translated its Rational software to work in the cloud. First, it had to adjust the software to scale out on multiple virtual machines rather than scale upon many dedicated servers. That process took about six months, and IBM now has two sets of tools, with one designed to run entirely in the cloud and another to run on desktops to build software that can then be tested in the cloud. Azua said running an application that hasn’t been optimized for the cloud, “Can help a customer get bigger, better and faster, and pay less for a mess, but it’s still a mess.” IBM will add other middleware that’s optimized for its cloud and other clouds in the coming months.

Another lesson was that once customers started getting involved in the private beta, they wanted bigger virtual machines, which surprised the IBMers. Azua said customers wanted composite images of their applications that they could see across all clouds they might be running. They also wanted openness, which Azua defined as using open APIs developed in some standards body, rather than by a single company, an open OS and open hypervisors.

With this public beta IBM says it will also offer telephone support for its customers in the IBM cloud, rather than an online form, email or a web notification system. That level of handholding will likely prove popular with enterprise users who may have experienced problems with other cloud providers, only to be directed to a web-based status log and a company blog post.

Beyond the test and development cloud and an announced data analytic cloud that will take advantage of IBM’s acquisition of SPSS, Azua mentioned that IBM will soon offer a cloud that addresses the enterprise need for a virtual private cloud. Such clouds provide secure access for data as it travels from a corporate office up to the cloud over the public Internet and then secures the data in the multi-tenant environment of the cloud. “It won’t be as simple as a cloud with a VPN stuck in front of it,” said Azua. That’s close to what Amazon announced this summer, although the internal security the online retailer offers is unknown. However, it’s becoming clear that IBM isn’t going to cede the cloud to the first movers if it can help it.

Is Hadoop Champion Cloudera the Next Red Hat?

Hadoopを製品化したCloudera社についての記事。 

Is Hadoop Champion Cloudera the Next Red Hat?

cloudera Cloudera, a startup based in Burlingame, Calif., today announced the release of its first commercial product, Cloudera Desktop. It's a graphical interface for managing Hadoop, the open-source framework that is catalyzing the data mining renaissance. Cloudera's Hadoop now works on almost all major cloud platforms: Amazon Web Services, Rackspace and soon, VMware's vCloud.

In light of today's news, as well as my recent conversations with industry insiders such as Netezza CEO Jim Baum, I realized how synonymous Cloudera has become with Hadoop, even though its three co-founders didn't really have anything to do with its early development. I wonder if you guys see that as well?

One of the upsides of getting old is that you see history repeat itself. Or as Yogi Berra would say, it's like déjà vu all over again. I see some interesting parallels between Hadoop and Red Hat, which rose to prominence on the back of Red Hat Linux, a version of Linux optimized for corporate users. (Related Research from GigaOM Pro, sub required: Open-Source Startups Follow Red Hat's Path to Profit.)


Red Hat Cloudera
Offerings Red Hat Linux OS, Services Cloudera Hadoop, Data Warehouse software, Services
Open Source Linkage Linux Hadoop
Key Open Source Champion Marc Ewing Doug Cutting
Venture Investors August Captial, Graylock, Benchmark Captial Graylock, Accel Partners
Key Executive Bob Young, CEO Mike Olson, CEO

For example, Red Hat CEO Bob Young used to run a catalog business that sold Linux and Unix software accessories and books before he bought Marc Ewing's Red Hat Linux in 1995, merged it with his ACC Corp. and named the new company Red Hat Software.

Cloudera, by comparison, was started in 2008 by Christophe Bisciglia, who created and led Google's academic cloud computing initiative; Dr. Amr Awadallah, Yahoo's former VP of engineering; and Jeff Hammerbacher, formerly of Facebook. The founders' pedigree gave the startup instant credibility, which in turn allowed them to snag Mike Olson, a well-respected open source executive, as their CEO and the fourth co-founder.

In the case of Red Hat, the Young-Ewing combo enabled the company to raise $6.25 million in funding from the likes of August Capital, which allowed it to quickly scale. I see the same happening at Cloudera.

Cloudera's talent pool has paved the way for it to raise $11 million in two rounds of funding from Accel Partners and Graylock. Cloudera's other backers include Diane Greene (former CEO of VMware), Marten Mickos (former CEO of MySQL) and Jeff Weiner (president of LinkedIn).

Back in the late 1990s, the focus was on lowering the cost of infrastructure by moving away from proprietary software platforms to open-source operating systems. The focus today is on data and using it smartly. Unlocking the data, mining it for intelligence and analyzing it is the next big opportunity. "The web changed the way we radiate and consume information and in doing so, created a new opportunity to measure and monetize it," writes Gary Orenstein. "The preferred architectural model for this web-derived data warehouse –- a combination of low-cost server hardware, distributed systems and open-source software — set off an innovation path that outpaced the commercial market." Hadoop is well on its way down that path.

Hadoop was developed to support the distribution of the open-source search engine project known as Nutch, and was inspired by Google's MapReduce and Google File System work. A top-level Apache project, it was created by Doug Cutting (and named after his child's stuffed elephant) and championed by Yahoo, which quickly became the largest contributor to the project as it implemented the technology in its web and advertising businesses.

The big change came this past August, when Doug Cutting left Yahoo and joined Cloudera. Cutting's involvement is like the icing on the cake, giving the company the ability to corner all the Hadoop talent out there. It also helps that Cloudera has started to make inroads into newer markets, including biotech and retail. "Hadoop is going to find potential markets in any industry where there are large data sets that need complex analysis," CEO Olson told me.

I remember talking to Red Hat executives back in the day and listening to their pitch about Linux everywhere, how they were going to go beyond the web community and help drive Linux into other corporate environments and eventually, build a services business around it.

Cloudera is following that same path. It's developed its own version of Hadoop, one that's optimized for the needs of large corporations, especially those that prefer a little hand-holding from their suppliers. By giving them this version of Hadoop, Cloudera hopes to make revenue from services. And the timing — the company unveiled Cloudera Desktop at Hadoop World (we are media partners) in New York, an event it organized — is perfect.

Game, set, match for Cloudera.

Related posts from The GigaOM Network:

2009年10月5日月曜日

Biggest cloud of all: Amazon EC2 makes about $220 million a year

Amazon EC2の事業売り上げが約$220Mある、という予測が関係者から出ている。 


Anyone wondering how the commercial cloud computing business model is working should look no further than Amazon Web Services.

Randy Bias just published estimates that AWS is pulling in about $220 million annually for its Elastic Compute Cloud (EC2) offerings. He bases his conclusions on “actual verified EC2 numbers plus some guesses and a rough model of it’s current annual usage.” He also estimates that AWS runs about 40,000 servers to support the service.  EC2 probably grew at a rate of 10% from year to year, Randy believes.

Not bad for a business model based on increments of 10 cents to 80 cents an hour for standard usage. EC2 is a Web service that provides resizable compute capacity in the cloud.

With these numbers in hand, Randy also observes that they may also tell the story about the overall size of the infrastructure cloud computing (Infrastructure as a Service) market. Randy sizes this marker at about $400 million to $600 million, and growing about 10% to 20% annually.

The EC2 revenues represent about 1% of Amazon’s revenues for the most recent fiscal year. ($19.2 billion.) Amazon has really effectively leveraged the capacity from its retail business to offer services to the rest of the market. Is this something other companies with large IT infrastructures can contemplate?

2009年10月2日金曜日

Microsoft Unveils Its Container-Powered Cloud

MIcrosoft社がシカゴ郊外に建設中のコンテナ技術を駆使したデータセンタが公開された。

A look at one of the double-decker data center containers housed at the massive new Microsoft data center near Chicago. The facility includes both raised-floor space and plug-n-play bays for containers packed with servers.

As the bay door opens at Microsoft's enormous new Chicago data center, the future backs in on a trailer. Forty-foot long containers packed with servers are unloaded with winches, and stacked two-high onto "air skates" that float on compressed air. Using the air skates, as few as four employees can move the 60-ton stack into place in Microsoft's "container canyon" in the lower floor of the facility in Northlake, Ill.

Within eight hours, the new container is fully installed, hooked up to chilled water, power and a network connection. "These hold 2,000 servers each, and they can be deployed in hours," said Kevin Timmons, Microsoft's general manager for data center operations. "That's an awesome, awesome thing."

$500 Million Investment
Microsoft opened the doors of its $500 million Chicago facility today, providing media and local officials with a look inside the 700,000 square foot data center. The tour showcased a container-driven design that Microsoft expects to deliver huge benefits in cost, energy efficiency and environmental sustainability.

The new data center, which began operations on July 20, is an unusual hybrid of what Microsoft views as the present and future of data center design, separated by a staircase.

The lower level is a vast space with a high ceiling and diagonal parking spaces for the 40-foot container stacks. Twelve containers are already installed, including 10 double-stacked versions with servers on the bottom and cooling infrastructure above, and two single-story containers.

The first phase can hold up to 56 containers, and a second phase (currently shell space) offers identical capacity. That gives the Chicago facility a total capacity of 112 containers holding 224,000 servers.

2009年9月30日水曜日

The top 150 players in Cloud Computing

Cloud Computing Journalを発行するSYS-CON社が発表したCloud Computing業界のトップ150社のリスト。


A robust ecosystem of solutions providers is emerging around cloud computing. Here, SYS-CON's Cloud Computing Journal expands its list of most active players in the fast-emerging Cloud Ecosystem, from the 'mere' 100 we identified back in January of this year, to half as many again - testimony, if any further were needed, to the fierce and continuing growth of the "Elastic IT" paradigm throughout the world of enterprise computing.

Editorial note: The words in quotation marks used to describe the various services and solutions in this round-up are in every case taken from the Web sites cited. As ever we encourage software engineers, developers, IT operations managers, and new/growing companies in every case to "suck it and see" by downloading or otherwise sampling the offering in question for themselves.

(Omissions to this Top 150 list should be sent to cloud (at) sys-con.com, and we will endeavor to include them in any future revision of this expanded round-up.)

3Leaf Systems - Describes itself as a provider of "next-generation server solutions to enable cloud computing." Specifically, 3Leaf offers to help companies "achieve a terabyte of DRAM at dramatically low cost" based on low-cost commodity servers by providing virtualization of CPU and memory for an entire server farm.

3PAR - Recently announced its "Cloud-Agile" program, a new partnership initiative "to promote the adoption of cloud computing and cloud-based services offered by leading providers with infrastructures powered by 3PAR Utility Storage."

3Tera - Offering what it calls "Cloud Computing Without Compromise," 3Tera enables the provision and deployment of "scalable clustered applications in minutes from anywhere in the world." The company currently has partners and is running in datacenters in seven countries (United States, Japan, Singapore, Argentina, United Kingdom, Netherlands and Serbia) on four continents (North America, South America, Asia, and Europe), with additional resources in South America and Australia soon to be available as well.

10Gen - Co-founded by Dwight Merriman, who also co-founded DoubleClick and served as its CTO for ten years, 10gen is a commercial entity offering "innovative platform technology" around  the Mongo database - an open source document-oriented database "which makes data storage for web (and other) applications fast and easy."

Adaptivity - Adaptivity provides integrated solutions that automate IT Delivery optimization across enterprise computing environments. Those behind the company built the largest private cloud while at Wachovia and are today building clouds with Unisys. Adaptivity sees the Cloud Computing opportunity from a much broader perspective. "IaaS type resources managed externally from the enterprise do provide value; however, the larger opportunity is enabling enterprises to change how they deliver and consume IT resources," says CEO Tony Bishop in a Q&A with Cloud Computing Journal.

Agathon Group - A dedicated grid environment that allows charitable and non-profit campaigns to scale on demand.

Akamai - Akamai claims to have been optimizing the cloud for over ten years, building a global computing platform "that helps make cloud computing a reality." Services for cloud optimization are now a vital part of the company's total offering, and go well beyond Content Delivery Network (CDN) cache-based technologies - marking Akamai's transition from CDN to full-fledged Cloud Computing player.

Amazon EC2 - When Amazon introduced its virtual computing environment, Amazon Elastic Compute Cloud or EC2, "to enable you to increase or decrease capacity within minutes, not hours or days," it single-handedly brought Cloud Computing to the very forefront of public awareness by using Web services to provide what it called "resizeable compute capacity in the cloud." EC2 runs within Amazon's proven network infrastructure and datacenters and allows customers to pay only for what they use. See also S3.

Apache Hadoop -

Appirio - Offers services and products to accelerate the adoption of on-demand solutions, and recently secured $5.6 million of financing in a Series B round led by Sequoia Capital.

Appistry - As a company that positions itself boldly "At the convergence of Grid Computing, Virtualization and SOA" Appistry offers a grid-based application platform that makes it very easy to scale-out CPU- and data-intensive applications across a virtualized grid of commodity servers. Unlike traditional grid products based on legacy scheduler technology, the company's robust "fabric" architecture has no single point of failure and "is well suited for extreme transaction processing (XTP), software-as-a-service (SaaS), cloud computing, and other data- and CPU-intensive applications."

AppNexus

Apprenda
- The true power of software-based computing was realized when software developers could stop focusing on interfacing directly with hardware, and instead focus on the ingenuity of their software, say the founders of Apprenda - the company behind SaaSGrid, an operating system for building and deploying Software as a Service applications, and a platform for conducting Software as a Service business.

Appzero - Pioneer of virtual application appliances (VAA) which decouple an application from the operating system (OS) and its underlying infrastructure." The resultant virtual application appliance contains an application with its dependencies, but with zero operating system (zeOS) component," says the company. The aim of VAAs is to enable enterprises to provision server based applications to any machine in the data center in a matter of seconds or move an application from the data center to the cloud (D2C).

