& cplSiteName &

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
    Educational Resources
    sponsor supplied content
    Educational Resources Archive
    From The Founder
    Cisco's Conrad Clemson, recently promoted to head up the company's Service Provider Apps & Platforms developments, talks to Light Reading's Founder and CEO Steve Saunders about how he's bringing cloud video, mobile and virtualization together to empower network operators.
    Flash Poll
    Live Streaming Video
    Charting the CSP's Future
    Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
    LRTV Custom TV
    CommScope – Meeting the Demands of Tomorrow's Networks

    3|24|17   |     |   (0) comments


    Phil Sorksy, Vice President International at CommScope, discusses addressing the challenges faced by service providers today, and as future trends emerge.
    LRTV Huawei Video Resource Center
    AMS-IX & Huawei's OSN 902

    3|24|17   |     |   (0) comments


    Huawei shows how its OSN 902 platform helps the Amsterdam Internet exchange to connect the world using multiplexing.
    LRTV Huawei Video Resource Center
    Huawei's Smart Energy Innovation Center

    3|24|17   |     |   (0) comments


    In Nuremberg, Huawei showcases its latest capabilities in the digitalization of Internet resources, network infrastructure and intelligence at its Smart Energy Innovation Center.
    Valley Wonk
    OFC & Hyperscale: A Good Mix?

    3|24|17   |   01:50   |   (0) comments


    Cloud and telecom players want different types of equipment for their networks, as the chatter at OFC reveals.
    LRTV Custom TV
    Etisalat on NFV Journey

    3|24|17   |   10:37   |   (0) comments


    Etisalat is a service provider that prides itself on bringing innovative technologies to the markets it serves. It was one of the first operators to implement 3G and leads the pack in fiber penetration. Now, Esmaeel Al Hammadi, Etisalat's SVP of Network Development, explains the operator's journey to virtualization, beginning with the network core, as well as the ...
    LRTV Huawei Video Resource Center
    Huawei at CeBIT 2017: Day 3

    3|22|17   |     |   (0) comments


    Light Reading reports from CeBIT 2017 in Germany, where Huawei is exhibiting on the application of technologies and key business verticals such as transportation, smart city, manufacturing, media and finance.
    LRTV Documentaries
    No Regrets: Cox's Finkelstein on Fiber & More

    3|22|17   |     |   (0) comments


    At the Cable Next-Gen Technologies & Strategies event in Denver, Cox's Jeff Finkelstein examines the cable capex conundrum.
    LRTV Documentaries
    Cable Next-Gen: The 'Mile High' View From Denver

    3|22|17   |   11:56   |   (0) comments


    Alan Breznick kicks off the Cable Next-Gen Technologies & Strategies event in Denver, casting his thousand-yard stare over cable's current competitive landscape.
    LRTV Huawei Video Resource Center
    Huawei at CeBIT 2017: Day 2

    3|21|17   |   2:27   |   (0) comments


    Light Reading reports from CeBIT 2017 in Germany, where Huawei is exhibiting digital transformation solutions around IoT, smart data centers, OpenCloud ecosystem and its newly announced storage-as-a-service solution.
    LRTV Custom TV
    Driving Better Mobile Customer Experience While Transforming the Mobile Network

    3|21|17   |   7:47   |   (0) comments


    The Citrix NetScaler mobile gateway is an intelligent traffic management solution which can markedly improve the customer experience provided by mobile operators, even when traffic is encrypted. Critical network services can be consolidated and virtualized using NetScaler. Because of the unique architecture, NetScaler can be deployed on any hypervisor, on a ...
    LRTV Custom TV
    Mastercard: What's Next for Mobile Payments?

    3|21|17   |   7:49   |   (0) comments


    2017 marks the fifth consecutive year for Mastercard at Mobile World Congress and it was a great time to reflect on the amazing advances the payments industry has made as well as discuss "What's Next' in the digital commerce future. We spoke to James Anderson, executive vice president of digital payments at MasterCard, about digital wallets to tokenization to ...
    LRTV Custom TV
    Mastercard: 2 Billion Adults 'Trapped' in Cash Economy

    3|21|17   |   03:51   |   (1) comment


    Despite advances made in the last several years, two billion adults around the world are trapped in a cash economy and lack what we take for granted -- a safe way to receive, save and use money. Shamina Singh, executive vice president of sustainability and president of the Mastercard Center for Inclusive Growth, chats about how Mastercard is developing new ways to ...
    Upcoming Live Events
    May 15-17, 2017, Austin Convention Center, Austin, TX
    May 15, 2017, Austin Convention Center - Austin, TX
    June 6, 2017, The Joule Hotel, Dallas, TX
    All Upcoming Live Events
    Infographics
    With the mobile ecosystem becoming increasingly vulnerable to security threats, AdaptiveMobile has laid out some of the key considerations for the wireless community.
    Hot Topics
    High-Band 5G: Let's Address the Range Question, Shall We?
    Dan Jones, Mobile Editor, 3/21/2017
    Eurobites: A1, Nokia Turn It Up to 11
    Paul Rainford, Assistant Editor, Europe, 3/22/2017
    FTTH No Slam Dunk for Cable
    Carol Wilson, Editor-at-large, 3/23/2017
    Top Priorities for B/OSS Transformation
    James Crawshaw, Senior Analyst – OSS/BSS Transformation, Heavy Reading, 3/20/2017
    Like Us on Facebook
    Twitter Feed
    BETWEEN THE CEOs - Executive Interviews
    TEOCO Founder and CEO Atul Jain talks to Light Reading Founder and CEO Steve Saunders about the challenges around cost control and service monetization in the mobile and IoT sectors.
    At MWC 2017, Qualcomm's CTO Matt Grob talks to Light Reading's CEO and Founder Steve Saunders about the progress being made in the development of the technologies and standards that will underpin 5G.
    Animals with Phones
    Neither Do We Click Here
    Is that a prerequisite?
    Live Digital Audio

    Playing it safe can only get you so far. Sometimes the biggest bets have the biggest payouts, and that is true in your career as well. For this radio show, Caroline Chan, general manager of the 5G Infrastructure Division of the Network Platform Group at Intel, will share her own personal story of how she successfully took big bets to build a successful career, as well as offer advice on how you can do the same. We’ll cover everything from how to overcome fear and manage risk, how to be prepared for where technology is going in the future and how to structure your career in a way to ensure you keep progressing. Chan, a seasoned telecom veteran and effective risk taker herself, will also leave plenty of time to answer all your questions live on the air.