Welcome!

Mobile IoT Authors: Elizabeth White, Scott Allen, Liz McMillan, Jamie Maidson, Jeev Trika

Related Topics: @CloudExpo, Java IoT, Mobile IoT, Microservices Expo, Containers Expo Blog, Agile Computing

@CloudExpo: Article

BYOD Security Is a Network Architecture Problem

Do we still need endpoint security in the shadow of more powerful network layer security controls?

The data center (as we knew it) is never going to be the same. Fluid changes are already in motion, brought about largely as a result of ‘paradigm' shifts in computing including....:

  1. Multi-core processing and parallelism
  2. Cloud computing and server virtualization
  3. Bring Your Own Device
  4. Complex Event Processing
  5. Software Defined Networks
  6. Big Data
  7. Analytics and In-Memory Computing

... actually, several other major factors too, but that's a good data-centric 7-pack to start with is it not?

This swollen spring tide of information management elements brings with it empowerment for those that can bring meaningful analytics to bear upon the new data stack and, conversely, security concerns for those who fail to grasp the new triffid-sized nettle that has the growth potential to run rampant.

Colorful analogies aside... what are we talking about here in real terms? Enterprises today are increasingly forced to deal with massive amounts of so-called Big Data as they have to contend with the risk of employees connecting to the network with Bring Your Own Device (BYOD) tablets, smartphones and more.

This has created an inflexion point for large organizations in terms of data center transformation. We have reached a chasm where network security infrastructures will fail to scale and cope with the complexity of compute throughput caused by our seven factors as mentioned above. Put simply, the new under-managed over-clocked network is a security risk.

How Do We Put Our Next Step Forward Without Falling?
"The reality is, if a hacker wants to get into your network, then they will, 100 percent of the time. Match that risk with the new reality of BYOD security concerns and it's a heady concoction," argues Peter Doggart, management executive for security platform company Crossbeam. "Once we accept these basic truisms we can move on. From this point we can start to plan for compromised user containment, mitigation and segregation/quarantine."

It's not all about mitigation argues Doggart. Too much discussion circulates in the security industry focused on mitigation and cure, with comparatively scant lip service being paid to pre-infection prevention instead.

"You can't put anti-virus controls on an iPad; so putting controls at the network layer is the only way to deal with the security risks we stand in front of today. But going deeper, companies need to think about the structural build of their data centers and networks to ensure that they architect them correctly. New security vectors demand a new approach to application and network architecture. As a basic example, servers that process credit card data should be physically and locally segregated from other basic services."

Crossbeam's Doggart is adamant that this problem of implementing network security within more dynamic, virtualized data centers means that network security infrastructure needs to evolve in order to help organizations achieve their vision for the next-generation data center (NGDC). Then (and only then) can we successfully reap the benefits of cloud computing technology for both public and private environments he says.

Where Do We Turn Next?
Contemporary technologies in this space lean towards intelligent "boxed" solutions, i.e., appliances such as Intrusion Prevention Systems (IPS) and Threat Management Systems (TMS). Crossbeam's X-Series ‘network-in-a-box' challenges purpose-built security device products from HP, Oracle, IBM and others, suggesting that there is a defined need to "corral" switches, routers, load balancers, network layer protection mechanisms and application delivery controllers into a unified single solution. Indeed, HP appears to also embrace the ‘unification' label directly, naming its HP 200 Unified Threat Management (UTM) Appliance Series as it does.

Do we still need endpoint security in the shadow of more powerful network layer security controls? Take HP's aforementioned product, which does indeed come with anti-malware controls plus denial-of-service (DoS) attack protection, plus optional services such as anti-virus, anti-spam and URL filtering capabilities. The consensus argues that yes, we mostly still do need user endpoint security at whatever level we can bring it to bear; but it must work in harmony and unison with the wider strategy for this new and more intelligently designed network and data center structure currently under construction.

This is happening. Not everywhere and not at every level. But a network architecture security handbook should be on every CIOs Christmas list this year. Until we get there, wear a hard hat.

•   •   •

This post was first published on the Enterprise CIO Forum.

More Stories By Adrian Bridgwater

Adrian Bridgwater is a freelance journalist and corporate content creation specialist focusing on cross platform software application development as well as all related aspects software engineering, project management and technology as a whole.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device. For more information, please visit https://www.mangoapps.com/.
SYS-CON Events announced today that EastBanc Technologies will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. EastBanc Technologies has been working at the frontier of technology since 1999. Today, the firm provides full-lifecycle software development delivering flexible technology solutions that seamlessly integrate with existing systems – whether on premise or cloud. EastBanc Technologies partners with p...
In his session at 18th Cloud Expo, Bruce Swann, Senior Product Marketing Manager at Adobe, will discuss how the Adobe Marketing Cloud can help marketers embrace opportunities for personalized, relevant and real-time customer engagement across offline (direct mail, point of sale, call center) and digital (email, website, SMS, mobile apps, social networks, connected objects). Bruce Swann has more than 15 years of experience working with digital marketing disciplines like web analytics, social med...
SYS-CON Events announced today that ContentMX, the marketing technology and services company with a singular mission to increase engagement and drive more conversations for enterprise, channel and SMB technology marketers, has been named “Sponsor & Exhibitor Lounge Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York. “CloudExpo is a great opportunity to start a conversation with new prospects, but what happens after the...
WebRTC is bringing significant change to the communications landscape that will bridge the worlds of web and telephony, making the Internet the new standard for communications. Cloud9 took the road less traveled and used WebRTC to create a downloadable enterprise-grade communications platform that is changing the communication dynamic in the financial sector. In his session at @ThingsExpo, Leo Papadopoulos, CTO of Cloud9, will discuss the importance of WebRTC and how it enables companies to fo...
SYS-CON Events announced today Object Management Group® has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discuss how businesses can gain an edge over competitors by empowering consumers to take control through IoT. We'll cite examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He'll also highlight how IoT can revitalize and restore outdated business models, making them profitable...
The IoTs will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm and share the must-have mindsets for removing complexity from the development proc...
Customer experience has become a competitive differentiator for companies, and it’s imperative that brands seamlessly connect the customer journey across all platforms. With the continued explosion of IoT, join us for a look at how to build a winning digital foundation in the connected era – today and in the future. In his session at @ThingsExpo, Chris Nguyen, Group Product Marketing Manager at Adobe, will discuss how to successfully leverage mobile, rapidly deploy content, capture real-time d...
What a difference a year makes. Organizations aren’t just talking about IoT possibilities, it is now baked into their core business strategy. With IoT, billions of devices generating data from different companies on different networks around the globe need to interact. From efficiency to better customer insights to completely new business models, IoT will turn traditional business models upside down. In the new customer-centric age, the key to success is delivering critical services and apps wit...
Join us at Cloud Expo | @ThingsExpo 2016 – June 7-9 at the Javits Center in New York City and November 1-3 at the Santa Clara Convention Center in Santa Clara, CA – and deliver your unique message in a way that is striking and unforgettable by taking advantage of SYS-CON's unmatched high-impact, result-driven event / media packages.
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, will provide an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life ...
SYS-CON Events announced today that BMC Software has been named "Siver Sponsor" of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2015 at the Javits Center in New York, New York. BMC is a global leader in innovative software solutions that help businesses transform into digital enterprises for the ultimate competitive advantage. BMC Digital Enterprise Management is a set of innovative IT solutions designed to make digital business fast, seamless, and optimized from mainframe to mo...
SYS-CON Events announced today that MobiDev will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex software systems for startups and enterprises. Since 2009 it has grown from a small group of passionate engineers and business managers to a full-scale mobile software company with over 200 develope...
SoftLayer operates a global cloud infrastructure platform built for Internet scale. With a global footprint of data centers and network points of presence, SoftLayer provides infrastructure as a service to leading-edge customers ranging from Web startups to global enterprises. SoftLayer's modular architecture, full-featured API, and sophisticated automation provide unparalleled performance and control. Its flexible unified platform seamlessly spans physical and virtual devices linked via a world...
SYS-CON Events announced today that Alert Logic, Inc., the leading provider of Security-as-a-Service solutions for the cloud, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Alert Logic, Inc., provides Security-as-a-Service for on-premises, cloud, and hybrid infrastructures, delivering deep security insight and continuous protection for customers at a lower cost than traditional security solutions. Ful...
Companies can harness IoT and predictive analytics to sustain business continuity; predict and manage site performance during emergencies; minimize expensive reactive maintenance; and forecast equipment and maintenance budgets and expenditures. Providing cost-effective, uninterrupted service is challenging, particularly for organizations with geographically dispersed operations.
As cloud and storage projections continue to rise, the number of organizations moving to the cloud is escalating and it is clear cloud storage is here to stay. However, is it secure? Data is the lifeblood for government entities, countries, cloud service providers and enterprises alike and losing or exposing that data can have disastrous results. There are new concepts for data storage on the horizon that will deliver secure solutions for storing and moving sensitive data around the world. ...
SYS-CON Events announced today TechTarget has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. TechTarget is the Web’s leading destination for serious technology buyers researching and making enterprise technology decisions. Its extensive global networ...
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management...