Light Reading
AT&T's chief security officer explains why a whole new approach to mobile network security is needed in a world of smartphones, the cloud, and virtualization.

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View
    Flash Poll
    LRTV Huawei Video Resource Center
    Sales Director of INIT on Plug & Play Switch Devices

    9|19|14   |   3:21   |   (0) comments


    INIT Italy uses both the Huawei S5700 and S7700 series switches for the campus LAN environment. Sales Director Andrea Curti says their company chose these Huawei devices over others because of their performance, flexible scalability and plug-and-play features.
    LRTV Huawei Video Resource Center
    Saudi Arabia Upgrades Vocational Training System

    9|19|14   |   3:31   |   (0) comments


    The Technical and Vocational Training Corporation (TVTC) has 100,000 students, 150 government-owned institutions and oversees 1000 private institutes. The CIO of TVTC explains that Huawei devices have allowed them to manage multiple datacenters using just one software program, scientifically tracking the progress of students and teachers, saving them millions.
    LRTV Huawei Video Resource Center
    Huawei's Media Solutions Are Here to Stay

    9|19|14   |   4:35   |   (0) comments


    The current media revolution requires rapid upgrades in technology. New formats (HD, 3D, 4K etc.) and the subsequent explosion of file sizes demand sophisticated network and storage architecture. Social media and the multiple distribution channels require a robust asset management system. Gartner analyst Venecia Liu speaks about the current technological trends in ...
    LRTV Huawei Video Resource Center
    Microgenesis on Huawei's Switches

    9|19|14   |   3:57   |   (0) comments


    Microgenesis is a solutions and system integrator company in the Philippines whose areas of expertise include data centers, networking and security products. In this video, Executive Director Jeffrey Choa talks to us about his customers needs and they benefit from using Huawei switches.
    LRTV Huawei Video Resource Center
    Network Solutions Help the Philippines Jump Ahead

    9|17|14   |   2:59   |   (0) comments


    In the past, the Philippines has under-invested in technology. Now, the CEO of Softshell talks about how Huawei products help the Philippines jump ahead as the economy improves.
    LRTV Huawei Video Resource Center
    VCS Observation for Safer Cities in the Netherlands

    9|17|14   |   5:20   |   (0) comments


    Holland's VCS Observation has been operating for 22 years. Its main goal is to get cities safer. CEO Wim van Deijzen tells us some of the challenges his company faces and how Huawei is helping to overcome these challenges.
    LRTV Huawei Video Resource Center
    A Conversation With Serbia's Ministry of Interior

    9|17|14   |   4:38   |   (0) comments


    At HCC 2014, the Assistant Minister of the Ministry of Interior of the Republic of Serbia talks to us about his projects and corporation with Huawei. Solutions like Safe City and E-Government and services like cloud computing are just some of the areas his department is interested in.
    LRTV Huawei Video Resource Center
    IHS Analyst Discusses eLTE at CCW 2014

    9|10|14   |   7:09   |   (0) comments


    Thomas Lynch, associate director of critical communications at IHS Technology, talks about broadband in critical communications.
    LRTV Huawei Video Resource Center
    TCAA on Huawei eLTE: A Broadband Solution for Mission-Critical Communications

    9|10|14   |   2:29   |   (0) comments


    At CCW2014 in Singapore, the TCCA's Phil Kidner talks about the importance of broadband data for critical communications.
    LRTV Custom TV
    Spotlight on Cisco: SDN for Optical Networks

    9|8|14   |   9:27   |   (0) comments


    Cisco's Greg Nehib talks OpenFlow and more on the 'Software-Defined Networking for Optical Networks' panel at the Big Telecom Event in June 2014.
    LRTV Custom TV
    Cisco's Evolved Programmable Network (EPN)

    9|8|14   |   4:05   |   (0) comments


    A look at the various demos Cisco showed at Light Reading's Big Telecom Event highlighting Cisco's EPN innovation and how SDN and NFV technologies are enabling a variety of new services.
    LRTV Huawei Video Resource Center
    The Future of Ultra-Broadband, With Kevin Kelly (UBBF2014)

    9|5|14   |   1:13   |   (1) comment


    If you think the technological changes we've seen up to now are astounding, just wait until you see what the future has in store. Discuss upcoming breakthroughs with Kevin Kelly, Founding Executive Editor of Wired Magazine, at the Huawei Ultra-Broadband Forum on September 24.
    Upcoming Live Events!!
    September 23, 2014, Denver, CO
    October 29, 2014, New York City
    November 6, 2014, Santa Clara
    November 11, 2014, Atlanta, GA
    December 2, 2014, New York City
    December 3, 2014, New York City
    December 9-10, 2014, Reykjavik, Iceland
    June 9-10, 2015, Chicago, IL
    Infographics
    A survey conducted by Vasona Networks suggests that 72% of mobile users expect good performance all the time, and they'll blame the network operator when it's not up to par.
    Today's Cartoon
    Vacation Special Caption Competition Click Here
    Latest Comment
    Hot Topics
    AT&T: We'll Bundle Fixed Wireless & DirecTV
    Mari Silbey, Independent Technology Editor, 9/15/2014
    New NFV Forum Focused on Interoperability
    Carol Wilson, Editor-at-large, 9/16/2014
    NFV & The Data Center: Top 10 Takeaways
    Sarah Reedy, Senior Editor, 9/18/2014
    Photos: Qualcomm Takes Over San Francisco
    Sarah Reedy, Senior Editor, 9/19/2014
    Connecticut Cities Crowdsource Gigabit Nets
    Jason Meyers, Senior Editor, Utility Communications/IoT, 9/15/2014
    Like Us on Facebook
    Twitter Feed