Light Reading
AT&T's chief security officer explains why a whole new approach to mobile network security is needed in a world of smartphones, the cloud, and virtualization.

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View
    Flash Poll
    From The Founder
    It's clear to me that the communications industry is divided into two types of people, and only one is living in the real world.
    LRTV Documentaries
    Optical Is Hot in 2015

    1|23|15   |   01:56   |   (2) comments


    Optical comms technology underpins the whole communications sector and there are some really hot trends set for 2015.
    LRTV Custom TV
    Policy Control in the Fast Lane

    1|22|15   |   2:57   |   (0) comments


    What's making policy control strategic in 2015 and beyond? Amdocs talks with Heavy Reading's Graham Finnie about the key factors driving change in the data services landscape. Find out what his policy management research reveals about the road ahead for policy control – and sign up for ...
    LRTV Documentaries
    Highlights From the 2020 Vision Executive Summit

    1|21|15   |   4:33   |   (2) comments


    In December 2014, Light Reading brought together telecom executives in Reykjavik, Iceland to discuss their vision for high-capacity networks through the end of the decade. The intimate, interactive meeting was set against the backdrop of Iceland's spectacular natural beauty. As one of the event's founding sponsors, Cisco's Doug Webster shared his company's ...
    LRTV Huawei Video Resource Center
    Huawei Pay-TV Partner Harmonic, Helping Carriers Accelerate 4K Video Deployment with Huawei

    1|20|15   |   5:42   |   (1) comment


    At IBC, Peter Alexander, Senior Vice President & CMO at Harmonic, speaks about the growing interest in pay-TV service and its branching into multiple devices.
    LRTV Huawei Video Resource Center
    Sony Marketing Director Olivier Bovis Discusses the Outlook for 4K and Cooperation With Huawei at IBC 2014

    1|20|15   |   6:50   |   (0) comments


    At IBC, Olivier Bovis, Marketing Director of Sony, speaks about the coming of the 4K era.
    LRTV Huawei Video Resource Center
    Huawei Pay-TV Partner Envivio, Helping Carriers Accelerate 4K Video Deployment

    1|20|15   |   2:57   |   (0) comments


    At IBC, Olivier Bovis, Marketing Director of Sony, speaks about the coming of the 4K era.
    LRTV Huawei Video Resource Center
    Pay-TV's Networked Future

    1|20|15   |   6:29   |   (0) comments


    At IBC, Jeff Heynen, Principal Analyst at Infonetics, speaks about the future of the pay-TV industry and its transition.
    LRTV Huawei Video Resource Center
    Jeff Heynen: Distributed Access Will Help MSOs Compete in the Future

    1|20|15   |   2:26   |   (0) comments


    At IBC, Jeff Heynen, Principal Analyst at Infonetics, speaks about moving to distributed access and the future trend of cable business.
    LRTV Interviews
    Cisco Talks Transformation

    1|20|15   |   13:02   |   (0) comments


    In December 2014, Steve Saunders sat down with Cisco VP of Products & Solutions Marketing Doug Webster at Light Reading's 2020 Vision executive summit in Reykjavik, Iceland. They spoke about Cisco's approach to network virtualization as well as how service providers can begin to monetize high-capacity networks through the end of the decade.
    LRTV Interviews
    Bob Wilson, Arsenal Legend: The Light Reading Interview

    1|16|15   |   35:36   |   (3) comments


    Arsenal goalkeeping legend Bob Wilson was Light Reading's guest interviewee at the 2020 Vision Executive Summit in December. See what the former soccer star and sports broadcaster had to say when he took to the stage in Iceland.
    LRTV Custom TV
    What MEF Third Network Initiative Means for SDN & NFV

    1|14|15   |   6:13   |   (0) comments


    Vitesse Semiconductor CTO Martin Nuss discusses the importance of the MEF Third Network initiative and why it's good news for SDN/NFV industry initiatives.
    LRTV Huawei Video Resource Center
    Frank Miller: Distributed Solutions are the Best Build for the Future - Part II

    1|9|15   |   2:46   |   (0) comments


    At SCTE, Frank Miller, Global CTO of MSO at Huawei, speaks about Cable 2.0 and its innovative future.
    Upcoming Live Events
    February 5, 2015, Washington, DC
    February 19, 2015, The Fairmont San Jose, San Jose, CA
    March 17, 2015, The Cable Center, Denver, CO
    April 14, 2015, The Westin Times Square, New York City, NY
    May 12, 2015, Grand Hyatt, Denver, CO
    May 13-14, 2015, The Westin Peachtree, Atlanta, GA
    June 9-10, 2015, Chicago, IL
    September 9-10, 2015, The Westin Galleria Dallas, Dallas, TX
    September 29-30, 2015, The Westin Grand Müchen, Munich, Germany
    November 11-12, 2015, The Westin Peachtree Plaza, Atlanta, GA
    December 1, 2015, The Westin Times Square, New York City
    December 2-3, 2015, The Westin Times Square, New York City
    Infographics
    Hot Topics
    BlackBerry Wants Net Neutrality Protection -- That's Just Sad
    Mitch Wagner, West Coast Bureau Chief, Light Reading, 1/22/2015
    FiOS Picks Up Pace Again
    Alan Breznick, Cable/Video Practice Leader, 1/22/2015
    Verizon Ready for Google MVNO Challenge
    Dan Jones, Mobile Editor, 1/22/2015
    Indiana Carrier Takes Fiber to the Farm
    Jason Meyers, Senior Editor, Gigabit Cities/IoT, 1/22/2015
    The New Internet Space Race: Google's Final Frontier?
    Dan Jones, Mobile Editor, 1/21/2015
    Like Us on Facebook
    Twitter Feed
    Webinar Archive