|By Lisa Lorenzin||
|October 18, 2012 02:00 PM EDT||
A wealth of security information exists in our networks from a variety of sources - policy servers, firewalls, switches, networking infrastructure, defensive components, and more. Unfortunately, most of that information is locked away in separate silos due to differences in products and technologies, as well as by companies' organizational boundaries. Further complicating the issue, information is stored in different formats and communicated over different protocols.
An open standard from the Trusted Computing Group (TCG) offers the capability to centralize communication and coordination of information to enable security automation. The Interface for Metadata Access Points - IF-MAP for short - is like Facebook for network and security technology, allowing real-time sharing of information across a heterogeneous environment.
IF-MAP, part of TCG's Trusted Network Connect (TNC) architecture, makes it possible for any authorized device or system to publish information to a Metadata Access Point (MAP), a clearinghouse for information about who's on the network, what endpoint they're using, how they're behaving, and many other details of the network. Systems can also search the MAP for relevant information and subscribe to any updates to that information. Just as IP transformed communications, IF-MAP revolutionizes the way systems share data.
Security automation is any part of a security system that is able to operate without - or with only limited - administrative involvement. As shown in Figure 1, a security administrator can define a unified security policy that applies to different types of protective mechanisms, such as next-generation firewalls (NGFW), intrusion prevention systems (IPS), unified threat management (UTM) systems, and more. Best-of-breed components from multiple vendors can share information using a standard information bus.
Figure 1: Effective security automation includes several protection mechanisms.
This coordination can extend beyond front-line access control products to back-end systems such as authorization databases, virtualization technology, and reputation systems. A policy server might create and modify policy based completely on the information received from other resources in the environment.
Logs from multiple sources can be collected and correlated by a security information and event management (SIEM) system, which itself acts as both a consumer of information and a provider of real-time intelligence based on that information. Security operations personnel can easily oversee activities in the network and provide human intervention in cases where full automation may not be achievable or desirable. Security automation enhances fundamental security solutions, adding dynamic, responsive, intelligent decision-making.
Establishing Network Trust
One of the basic solutions enabled by the TNC architecture is Comply to Connect, which incorporates Network Access Control (NAC) principles - an endpoint must first show its compliance with selected endpoint health requirements before being granted access to the network. Figure 2 shows a common Comply to Connect scenario.
Figure 2: The TNC architecture enables evaluation and enforcement of compliance at admission.
The endpoint, on the left, is a device attempting to access a protected network. The enforcement point is a guard that grants or denies access based on instructions from the policy server. The policy server is really the brains of the operation; it looks at the configured policy and decides what level of access should be granted. Then it informs the enforcement point, which executes those instructions.
Many enforcement options exist; the example in Figure 2 shows a wireless access point and a switch, but environments may also use a firewall or a virtual private network (VPN) gateway. Each of these has its own pros and cons; for example, a wireless access point with 802.1X can totally block unauthorized users. But while it provides admission control, it doesn't offer enforcement deeper in the network. For that reason, most NAC solutions support a combination of different enforcement points, which can be used individually or in combination.
The security policy controlling the compliance check shown in Figure 2 is quite simple: every Windows 7 endpoint on the network must have a self-encrypting drive (SED), up-to-date anti-virus protection, and a personal firewall. When a new Windows 7 endpoint comes on the network, the enforcement point will query it and then consult the policy server. If the endpoint complies with security policy, it is given access to the production network. Another endpoint that does not have an SED may be given only limited access to the network. That way, if either endpoint is lost or stolen, protected information is only on the endpoint that could store it securely on an SED.
Expanding Network Trust Evaluation
Behavior monitoring is another way to evaluate an endpoint. Many security-related sensor devices are already deployed in networks to monitor behavior: intrusion detection systems, leakage detection systems, endpoint profiling systems, and more. The TNC architecture lets users integrate those existing systems with each other and with the NAC solution by sharing information via a MAP.
Figure 3 shows an approach to check behavior. Security sensors in the network monitor behavior, and a security policy identifies acceptable behavior.
Figure 3: Behavior checking enables automated response to changes in the endpoint's activity.
Once an endpoint has connected to the network, even if it has passed authentication and compliance checks, it could behave in an unauthorized fashion. If the endpoint starts violating security policy by trying to spread a worm, that traffic is detected and stopped by an IPS sensor.
Even more important, that sensor publishes information to the MAP about the attack it stopped. The MAP notifies the policy server, which evaluates its security policy and instructs the enforcement point to move the endpoint to a remediation network until it can be addressed.
The end result is an entire network security system that is working together. Each part performs its function, and each piece is integrated with the whole using the open IF-MAP standard.
Extending Security to Mobile Devices
TNC standards have enabled NAC to evolve into a foundation technology for business requirements such as mobile security and Bring Your Own Device (BYOD). A common scenario in today's connected world occurs when a mobile user accesses the Internet and social networks on a personal device, such as a smartphone, which they also use to access their corporate network. If the smartphone inadvertently becomes infected with malware, corporate data on that device is now at risk. And it's even worse when the user connects their smartphone to the corporate network; the attacker, who has taken control of the device, can access sensitive information.
This situation occurs when a company's security team lacks the tools to accommodate employees using their own consumer devices to improve productivity. Without the appropriate technology, the IT team cannot:
- detect malware on the mobile device
- protect the user from cloud-based threats
- control access based on user identity, device, and location
- coordinate security controls to protect sensitive information
This clearly needs a new approach!
Addressing the new requirements of BYOD and providing broad protection involves flexible deployment models that can be tailored to individual environments and security context, and coordination to keep users protected against the dynamic threat landscape.
Security automation makes it possible to detect and address compromised mobile devices; protect the user from malicious sites and applications; restrict network and resource access based on user identity, device, and location; and correlate endpoint activity monitoring across the corporate network infrastructure.
Leveraging Standard Network Security Metadata
These capabilities are enabled by TNC's standardization of basic metadata for network security. Metadata is the information stored in a MAP, representing anything that is known about the network: traffic flows, scan results, user authentications, or other events. In the case above, metadata represents information about network components and applicable security policies. The MAP is a clearinghouse for metadata; MAP clients can publish metadata to it, search it for specific metadata, and/or subscribe to metadata about endpoints in the network.
These inquiries include common things that it might be helpful to know about an endpoint - the type of device, identity of the user operating the device, role assigned to that user, association between the MAC address and IP address of the endpoint, location of the endpoint, and any events related to that endpoint.
Extending Security Automation to Other Use Cases
While standard metadata is useful for out-of-box interoperability, much more information about an endpoint or a network is available. IF-MAP can be extended by creation of vendor-specific metadata, similar to Vendor-Specific Attributes (VSAs) in RADIUS, enabling anyone to publish anything that can be expressed in XML!
Imagine a manufacturing line, where a physical process is controlled by a digital component called a Programmable Logic Controller (PLC). An operator display panel, the Human Machine Interface (HMI), is typically physically remote from the actual process that needs monitoring. As changes in the process occur, the operator display updates in real-time.
Many HMIs use a legacy protocol called Modbus to poll the PLC, retrieve these process variables, and display them. Originally designed to be run over a serial connection, Modbus has been ported to TCP. One of the problems with the Modbus protocol and many others in this space is that there are zero security features in the protocol - no authentication, no authorization - which means no way of knowing whether a requestor is authorized to gain access requested, or even who is sending data the request. If an endpoint (or intruder) can ping the PLC, it can issue commands to it!
Many control systems components operate this way. Until now, they have been small islands of automation with very little interconnection to other systems. Running over a serial bus required physical serial connections - typically, the operator had to be present in front of the machine to affect it, so physical security was sufficient. And once these systems are in place, they are designed to stay in production for decades. So now these systems are getting more and more interconnected with the enterprise network - and, by extension, to external networks - and they encounter the same types of security issues as enterprise systems.
Overlaying Security onto Industrial Control Systems
A single manufacturing line could have hundreds, or even thousands, of these PLCs. Replacing them is out of the question, as is retro-fitting them to add on security. But what if a transparent security overlay was inserted to protect these legacy components?
Deployment and lifecycle management for such an overlay would be a huge challenge - unless there was a mechanism for provisioning certificates, communication details, and access control policies to the overlay components. That's exactly what one manufacturing company has done with IF-MAP, by using vendor-specific metadata for provisioning of certificate information and access control policy, as shown in Figure 4.
Figure 4: IF-MAP enabled security overlay protects industrial control system components.
The first step is to add the overlay protection. In this case, the enforcement points are customized components, designed for Supervisory Control And Data Acquisition (SCADA) networks, that can create an OpenHIP "virtual private LAN" on top of standard IP networks. This requires no changes to the underlying network, protects communications between SCADA devices, and is completely transparent to the protected SCADA devices.
A MAP and a provisioning client enable centralized deployment, provisioning, and lifecycle management for the myriad enforcement points. The provisioning client publishes metadata to the MAP to define the HMIs and PLCs and to specify security policies that allow them to talk to each other, but do not allow external access to them.
For example, when an HMI comes into the network and queries for a PLC, the HMI does an Address Resolution Protocol (ARP) lookup. The enforcement point receives that traffic, searches the MAP, and finds the access control policy determining whether this specific HMI can talk to that particular PLC. Enforcement points can be moved around the network without requiring manual reconfiguration or reprovisioning, since all of the provisioning is centralized via the MAP.
This is not just a neat thought experiment - it is actually in production deployment on hundreds of endpoints in critical manufacturing lines today!
The Future of Security Automation
We've barely scratched the surface of security automation. For one thing, it goes far beyond access control. Imagine...
- A content management database (CMDB) receives notification of a new device on the network and scans the new endpoint, then updates its data store
- An analysis engine observes some behavior on the network and requires more information about the associated endpoint, so it requests an investigation by another component such as an endpoint profiler or vulnerability scanner
- Carrier routers redirect traffic through deep packet inspection based on suspicious user activity
- A security administrator modifies an existing security policy, or adds a new policy, and various policy servers / sensors are notified, triggering a re-evaluation of the network's endpoints
- An application server publishes a request for bandwidth for a particular user based on the service the user is accessing, and network infrastructure components change QoS settings for those traffic flows based on that request
- An IF-MAP enabled OpenFlow switch controller makes packet-handling decisions based on information from other network components
- An analysis system determines that there's an attack underway; in addition to triggering a response, it notifies security administrators of the attack taking place, populating a dashboard with information to create a "heat map" of the attack
All of these are examples of a common three-step process: sensing, analysis, and response. Security automation is enabled by the abstraction and coordination of these functions across multiple disparate components in the network.
Imagine the power gained by linking together information from all of the various infrastructure and security technologies in a network and using that information to make dynamic, intelligent, automated decisions. That's the true promise of security automation - and the realization of that promise is in its infancy.
You think you know what’s in your data. But do you? Most organizations are now aware of the business intelligence represented by their data. Data science stands to take this to a level you never thought of – literally. The techniques of data science, when used with the capabilities of Big Data technologies, can make connections you had not yet imagined, helping you discover new insights and ask new questions of your data. In his session at @ThingsExpo, Sarbjit Sarkaria, data science team lead ...
Jul. 25, 2016 03:45 PM EDT Reads: 936
Extracting business value from Internet of Things (IoT) data doesn’t happen overnight. There are several requirements that must be satisfied, including IoT device enablement, data analysis, real-time detection of complex events and automated orchestration of actions. Unfortunately, too many companies fall short in achieving their business goals by implementing incomplete solutions or not focusing on tangible use cases. In his general session at @ThingsExpo, Dave McCarthy, Director of Products...
Jul. 25, 2016 03:30 PM EDT Reads: 1,681
"delaPlex is a software development company. We do team-based outsourcing development," explained Mark Rivers, COO and Co-founder of delaPlex Software, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Jul. 25, 2016 03:00 PM EDT Reads: 1,968
WebRTC is bringing significant change to the communications landscape that will bridge the worlds of web and telephony, making the Internet the new standard for communications. Cloud9 took the road less traveled and used WebRTC to create a downloadable enterprise-grade communications platform that is changing the communication dynamic in the financial sector. In his session at @ThingsExpo, Leo Papadopoulos, CTO of Cloud9, discussed the importance of WebRTC and how it enables companies to focus...
Jul. 25, 2016 02:45 PM EDT Reads: 849
Is your aging software platform suffering from technical debt while the market changes and demands new solutions at a faster clip? It’s a bold move, but you might consider walking away from your core platform and starting fresh. ReadyTalk did exactly that. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, will discuss why and how ReadyTalk diverted from healthy revenue and over a decade of audio conferencing product development to start an innovati...
Jul. 25, 2016 02:00 PM EDT Reads: 942
Early adopters of IoT viewed it mainly as a different term for machine-to-machine connectivity or M2M. This is understandable since a prerequisite for any IoT solution is the ability to collect and aggregate device data, which is most often presented in a dashboard. The problem is that viewing data in a dashboard requires a human to interpret the results and take manual action, which doesn’t scale to the needs of IoT.
Jul. 25, 2016 01:00 PM EDT Reads: 1,927
SYS-CON Events announced today that 910Telecom will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Housed in the classic Denver Gas & Electric Building, 910 15th St., 910Telecom is a carrier-neutral telecom hotel located in the heart of Denver. Adjacent to CenturyLink, AT&T, and Denver Main, 910Telecom offers connectivity to all major carriers, Internet service providers, Internet backbones and ...