Aptana - Aptana has recently beta-released Aptana Cloud, which it says "is architected to complement Cloud infrastructure providers like Amazon, Google, Joyent and others." Targeted at rapid development, in particular web applications that need to scale rapidly (think Facebook applications etc.), Aptana cloud plugs into the Aptana IDE.

Arjuna - Describing its Agility offering as an "on-ramp to the Cloud [that] allows the IT department to begin to experiment with cloud computing in a gradual, incremental way, without any need for disruption to existing service," Arjuna is positioned to help IT towards a world in which internal IT infrastructure can over time be increasingly subsumed into the cloud.

Asankya -

AT&T - AT&T broke into the cloud business in August 2008 with the global launch of what it calls AT&T Synaptic Hosting - described as "a next-generation utility computing service with managed networking, security and storage for businesses."

Azure - see Microsoft

Bluewolf - A leading provider of on-demand software deployment services, Bluewolf offers remote database management and recently announced its "Arcade" cloud storage offering that allows users to economically store a virtually unlimited number of files of all sizes through the Salesforce interface.

Boomi - Creator of AtomSphere, which the company calls "the industry's first integration platform-as-a-service." It is a pure SaaS integration platform that does not require software or appliances.

Box-Net

Booz Allen Hamilton - Management consultancies are also now part of the Cloud ecosystem by dint of their wide range of offerings aimed at all aspects of the phenomenon, and Booz Allen Hamilton (BAH) in particular has positioned itself in the forefront the federal government's Cloud Computing initiative. According to its special Cloud Computing website. "Booz Allen is prepared to support all elements of government defense and civilian missions and migration efforts to "the cloud." ... Booz Allen is also developing new economic analysis—addressing all cost categories for a variety of potential cloud uses—to help agencies "make the case" for migrating to the cloud."

CA - Bought the key assets - software assets and engineering team - of Cloud Computing player Cassatt in June 2009.

Callidus On-Demand SPM
- see Callidus Software

Callidus Software - This leading provider of Sales Performance Management (SPM) solutions has launched Callidus On-Demand SPM, "a scalable, secure, subscriber-based model that does not require additional IT resources."

Cassatt - [UPDATE: Cassatt is no more. Its key assets were sold to CA in June 2009.] As early as 2004 Cassatt, led by visionary CEO Bill Coleman (the 'B' in BEA Systems), was outlining a roadmap to deliver on the promise of automating IT operations for on-demand computing. Its angle, Cloud Computing-wise: a focus not on public or external clouds but on 'Internal Clouds' since external cloud computing but may be ruled out due to lack of SLA control, security, and compliance, whereas Cassatt contends there is an alternative: an internal Utility Computing architecture yielding the same simplicity and economies-of-scale as an external PaaS cloud.

Cisco -
By virtue of its recent acquisitions, most significantly WebEx and PostPath, Cisco is firmly on its way to joining the Cloud Crowd. "We are believers in the cloud-based delivery model for certain types of services in particular inter-company collaboration services, and that is why we got WebEx and now PostPath," Charles Carmel, Cisco's vice president of corporate development, told Red Herring in August 2008.

Citrix

Cloud9 Analytics - Offers what is calls "the industry's first truly on-demand analytics platform" - the brainchild of CTO Scott Weiner, who views the Cloud as the ultimate data warehouse in the sky.

CloudBerry Lab - Established in 2008 by a group of experienced IT professionals with the mission "to help organizations in adopting Cloud computing technologies by closing the gap between Cloud vendors propositions and consumer needs through development of innovative low-cost solutions" - flagship product: CloudBerry Explorer for Amazon S3.

Cloudera - Recently co-founded by former Googler Christophe Bisciglia and others, Cloudera help its customers install, configure and run Hadoop for large-scale data processing and analysis.

Cloudscale - Cloudscale's unique patent-pending cloud dataflow technology "automatically provides the parallelism and scalability required to handle anything from one-off personal analytics agents up to the most demanding live analytics applications required by the world's leading organizations in business, web, science and government."

Cloudswitch - Fast-growing cloud computing company backed by Matrix Partners, Atlas Venture and Commonwealth Capital Ventures, currently in stealth mode. CloudSwitch is developing what it describes as "an innovative software appliance that delivers the power of cloud computing seamlessly and securely so enterprises can dramatically reduce cost and improve responsiveness to the business."

Cloudworks
-
The goal of Cloudworks is to allow small and mid-market companies to outsource all of their computers, software, and data. Completely web-based, it works like Salesforce or Hotmail - a company's employees can log in through a web browser to access their desktop, server, software, files, email...everything.

Coghead
-
[Closed its doors February 2009.]

