Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Interop Tackles Control Issues

    Written by

    Cameron Sturdevant
    Published May 18, 2007
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Interop in Las Vegas May 20-25 will attempt to answer yet again the question, whither network access control?

      Cisco, Microsoft and the Trusted Computing Group, backed by an entire NAC (network access control) Day track and a host of lesser players that provide so-called NAC right now products, will attempt to answer the question by asserting that the network is the best place to control access.

      The NAC Interop Lab is certainly a place to go to get some nitty-gritty questions answered. The lab has been up and running for at least the last two shows and has plenty of handouts and demonstrations for attendees to observe. Keep in mind, however, that the NAC Interop Lab is tilted toward securing guest access by using the network as an access choke point.

      Despite what NAC vendors at Interop will argue, the question of whether the network is best place for checking endpoint compliance with security policies remains unsettled for now. For one thing, using NAC devices and services to assess endpoint health—including the currency of antivirus signatures, operating system and application patches, and firewall status—and to ensure that unauthorized programs and malware are not running on endpoints threatens to be a policy writing nightmare.

      Whats more, NAC tools today often use a tightly constricted definition of endpoint that usually means supporting various flavors of the Windows operating system. As a result, Apple, Linux, Unix and myriad other handset operating systems, as well as network appliances such as printers and copiers, are almost always excluded from NAC conversations.

      Today, NAC tools are aimed primarily at endpoints used by contractors and auditors, which are machines that lay outside the strict control of central IT. Its clear that many of these systems must be allowed onto controlled networks to provide valuable services and to ensure compliance with a burgeoning host of regulations.

      Contractor and auditor systems that are outside central IT control are, as our tests have shown, some of the most resistant to being checked as safe to use. For one thing, its hard to put an agent on the systems to run the checks. For another, its almost impossible to remediate these systems because of licensing concerns assuming that the host network even has access to, for example, the antivirus signatures used by a particular endpoint.

      Other Approaches

      The other way to combat viruses and malware being carried into the network by visiting systems is to harden internal clients and servers to better withstand the onslaught infected systems will inevitably bring into the network.

      Server managers can take a page from the trusted operating system functionality and best practices that are emerging from the Linux and Solaris platforms. Servers can also be protected by taking advantage of their special location in the data center where firewalls and identity-based access systems can be effectively combined to ensure that authorized users alone are able to access the protected resources.

      Weve talked for years about ways that client side systems can be protected, and we stand by those recommendations today. Least user privilege combined with strict user system lockdown is still one of the best ways to ensure that systems arent susceptible to the effects of malware. IT managers who havent taken this mantra to heart should pay careful attention to Interop exhibitors that provide endpoint configuration products and services.

      Virtualization can also become part of the solution on both the server and client sides of the problem. We are especially interested in virtualized security appliances that can be placed in front of virtualized servers to protect individual applications. This same technology is starting to appear on user systems as well.

      At the end of the day, it will likely be a combination of some form of network-based access control combined with much tighter client-side configuration that will solve the problem of providing network access to information without destroying the network or the clients attached to it. Having said this, however, we think that the questions that Interop will attempt to answer are worth asking, and we will likely see the NAC technologies that are being put forward today for several years to come.

      ´

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Cameron Sturdevant
      Cameron Sturdevant
      Cameron Sturdevant is the executive editor of Enterprise Networking Planet. Prior to ENP, Cameron was technical analyst at PCWeek Labs, starting in 1997. Cameron finished up as the eWEEK Labs Technical Director in 2012. Before his extensive labs tenure Cameron paid his IT dues working in technical support and sales engineering at a software publishing firm . Cameron also spent two years with a database development firm, integrating applications with mainframe legacy programs. Cameron's areas of expertise include virtual and physical IT infrastructure, cloud computing, enterprise networking and mobility. In addition to reviews, Cameron has covered monolithic enterprise management systems throughout their lifecycles, providing the eWEEK reader with all-important history and context. Cameron takes special care in cultivating his IT manager contacts, to ensure that his analysis is grounded in real-world concern. Follow Cameron on Twitter at csturdevant, or reach him by email at [email protected].

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.