Light Reading
AT&T's chief security officer explains why a whole new approach to mobile network security is needed in a world of smartphones, the cloud, and virtualization.

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View
    Flash Poll
    From The Founder
    It's clear to me that the communications industry is divided into two types of people, and only one is living in the real world.
    LRTV Interviews
    From 4G to 5G: Alcatel-Lucent's Dave Geary

    11|25|14   |   09:09   |   (1) comment


    Dave Geary, President of Wireless at Alcatel-Lucent, talks about the evolution of the 4G market, small cells, partnerships, 5G and the IoT.
    LRTV Huawei Video Resource Center
    Building a Secure Telefonica Network With Huawei's High-End Firewall

    11|24|14   |   4:37   |   (0) comments


    Andrew Davies, IP architect of the Telefonica, a leading digital communications company, discusses the Huawei security gateway solution and putting the solution into the testbed.
    LRTV Huawei Video Resource Center
    Huawei Partners with Spirent to Verify CE12816's 10GE Port & TRILL Networking Capabilities

    11|24|14   |   2:50   |   (0) comments


    Spirent Communications is the world's leading supplier for telecom testing appliances and solutions. Spirent has been in a close partnership with Huawei for a long time.
    LRTV Huawei Video Resource Center
    Saudi Airlines & Its ICT Transformation

    11|24|14   |   2:07   |   (0) comments


    In this video, Saudi Airlines discusses its network problems and how Huawei's Agile Network is its all-in-one solution.
    LRTV Huawei Video Resource Center
    Huawei's Agile Switch Benefiting Saudi Arabia's Yamamah Hospital

    11|24|14   |   2:40   |   (0) comments


    Saudi Arabia's Yamamah Hospital speaks about how Huawei's Agile Switch has improved the medical service's network infrastructure.
    LRTV Huawei Video Resource Center
    FanPlay & Huawei Build a Wireless Agile Smart Stadium

    11|24|14   |   2:13   |   (0) comments


    FanPlay is a cloud-based white label service, which is effectively a football fan engagement platform underpinned by mobile payment technology.
    LRTV Huawei Video Resource Center
    Building an Agile Stadium

    11|24|14   |   3:54   |   (0) comments


    Stadiums may be thousands of tons of concrete and steel, but they now need to be agile. Being at the stadium may not be as alluring as it once was. Sports franchises and stadium operators discuss how to get fans back.
    LRTV Huawei Video Resource Center
    Huawei Helps ChinaCache Tackle Challenges in the Internet Industry

    11|24|14   |   3:09   |   (0) comments


    ChinaCache is China's largest content distribution network supplier. Huawei's CE12800 has provided ChinaCache with very strong support in its establishment of an infrastructure network.
    LRTV Huawei Video Resource Center
    Cefinity on Managed Security Services & Next-Generation Firewall

    11|24|14   |   7:05   |   (0) comments


    Cefinity is a cloud management service provider in Southeast Asia. Ivan Zhang, CEO of the company, discusses the implementation of security service management in the cloud era.
    LRTV Huawei Video Resource Center
    Huawei's Agile Gateway in the Eyes of Cefinity

    11|24|14   |   2:11   |   (0) comments


    Cefinity is a managed service provider for enterprise networks. The company currently uses Huawei's AR series routers for the most complete range of functions. CEO Ivan Zhang speaks about the advantages of the AR series routers.
    LRTV Huawei Video Resource Center
    CTO of Bus-Online Talks About Huawei's Agile Gateway

    11|24|14   |   2:53   |   (0) comments


    Bus-Online covers around 100 million users everyday. In addition to providing mobile TV, and advertising services to the public, Bus-Online has also entered the field of mobile Internet.
    LRTV Huawei Video Resource Center
    Amsterdam ArenA as an Agile Campus

    11|24|14   |   3:31   |   (0) comments


    The Amsterdam ArenA, home of the Ajax soccer team, can be a crowded space. ArenA has partnered with Huawei to work on bringing ample bandwidth to 53,000 people at the same time.
    Upcoming Live Events
    December 2, 2014, New York City
    December 3, 2014, New York City
    December 8-10, 2014, Reykjavik, Iceland
    February 10, 2015, Atlanta, GA
    April 14, 2015, New York City, NY
    May 6, 2015, McCormick Convention Center, Chicago, IL
    May 13-14, 2015, The Westin Peachtree, Atlanta, GA
    June 9-10, 2015, Chicago, IL
    Infographics
    Irish Telecom outlines the rise of VoIP technology, including its adoption within businesses and their perception of its quality.
    Hot Topics
    $38.3M: Ain't That a Kik in the SMS
    Sarah Reedy, Senior Editor, 11/20/2014
    Net Neutrality Even Mark Cuban Could Love
    Mitch Wagner, West Coast Bureau Chief, Light Reading, 11/26/2014
    Do You Have a 2020 Vision?
    Dennis Mendyk, Vice President of Research, Heavy Reading, 11/21/2014
    New Juniper CEO Can Be Thankful for $14.5M
    Mitch Wagner, West Coast Bureau Chief, Light Reading, 11/25/2014
    Amazon Eyes Ad-Supported Video – NY Post
    Mari Silbey, Independent Technology Editor, 11/25/2014
    Like Us on Facebook
    Twitter Feed