CohesiveFT
- As the provider of what it calls 'Elastic Server On-Demand' - aimed at "enabling customers to build and manage applications for virtualized infrastructure and cloud computing," CohesiveFT's Elastic Server Platform allows users to assemble and deploy servers to Cloud Computing Platforms "in minutes." The company likes to think of Elastic Server as a Great Enabler, "allowing you to package your apps for prime time, and do it all by yourself."

Cordys - The Process Factory by Cordys is a simple, reliable and secure solution for anyone to create MashApps business processes from the Cloud - simply by mixing and matching standard business applications such as Google apps and commercially available services. MashApps can be made in minutes, without any coding. This tool has the capability to do for cloud application development environments what Visual Basic did for Windows - fast, easy, and efficient to develop and deploy bespoke applications.

Cumulux - Cumulux is a Cloud solution provider offering products and services that "help enterprises harness the benefits of the cloud." Cumulux' flagship product, Hybrid Axis "helps enterprises extend their current investments to the cloud by integrating traditional and cloud based applications." Cumulux also offers services like cloud assessments, "rapid prototyping to help enterprises take the right steps towards cloud adoption."

Dataline - Provides cloud computing advice and expertise to the larger FSIs (i.e. Northrop Grumman, Lockheed Martin, etc) and bundles commercial cloud computing offerings in a way that meets Federal customer requirements. Although not a product vendor, the role this company fills as a mid-level Federal System Integrator is crucial to the adoption of these technologies by the public sector.

Dell

Desktoptwo -
This "Cloud desktop" offering from Sun Global Partner Sapotek describes itself as "your home in the cloud" and already claims to have users in 120 countries and a vibrant community.

ElasticHosts

Elastic Compute Cloud - see Amazon EC2

Elastic Drive
- see Enomaly

Elastra - Styling itself as a provider of "Elastic Computing," Elastra offers to "design, deploy & manage database and application infrastructure in the Cloud in minutes - all with the click of a button." Dedicated to providing companies building applications with a way to radically innovate the way they develop their products and deliver them on IT infrastructure, Elastra's aim is to help a company "unlock the value of cloud computing by using virtualized hardware environments with cloud-provisioned database and infrastructure software that are easily configurable and do not require scripting, respond elastically to changing load and are delivered in the cloud with meter-based pricing."

EMC - When creating a Cloud Computing division within the company in February 2008, EMC CEO Joe Tucci delared that 85 percent of data will be managed in what he called "big, safe information repositories in the Internet 'sky,' so to speak. We're [talking] cloud computing..."

Engine Yard - As a company dedicated to "furthering innovation in Ruby, Rails and cloud computing," Engine Yard offers Rails-focused 24/7 operations support on top of great infrastructure to companies in search of a smooth path from 100 users to 100,000 users. In July 2008 the company closed $15 million of Series B financing led by New Enterprise Associates (NEA), which included participation from Amazon.com.

ENKI - The company aim is "to allow you to focus on delivering your application to your customers while we handle the operations side: providing computing as a reliable service."

Enomaly - see Enomalism

Enomalism - Founded in November 2005 by Enomaly Inc, Enomalism - a so-called "Elastic Computing" platform - focuses on "solving the cost and complexity for enterprises that run large technical server infrastructures." Enomalism's flavor of cloud computing simplifies IT management as well as increases efficiencies of system resources. "IT administrators no longer need to install software and manually set up all the systems, but may instead use management software do this. Resources are used more efficiently because computers can be consolidated to achieve more tasks. This ensures that underutilized systems do not sit idle."

Eucalyptus

eVapt - Claims to enable "usage based monetization (instant SaaS metering) for SaaS and Cloud Computing vendors."

EyeOS -

FlexiScale - The brainchild of CEO Tony Lucas, FlexiScale is a flexible, scalable, automated hosting platform ("Cloud Computing On-Demand").

Force.com - see Salesforce.com

Fortress ITX


G.ho.st


GigaSpaces
-
Founded in 2000, with offices in the US, Europe and Asia, GigaSpaces allows businesses and developers "to predictably scale on-line systems under any peak demand, guarantee real-time performance under any data processing load and seamlessly leverage the economies of scale offered by virtual computing environments such as clouds and grids."

GoGrid/ServPath - Launched in 2006 as ServePath's latest growth opportunity, GoGrid, claims the company, "delivers true 'Control in the Cloud' by combining many of the familiar features of dedicated server or managed hosting with the flexibility and scalability of cloud server hosting." In other words, with GoGrid customers can grow production servers in real time to meet demand without affecting their uptime. Provisioning and de-provisioning of servers is all done via the Internet.

Google - Without a doubt 'the elephant in the cloud' - According to this well-researched article, Google filed as long ago as February 2006 a provisional patent application with 91 different numbered claims that arguably makes it clear that Google has a multi-year lead in cloud computing.

gOS - Founded in early 2007, Good OS is an operating system software company based in Silicon Valley, California, USA and Taipei, Taiwan. Its mission is: "to enable cloud computing through software."

Grid Dynamics - Yechnology consultancy that helps customers "architect, design and deliver business systems that handle peak loads, scale on demand and always stay up - using the latest advances in grid and cloud computing."

Hadoop - See Apache Hadoop

Heroku - According to the San Francisco-based company's founders, "Heroku means never thinking about hosting or servers again." In May 2008 they raised a $3 million round of funding for their online deployment system for Ruby on Rails apps. Heroku is a Y! Combinator start-up.

Hosting.com

HP


Hyperic
-
Founded in 2004, Hyperic provides complete, easy-to-use monitoring and management software for all types of web applications, including hosting it in the cloud via its CloudStatus dashboard currently in beta.

IBM - IBM approaches cloud computing "from the inside out" as it describes it. This means that Big Blue's focus is on building the most secure, efficient and resilient infrastructure for today's organizations, and building the cloud experience as part of that infrastructure. With more than a dozen Blue Cloud Computing Centers worldwide, IBM provides cloud services, ready for use, designed to assist organizations in proving a cloud experience for their constituents. In addition, IBM is the premier company to help build an organization's private cloud, or leverage any of the many IT services that are today provided by IBM through cloud computing, like Capacity on Demand, or the IBM Information Protection Services.

iCloud

IMOD
- see Kaavo

Intel - Intel believes in Open Cloud Standards and one commentator believes there is a strong correlation between how fast cloud computing can proliferate and how well Intel plays its role to lead the open cloud solutions at IaaS and PaaS layers.

Interoute -
Europe's largest and most advanced fibre optic network, the Interoute platform operates as effectively Europe's largest privately owned cloud.

iTricity

Joyent - The Joyent platform, which "enables teams to effectively communicate and collaborate with email, calendaring, contacts, file sharing, and other shared applications," already serves billions of Web pages every month and helped LinkedIn scale to 1 billion page views per month. Self-described as an "On-Demand Computing" provider, Joyent has developed, built and scaled some of the earliest Ruby on Rails applications – and as a result, developed a world-class infrastructure, a methodology around how to deploy and scale (both up and down) Rails applications.

JumpBox - Describes itself as a supplier of "Instant Infrastructure." Specifically, it is a ready-to-deploy virtual computer that contains a pre-configured instance of an application.

Juniper Networks -

Kaavo - provides a platform for managing distributed applications in the clouds. Kaavo's core product, Infrastructure and Middleware on Demand (IMOD), "makes it easier for individuals and businesses to implement on-demand infrastructure and middleware and run secure and scalable web services and applications." The Kaavo philosophy is that taking a top down application-centric approach of managing infrastructure and middleware makes it easy to fully automate application lifecycle management.

Kadient
-

Keynote Systems - Long a player in the SaaS space, in 2009 Keynote opened its cloud infrastructure and offered any Web team free access to KITE (Keynote Internet Testing Environment), its product for testing and analyzing the performance of Web applications across the Internet cloud. With a Web application's performance depending on a variety of clouds' infrastructures, ad servers and other third party content, potential pitfalls grow exponentially and Keynote contends understandably that "it's more important than ever for Internet companies to test and measure applications to ensure a superior end user experience." With KITE, companies have free access to Keynote's cloud infrastructure and a tool to test and monitor their applications from cities all over the world.

Layered Technologies - Offers virtualization and cloud computing systems.

LinkedIn - see Joyent

LongJump - The Platform-as-a-Service (PaaS) solution that LongJump offers is described by the company as "an on-demand platform for creating and delivering business applications to manage data, streamline collaborative processes and provide actionable analysis." The company claims that the LongJump platform has "extensive features around security access, data analysis and visualization, and process automation – all on the web."

Meeza -
Qatar-based, Meeza is currently the main Cloud Services Provider within Middle East North Africa region.

Mezeo Software -
Houston-based, privately funded software solution provider that has created what it calls "the industry's first deployable, white label cloud storage platform, enabling service providers to quickly and efficiently enter the cloud storage market" (Mezeo Cloud Storage Platform).

Microsoft -
According to this recent article - "Microsoft's Cloud Vision is Coming Together" - Redmond's Cloud Platform vision is coming together. "Look for more information at PDC2008!" writes Microsoft Developer & Platform Evangelist John C. Stame.

Morgan Stanley -

MorphExchange

Netsuite

Ning

Nirvanix - Provider of an enterprise cloud offering that offers companies with more than 5TBs of data a highly scalable storage and delivery platform, Nirvanix has already raised more than $18 million in funding from world-class investors including Intel Capital. The company's customers include Fortune 50, media and entertainment and innovative Web 2.0 customers.

Novell - The recently-announced Novell Cloud Security Service "enables cloud service providers and Software-as-a-Service vendors to ensure their offerings meet the strict security and compliance standards required by global businesses."

OpenNebula - OpenNebula is a widely used open-source tool for the efficient, dynamic and scalable management of VMs within datacenters (private clouds) involving a large amount of virtual and physical servers. It supports Xen, KVM and on-demand access to Amazon EC2. The tool is being used as core component in several cloud projects, such as RESERVOIR.

OpSource - Delivers a complete Web operations solution for software as a service and web companies. Its OpSource Cloud is currently in private beta, aimed at providing every user with a "Virtual Private Cloud" within the public cloud.

Oracle - The world's largest business software company believes that Private Clouds for the exclusive use of one enterprise can mitigate concerns about security, quality of service, integration, compliance, lock-in, and long term costs of public clouds by giving the enterprise greater control.

OTOY

Parallels - Founded in 1999, Parallels optimizes computing by providing virtualization and automation software to businesses and service providers across all major hardware, operating systems, and virtualization platforms. Parallels is working closely with a network of ISVs and service providers to enable them to build their cloud computing and software-as-a-service offerings, meeting the needs of end-user organizations of all size. Parallels technology is also used by large enterprises creating their own in-house clouds.

ParaScale -
"Cloud storage" involves clustering tens to hundreds of servers together to act as one giant file repository with massive capacity and parallel throughput for a variety of applications. ParaScale's software "enables the enterprise or service provider to build enormous storage pools on commodity hardware at an affordable cost."

Penguin Computing - Penguin has launched an HPC cloud called Penguin on Demand (POD). Penguin is targeting researchers, scientists and engineers who need surge capacity for time-critical analyses or can't afford their own HPC cluster.

Platform Computing - Founded in 1992, Platform is a pioneer and global leader in HPC (high-performance computing) and takes the view that there is an intersection between grid computing and cloud computing in that both cloud and grid propose an architecture that masks the complexity of managing thousands of commodity servers from their users.

Q-layer

Qrimp

Quantivo -
Claims to be "revolutionizing the Business Intelligence (BI) world by combining Cloud Computing with an innovative and patented 'Affinity Analytics' technology." Company recently won the Silicon Valley/San Jose Business Journal's prestigious Emerging Technology Award in the Cloud Computing category.

Quickbase

Rackspace - Market-leading specialist in hosting and cloud computing services, Rackspace Hosting is "changing the way businesses worldwide buy IT." Rackspace delivers computing-as-a-service, "integrating the industry's best technologies into a flexible service offering, making computing more reliable and affordable." Rackspace is distinguished by its award-winning "Fanatical Support," furthering the company's mission to be one of the world's greatest service companies. Rackspace is recognized as one of FORTUNE Magazine's 100 Best companies to work for in the US, ranking number 43 on the list. Rackspace's portfolio of hosted IT services includes Managed Hosting, Cloud Hosting, and Email and Apps.

Red Hat - RH believes that its consistent dedication to open source and open standards will further the success of a strong cloud ecosystem. "By bringing together thousands of Red Hat-certified applications, Red Hat Enterprise Linux, JBoss Enterprise Middleware and Red Hat Enterprise Virtualization we aim to deliver the next generation of computing architectures, today," says a company spokesman.

Reservoir

Rhomobile -
Rhomobile provides RhoHub, which is describes as "the world's first Development-as-a-Service for Mobile." RhoHub provides a cloud-based service for both smartphone app development and hosting of mobile applications.

RightScale - RightScale offers a fully automated cloud management platform that enables organizations "to easily deploy and manage business critical applications across multiple clouds with complete control and portability." The RightScale Cloud Management Platform is delivered as software-as-a-service (SaaS) and is available in a range of editions, froma free Developer Edition to Enterprise Editions.

Rollbase

rPath -
Founded in 2005, rPath helps organizations "realize the promise and avoid the perils" of cloud computing, "rPath's Cloud Computing Adoption Model provides a pragmatic, actionable, step-by-step framework for achieving measurable benefits now, while laying the foundation for the strategic benefits of a cloud infrastructure over time."

S3 -

SalesForce.com - has a toolkit for cloud computing development, Force.com.

Savvis - Provider of Savvis Cloud Compute, a "right-sized computing environment" launched in February 2009.

ServePath/GoGrid - Launched in 2006 as ServePath's latest growth opportunity, GoGrid, claims the company, "delivers true 'Control in the Cloud' by combining many of the familiar features of dedicated server or managed hosting with the flexibility and scalability of cloud server hosting." In other words, with GoGrid customers can grow production servers in real time to meet demand without affecting their uptime. Provisioning and de-provisioning of servers is all done via the Internet.

SIMtone - Durham, NC based SIMtone has developed and commercialized a 'Universal Cloud Computing Platform' that allows network operators and businesses "to host, manage and quickly provision any cloud-hosted services, and ubiquitously deliver them to zero-touch terminals that can be standalone, low cost hardware appliances, or software terminals usable via browsers or on PCs, thin clients and mobile devices."

Skytap
- Seattle-based Skytap's goal is "to make serving up virtual machines over the internet as ubiquitous as delivering HTML to a browser." Its initial product offering, Skytap Virtual Lab, is a hosted, on-demand service for virtual lab automation and management.

SLA@SOI - SLA@SOI's vision is "to create a business-ready service-oriented infrastructure that will empower the service economy in a flexible and dependable way."

SmugMug - Founded 5 years ago, SmuMug calls itself "the ultimate in photosharing" since it offers unlimited storage and stores backup copies of each photo in multiple datacenters. With more than 315,000 paying customers already, and 288,000,000 photos, SmugMug is a QED of cloud computing.

SOASTA - No one who heard SOASTA speak at AJAXWorld in 2007 about best practices in AJAX testing will be surprised to hear that Web testing is also at the heart of its CloudTest offering, a Cloud-based testing solution "built on the cloud to enable application testing in the cloud."

StrikeIron IronCloud

Sun - In July 2008, David Douglas was named Senior Vice President of Network.com, Sun's offering based on the Sun Grid project. Douglas is now the head of Sun's overall cloud computing initiative and his group now reports directly to Sun's CEO Jonathan Schwartz. ""We continue to see huge potential in the cloud space," commented Douglas as the news of his appointment was announced.

Terremark - Offering 'Enterprise Cloud' services that "let you control a resource pool of processing, storage and networking and allow you to deploy server capacity on demand," Terremark as years of experience managing complex, mission critical infrastructures and applications for leading companies around the world.

The GridLayer - see Layered Technologies

ThinkGrid -

Unisys -The Unisys cloud computing strategy enables clients to choose the type of data center computing services that best meet their business objectives, from self-managed, automated IT infrastructures to Unisys-managed cloud services. Using Unisys services and technologies, organizations can create a private cloud within their data centers, a public cloud through secure Unisys-managed cloud solutions, or a hybrid cloud solution combining the best of both private and Unisys-managed cloud services.

Univa UD - Univa UD is a leader and innovator in software solutions for cloud enablement. The company's software suite includes infrastructure management and service governance for cloud and HPC environments and spans all 3 cloud scenarios: public, private and hybrid. "With Univa products, companies can build private internal compute clouds, create clusters in a public cloud, or span the two by cloudbursting from an internal to external environment on demand."

vCloud - see VMware

Vertica - Vertica Analytic Database for the Cloud is "an on-demand version of Vertica's blazingly fast, grid-enabled columnar database hosted on Amazon's EC2."

Virtual Workspaces

VMware - A virtualization leader and pioneer, VMware has effectively delivered the technology that makes today's clouds possible. With the pervasive presence of VMware in many accounts, enterprises are leveraging their virtualization infrastructure to build internal clouds, and leverage technology like VMotion to flex resources for DR or test and development to external clouds, as needed. Its vCloud initiative, says the company, "offers users of all sizes this robust and reliable platform, support for any application on or off site, and choice from over 100 service providers worldwide who deliver the cloud on VMware."

WorkXpress - PaaS pioneer WorkXpress released v 2.0 of its flagship customizable software platform in April 2009. "WorkXpress 2.0 is the world's most functional PaaS (Platform as a Service)" claimed the Company in an accompanying statement.

Yahoo!

Zetta - Provider of what it describes as "best-in-class NAS storage in the cloud." Zetta's founders are the team who commercialized the web as the leaders of Netscape.

Zimory - A spin-off of Deutsche Telekom Laboratories, Zimory "enables dynamic, on-demand movement of applications automatically between servers in one or many locations, as well as creating the world's first marketplace for computing capacity." Based in Berlin, the company develops a dynamic infrastructure solution for data centers to create a modern Adaptive Cloud Infrastructure - "improving flexibility and reducing operating costs."

Zoho

Zuora - With its "Powering the Business Cloud" slogan, Zuora has planted its flag firmly atop the Cloud Billing mountain. The company describes its Z-Commerce Platform as "the first commerce platform for cloud developers."

© 2008 SYS-CON Media Inc.