In Depth

The Book on Amazon's Web-based Storage and Computing Services

Can you trust the giant retailer—or any Web-based service—with your information storage and computing tasks?

By Simson Garfinkel

February 05, 2007CSO

Amazon.com wants to sell your organization a whole lot more than books, music and electronics. Amazon, the Seattle-based e-commerce giant, wants to rent your organization storage space for your mission-critical data and virtual machines for doing your information processing. The offerings are enterprise-quality, and the prices are astonishingly low. But is it safe to trust your business to Amazon's infrastructure?

These days it's common for businesses to host their websites and e-commerce systems at colocation facilities. And increasingly much of this equipment is outsourced as well. Although many businesses still like to buy their own servers, disk arrays, load balancers and firewalls, it's much more economical to rent a few dedicated servers at a service provider and let somebody else worry about the plumbing. ISPs get economies of scale by managing hundreds or thousands of identical machines, while the customer can concentrate on building a high-quality website.

Elastic Computing

Amazon's new Elastic Compute Cloud (EC2) Web service takes this idea of hosted servers to a new level. Instead of renting physical servers on a month-by-month basis, Amazon is now renting virtual computers by the hour—10 cents an hour, to be exact. That 10 cents gets you the equivalent of a 1.7GHz Xenon processor with 1.25GB of RAM and 160GB of hard drives. Bandwidth is 250Mbps, at the cost of 20 cents per gigabyte transferred.

One reason that EC2 is so cheap is that the virtual servers can crash at any time and they aren't backed up. If you want to build a reliable system, you need to do it yourself by renting multiple servers and fashioning them into a redundant cluster. This approach provides not just redundancy but scalability. For example, you might build a little e-commerce website with two Web servers and two database engines. If you notice that your site is more popular on weekdays than on weekends, you might bring up an extra two or three servers on Mondays and shut them down on Friday afternoons. By forcing the customer to address the issue of backup and scaling directly, EC2 lowers costs for both Amazon and the customer alike.

Simple Storage

Applications that need more than 160GB of storage should use Amazon's Simple Storage Service (S3). With S3, data is stored redundantly on multiple computers at multiple data centers around the world. Information can be stored with HTTP "PUT" commands and downloaded with HTTP "GET". The cost to store data is 15 cents per gigabyte per month, with an added bandwidth cost of 20 cents for every gigabyte of data that's uploaded or downloaded. Fortunately, there is no cost to move data between EC2 and S3. According to Amazon, you can store an "unlimited" amount of information with S3, which basically means that Amazon can buy disks faster than your organization can fill them.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Ponemon Study: How Much Does a Data Breach "Cost"?

Data Protection: Challenges for the Traveling User

Envision Identity-Based Access Control for the Datacenter

IT Service Management: Metrics That Matter

Configuration Audit and Control for Virtualized Environments

The PCI Data Security Standard

Configuration Audit and Control for Virtualized Environments

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Solving Online Credit Fraud Using Device Reputation

Take our CSO role survey and receive a copy of the results

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Revolutionizing Endpoint Security with a Single Agent

Prepare for (ISC)2® Certification With Villanova - Online

Key strategies for C-level executives and security staff

Configuration Assessment: Choosing the Right Solution

ITCi White Paper: Challenges and Opportunities of PCI

Effective Security with a Continuous Approach to ISO 27001 Compliance

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

The Case for Business Software Assurance ~ Securing Your Applications

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage