home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



  F E A T U R E

Hammering Out a Secure Framework

January 24, 2000
By Mike Fratto

Managing security is getting much more complex . The days of feeling safe because you have a firewall are nearly history. Crackers the world over are finding increasingly ingenious ways to break into networks. They are getting through your firewall at the application layer; they are getting in through ill-secured SOHO/ROBO (remote office/branch office) connections; they are getting in through mobile code exploits. They are walking in the front door as employees and temps. The very nature of network security is changing, from just keeping out the bad guys to controlling the flow of data out of the network and limiting access to outside resources. As companies employ more point products to stop trespassers, security frameworks--platforms aimed at consolidating and managing multiple security functions--are on the rise. Frameworks promise to unify network security under a single platform with multivendor support and advanced security management.

But there are gaps between the promise and the reality of security frameworks, mainly because of the immaturity of the market. Only the OPSEC (Open Platform for Security) Alliance has the much needed multivendor support and broad application support to give it a healthy head start.

Launched in 1997 by Check Point Software Technologies, the OPSEC architecture now has more that 200 partners, including Microsoft Corp., IBM Corp., Computer Associates International and Novell. The goal is to provide a standard security framework that guarantees a certain level of product integration.

But look for framework initiatives from vendors such as Axent Technologies, IBM and Network Associates, to name a few, to make a bigger play for your security dollars this year and beyond with unique offerings. One thing is certain: As network applications extend beyond current boundaries and attacks become more sophisticated, the tools needed to protect your assets must evolve. Many of today's security frameworks are more impressive on paper than in reality, but by the end of 2000, there should be several solid solutions from which to choose.

To assess the viability and future prospects of these frameworks, we invited Check Point and Network Associates to show off their security frameworks. In our Real-World Labs® at Syracuse University, we poked and prodded OPSEC and Network Associates' Active Security in an attempt to evaluate interoperability and ease of integration. Although we did not do extensive testing, we came away with a clear understanding of each vendor's architecture and ability to live up to its marketing claims. We think that security frameworks eventually will ease security administration by providing needed centralized policy management facilities and automated response systems.

Centralized Security Management Is Becoming a Necessity
Network-site security started with a firewall protecting the network perimeter, inspecting inbound and outbound traffic, and passing authorized data. As interest in the Internet grew, more files were being downloaded and installed on corporate desktops. This made virus scanning on the desktop and at the firewall more of a necessity. Concurrently, URL filtering and e-mail scanning protected data flowing in and out of the network at the application layer. The public release of Satan brought the idea of vulnerability scanning into the mainstream--and with it the need for intrusion detection. Intrusion-detection systems (IDS), content- and URL-filtering servers, network virus scanners and vulnerability scanners augment network security by examining data that's passed through the firewall.

Not surprisingly, the evolution of network security products has followed a point approach. Niche vendors have created vertical applications that address the needs of one security threat. For example, numerous point products have appeared to block access to networks, scan for viruses, filter unauthorized Internet access via e-mail or HTTP, track network usage and scan for vulnerabilities and ongoing attacks. With numerous point products to install, manage and maintain, the increased burden on management, the need for consolidated reporting and the requirement to bind these disparate products into a cohesive whole becomes increasingly apparent to end users and vendors alike. Security frameworks are aimed at providing the means for consolidating these disparate functions into a single console.

The ultimate promise of security frameworks is twofold. First, frameworks should assist network managers in tightening security across the enterprise network, not only at the perimeter but also where point products reside, by simplifying the implementation of a security policy. Second, frameworks should provide a seamless view of the network from a security perspective, including applications, policies and vulnerabilities. Frameworks also should aggregate data, perform event correlation, handle routine events and alert administrators to events needing immediate attention.



PAGE: 1 I 2 I 3 I 4 I 5 I NEXT PAGE
 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service