Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up


Your Network's Not Ready for E-Commerce

By Brian Walsh  A first-time e-commerce project manager informs management that after due diligence, package selection and integration, enabling the company's Web site for e-commerce will take six months and cost approximately $400,000. He then notes that the only thing left to do is to inform the network group. But what can the network group really add to the project, he wonders? Maybe a new T1 line? Well, he has already budgeted for that, to the tune of $1,000 per month and 30-days' notice to install. All in all, he anticipates no problems.

The lies we tell others are bad, but it's the lies we tell ourselves that really get us into trouble. The reality is that security is hopelessly lacking on internal segments behind the firewall, which could cause our project manager's figures to grow by half, or even double, by the time the project is completed.

Introducing e-commerce to an organization exposes quite a few of these little lies. You've heard them: "Our firewall protects us from the Internet." "Since the Web server is in the DMZ (demilitarized zone), we don't have to worry about it." "Our internal systems are secure." "We don't have anything worth hacking." "Security is a network problem." And my favorite, "Our production systems are flexible because they're based on standards." What a panic! It actually would be funny if not for the time and money involved.

These lies contribute to the security rationalization concerning network deployment behind the firewall. The architecture of internal segments is driven by several factors: historical accident (we needed it, we added it), performance (based on user complaints, we moved the servers to their own segment) and/or reliability (someone will get fired if there's a problem with this application, so we'll buy two of everything). Rarely has security been the driving factor in the tactics of network architecture and, consequently, the firewall is often the only secure part of your network. E-commerce just happens to be the first application to demand the same degree of security behind the firewall as is traditionally applied to the DMZ.

Making Myths Web server host security is enough for e-commerce, right? Wrong. Although Web application folks and project managers often believe this myth, the truth is that no matter what security scheme you've employed to protect your Web content, it won't be good enough for e-commerce. However, those of us in the networking space must also shoulder some blame. See, the project manager remembered what you said in passing last year, "Our Web server is secure." And, of course, the project manager then assumed that your statement applied to any Internet application. You then supported that implication by not explicitly stating, "But our internal systems A through Z are not secured."

Essentially, the problem is that the e-commerce initiative everyone in IT is so jazzed about will touch practically every application and database in your shop. Gone is the luxury of defending only a single segment. That innocent Web server will start opening sessions to servers on all of your production segments. Take heed: Do not respond to this challenge by questioning, "Well, can't we just duplicate all that data onto servers on the DMZ?"

Until now, your firewall has served as "a hard crunchy shell around a soft chewy center." (Thank you Bill Cheswick, Bell Labs, Lucent Technologies, for the imagery.) I know, I know--administrators look after all the servers, and you've distributed a security policy to all your personnel. However, if the thought of a server on your DMZ opening a session with a server on an interior segment fills you with dread (because once hackers have access to the production segment they can traverse all segments at will), how do you define usable, flexible security? E-commerce is more than just selling online; it gives your customers and partners access to some of your core data and applications.


Related Links

Inside Outsourcing
August 1, 1998

The 'Q' In QoS Stands For Quality
September 1, 1998

Building a Business Plan for an E-commerce Project
September 15, 1998

Is 'Good Certification Program' an Oxymoron?
October 1, 1998

The Once and Future Development Standard
November 1, 1998


Other Columnists

Top of the Stack
By David Willis
On the Edge
By Art Wittmann

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers