CC Week 05
CC Week 05
CC Week 05
Week # 05
1
Previous Week
2
This Week
• SaaS Examples
• SaaS Benefits
3
IaaS, PaaS & SaaS Provisioning
4
IaaS Provisioning
9
IaaS, PaaS & SaaS Comparison
Control level:
• SaaS: Usage and usage related configuration
14
Software as a Service (SaaS)
[Thomas Erl [2014], Cloud Computing Concepts, Technology and Architecture, Pearson]
• For the time being we shall assume that the browser acts as
cloud service consumer when accessing a SaaS.
Software as a Service (SaaS)
Classes of SaaS:
• Business logic: Connect the suppliers, employees,
investors and customers.
• Example: Invoicing, fund transfer, inventory
management, customer relationship management
(CRM)
Software as a Service (SaaS)
together.
30
SaaS Software Stack
Application
Middleware
Operating
System
Hardware
SaaS Software Stack
• Application: Email
• Middleware: software libraries, run time environments
(Java, Python)
Application
Middleware
Operating
System
Hardware
SaaS Software Stack
Application
Middleware
Operating
System
Hardware
SaaS Software Stack
Application
Middleware
Operating
System
Hardware
SaaS Software Stack
SaaS Benefits
36
SaaS Benefits
40
SaaS: Issues and Concerns
• The NIST has identified few issues and concerns about SaaS.
• Most of these issues are due to network dependency of
SaaS.
1) Browser based risks and remedies:
• Since the SaaS is accessed through browser installed on
consumers’ device, the inherent vulnerabilities of the web
browsers do have impact over SaaS security.
• Although the browsers apply encryption upon network
traffic, yet various network attacks such as brute force and
man in the middle attacks are possible upon the SaaS data.
• The resources leased by a consumer can be hijacked by
malicious users due to poor implementation of cryptographic
features of browsers.
SaaS: Issues and Concerns
2) Network dependence:
• SaaS application depends upon reliable and continuously
available network.
• The reliability of a public network (Internet) can not be
guaranteed as compared to dedicated and protected
communication links of private SaaS applications.
SaaS: Issues and Concerns
46
NIST Recommendations for SaaS
1. Data protection:
3. Encryption:
49