The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
Comments
Drool, Britannia? Is the UK Failing the Cloud?
By Roger Strukhoff
Richard Davies wrote: The UK has a good crop of technology pioneers in cloud computing - for example ElasticHosts, FlexiScale, Flexiant, OnApp - and also some strong government initiatives such as G-Cloud. We will have to see whether this kind of technical leadership converts into swift mass-market adoption or not.
Jan. 8, 2012 11:38 AM EST
read more & respond »
Cloud Expo on Google News
Did you read today's front page stories & breaking news?

Cloud Expo & Virtualization 2011 West
Keynotes
Oracle
Opening Keynote | An Enterprise Cloud for Business-Critical Applications
Abiquo
Day 2 Keynote | The Enterprise Cloud Tightrope - Balancing for Success
Akamai
Day 3 Keynote | The DNA of an Enterprise Cloud
DIAMOND SPONSOR:
Oracle
Many Clouds, Many Choices'Cloud
PLATINUM PLUS SPONSORS:
Abiquo
Enterprise Cloud Best Practices - Town Hall - Join the discussion…
PLATINUM SPONSORS:
Intel
Progressing Toward the Federated, Automated and Client-Aware Cloud
New Relic
How to build an app with Twitter-like throughput
Rackspace
Computing in the Cloud Era
GOLD SPONSORS:
Gale Technologies
Practical Cloud Migration
IBM
Re-think IT. Re-inventing Business.
Intel/McAfee
Identity Driven Security in the Cloud
PerspecSys
Hackers Hackers Everywhere, Is My Public Cloud That Safe?
Red Hat
Unlock the Value of the Cloud
SHI
Mission Critical Applications and the Cloud - Myth or Reality?
SoftLayer
Not Your Grandpa's Cloud
Terremark
Integrating Enterprise Clouds
VMware
Upgrade to a vCloud
POWER PANELS:
Cloud Expo Silicon Valley: CTO Power Panel
Cloud Expo Silicon Valley: CEO Power Panel
Cloud Expo Silicon Valley: Cloud SuperStars Panel
Cloud Expo Silicon Valley: CloudNOW Panel
Click For 2010 West
Event Webcasts
Cloud Expo & Virtualization 2011 East
DIAMOND SPONSOR:
Dell
Dell & VMware Deliver the Enterprise Hybrid Cloud
PLATINUM PLUS SPONSORS:
Abiquo
Are Financial Services Organizations Risking Security by Avoiding Cloud Computing?
Oracle
From Consolidation to Enterprise Private PaaS
PLATINUM SPONSORS:
Intel
Driving the Transformation to Next Generation Cloud Data Centers
Rackspace
The Inevitability of an Open Cloud
GOLD SPONSORS:
CA Technologies
Follow YOUR path to Cloud Computing
Interxion
Who Keeps the Cloud in the Air?
Microsoft
Patterns for Cloud Computing
PerspecSys
War in the Clouds: Are you ready?
ServiceMesh
The Big Win: Stop Playing Small-Ball with Your Cloud Strategy
Terremark
Evaluating Enterprise Clouds
Xiotech
Cloud Storage: Myths and Realities
POWER PANELS:
Cloud Expo New York: CTO Power Panel
Cloud Expo New York: CEO Power Panel
Cloud Expo New York: CMO Power Panel
Cloud Expo New York: Wrap-Up Power Panel
Click For 2010 West
Event Webcasts
Live Google News by SYS-CON!
Top Three Links You Must Click On


Be Our Guest

By: Peter Silva
Aug. 24, 2009 07:14 PM


MP: (knocks on the door – Waits. Door opens with MA)
MA: (in a deep fatherly voice) May I help you?
MP: ah, Hi, Mr. App…err, sir….um I’m here to see your daughter, Oracle.
MA: Oh you are, are you? Let me take a look at you. (Looks up/down, turns him around) Have you had a cold or flu recently?
MP: No
MA: Do you always have your firewall enabled before entering unknown areas?
MP: Absolutely!
MA: Have you graduated high school & up to date on your shots?
MP: Yes sir! I’m actually attending Jr Community College Institute.
MA: Ok then (calling over shoulder) Oracle, your friend is here.

After that, you don’t know if they are going to the prom, going to a movie, going to the beach or anything and if poor little Oracle is vulnerable, I don’t think any of you want to see Mr. Packet take advantage of that!

80% of NAC deployments are driven by Guest Access.  What once was the main driver, ‘Endpoint Base lining’ now only accounts for 15% of installations which might explain NAC’s downturn.  At first this was going to be a ‘NAC is whack’ post due to interoperability, standards, cost/complexity and so forth but that seems so 2007.  Plus, TCG is trying to push specifications forward.  So instead of ripping on a technology, I wanted to provide some ideas on Guest Access.  Plus, most companies most are now doing ‘Laid-Back NAC,’ since they are not sure what to do if a device is non-compliant.  According to Gartner, only 7% push/enforce device policies but when it comes to querying, checking the device is ‘good enough’ since if it’s not ours, then you must be a guest.  While compliance & protecting intellectual property are important, it’s mostly about the fear of strangers on the network.

