Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs



Send to a friend

Feedback
Breaking news
Today's top news.

Users mistrust bundled security products

Reluctance to adopt an integrated approach stems from several sources.

Related linksToday's breaking news
Send to a friendFeedback


The renewed user interest in the security product bundling concept comes from the heightened awareness of security after Sept. 11, along with the general sense that networks are now more mission-critical because they support e-business initiatives and remote employees, analysts say (see main story). But these experts point out that most enterprises haven't committed to full-scale adoption of bundled security products.

"Certainly, [companies] now have allocated extra money for security. And yes, they are looking at things like vulnerability assessment and IDS. But honestly, integrated appliances don't seem to be their first pick, though they are on the radar," says Joel Conover, an analyst at Current Analysis.

Analysts acknowledge that service providers, such as Divine, and small to midsize businesses account for the bulk of integrated security product sales, despite vendor attempts to appeal to larger corporations.

"Many [companies] still think they'd be going out on a limb with such products, but they are inviting them into the evaluation space. Vendors seem to be counting those evaluations as shipped products," Conover says.

Communications Supply in Carol Stream, Ill., is one user that recently invited integrated product offerings into an IDS evaluation. But Robert Fischer, director of technical services, is quick to point out the uphill battle ahead for those vendors. He expresses skepticism that a firewall/IDS product will provide the same set of checks and balances as distinct firewalls and IDS devices.

"They will have to prove to us that one feature set will find problems in another feature set," he says. Another prickly point is vendors' claims that these products reduce duplication of security features. Users who have pieces of their security strategy in place tend to view integrated offerings as redundant. Plus, integrated packages are frequently more expensive, he says.

"A lot of this is just packaging," Chris Christensen, an analyst with IDC, says of added security features. "And a lot of companies already have a large range of existing products doing security and management."

Jim Slaby, an analyst with Giga Information Group, agrees. "With Swiss-Army-knife appliances comes the potential for duplication of functions,'' he says.

On top of that is the hesitancy among users to rely too heavily on one provider. " One downside is getting entrenched with single-vendor solutions. After the dot-com bomb, you've got to be careful who you choose," Phil Ruenhorst, director of ChimeNet, an affiliate company of the Connecticut Hospital Association in Wallingford, says. Even something that seems as common sense as bringing authentication techniques into laptops will meet with user resistance, analysts say.

"It is pretty well-known at this point that the information on the laptop is worth far more than the actual device," Christensen says. "There is also a desire to protect the connection to the LAN or corporate network."

So vendors will likely integrate tokens and biometrics into mobile devices, and possibly into operating systems, Christensen says. "But margins on laptops are thin. Building authentication into these devices begs the question of whether there will be enough buyers," he adds.

While users are dabbling with integrated products, traditional strategies that mix dedicated offerings are still the preferred route for many corporate users.

"Large enterprises would rather go with best-of-breed solutions, since they consider their own internal integration efforts as a competitive advantage," Christensen says.

Related Links

Topics: Security
Get the latest news, opinions, how-tos, reviews and more.

Error 404--Not Found

Error 404--Not Found

From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:

10.4.5 404 Not Found

The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.

If the server does not wish to make this information available to the client, the status code 403 (Forbidden) can be used instead. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address.

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.