CCP Notes Module-5
CCP Notes Module-5
Module-5
Dr. Bhupendra Singh
1
Amity School of Engineering & Technology
AWS allows you to automate manual security tasks so you can shift your focus to
scaling and innovating your business. Plus, you pay only for the services that you
use. All customers benefit from AWS being the only commercial cloud that has had
its service offerings and associated supply chain vetted and accepted as secure
enough for top-secret workloads.
2
Amity School of Engineering & Technology
An advantage of the AWS Cloud is that it allows you to scale and innovate, while
maintaining a secure environment and paying only for the services you use. This
means that you can have the security you need at a lower cost than in an on-
premises environment.
As an AWS customer you inherit all the best practices of AWS policies,
architecture, and operational processes built to satisfy the requirements of our most
security-sensitive customers. Get the flexibility and agility you need in security
controls.
3
Amity School of Engineering & Technology
AWS provides you with guidance and expertise through online resources,
personnel, and partners. AWS provides you with advisories for current issues, plus
you have the opportunity to work with AWS when you encounter security issues.
You get access to hundreds of tools and features to help you to meet your security
objectives. AWS provides security-specific tools and features across network
security, configuration management, access control, and data encryption.
Keep Your Data Safe: The AWS infrastructure puts strong safeguards in place to
help protect your privacy. All data is stored in highly secure AWS data centers.
Save Money: Cut costs by using AWS data centers. Maintain the highest standard
of security without having to manage your own facility
Scale Quickly: Security scales with your AWS Cloud usage. No matter the size of
your business, the AWS infrastructure is designed to keep your data safe.
5
Amity School of Engineering & Technology
The IT infrastructure that AWS provides to its customers is designed and managed
in alignment with best security practices and a variety of IT security standards. The
following is a partial list of assurance programs with which AWS complies:
6
Amity School of Engineering & Technology
AWS
Availability
AWS delivers the highest network availability of any cloud provider, with 7x fewer
down time hours than the next largest cloud provider.* Each region is fully isolated
and comprised of multiple AZ’s, which are fully isolated partitions of our
infrastructure. To better isolate any issues and achieve high availability, you can
partition applications across multiple AZ’s in the same region. In addition, AWS
control planes and the AWS management console are distributed across regions, and
include regional API endpoints, which are designed to operate securely for at least
24 hours if isolated from the global control plane functions without requiring
customers to access the region or its API endpoints via external networks during any
isolation.
7
Amity School of Engineering & Technology
AWS
Performance
The AWS Global Infrastructure is built for performance. AWS Regions offer low
latency, low packet loss, and high overall network quality. This is achieved with a
fully redundant 100 GbE fiber network backbone, often providing many terabits of
capacity between Regions. AWS Local Zones and AWS Wavelength, with our telco
providers, provide performance for applications that require single-digit millisecond
latencies by delivering AWS infrastructure and services closer to end-users and 5G
connected devices. Whatever your application needs, you can quickly spin up
resources as you need them, deploying hundreds or even thousands of servers in
minutes.
8
Amity School of Engineering & Technology
AWS
Global Footprint
AWS has the largest global infrastructure footprint of any provider, and this
footprint is constantly increasing at a significant rate. When deploying your
applications and workloads to the cloud, you have the flexibility in selecting a
technology infrastructure that is closest to your primary target of users. You can run
your workloads on the cloud that delivers the best support for the broadest set of
applications, even those with the highest throughput and lowest latency
requirements. And If your data lives off this planet, you can use AWS Ground
Station, which provides satellite antennas in close proximity to AWS infrastructure
Regions.
9
Amity School of Engineering & Technology
AWS
Scalability
10
Amity School of Engineering & Technology
AWS
Flexibility
The AWS Global Infrastructure gives you the flexibility of choosing how and where
you want to run your workloads, and when you do you are using the same network,
control plane, API’s, and AWS services. If you would like to run your applications
globally you can choose from any of the AWS Regions and AZ’s. If you need to run
your applications with single-digit millisecond latencies to mobile devices and end-
users you can choose AWS Local Zones or AWS Wavelength. Or if you would like
to run your applications on-premises you can choose AWS Outposts.
11
Amity School of Engineering & Technology
All Availability Zones (AZs) are connected through low latency, high throughput,
and highly redundant networking. AZs are physically separated by an unknown
minimum distance to ensure availability of the network even in the event of
catastrophic events like extreme weather. As of April 2020, AWS spans 70
Availability Zones within 22 Regions around the world.
12
Amity School of Engineering & Technology
Another part of the AWS Global Infrastructure are Points of Presence (POP). The
POPs are used for both AWS CloudFront to deliver content to end users at high
speeds, and Lambda@Edge to run Lambda functions with the lowest possible
latency. As of April 2020, there are 216 Points of Presence in 84 cities across 42
countries.
Using the AWS Global Infrastructure, it’s easy to design fault tolerant
infrastructure. We can achieve this by having multiple EC2 instances in different
Availability Zones or even Regions. In the unlikely event of an Availability Zone or
entire Region failing, your applications are not impacted. Other services like
Relational Database Service (RDS) can achieve fault tolerance because they have
Multi-AZ deployment models built-in. Of course, there is always extra cost
involved when having your servers and data stored in multiple AZs.
13
Amity School of Engineering & Technology
VPC Peering
VPC networks in different regions can be tied together using VPC Peering.
Instances in either VPC can communicate with each other as if they are in the same
private network. You can create VPC peering connections between your own VPCs,
with a VPC in another AWS account, or with a VPC in a different AWS region. It is
neither a gateway nor a VPN connection and doesn’t need physical hardware,
mitigating the need for maintenance.
14
Amity School of Engineering & Technology
AWS and its customers share control over the IT environment, both parties have
responsibility for managing the IT environment. AWS’ part in this shared
responsibility includes providing its services on a highly secure and controlled
platform and providing a wide array of security features customers can use.
The customer assumes responsibility and management of the guest operating system
(including updates and security patches), other associated application software as
well as the configuration of the AWS provided security group firewall. Customers
should carefully consider the services they choose as their responsibilities vary
depending on the services used, the integration of those services into their IT
environment, and applicable laws and regulations.
It is possible for customers to enhance security and/or meet their more stringent
compliance requirements by leveraging technology such as host based firewalls,
host based intrusion detection/prevention, encryption and key management. The
nature of this shared responsibility also provides the flexibility and customer control
that permits the deployment of solutions that meet industry-specific certification
16
requirements.
Amity School of Engineering & Technology
AWS Organizations
AWS Organizations helps you centrally manage and govern your
environment as you grow and scale your AWS resources. Using AWS
Organizations, you can programmatically create new AWS accounts and
allocate resources, group accounts to organize your workflows, apply
policies to accounts or groups for governance, and simplify billing by
using a single payment method for all of your accounts.
17
Amity School of Engineering & Technology
Industry 4.0
Industry 4.0 is revolutionizing the way companies manufacture, improve
and distribute their products. Manufacturers are integrating new
technologies, including Internet of Things (IoT), cloud computing and
analytics, and AI and machine learning into their production facilities and
throughout their operations.
Industry 4.0 concepts and technologies can be applied across all types of
industrial companies, including discrete and process manufacturing, as
well as oil and gas, mining and other industrial segments. 19
Amity School of Engineering & Technology
21
Amity School of Engineering & Technology
23
Amity School of Engineering & Technology
Vulnerability Reporting
Amazon Web Services takes security very seriously, and investigates all
reported vulnerabilities.
Vulnerability Reporting
AWS Abuse: If you suspect that AWS resources (such as an EC2 instance or
S3 bucket) are being used for suspicious activity, you can report it to the AWS
Abuse Team using the Report Amazon AWS abuse form, or by contacting
[email protected].
26
Amity School of Engineering & Technology
AWS Manufacturing
For more than 25 years, Amazon has designed and manufactured smart
products and distributed billions of products through its globally connected
distribution network using cutting edge automation, machine learning and AI,
and robotics, with AWS at its core.