Probably the most prevalent way visiting guests get access (internal or outbound) is Wireless.  Most companies have a WiFi AP that is visible to anyone with a radio and the password is freely given out.  Some broadcast SSID while others keep it secret and usually there is a password (not always the strongest or most secret) to jump on the wireless LAN.  Often, 802.1x will do it’s part by authenticating the user and opening a port.  After that, replay the opening scene since there’s no application awareness.  To protect internal resources, IT might VLAN (segment) the Wireless traffic so it is unable to reach internal destinations.  Another easy prevention mechanism is to only allow Outbound HTTP/HTTPS (ports: 80/443) traffic.  For many visitors, this works well since all they needed was the internet anyway; for others or internal employees that need access to internal systems, an SSL VPN can do the trick.  Just treat your Wireless users as any other ‘remote’ user {pdf}.  They have HTTPS access to the internet and all they have to do is type/bookmark the SSL VPN URL.  Host Check……authenticate…and resource assignment gives users internal access.  You could also create a portal page with available systems and depending on the request, force UN/PW then.  You get granular access control, encryption, application awareness (when coupled with BIG-IP LTM {pdf}) and whatever reports/stats needed for management.

IAM or Identity and Access Management is becoming a hot topic both for general access and NAC.  Regulatory compliance, protecting intellectual property, guest access and the fear of strangers are all driving the NAC & IAM intersection.  Who’s on my network, who has access to corporate secrets, are you one of us and how do we report and control all that are great concerns for IT.  As IAM meets NAC, the crossroads needs smarter signals. When adding Identity to NAC, the focus should be on the user rather than device (even though you’ll still probably check endpoint ‘health’) but companies are having some difficulty with role based info/authorization.  This idea is still in the Technology Trigger (early adopter) phase of the Gartner hype-cycle, but they do predict through 2011, 70% of large enterprises will have implemented authentication for all forms of network access.

ps

  • #7 out of 26 Short Topics about Security
  • previous stories: 6, 5, 4, 3, 2, 1

Read the original blog entry...

Published Aug. 24, 2009— Reads 559
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About Peter Silva
Peter Silva covers security for F5’s Technical Marketing Team. After working in Professional Theatre for 10 years, Peter decided to change careers. Starting out with a small VAR selling Netopia routers and the Instant Internet box, he soon became one of the first six Internet Specialists for AT&T managing customers on the original ATT WorldNet network.

Now having his Telco background he moved to Verio to focus on access, IP security along with web hosting. After losing a deal to Exodus Communications (now Savvis) for technical reasons, the customer still wanted Peter as their local SE contact so Exodus made him an offer he couldn’t refuse. As only the third person hired in the Midwest, he helped Exodus grow from an executive suite to two enormous datacenters in the Chicago land area working with such customers as Ticketmaster, Rolling Stone, uBid, Orbitz, Best Buy and others.

Bringing the slightly theatrical and fairly technical together, he covers training, writing, speaking, along with overall product direction and evangelism for F5’s security line. Prior to joining F5, he was the Business Development Manager with Pacific Wireless Communications. He’s also been in such plays as The Glass Menagerie, All’s Well That Ends Well, Cinderella and others. He earned his B.S. from Marquette University, and is a certified instructor in the Wisconsin System of Vocational, Technical & Adult Education.

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers

ADS BY GOOGLE

Breaking Java News
Get 12X Points at Red Hawk Casino on Presidents Day
HP Introduces Thin Clients With Unprecedented Security, Exceptional Flexibility and Performance
Red Hawk Casino Awards $48,076 Nickel Slot Jackpot
Maxthon 3 Named a Finalist for a 2012 Edison Award: "Game Changing" Nominations from a Variety of Products and Services
IRSA Inversiones y Representaciones Sociedad Anonima Announces Results for the Six-Month Period of FY 2012 Ended December 31, 2011
Local SEO Industry Expert Founds Argent Media Search Marketing Agency in Dallas
Statement by U.S. Conference of Mayors President Los Angeles Mayor Antonio Villaraigosa on President Obama's FY 2013 Budget
Madonna World Tour 2012 Includes Instant Sell Outs in Berlin, Amsterdam, New York City's Yankee Stadium, Philadelphia, Boston, Los Angeles, San Jose, Seattle, Washington, Toronto, Ottawa and Vancouver
Honeywell Takes Air China to New Heights
Minister Raitt Congratulates Air Canada and the Canadian Airline Dispatchers Association on Reaching a Tentative Agreement

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  Cloud Computing Conference & Expo  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window