|By Don MacVittie||
|May 5, 2011 04:42 PM EDT||
There is a theory in traditional military strategy that goes something along the lines of “take land, consolidate your gains, take more land…” von Moltke the Elder found this theory so profound that he suggested a defender could trade land for time – advice that Russia managed pretty well in The Great Patriotic War (known in the west as World War II), and German General Kesselring practiced against the allies in Italy during the same war. By giving up land, the enemy is forced to occupy it before they can begin forward movement again, buying you time to build your defenses at a new location, and often forcing them to change their tactics and strategic goals.
There are a lot of reasons why comparisons between warfare and security exist, and I’m going to continue the long-standing tradition here. We are ready to move into the cloud… But there’s a problem. We have to change some of our tactics before we can take overall advantage of cloud infrastructure. At least in the short-term.
People like myself, some with more experience in the space than others, have been recommending that developers leave large swaths of security implementations to firewalls and web application firewalls. This was sound advice, I’ve been a developer, I know the way that code is crafted, I know that it doesn’t take much to leave a gaping hole in one little tiny bit of code. Web application firewalls offer a layer of protection in case you missed something, and can be expanded to lighten the amount of code required to do many mundane tasks.
And there’s the problem. We’ve been telling developers to largely remove themselves from the security business, but now we’re moving to the cloud, where the infrastructure of the corporate datacenter is not necessarily available. Which means the weight of all that redundant security coding falls right back onto developers’ shoulders for the short term. Companies like F5 are moving an increasing amount of high-caliber infrastructure to VMs that can be deployed to the cloud and restore access to the datacenter infrastructure either with manual separate configuration or by slaving the VM appliances to your corporate appliances, which will then put us back where we are today.
von Moltke the Elder
But until your organization has web application firewalls and other security devices on-par in the cloud with what is in the datacenter, I’m afraid there’s going to be a return to the good old “is field all alphanumeric?” “Is field < 8 characters” type checking all over your source code. But it really is a temporary situation, before you know it, you will be able to say “my datacenter device has all the information for this application, share it with my cloud VM appliance”, and you’ll be off and running.
So dig out the security books from a few years back, study up on web application security, schedule extra time for writing and testing your application… And then be prepared to put things back under the umbrella of web application firewalls.
You still won’t be completely out of the security business. No one knows your application and its most glaring security weaknesses better than the developer that wrote it, but that’s the status quo for in-datacenter applications today – developers in shops making use of all of the great network-based security products on the market are able to focus their security efforts on the one or two areas that must have extra protection instead of all possible security vulnerability points.
The bigger problem is deploying purchased applications to the cloud, where you can’t lock it down without tools to help, and those tools have to run in VMs. This is an aspect that I’m not certain has gotten all the attention it deserves yet, but is definitely going to be a problem in the near-term.
I’d say “you could delay deploying to the cloud…” I could also say “You could wait for the sun not to come up tomorrow…” because generally speaking, developers do not get to choose deployment methodology, only influence it, and cloud has taken on a life (or a hype) all its own.
So be careful, have a plan for how to address application-specific security in the cloud, check out VM security offerings as they become available, and keep rocking the apps. Consolidate, reconsider tactics, move to a new attack.
|Connect with Don:||Connect with F5:|
Related Articles and Blogs:
- BIG-IP ASM v.10 Application Ready Security Policy Templates
- v.10 – Application Security Manager (ASM) From iControl
- ASM Layer 7 DoS And Brute Force Protection
- F5 Networks Delivers Comprehensive Application Security Solution ...
- Web Application Security at the Edge is More Efficient Than In the ...
- 4 Reasons We Must Redefine Web Application Security
- Would you risk $31000 for milliseconds of application response time?
- When Is More Important Than Where in Web Application Security
- PCI DSS Deadline Looming Large While Debate Continues - WAF vs VA
- Web Application Security: Where do we go from here?
- What's the difference between a web application and a blog?
- Remember when…you had to choose between security and speed?
- 3 reasons you need a WAF even if your code is (you think) secure
- The Application Delivery Spell Book: Detect Invisible (Application ...
SYS-CON Events announced today that Pulzze Systems will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Pulzze Systems, Inc. provides infrastructure products for the Internet of Things to enable any connected device and system to carry out matched operations without programming. For more information, visit http://www.pulzzesystems.com.
Sep. 25, 2016 09:45 AM EDT Reads: 1,759
If you’re responsible for an application that depends on the data or functionality of various IoT endpoints – either sensors or devices – your brand reputation depends on the security, reliability, and compliance of its many integrated parts. If your application fails to deliver the expected business results, your customers and partners won't care if that failure stems from the code you developed or from a component that you integrated. What can you do to ensure that the endpoints work as expect...
Sep. 25, 2016 09:00 AM EDT Reads: 1,530
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business in 2016. However, IoT is far more complex than most firms expected. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, a renowned visionary and thought leader, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology and business models to adopt and leverage IoT. He will drill down to the components in this fra...
Sep. 25, 2016 08:00 AM EDT Reads: 1,495
The Internet of Things can drive efficiency for airlines and airports. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Sudip Majumder, senior director of development at Oracle, will discuss the technical details of the connected airline baggage and related social media solutions. These IoT applications will enhance travelers' journey experience and drive efficiency for the airlines and the airports. The session will include a working demo and a technical d...
Sep. 25, 2016 08:00 AM EDT Reads: 1,667
WebRTC adoption has generated a wave of creative uses of communications and collaboration through websites, sales apps, customer care and business applications. As WebRTC has become more mainstream it has evolved to use cases beyond the original peer-to-peer case, which has led to a repeating requirement for interoperability with existing infrastructures. In his session at @ThingsExpo, Graham Holt, Executive Vice President of Daitan Group, will cover implementation examples that have enabled ea...
Sep. 25, 2016 08:00 AM EDT Reads: 1,481
SYS-CON Events announced today the Enterprise IoT Bootcamp, being held November 1-2, 2016, in conjunction with 19th Cloud Expo | @ThingsExpo at the Santa Clara Convention Center in Santa Clara, CA. Combined with real-world scenarios and use cases, the Enterprise IoT Bootcamp is not just based on presentations but with hands-on demos and detailed walkthroughs. We will introduce you to a variety of real world use cases prototyped using Arduino, Raspberry Pi, BeagleBone, Spark, and Intel Edison. Y...
Sep. 25, 2016 06:30 AM EDT Reads: 2,802
Technology vendors and analysts are eager to paint a rosy picture of how wonderful IoT is and why your deployment will be great with the use of their products and services. While it is easy to showcase successful IoT solutions, identifying IoT systems that missed the mark or failed can often provide more in the way of key lessons learned. In his session at @ThingsExpo, Peter Vanderminden, Principal Industry Analyst for IoT & Digital Supply Chain to Flatiron Strategies, will focus on how IoT de...
Sep. 25, 2016 05:30 AM EDT Reads: 990
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
Sep. 25, 2016 04:45 AM EDT Reads: 1,512
SYS-CON Events announced today that China Unicom will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. China United Network Communications Group Co. Ltd ("China Unicom") was officially established in 2009 on the basis of the merger of former China Netcom and former China Unicom. China Unicom mainly operates a full range of telecommunications services including mobile broadband (GSM, WCDMA, LTE F...
Sep. 25, 2016 04:15 AM EDT Reads: 1,686
SYS-CON Events announced today that Roundee / LinearHub will exhibit at the WebRTC Summit at @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LinearHub provides Roundee Service, a smart platform for enterprise video conferencing with enhanced features such as automatic recording and transcription service. Slack users can integrate Roundee to their team via Slack’s App Directory, and '/roundee' command lets your video conference ...
Sep. 25, 2016 04:15 AM EDT Reads: 1,384
DevOps at Cloud Expo, taking place Nov 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 19th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long dev...
Sep. 25, 2016 03:15 AM EDT Reads: 3,355
There is growing need for data-driven applications and the need for digital platforms to build these apps. In his session at 19th Cloud Expo, Muddu Sudhakar, VP and GM of Security & IoT at Splunk, will cover different PaaS solutions and Big Data platforms that are available to build applications. In addition, AI and machine learning are creating new requirements that developers need in the building of next-gen apps. The next-generation digital platforms have some of the past platform needs a...
Sep. 25, 2016 02:45 AM EDT Reads: 1,716
I'm a lonely sensor. I spend all day telling the world how I'm feeling, but none of the other sensors seem to care. I want to be connected. I want to build relationships with other sensors to be more useful for my human. I want my human to understand that when my friends next door are too hot for a while, I'll soon be flaming. And when all my friends go outside without me, I may be left behind. Don't just log my data; use the relationship graph. In his session at @ThingsExpo, Ryan Boyd, Engi...
Sep. 25, 2016 02:15 AM EDT Reads: 1,217
SYS-CON Events announced today that Numerex Corp, a leading provider of managed enterprise solutions enabling the Internet of Things (IoT), will exhibit at the 19th International Cloud Expo | @ThingsExpo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Numerex Corp. (NASDAQ:NMRX) is a leading provider of managed enterprise solutions enabling the Internet of Things (IoT). The Company's solutions produce new revenue streams or create operating...
Sep. 25, 2016 12:45 AM EDT Reads: 1,931
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
Sep. 25, 2016 12:45 AM EDT Reads: 1,037
Data is an unusual currency; it is not restricted by the same transactional limitations as money or people. In fact, the more that you leverage your data across multiple business use cases, the more valuable it becomes to the organization. And the same can be said about the organization’s analytics. In his session at 19th Cloud Expo, Bill Schmarzo, CTO for the Big Data Practice at EMC, will introduce a methodology for capturing, enriching and sharing data (and analytics) across the organizati...
Sep. 24, 2016 09:45 PM EDT Reads: 1,621
The vision of a connected smart home is becoming reality with the application of integrated wireless technologies in devices and appliances. The use of standardized and TCP/IP networked wireless technologies in line-powered and battery operated sensors and controls has led to the adoption of radios in the 2.4GHz band, including Wi-Fi, BT/BLE and 802.15.4 applied ZigBee and Thread. This is driving the need for robust wireless coexistence for multiple radios to ensure throughput performance and th...
Sep. 24, 2016 08:30 PM EDT Reads: 1,453
Enterprise IT has been in the era of Hybrid Cloud for some time now. But it seems most conversations about Hybrid are focused on integrating AWS, Microsoft Azure, or Google ECM into existing on-premises systems. Where is all the Private Cloud? What do technology providers need to do to make their offerings more compelling? How should enterprise IT executives and buyers define their focus, needs, and roadmap, and communicate that clearly to the providers?
Sep. 24, 2016 01:00 PM EDT Reads: 1,498
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace.
Sep. 24, 2016 12:00 PM EDT Reads: 797
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
Sep. 24, 2016 12:00 PM EDT Reads: 795