by Readers

Letters to the editor: When enterprise networks stay up late

Opinion
Mar 12, 20076 mins

When enterprise networks stay up late; AdvancedTCA: cure for chaos?

When enterprise networks stay up late

According to the book Where Wizards Stay Up Late: The Origins of the Internet, TCP/IP co-designer Bob Kahn is said to have injected 12 packets into the first four-interface-message-processor Internet and brought it down — the first denial-of-service attack on the Internet. Today, would Kahn’s actions be considered testing or hacking? Hacking is mostly about making a system do something different from its designed purpose. Exposing the system’s flaws is certainly making it do something different. In the connected enterprise network, hacking really has turned out to be outsourced quality assurance.

Nearly every enterprise product or application connects to a network and the Internet today. A formerly isolated product bug quickly becomes a network-based exploit or robustness issue once the product is connected to the network. The underlying question for companies: What can be done to minimize any product’s attack surface when it is first purchased, subsequently upgraded or during a planned configuration change? Vista, managed services and VoIP are a few of the popular enterprise purchases right now. The trust-but-verify model typically was used only for testing performance. Service availability (as a superset of vulnerabilities and robustness) has been next to impossible to quantify for a number of reasons – finding the expertise, the tools and the automation required to perform such a feat in a repeatable and methodical manner. Today businesses can baseline performance, but can they baseline security?

Microsoft and Carnegie Mellon University pioneered the concept of attack surface for quantifying the exposure of systems to attack. Ironically, large companies newly deploying Vista (which has native IPv6 support) and other complex applications this year will face continued downtime and information theft due to poor attack surface coverage. It’s not that hackers are breaking systems; the systems are already broken before the hackers get there. Security analysis is a methodical way of identifying service availability issues, effectively baselining the attack surface of a system. The concept of attack surface coverage testing is widely known yet not aggressively used by either businesses or their IT suppliers.

Three facets combine to measure the quality of security analysis: specification, code and configuration coverage. Specification coverage provides a metric for how deep the attacks are applied and how it leverages the interconnectedness of protocols to penetrate deeper into the system to uncover vulnerabilities. While businesses are unable to modify their product code, with code coverage they can indirectly measure its impact on the attack surface. Configuration coverage gives companies the flexibility to analyze systems deployed with a variety of modes and policies. For example, deploying a system with or without IPv6 can drastically change the attack surface. In order to quantify service availability, all three of these factors are critical, though companies typically can modify only the configuration of a system. The three metrics of coverage broadly map into the design, development and deployment of the product development life cycle.

In the end, deploying Microsoft’s Vista or other networked enterprise product is now ideally preceded by a security analysis baseline of the product’s unique attack surface. This stance proactively shrinks the malicious opportunities available to hackers. As IPv6 and other complex voice, data or video protocols become enterprise requirements, the urgency for so-called negative testing of attack surface for vulnerabilities and robustness issues expands exponentially.

Kowsik Guruswamy

Founder and CTO

Mu Security

Sunnyvale, Calif.

AdvancedTCA: cure for chaos?

In the rush to stake out their ground in the growing blade server market, the big players each launched their own blade server offerings, and the industry has been punished ever since with proprietary and many times incompatible form factors. At the same time, AdvancedTCA (ATCA) architecture has finally moved from the drawing board to commercialization with strong interest by leading telecommunication equipment manufacturers. With this in mind, the data center is on the cusp of a big change: ATCA is ripe to invade the data center and displace many of the current proprietary platforms. IBM is the only player in the blade server market that can counter this eventual migration.

Think about it. The major challenge for telecom equipment manufacturers – and the real impetus behind ATCA – was to enable development of new applications without having to invest in proprietary platforms. Also, while blade servers provide the necessary density, most do not meet NEBS and lack network interface capabilities. ATCA interfaces, on the other hand, can terminate digital telephone circuits (T1/E1 or T3) or optical data circuits (OC3 and OC12). This feature will be important for the data center market as advanced converged applications such as contact center, conferencing/collaboration and unified messaging become more commonplace. To be sure, the seeds of change may already be planted – in the last year, a community of leading server vendors began to offer ATCA processor blades, chassis, management modules and accessories. These vendors quickly adapted from proprietary blade servers to high-performance platforms.

Consider also that the blade server market is so splintered. Even reasonable market adoption of a standards-based platform like ATCA would be able to capture a meaningful percentage of the data center market. With a meaningful market share, the price gap between ATCA and proprietary blade servers would narrow and volume of ATCA would grow as a result. It seems the ATCA blade server market has reached the critical tipping point and the door is open for real competition.

If blade servers can flourish in the data center, then with some adjustments, ATCA can too. Many of the core capabilities for use as a blade server outside the central office are inherent in ATCA, including space-saving blade architecture, modular design, hot swap, remote management, high-speed network interfaces, plenty of power and cooling to accommodate high-performance processors.

But there is always room for improvement. Here are some suggestions that would make ATCA even more attractive for data center applications:

* CPU blades – additional lower-cost CPU blade options that can address the mid-tier markets. Many of the current blades are at the high-end and use costly bleeding-edge CPUs. An option or two without the mechanically complex ATCA mezzanine card slots would be a good start.

* Chassis – a greater selection of 120VAC data center-ready chassis. Redundancy and other high-availability options are overkill for many applications.

* Storage blades – a collection of low-cost blades to provide the all-important CDROM and spinning storage resources.

* KVM interface – a simple and standard approach to dealing with standard keyboard/video/mouse interfaces.

While the future of ATCA in central office applications seems to be assured, with some moderate adjustments, and product re-positioning, ATCA could bring order from chaos in the data center blade server market. Expect adoption of ATCA outside telecom to take a year or two.

Alan Percy

Director of business development

AudioCodes

Somerset, N.J.