& cplSiteName &

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
    Educational Resources
    sponsor supplied content
    Educational Resources Archive
    Light Reading’s Upskill U is a FREE, interactive, online educational resource that delivers must-have education on themes that relate to the overall business transformation taking place in the communications industry.
    Friday, October 28, 1:00PM EDT
    Security: The Plusses and Minuses of Open Source Software
    Nick Feamster, Acting Director, Center for Information Technology Policy, Princeton University
    Wednesday, November 16, 1:00PM EST
    SDN 101
    John Isch, Practice Director, Network & Voice, Orange Business Services
    Friday, November 18, 1:00PM EST
    SDN & Open Source
    Christopher W. Rice, Senior Vice President of AT&T Labs, Domain 2.0 Architecture and Design
    Wednesday, November 30, 1:00PM EST
    SDN & the Software Defined Data Center
    in association with:
    From The Founder
    Light Reading today starts a new voyage as part of a larger Enterprise.
    Flash Poll
    Live Streaming Video
    Charting the CSP's Future
    Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
    LRTV Custom TV
    ZTE BBWF Highlights

    10|26|16   |     |   (0) comments

    At BBWF 2016, ZTE showed a broad range of innovative technologies that are kick-starting an ultrafast broadband journey.
    LRTV Custom TV
    Next-Generation Technology Beyond DOCSIS 3.1

    10|20|16   |     |   (0) comments

    At SCTE 2016, Huawei's Liu Jianhua speaks with Alan Breznick for an exclusive interview.
    LRTV Custom TV
    Hybrid Video Solutions to Change TV, Change Future

    10|20|16   |     |   (0) comments

    At SCTE 2016, Huawei's Ian Locke speaks with Alan Breznick for an exclusive interview.
    LRTV Custom TV
    Huawei Future-Oriented Giga Coax Network

    10|20|16   |     |   (0) comments

    At SCTE 2016, Huawei's Allen Wang speaks with Alan Breznick for an exclusive interview.
    LRTV Custom TV
    Huawei at SCTE 2016

    10|20|16   |     |   (0) comments

    Join Alan Breznick of Light Reading and take a sneak peek at the Huawei booth at SCTE 2016.
    LRTV Custom TV
    Assuring Network Quality in a Rapidly Changing Environment

    10|20|16   |     |   (0) comments

    As the rate of change and complexity increases in agile networks, the importance of introducing DevOps methodologies for integrating active test and assurance solutions throughout the full service lifecycle becomes critical to ensure that customers are experiencing the service quality they demand. The industry landscape is changing, and software-based test and ...
    Telecom Innovators Video Showcase
    A10 Networks on Service Providers' Industry Needs

    10|20|16   |     |   (0) comments

    Light Reading's Steve Saunders hears how A10 enables service providers to accelerate, secure and optimize their application delivery to drive down costs, enhance service availability, and better respond to customer requirements, so they can improve customer satisfaction, monetize their network, and grow revenues.
    LRTV Custom TV
    New NFV Use Cases for Cable TV

    10|19|16   |     |   (0) comments

    A large number of NFV use cases are focused on the enterprise domain, looking at virtualization of customer-premises equipment (CPE). To date, there has been little focus on the use cases and business case for virtualization of the video content delivery networks required to deliver unicast and streaming video to consumers. Amdocs commissioned Analysys Mason to ...
    Women in Comms Introduction Videos
    Meet the Future Workforce: New Faces, Expectations & Motivations

    10|19|16   |   5:33   |   (1) comment

    Millennials and their younger peers, Gen Z, expect more out of their network and more out of their work. Intel's Lynn Comp shares how the industry can prepare for this new generation of workers.
    LRTV Custom TV
    ZTE Global Services User Congress 2016 Highlights

    10|19|16   |     |   (0) comments

    ZTE held its 2nd Global Service User Conference in Dusseldorf on October 13-14. Representatives from network operators, leading industry analysts and ZTE senior expertsattended the event, exploring the best practice in managed services and the vision to transform network operations into the operations center of the future (OpCF) in the software-defined networking ...
    LRTV Custom TV
    Cliff Grossner on Cloud & Network Synergy From Carrier Service

    10|18|16   |     |   (0) comments

    Local carriers offer the collaborated cloud and network service that benefits from their understanding of the regulations operating in different vertical markets.
In this interview, Cliff Grossner from IHS Technology talks about how this advanced service can support business agility and flexibility.
    LRTV Custom TV
    VeEX: Live from SCTE Cable-Tec Expo 2016

    10|17|16   |     |   (0) comments

    Cyrille Morelle, VeEX's President and CEO, talks with Light Reading's Alan Breznick live from the SCTE Cable-Tec Expo 2016. They discuss DOCSIS 3.1 technology, deployments and early lessons learned. New products on display include the CX350s-D3.1, CX380s-D3.1, CX310, AT2500-3G, FX150 OTDR and MTT WiFI Air Expert.
    Upcoming Live Events
    November 3, 2016, The Montcalm Marble Arch, London
    November 30, 2016, The Westin Times Square, New York City
    December 1, 2016, The Westin Times Square, New York, NY
    December 6-8, 2016, The Westin Excelsior, Rome
    May 16-17, 2017, Austin Convention Center, Austin, TX
    All Upcoming Live Events
    Hot Topics
    Attacks Have Major Internet Sites on the Ropes
    Brian Santo, Senior editor, Test & Measurement / Components, Light Reading, 10/21/2016
    Trump: Dump AT&T/TW & Comcast/NBC
    Alan Breznick, Cable/Video Practice Leader, Light Reading, 10/24/2016
    Layer3 TV Comes to Town, Hints at Future
    Mari Silbey, Senior Editor, Cable/Video, 10/21/2016
    T-Mobile: AT&T & TW Means Ma Bell Not Focused on Mobile
    Dan Jones, Mobile Editor, 10/24/2016
    Sprint: Revenue up 3%, Capex Will Rise Again
    Dan Jones, Mobile Editor, 10/25/2016
    Like Us on Facebook
    Twitter Feed
    BETWEEN THE CEOs - Executive Interviews
    Join us for an in-depth interview between Steve Saunders of Light Reading and Alexis Black Bjorlin of Intel as they discuss the release of the company's Silicon Photonics platform, its performance, long-term prospects, customer expectations and much more.
    There's no question that, come 2020, 5G technology will turn the world's conception of what mobile networking is on its head. Within the world of 5G development, Dr. ...
    Animals with Phones
    'Oh, Were You Looking for This?' Click Here
    'I was just playing some games...'
    Live Digital Audio

    A vital part of increasing the number of women in comms is transforming the ways companies can support and empower women. While progressive company policies that support both men and women in achieving work-life balance are a step in the right direction, creating a company culture that supports those policies can at times be more challenging.

    During this show, we'll talk to Lynn Comp, Senior Director of Industry and Sales Enabling (ISE) in the Network Platforms Group at Intel, about why those challenges exist and how companies can overcome them. She'll provide insight into how Intel has worked to create a culture that supports work-life balance, and provide steps and guidance for other companies wishing to do the same. We will also leave plenty of time to get your questions answered live on the air.