Jul. 25, 2016 12:15 PM EDT Reads: 439
CenturyLink has announced that application server solutions from GENBAND are now available as part of CenturyLink’s Networx contracts. The General Services Administration (GSA)’s Networx program includes the largest telecommunications contract vehicles ever awarded by the federal government. CenturyLink recently secured an extension through spring 2020 of its offerings available to federal government agencies via GSA’s Networx Universal and Enterprise contracts. GENBAND’s EXPERiUS™ Application...
Jul. 25, 2016 12:00 PM EDT Reads: 1,817
IoT generates lots of temporal data. But how do you unlock its value? You need to discover patterns that are repeatable in vast quantities of data, understand their meaning, and implement scalable monitoring across multiple data streams in order to monetize the discoveries and insights. Motif discovery and deep learning platforms are emerging to visualize sensor data, to search for patterns and to build application that can monitor real time streams efficiently. In his session at @ThingsExpo, ...
Jul. 25, 2016 11:00 AM EDT Reads: 904
Verizon Communications Inc. (NYSE, Nasdaq: VZ) and Yahoo! Inc. (Nasdaq: YHOO) have entered into a definitive agreement under which Verizon will acquire Yahoo's operating business for approximately $4.83 billion in cash, subject to customary closing adjustments. Yahoo informs, connects and entertains a global audience of more than 1 billion monthly active users** -- including 600 million monthly active mobile users*** through its search, communications and digital content products. Yahoo also co...
Jul. 25, 2016 10:30 AM EDT Reads: 329
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
Jul. 25, 2016 10:30 AM EDT Reads: 1,942
"Tintri was started in 2008 with the express purpose of building a storage appliance that is ideal for virtualized environments. We support a lot of different hypervisor platforms from VMware to OpenStack to Hyper-V," explained Dan Florea, Director of Product Management at Tintri, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Jul. 25, 2016 10:15 AM EDT Reads: 1,868
The best-practices for building IoT applications with Go Code that attendees can use to build their own IoT applications. In his session at @ThingsExpo, Indraneel Mitra, Senior Solutions Architect & Technology Evangelist at Cognizant, provided valuable information and resources for both novice and experienced developers on how to get started with IoT and Golang in a day. He also provided information on how to use Intel Arduino Kit, Go Robotics API and AWS IoT stack to build an application tha...
Jul. 25, 2016 10:00 AM EDT Reads: 996
SYS-CON Events announced today that LeaseWeb USA, a cloud Infrastructure-as-a-Service (IaaS) provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LeaseWeb is one of the world's largest hosting brands. The company helps customers define, develop and deploy IT infrastructure tailored to their exact business needs, by combining various kinds cloud solutions.
Jul. 25, 2016 09:45 AM EDT Reads: 1,133
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
Jul. 25, 2016 09:30 AM EDT Reads: 2,106
The cloud market growth today is largely in public clouds. While there is a lot of spend in IT departments in virtualization, these aren’t yet translating into a true “cloud” experience within the enterprise. What is stopping the growth of the “private cloud” market? In his general session at 18th Cloud Expo, Nara Rajagopalan, CEO of Accelerite, explored the challenges in deploying, managing, and getting adoption for a private cloud within an enterprise. What are the key differences between wh...
Jul. 25, 2016 09:15 AM EDT Reads: 2,012
SYS-CON Events announced today that Venafi, the Immune System for the Internet™ and the leading provider of Next Generation Trust Protection, will exhibit at @DevOpsSummit at 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Venafi is the Immune System for the Internet™ that protects the foundation of all cybersecurity – cryptographic keys and digital certificates – so they can’t be misused by bad guys in attacks...
Jul. 25, 2016 08:30 AM EDT Reads: 1,280
Large scale deployments present unique planning challenges, system commissioning hurdles between IT and OT and demand careful system hand-off orchestration. In his session at @ThingsExpo, Jeff Smith, Senior Director and a founding member of Incenergy, will discuss some of the key tactics to ensure delivery success based on his experience of the last two years deploying Industrial IoT systems across four continents.
Jul. 25, 2016 06:00 AM EDT Reads: 1,505
There will be new vendors providing applications, middleware, and connected devices to support the thriving IoT ecosystem. This essentially means that electronic device manufacturers will also be in the software business. Many will be new to building embedded software or robust software. This creates an increased importance on software quality, particularly within the Industrial Internet of Things where business-critical applications are becoming dependent on products controlled by software. Qua...
Jul. 25, 2016 05:45 AM EDT Reads: 1,382
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2016 Silicon Valley. The 19th Cloud Expo and 6th @ThingsExpo will take place on November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Interne...
Jul. 25, 2016 05:00 AM EDT Reads: 2,021