Orchestrating a secure network

Opinion
Oct 25, 20043 mins

* Bayshore Networks' hopes its security system is music to your ears

Running a software company – or any enterprise, for that matter – is sometimes compared to conducting an orchestra. The leader needs to see that every “section” does what they’re supposed to, when they are supposed to. No one section should dominate, but all should work together in harmony to deliver a customer-pleasing experience whether it’s a piece of software or a symphony.

One software exec has the requisite experience to do just that. Yes, Francis Cianfrocca’s past experience leading an orchestra helped prepare him for his current role as CEO of Bayshore Networks whose lead product, SingleKey, acts as an identity proxy engine.

Cianfrocca studied Music History as an undergraduate at the Eastman School of Music. Later, at the University of Michigan, he pursued a Master’s Degree in Orchestral Conducting. While at Michigan, he conducted the orchestra for the Gilbert & Sullivan Society’s production of the Pirates of Penzance, a performance that was recently released on CD (https://www.cris.com/~oakapple/gasdisc/pirumgass86.htm).

Cianfrocca’s attention wandered, though, to the relatively new area of Intel-based PCs. His first company was called Heldenleben, the name of an orchestral piece (the style is called a “tone poem”) by Richard Strauss, which tells the story of a hero (Strauss himself) and his enemies (music critics).

It has been called “…a record of reactions and responses on the theme of heroism.” Make of that what you will in terms of an independent software vendor. He sold Heldenleben’s product, a compiler for a 4GL programming language called Heldenport, to Gupta, freeing Cianfrocca to set up Tempest Software.

Tempest was quite a bit ahead of its time. Ten years ago XML was hardly on anyone’s radar except for publishers. Tempest developed a system for securely exchanging messages and data between applications over the Internet, a task that is now overwhelmingly handled by XML in its various dialects. So Cianfrocca moved on, to co-found Bayshore Networks.

Bayshore and its products reflect a simple, but important, philosophy, which I, among others, have espoused since the earliest days of networking: if the server isn’t secure, then the network isn’t secure. No matter how many firewalls, border guards and sandboxes you have, if the server isn’t physically secure, then you have a glaring hole that any half-baked hacker can climb through.

But in today’s world of easy Internet connections, wireless ubiquity and sophisticated cracking tools, physical security may no longer be enough. The enterprise that wants to be truly secure must also provide logical security for its servers. Bayshore Network’s SingleKey does just that.

SingleKey acts as an identity proxy engine sitting between the server and any person or thing attempting to access it. There’s only one connection to the server, and it runs through the SingleKey appliance. SingleKey works in harmony with your existing identity tools, using any LDAP-enabled directory service. It will also interface with your policy server (i.e., your source for rules-based access) or Bayshore’s own SingleTone engine. Finally, you can add SingleView (formerly called “Eagle”) for access monitoring, auditing and compliance.

Check out Bayshore Networks and SingleKey – you might make beautiful music together!