Senin, 03 Oktober 2016

The Internet of Things is yet to arrive at the starting blocks of innovation fifianahutapea.blogspot.com

“We are but puny dwarfs perched on the shoulders of giants. We see more and farther… not because we have keener vision or greater height, but because we are lifted up and borne aloft on their gigantic structure.” Bernard of Chartres, died c.1124 (via John of Salisbury, 1159)

It may seem strange to trace the origins of the digital age back 900 years, but humanist and philosopher Bernard of Chartres nails it. Not only did he foresee the main tenet of the Platform Economy but he offered a useful framing of the potential of the Internet of Things, based on the relationship between eternal ideas and material objects.

Stretching a point? D’ya think? It’s worth reviewing how far we have got with the with the IoT so far. While we’ve seen a considerable amount of effort to standardise in the platform level, we are still a long way from providing the ‘giants’ upon which the broader section of us lowly creatures can innovate.

That’s not to understate the considerable effort that has already been made. In the Platform as a Service layer, Amazon AWS IoT, IBM Watson and Microsoft’s Azure IoT Suite, Zebra and a host of smaller players such as Thingworx and Evrythng offer massively scalable and open integration, streaming, storage and analytics capabilities.

In industry, the likes of Fujitsu (with GlobeRanger)  and Bosch have things going on; meanwhile Intel has an IoT Platform reference architecture to which a number of vendors have subscribed, including GE with its Predix industrial IoT framework and services. How easy and unfair it is, one might say, to suggest that such efforts are not already substantial.

But while such platforms and standardisation efforts are taking us way beyond where we have been, they are yet to arrive at a point where the real innovation explosion will take place. Solutions are currently domain-specific, frequently proprietary and a long way from the adoption levels seen by, say, social media.

Perhaps the closest is Xively or even IFTTT, but none have the immediacy of their social networking. In wearables for example, Garmin, Strava et al continue to fight their corners. Apple just added a ‘home’ icon to its mobile device screens, but it may have left many scratching their heads as to what it was for (as did my wife). The challenges currently faced by Nest reflect the ‘solution without a problem’ stage we are in.

This isn’t a complaint. If I had a concern at all, it’s whether we are prepared for the wave of joined-up connectedness that will inevitably hit. Today’s ‘advances’ will be seen as a world-spanning gestation, a global laying of smart infrastructure upon which the next two decades of innovation will be built.

No user-facing ‘smart’ portal has been adopted to any extent — while some (such as Fluke) have mentioned a ‘Facebook of Things’, we are yet to see a billion-user go-to page to access and control our smart devices, either in work or at home. But we will, as sure as birth follows pregnancy.

Of course, this suggests that such an opportunity is sitting on the table. Why the Googles, Facebooks, Microsoft and indeed, Alibabas aren’t ripping their gloves off and fighting tooth and nail to gain this position is quite astonishing. Once they do (and are joined by whichever next-upstart-to-become-a-household-name in the process), we will enter a new phase of innovation, thrilling and downright scary in equal measure. Lives will be saved, even as the rights of individuals significantly undermined.

For we are but puny, in the face of such developments. But we will see more, and farther than the giants themselves. The relationship between eternal ideas and material objects is about to get a significant run for its money.

Easy Way to Download

Selasa, 27 September 2016

Review: DB Networks Enhances Database Security with Machine Learning fifianahutapea.blogspot.com

Protecting databases takes more than just securing the perimeter, it also takes a deep understanding of how users and applications interact with databases, as well as knowing what databases are alive and breathing on the network. DB Networks aims to provide the intelligence, analytics and tools to bring insight into the database equation.

It’s no secret that database intrusions are on the rise, much to the chagrin of those responsible for infosec.  While many have focused on the notions of protecting the edge of the network and wrapping additional security around user access, the simple fact of the matter is that databases are the primary storehouses of private and sensitive information, and are often the true targets of intruders.

Recent events, such as the Target breach, the theft of security clearance information from the US OPM (Office of Personnel Management) and the theft of medical records from Anthem Healthcare, illustrates that protecting sensitive data is quickly becoming a losing battle. DB Networks is taking steps to turn the tide and bring victory to those charged with protecting databases.

The San Diego based company offers their DBN-6300 appliance and its virtual cousin, the DBN-6300v as founts of database activity, analytics, and discovery to give today’s security professionals an edge in the ever growing cyberattacks that are targeting databases. Those products promise to equip security professionals and database administrators with the tools that can identify and mitigate breaches before irreparable damage is done.

Case in point is the ubiquitous sql injection attack, which is far more common than most will admit to. SQL injection attacks have been around for more than ten years, and security professionals are more than capable of protecting against them. However, according to Neira Jones, the former head of payment security for Barclaycard, some 97 percent of data breaches worldwide are still due to an SQL injection somewhere along the line.

Taking a Closer Look at DBNetworks IDS-6300:

I recently had a chance to put DBNetworks IDS-6300 through its paces at the company’s San Diego Offices. The IDS-6300 is a physical appliance, built on Intel Hardware as a 2U rack mountable server. The device features four 10/100/1000 Ethernet Ports for data capture, one 10/100/1000 Ethernet admin port and one 10/100/1000 Ethernet customer service port, as well as a 480Gb SSD and 2Tb archival storage.

The device can be deployed by plugging it into either a span port or a tap port located at the core switch in front of the database servers. The idea is to place the device, logically ahead of the database servers, yet behind the application servers, so it can focus on SQL traffic. The IDS-6300 is managed via a browser based interface and supports the Chrome, Firefox and Safari browsers and will fully support IE in the near future.

I tested the device in a mock operational environment that included MS-SQL Databases with a demo version of a banking application that incorporated some known vulnerabilities. Setting up the device entailed little more than defining the capture ports and some very basic post installation items. Once configured to capture data, the next step was to identify databases.

Here, the IDS-6300 does an admirable job; it is able to automatically discover any databases that experience any traffic, even simple communications, such as a basic SQL statement. The device monitors for traffic 24/7 and continually checks for database activity.

That proves to be a critical element in the quest for securing databases – according to company representatives, many customers have discovered databases that IT was unaware operating in production environments. What’s more, the database discovery capability can be used to identify rogue databases or databases that were never shutdown after a project completed.

The database discovery information offers administrators real insight into what exactly is operating on the network, and what is vulnerable to attack – knowing that information can be the first step in mitigating security problems, before even venturing into traffic analysis and detection.

Never the less, the product’s real power comes into play when detecting SQL injection attacks. Instead of using caned templates or signatures, the IDS-6300 takes SQL attack detection to the next level – the device is able to learn what normal traffic is and record/analyze what that traffic accomplishes, and then builds a behavioral model.

Simply put, the device learns how an application communicates with a database, that information is used to create a behavioral model. Once learning is completed, the device uses multiple detection techniques to validate future SQL statements against expected behavior.  In practice, behavioral analysis proves immune to zero day attacks, newly scripted attacks and even old, recycled attacks, because all of those attacks fall out of the norms of expected behavior.

That behavioral analysis eliminates the need for signatures, black lists, white lists and other technologies that rely on pattern matching or static detection, which in turn reduces operational overhead and maintenance chores, almost converting SQL Injection attack monitoring into a plug and play paradigm.

When SQL Injection attacks occur, the IDS-6300 captures all of the traffic and transaction information around that attack. What’s more, the device categorizes, analyzes and presents the critical information about the attack so that administrators (or application engineers) can modify database code or incorporate firewall rules very quickly to remediate the problem.

Which brings up another interesting point, the IDS-6300 proves to be a good candidate for helping organizations improve application code. With many businesses turning to outsourcing and/or modifying off the shelf/open source software for application development, situations may arise where due diligence is not fully implemented and agile development projects may lead to introducing security flaws into application code.  That is not an uncommon problem,  at least according to Forrester Research’s Manatosh Das –  Poor application coding persists despite lessons learned.  Das claims that more than two-thirds of applications have cross-site scripting vulnerabilities, nearly half fail to validate input strings thoroughly, and nearly one-third can fall foul of SQL injection. Das adds security professionals and software engineers have known about these types of flaws for years, but they continue to show up repeatedly in new software code.

The IDS-6300 will quickly detect those newly introduced flaws and prevent poor programing practices from creating vulnerabilities, and then provide the information that is needed to fix those flaws.

The IDS-6300 offers another advantage to customers; it can help customers to consolidate databases by identifying what databases are active and what they are used for. That in turn can lead to companies combining databases and significantly reducing licensing and support costs. DBNetworks reports that one of their customers were able to reduce database licensing costs by over $1,000,000 by detecting and consolidating databases that were discovered by the IDS-6300

The IDS-6300 starts at $25,000 and is available directly from DBNetworks and authorized partners. For more information, please visit DBNetworks.com

 

 

Easy Way to Download

Kamis, 22 September 2016

Performance Management Brings New Found Value to IT fifianahutapea.blogspot.com

IT departments are always struggling to garner the praise they deserve. Yet, most organizations look upon IT as a necessary evil, one that is both expensive and somewhat obstructionist. However, nothing could be further from the truth, and IT departments the world over have pursued ideologies that highlight the value of the services they offer, while also demonstrating the importance that a properly executed IT management plan brings to the bottom line.

At last weeks Riverbed Disrupt event, GigaOM had a chance to talk with CIOs, as well as network managers that have demonstrated the value of IT with application performance management platforms and services.

John Green, Chief Information Officer at Baker Donelson, the 64th largest law firm in the country, offered some real world examples of how Application Performance Management (APM) and end user monitoring bring demonstrable value to an organizations IT department.

Green said “my staff supports some 275 different applications and more than 40 video conferencing rooms, which are in near constant operation.” Simply put, Green has come to know the importance of how reliable service and end acceptable user experience impacts the view that the firm’s 1,500 employees have of the IT department.

Green said “I was deploying the best technology money could buy, but my end-users still weren’t happy.” Green was looking at a situation where unhappy end users could create dire circumstances, which could impact the firms bottom line. Green added “I could go to management meetings and offer proof that the networks were up 99.9% of the time, and the that the databases and the email servers were delivering five-nine statistics of operation. Yet, my end users were still complaining.”

That is when Green had an epiphany, one that amounted to realizing network performance statistics and end user expectations rarely do not go hand in hand. Green said “We needed the ability to track the actual end-user experience, and then use that information to meet user expectations.”

Green found those much desired capabilities with SteelCentral Aternity, a product that offers the ability to monitor any application on any device to provide the actual user perspective, at least when it comes to responsiveness and performance. Green said “I have been an Aternity user for about seven years, and it completely transformed the way we relate to our end users.”

Nonetheless, Green said “Aternity is only one part the puzzle, although it provides valuable information, I would like to see the whole performance and experience picture on one pane of glass.”

That was a need that brought Green to the Riverbed Disrupt event. Riverbed recently purchased Aternity and is integrating the technology into their SteelCentral product line, looking to give its customers that single pane of glass view. Green was impressed with the direction Riverbed is taking with end-to-end monitoring and offered ““With the Riverbed and Aternity combination, there is now a mix of tools, that when combined into a single pane of glass, gives you total visibility across your network, from the servers to the circuits.”

While the Riverbed event was about new technologies, the real message was that by providing full monitoring capabilities to IT, staffers can better serve end-users and demonstrate the value of effective IT.

 

 

 

Easy Way to Download

Selasa, 20 September 2016

Riverbed Demonstrates the Importance of Full Stack Monitoring fifianahutapea.blogspot.com

Complete end to end monitoring has become increasingly important as enterprises strive to move from legacy data centers to the promise of software defined environments. After all, network managers encumbered by missing pieces of the network connectivity puzzle are likely to fail the transition to software defined solutions. An observation made abundantly clear at Riverbed’s Disrupt Event held in Manhattan last week. Overcoming the obstacles of connectivity has become Riverbed’s clarion call, and the company is now offering comprehensive solutions that not only ease the transition to software defined solutions, but also bring much more control and information to the network management realm.

Case in point is the company’s move to products that embrace the ideologies of a Software Defined Wide Area Network (SD-WAN), such as the company’s SteelConnect 2.0, an application-defined SD-WAN solution. In an interview with GigaOM, Joshua Dobies, vice president of product marketing at Riverbed, said “the new capabilities offered allow branch offices to directly access the cloud, all without having to backhaul everything back to the data center.” Dobies added “SD-WAN paves the way for complete digital transformation, allowing enterprises to quickly access the benefits of the cloud, while not discarding their existing investments in Data Center Technologies.”

Of course, the wholesale movement to the cloud means that technologies must transition to platforms that enable transformation, without incurring disruption. A situation that proves to be the sweet spot for end to end monitoring. With the addition of full network visibility, along with end user experience monitoring, network managers now have the ability to identify connectivity and performance problems on the fly, and can quickly address those problems with policies and tuning.

With the introduction of Riverbed’s next version of its SD-WAN offering, SteelConnect 2.0, the company is giving its customers greater visibility throughout the network, thanks to integration with Riverbed’s SteelCentral, it’s end-to-end performance management platform, and SteelHead products and Riverbed’s Interceptor offering, which gives SteelConnect greater scale for dealing with larger enterprise deployments. Riverbed Chairman and CEO Jerry Kennelly said “Today, we’re delivering a software-defined architecture for a software-defined world, and expanding that infrastructure deeper into the cloud and more broadly across all end users.”

In addition to the new SteelConnect 2.0 release, SteelCentral, it’s end-to-end performance management platform will now incorporate technology from Aternity, which Riverbed acquired in July. Aternity brings the ability to monitor application performance on physical and mobile end-user devices to the SteelCentral product line. The addition of the Aternity technology and extending visibility into the end-user devices give Riverbed a full portfolio of management offerings, according to Nik Koutsoukos, vice president of product marketing at Riverbed. “This brings full end-to-end management capabilities to those who need it most” Koutsoukos told GigaOM.

 

Easy Way to Download

Senin, 19 September 2016

Survey Reveals InfoSec is Doing it all Wrong! fifianahutapea.blogspot.com

While, “doing it all wrong” may be an exaggeration, no one can deny the fact that breaches are on the rise, and IT security solutions seem to be falling behind the attack curve. Yet, those looking to place blame may need only look in the mirror. At least that what a survey from cyber security vendor BeyondTrust is indicating.

BeyondTrust surveyed Over 500 senior IT, IS, legal and compliance experts about their privileged access management practices. The survey revealed some interesting trends, some of which should fall under the banner of “they should know better”. For example, only 14 percent regularly cycle their passwords, meaning that 86 percent of those surveyed are avoiding one of the top best practices for password and credential management. Adding insult to injury, only 3 percent of those surveyed monitor systems in real-time and have the capability to terminate a live session that may be indicative of a breach.

Simply put, the survey indicates that the majority of organizations need to do much more to protect systems from breaches. Many of which, could be easily avoided if the proper policies are put into effect. That said, the survey also revealed that 52 percent of respondents are not doing enough about known risks. In other words, they understand what the risks are, but have not deployed the technologies or crafted the policies to mitigate those risks.

Mitigating those risks should be one of the top jobs of InfoSec today, especially since most of the identified risks can be quickly resolved, using off the shelf products and by just applying best practices. BeyondTrust has developed some recommendations that InfoSec professionals can take to heart to lower risk and harden systems from breaches.

Those recommendations include:

  • Be granular: Implement granular least privilege policies to balance security with productivity. Elevate applications, not users.
  • Know the risk: Use vulnerability assessments to achieve a holistic view of privileged security. Never elevate an application’s privileges without knowing if there are known vulnerabilities.
  • Augment technology with process: Reinforce enterprise password hygiene with policy and an overall solution. As the first line of defense, establish a policy that requires regular password rotation and centralizes the credential management process.
  • Take immediate action: Improve real-time monitoring of privileged sessions. Real-time monitoring and termination capabilities are vital to mitigating a data breach as it happens, rather than simply investigating after the incident.
  • Close the gap: Integrate solutions across deployments to reduce cost and complexity, and improve results. Avoid point products that don’t scale. Look for broad solutions that span multiple environments and integrate with other security systems, leaving fewer gaps.

 

In an interview with GigaOM, Kevin Hickey, President and CEO at BeyondTrust, offered “Companies that employ best practices and use practical solutions to restrict access and monitor conditions are far better equipped to handle today’s threat landscape.”

Hickey added “The survey proved critical for helping BeyondTrust to better identify threats based upon privilege management, and also helped us evolve our product offerings to make privilege management a much easier process for security professionals.”

Hickey’s statements were validated by the launch of some new product offerings, which are aimed at bringing privilege management ease to those charged with IT security. The two new offerings are the BeyondTrust Managed Service Provider (MSP) Program and an Amazon Machine Image (AMI) of BeyondInsight available on the Amazon Marketplace. Those products are geared to prevent breaches that involve privileged credentials with deployments that include on premise solutions, virtual device solutions, as well as in the Cloud or from a Managed Services Provider.

Easy Way to Download

Jumat, 16 September 2016

Hyper Convergence Poses Unique Challenges for SAN Technologies fifianahutapea.blogspot.com

With the move towards hyper-convergence in full swing, many organizations are faced with the challenge of moving their massive data stores into virtualized environments.  A situation that came to the forefront of discussion at VMworld 2016, where all things related to hyper-convergence were discussed ad nauseam.

Even so, many were still left wondering if it was even possible to have traditional storage technologies, such as SAN and NAS, effectively coexist in an environment that was transitioning into a hyper-converged entity. What’s more, the uncertainties of transition, driven by potential communications problems, performance issues and incompatibilities could force wholesale, expensive upgrades to support the move to hyper-convergence. An issue many network managers and CIOs would love to avoid.

Simply put, the move towards hyper-convergence, which promises improved efficiencies and reduced operating expenses, can be derailed by the high costs of transitioning to virtualized SANs. An irony worth noting. Never the less, those challenges have not stopped VMware Virtual SAN from becoming the fastest growing hyper-converged solution with over 3,000 customers to date. That said, there is still room for improvement, such as helping VMware Virtual SAN support even more workloads, and that is exactly where vendor Primary Data comes into play.

At VMworld 2016, Primary Data announced the availability of the company’s DataSphere platform, which brings a storage agnostic platform to virtualized environments. In other words, Primary Data is able to tear down storage silos, without actually disrupting the configuration of those silos. It accomplishes that by creating a virtualization platform that is able to mask the individual storage silos and present them as a unified, tiered storage lake, which is driven by policies and offers almost infinite configuration options.

Abstracting data from storage hardware is not a new idea. However, Primary Data goes far beyond what companies such as FalconStore and StoneFly bring to the world of hyper-convergence.  For example, DataSphere offers a single plane of glass management console, which unifies the management of across the various storage tiers, regardless of the storage type. What’s more, the platform goes beyond the concept of a SLA (Service Level Agreement) and introduces a new concept, aptly abbreviate as SLO (Service Level Objective). Primary Data’s Kaycee Lai, an executive with the company, explained to GigaOM that “SLOs are business objectives for applications. They define a commitment to maintain a particular state of the service in a given period. For example, specific write IOPS, read IOPS, latency, and so forth, to maintain for each application. SLOs are measurable characteristics of the SLA.”

Lai added “DataSphere will support DAS, NAS, and Object as storage types. Block level support for SAN will follow in the next release.” One of the key elements offered by the platform is the ability to work with storage tiers, without the disruption of having to rebuild storage silos. Lai added “Tiers are a logical concept in DataSphere. Tiers are simply a class of storage that is mapped to a particular SLO. The notion of having multiple tiers is not as important as having multiple objectives requiring the specific storage to meet those objectives. Customers can create as many objectives as their business requires.”

In the quest to make hyper-convergence common place, Primary Data smooths the bumpy storage path with several abilities, which the company identifies as:

  • Adapt to continually changing business objectives with intelligent data mobility.
  • Scale performance and capacity linearly and limitlessly with unique out-of-band architecture.
  • Reduce costs through increased resource utilization and simplified operations.
  • Simplify management through global and automated policies.
  • Accelerate upgrades of new solutions such as VMware vSphere 6 with seamless migration using existing infrastructure.
  • Reduce application downtime with automated non-disruptive movement of data.
  • Deliver a full range of data services across all applications in the data center.

 

 

Easy Way to Download