Tony Redmond, vice president and CTO at HP Services and HP Security Program Office, explains HP’s priorities, including a new service called Active Countermeasures, now in beta.
Tony Redmond, vice president and CTO at HP Services and HP Security Program Office, is in charge of setting security strategy for the company’s products and services. In an interview with Network World Senior Editor Ellen Messmer, Redmond explains HP’s priorities, including a new service called Active Countermeasures, now in beta.
What does HP mean by trustworthy systems?
There’s been a general aspiration toward trustworthy systems for a long time. However, the fact is today’s architectures that we have for PCs and servers in particular are fundamentally untrustworthy because in many respects the basic principles of those systems were laid down in 1981 when IBM designed the original PC. HP believes one of the best ways to drive things forward is by helping people in a collaborative manner set standards we can all build toward. So we’ve got a huge investment in the Trusted Computing Group (TCG) where we’re working with other industry heavyweights such as IBM, Intel, Microsoft and AMD to figure out what the next iteration of systems is going to be.
In terms of TCG’s chip-based security trusted platform module (TPM), what commitment has HP made in its lines of computer and other devices to include TPM-based security?
We’re already shipping product with TPMs integrated into the nc6000 and nc8000 as optional chips. Most customers don’t buy them today. You need an infrastructure to be able to leverage the chips there. You need the operating systems and applications to leverage off them. The real change to trustworthy systems isn’t going to happen today or tomorrow. It’ll happen when we have operating systems such as Microsoft Longhorn and an updated version of Linux and an updated version of Unix that can exploit the fact that we have got trusted modules integrated into the platforms. We have new platforms such as Intel’s La Grande platform available to us. Today, we’re taking the first steps. We’re taking standard PC equipment that we already have and integrating TPMs into those boxes for customers. But if you’re talking about a general rollout, I believe that’s only going to happen from 2006 onward.
Who’s supposed to be in charge of an updated version of Linux for TPM? And the Unix versions for TPM?
HP will make it available through our Unix, HP-UX. I believe IBM will make it available through their Unix. In terms of Linux, HP has a big interest because we have a huge business in terms of shipping Linux servers. And we have a Linux business unit that builds software for those systems. But we haven’t figured out those details yet. But one thing is clear, HP and [TCG] have been in considerable dialogue with governments to make it very clear to them we’re not building in a dependency on a single operating system for trusted systems. We want this to be heterogeneous.
What is HP doing in identity management?
You can have the most trustworthy systems you like, but if you have weak passwords and too many accounts, and people swap passwords, then they fail. The problem is caused fundamentally by the fact that every system that seems to be deployed is insisting on its own credentials. Our view is that this situation only can be solved by the advent of true federated identity management. And that’s what we’re aiming for. Now true federated identity management, again, is a long-term play. So we have to take some initial steps to get there. And our initial steps are in two particular areas; within the OpenView business, to build an identity management suite of products, and you’ve seen us go to market and acquire Select Access and TruLogica, which is now named Select Identity. For the past year or so, integrating them into OpenView to provide major value to customers that want an identity-management solution. Select Access and Select Identity provide provisioning and grant privileges as they move between different jobs according to security policy.
What standards are important here?
The Liberty Alliance is a very important consortium that’s trying to drive standards in the identity-management space and is having some success around protocols such as Security Assertion Markup Language. We’re also conscious Microsoft has an effort in this space they announced recently called Web Services Federation. So we’re working closely with Microsoft to make sure the two potential standards efforts don’t get out of sync. In our view, the long-term win for the industry would be to have one standard. I’m optimistic that we will get to that stage slowly but surely, where we can have the ability to let users go to a single point of authority, gain some network credentials from that authority and then be able to use those credentials to go from one system to another without being forced to constantly re-authenticate themselves.
What about proactive security management? It’s an idea, but how is that specifically put forth as products or services?
The problem we see today is the rate of attacks is growing on an exponential curve, and those attacks are being performed at a computational speed. For example, a few years ago we worried about floppy disks because that was the way things spread. Then we got worried about e-mail viruses. Now we get worried about the likes of Slammer and Blaster, which can reach out and connect to a thousand systems in a second. That kind of rate of increase of potential infection is too difficult and hard for human beings to cope with. So the researchers in the labs felt the only thing they could do was to move from a reactive to a proactive stance to make the computers, the infrastructure, do more to protect itself. The lab researchers started working on this technology around the middle of 2002. We have something called Active Countermeasures that’s been in production at HP for roughly two years,although it’s still in its early stages. We use it to protect a network running in 176 countries that supports an average of 250,000 network devices on a daily basis.
What exactly is Active Countermeasures?
The thought behind it is very simple. A worm or a virus exploits a vulnerability to infect a system. If we can decompose that vulnerability to understand it and then go and interrogate a system to validate whether it’s open to that vulnerability, we can then detect where the vulnerable systems are in the network. And then go and deposit a remediation package on that system, which is similar to what a worm does because a worm interrogates a system to see if it’s vulnerable, and if it is it then deposits a malignant payload. Now the remediation package we deposit is not malignant.
It’s there to close off the vulnerability. And it could be as simple as just flagging the system administration to say you have to go do something, such as turn off this port. Or it could be something as fundamental as ‘We’ve detected your system is fundamentally unsecure, and we are closing it down now.’ And then go and perhaps update the start-up menu for this system to say before you start this system again you have to apply these patches before applying to get on the network. We’re doing this today and it’s helped us resist every outbreak of worms and viruses since 2002.
Does this involve an agent running on your devices?
No, it’s not an agent. We have a set of Linux systems that are dotted around our network, constantly scanning systems by their IP addresses for vulnerabilities. The HP network spans two Class A network addresses, so we know that this technology is very scalable and it works. Every system on the HP network gets probed twice a day.
Are any customers using it today?
I can’t give you names, but I can tell you one is a very large European bank and the other is a very large federal U.S. agency, and others are also ready to kick in. With these customers we’re figuring out how to take technology that’s been molded to doing things the way we do at HP, and bring it into customer networks so we understand how to make it more generally available.




