Light Reading

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
    Flash Poll
    From The Founder
    Anshul Sadana answers questions from Steve Saunders, Light Reading's founder and CEO, about Arista's CloudVision, a global cloud network controller for workload orchestration and workflow automation delivering a turnkey solution for cloud networking.
    Live Streaming Video
    CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
    Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
    Between the CEOs
    Video Exclusive With Basil Alwan, Alcatel-Lucent

    7|24|15   |   26:44   |   (4) comments


    Basil Alwan, President of IP Routing & Transport at Alcatel-Lucent, discusses virtualization, cultural challenges, the capex crunch and more with Light Reading founder and CEO Steve Saunders.
    LRTV Custom TV
    VDF: Enable the Financial With Mobile Money

    7|20|15   |   06:53   |   (0) comments


    Ian Ravenscroft discusses how operators can expand to occupy the entire digital services value chain through service innovation.
    LRTV Custom TV
    Telefónica on OSS Transformation

    7|20|15   |   06:01   |   (0) comments


    Jose Gonzales discusses the details of Telefónica's operation transformation program.
    LRTV Custom TV
    Judi Achmadi on Huawei's Cloud Storage Solution

    7|20|15   |   03:33   |   (0) comments


    Judi discusses the key business goals of TelekomSigma's public cloud service and how Huawei's solution helps them address challenges.
    LRTV Custom TV
    KPN Enlightening Digital Business & IT Transformation

    7|20|15   |   06:19   |   (0) comments


    Rob de Beer discusses the changes that operators need to make with service innovation now coming from the Internet world.
    LRTV Custom TV
    Stratus Telco-Grade Cloud Solutions & NFV

    7|20|15   |   07:34   |   (0) comments


    Ali Kafel from Stratus Technologies addresses high-availability concerns within the telco industry with a solution that enables telcos to provide high-availability and stateful fault-tolerance using a software-based approach.
    LRTV Documentaries
    The Six Million Dollar Business Man

    7|20|15   |   01:52   |   (0) comments


    Steve Saunders, publisher. A man barely alive after an acquisition malfunction imploded the company he founded. Gentlemen, we can rebuild Light Reading. Better, faster, stronger.
    Between the CEOs
    CEO Chat With Anukool Lakhina, Guavus

    7|20|15   |   38:51   |   (1) comment


    Guavus CEO Anukool Lakhina talks to Light Reading founder and CEO Steve Saunders about the role of operational analytics in the communications services and networking sectors, particularly in relation to IoT.
    LRTV Custom TV
    IBM's Flash Storage With Intel QuickAssist

    7|20|15   |   03:18   |   (0) comments


    Intel's Bev Crair and IBM's Eric Herzog discuss how IBM's V9000 Flash Storage System has helped customers around the world. Featuring real-time compression powered by Intel QuickAssist Technology, the V9000 is a next-gen flash storage solution.
    LRTV Huawei Video Resource Center
    Thailand's AIS: Transforming to an FMC Operator

    7|17|15   |   4:53   |   (0) comments


    Saran Phaloprakarn, Senior VP of Fixed Broadband Business Management of Thailand's AIS, was a keynote speaker at the first Asia-Pacific Ultra Broadband Summit in Bangkok. In this video, he talks to Heavy Reading about transforming into an FMC (FBB+MBB+Content) operator.
    LRTV Huawei Video Resource Center
    Cambodia's TRC Discusses Its Plans for National Broadband

    7|17|15   |   10:33   |   (0) comments


    In this video, Chakyra Moa, Chairman of Telecommunication Regulator of Cambodia (TRC), talks in in-depth with Heavy Reading about the Cambodia's current telecom market and TRC's goals and expectations for the future.
    LRTV Documentaries
    5G Phone

    7|16|15   |   2:09   |   (4) comments


    A man has an opportunity to purchase the world's first working 5G phone. Imagine the possibilities...
    Upcoming Live Events
    September 16-17, 2015, The Westin Galleria Dallas, Dallas, TX
    September 16, 2015, The Westin Galleria Dallas, Dallas, TX
    September 16, 2015, The Westin Galleria Dallas, Dallas, TX
    September 29-30, 2015, The Westin Grand Müchen, Munich, Germany
    October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
    November 5, 2015, Hilton Santa Clara, Santa Clara, CA
    December 1, 2015, The Westin Times Square, New York City
    All Upcoming Live Events
    Infographics
    Network operators start seeing savings from NFV in the first year, according to a study by Affirmed Networks and ACG.
    Hot Topics
    T-Mobile Launches RCS Messaging
    Sarah Thomas, Editorial Operations Director, 7/22/2015
    AT&T U-verse TV Hits the Skids
    Alan Breznick, Cable/Video Practice Leader, 7/24/2015
    Robbins Succeeds Chambers as Cisco Changes CEOs
    Mitch Wagner, West Coast Bureau Chief, Light Reading, 7/27/2015
    RJio to Launch Its Own 4G Devices Brand
    Gagandeep Kaur, Contributing Editor, 7/27/2015
    Like Us on Facebook
    Twitter Feed
    Webinar Archive
    BETWEEN THE CEOs - Executive Interviews
    Basil Alwan, President of IP Routing & Transport at Alcatel-Lucent, discusses virtualization, cultural challenges, the capex crunch and more with Light Reading founder and CEO Steve Saunders.
    Guavus CEO Anukool Lakhina talks to Light Reading founder and CEO Steve Saunders about the role of operational analytics in the communications services and networking sectors, particularly in relation to IoT.
    Cats with Phones
    Distract-a-Cat Click Here
    The vibrate function makes for a useful cat distraction.