Benefits
AWS Manufacturing
Benefits
Innovate faster
AWS offers a broad set of global cloud-based products including
compute, storage, analytics, IoT, and security. Running these services in
the cloud allows your engineers and designers to solve problems quickly
- accelerating time to market. AWS also offers a leading suite of
purpose-built manufacturing services and solutions.
Improve operations
AWS makes it easy to build and tailor your data strategy by allowing
you to securely store, categorize, and analyze all your data in one,
centralized repository. Provide real-time and predictive analytics to
improve overall equipment effectiveness (OEE), service levels, product
quality, and supply chain efficiency.
28
Amity School of Engineering & Technology
AWS Manufacturing
Benefits
Enhanced security
Cloud security at AWS is the highest priority. As an AWS customer,
you benefit from a data center and network architecture built to meet the
requirements of the most security-sensitive organizations.
29
Amity School of Engineering & Technology
Its 2013 reported net sales totaled $14.8 billion. Kellogg’s brands include
Froot Loops, Frosted Flakes, Special K, Rice Krispies, Pop Tarts, Eggo
Waffles, Nutri-Grain Bars, and of course, Kellogg’s Corn Flakes.
30
Amity School of Engineering & Technology
The Challenge
• Margins are tight in the ready-to-eat cereal industry.
Kellogg had been using a traditional relational database on premises for data
analysis and modeling, but by 2013, that solution was no longer keeping up
with the pace of demand.
“Margins are very tight in our industry, and even slight changes in trade spend
can swing market share,” McIlwain says. “Revenue growth is flat in some of
our categories, so we need to be very agile to stay competitive. 32
Amity School of Engineering & Technology
We needed to eliminate waste and invest more in the trade spend that drives
faster time to market and greater revenue.” It was clear that Kellogg needed to
move away from its traditional on-premises infrastructure.
33
Amity School of Engineering & Technology
34
Amity School of Engineering & Technology
The company also uses Amazon Virtual Private Cloud (Amazon VPC), which
is connected directly to the Kellogg data centers to allow access to SAP TPM
directly for employees who are on the company network.
Amazon Simple Storage Service (Amazon S3) is used for data backups,
including HANA, and Amazon Elastic Block Store (Amazon EBS)
provisioned IOPS (P-IOPS) volumes for storage. The company logs events
35
Amity School of Engineering & Technology
36
Amity School of Engineering & Technology
“Using AWS saves us more than $900,000 and lets us run dozens of data
simulations a day so we can reduce trade spend. It’s a win-win, and a pretty
compelling business case for moving to the cloud,” said by McIlwain
Instead of having to wait 30 days to make changes to its trade spend analysis
system, the company can spin up instances immediately to perform the
necessary data simulations (or calculations).
37
Amity School of Engineering & Technology
In addition, by using AWS, the IT team’s internal customers can now self-fund
IT projects—saving the IT team from having to budget for projects from other
departments and driving more efficient use of resources.
The company uses AWS Support, Business Level, and training, as well; one
engineer already has successfully achieved the AWS Certified Architect
certification.
Kellogg is using AWS for its US operations, and plans to expand worldwide in
2014 — which should increase the amount of data being processed from 16
TB to 50 TB. “By using AWS, we have happier customers and we work faster,
cheaper, and better,” McIlwain says. 38
Amity School of Engineering & Technology
39
Amity School of Engineering & Technology
Today, iRobot is a global enterprise that has sold more than 20 million robots
worldwide. iRobot's product line, including the Roomba and the Braava family
of mopping robots, features proprietary technologies and advanced concepts in
cleaning, mapping, and navigation. iRobot engineers are building an
ecosystem of robots and data to enable the smart home.
40
Amity School of Engineering & Technology
Today, iRobot is a global enterprise that has sold more than 20 million robots
worldwide. iRobot's product line, including the Roomba and the Braava family
of mopping robots, features proprietary technologies and advanced concepts in
cleaning, mapping, and navigation. iRobot engineers are building an
ecosystem of robots and data to enable the smart home.
Use the link : https://aws.amazon.com/solutions/case-studies/irobot/
41
Amity School of Engineering & Technology
42