& cplSiteName &

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre
6/12/2014
50%
50%

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
    Light Reading’s Upskill U is a FREE, interactive, online educational resource that delivers must-have education on themes that relate to the overall business transformation taking place in the communications industry.
    NEXT COURSE
    Wednesday, August 3, 1:00PM EDT
    The Central Office Re-Architected as a Data Center
    Guru Parulkar, Executive Director, Open Networking Research Center, Open Networking Lab
    UPCOMING COURSE SCHEDULE
    Wednesday, August 10, 1:00PM EDT
    Telcos & Open Source 101
    Phil Robb, Senior Technical Director, OpenDaylight
    Friday, August 12, 1:00PM EDT
    The Role of Open Source in NFV
    Jim Fagan, Director, Cloud Practice, Telstra
    Wednesday, August 17, 1:00PM EDT
    Using Open Source for Data Centers and Cloud Services
    Roz Roseboro, Senior Analyst, Heavy Reading
    in association with:
    From The Founder
    Light Reading today starts a new voyage as part of a larger Enterprise.
    Flash Poll
    Live Streaming Video
    Charting the CSP's Future
    Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
    Women in Comms Introduction Videos
    Fujitsu Sales Leader Shares Lessons Learned

    7|27|16   |   5:12   |   (0) comments


    As Fujitsu's only female sales leader, Annie Bogue knows the importance of asking for what you want, being flexible (she's been relocated five times), keeping a meticulous calendar, 'leaning in,' working harder than everyone else around you, being aware and more.
    Telecom Innovators Video Showcase
    VeEX Test & Measurement Solutions

    7|25|16   |   08:57   |   (0) comments


    Cyrille Morelle, president and CEO of VeEX Inc., talks test and measurement with Light Reading's Steve Saunders at BCE 2016. This includes innovative products such as VeSion Cloud-Based platform for network monitoring; MTTplus Modular Test platform for Access, Business, Carrier Ethernet, Transport and Core services; and OPX-BOX+ for Fiber Optics.
    LRTV Custom TV
    VeEX: Live From BCE 2016

    7|25|16   |   03:20   |   (0) comments


    VeEX's Senior Director of Business Development, Perry Romano, explains how VeEX provides tools to help install, maintain, monitor and manage network infrastructure efficiently and effectively. The portfolio of products on display include the RXT-6000, MTTplus and TX300s.
    LRTV Custom TV
    Real-Time Telemetry & Analytics for Intelligent SDN Orchestration

    7|25|16   |   03:09   |   (0) comments


    Packet Design CEO Scott Sherwood discusses how real-time network telemetry and analytics are enabling a new breed of SDN orchestration applications.
    From the Founder
    The Russo Report: Driving Disruption

    7|25|16   |   07:44   |   (0) comments


    In the first episode of a four-part series, Light Reading Founder and CEO Steve Saunders and Calix President and CEO Carl Russo drive around town discussing the disruptive mega-changes in the communications industry and where hope lies for service providers to meet the escalating demands of the cloud.
    LRTV Custom TV
    NetScout: Maximizing Enterprise Cloud for Digital Transformation

    7|20|16   |   04:53   |   (0) comments


    Light Reading Editor Mitch Wagner talks to NetScout CMO Jim McNiel about maximizing the benefits of enterprise cloud and digital transformation while minimizing potential pitfalls with a proper monitoring and instrumentation strategy.
    Women in Comms Introduction Videos
    Ciena's VP Offers a Career Crash Course

    7|20|16   |   4:14   |   (2) comments


    How did Ciena's Vice President of Sales, Angela Finn, carve out her career path? Simple, she tells WiC. She stayed true to her company, customers and principles. She shares her advice for women on how to be authentic and credible, as well as for companies that want to make a real change to their culture and practices.
    LRTV Custom TV
    NFV in 2016: Part 2 – Climbing the Virtualization Maturity Curve

    7|19|16   |   06:56   |   (0) comments


    Many of the initial use case implementations are single-vendor and self-contained. The industry is still climbing the virtualization maturity curve, needing further clarity and stability in the NFV infrastructure (NFVi) and greater availability and choice of virtualized network functions (VNFs). Interoperability between NFVis and VNFs from different vendors ...
    Telecom Innovators Video Showcase
    Versa Networks' Kumar Mehta on SD-WAN Managed Services

    7|19|16   |     |   (0) comments


    In Silicon Valley, Steve Saunders sits down with Versa's Kumar Mehta for an interview focused on why service providers are building SD-WAN managed services, and how Versa's telco customers are innovating.
    LRTV Custom TV
    Juniper Networks & The Evolution of NFV

    7|19|16   |   06:01   |   (0) comments


    Senior Juniper Networks executives talk to Light Reading Founder & CEO Steve Saunders about NFV developments and the recent independent evaluation by test lab EANTC of Juniper's Cloud CPE solution.
    LRTV Interviews
    CenturyLink Goes Beyond Managed WiFi

    7|19|16   |     |   (0) comments


    CenturyLink's managed WiFi allows enterprises, such as retailers and resorts, to track guest WiFi usage in order to help them better communicate with customers.
    LRTV Interviews
    AT&T Launches Network Functions on Demand

    7|17|16   |   05:26   |   (0) comments


    Roman Pacewicz, Senior Vice President, Offer Management & Service Integration, AT&T Business Solutions, discusses the operator's launch of its Network Functions on Demand service.
    Upcoming Live Events
    September 13-14, 2016, The Curtis Hotel, Denver, CO
    September 27, 2016, Philadelphia, PA
    November 3, 2016, The Montcalm Marble Arch, London
    November 30, 2016, The Westin Times Square, New York City
    December 6-8, 2016,
    May 16-17, 2017, Austin Convention Center, Austin, TX
    All Upcoming Live Events
    Infographics
    Five of the Top 10 most targeted countries in Check Point Software Technologies' global Malware & Threat Index for Q1 2016 are in Africa.
    Hot Topics
    Verizon Sports Big Plans for Yahoo
    Alan Breznick, Cable/Video Practice Leader, Light Reading, 7/26/2016
    Yahoo Signing Off in $4.83B Sale to Verizon
    Mari Silbey, Senior Editor, Cable/Video, 7/25/2016
    Ericsson Board Has Been Asleep at the Wheel – Consultant
    Ray Le Maistre, Editor-in-chief, 7/25/2016
    Ericsson Ejects CEO Vestberg
    Ray Le Maistre, Editor-in-chief, 7/25/2016
    Is Dish Going Down the Drain?
    Alan Breznick, Cable/Video Practice Leader, Light Reading, 7/21/2016
    Like Us on Facebook
    Twitter Feed
    BETWEEN THE CEOs - Executive Interviews
    There's no question that, come 2020, 5G technology will turn the world's conception of what mobile networking is on its head. Within the world of 5G development, Dr. ...
    I've enjoyed interviewing many interesting people since I rejoined Light Reading, but William A. "Bill" Owens certainly takes the biscuit, as we say where I come from.
    Animals with Phones
    Live Digital Audio

    Our world has evolved through innovation from the Industrial Revolution of the 1740s to the information age, and it is now entering the Fourth Industrial Revolution, driven by technology. Technology is driving a paradigm shift in the way digital solutions deliver a connected world, changing the way we live, communicate and provide solutions. It can have a powerful impact on how we tackle some of the world’s most pressing problems. In this radio show, Caroline Dowling, President of Communications Infrastructure & Enterprise Computing at Flex, will join Women in Comms Director Sarah Thomas to discuss the impact technology has on society and how it can be a game-changer across the globe; improving lives and creating a smarter world. Dowling, a Cork, Ireland, native and graduate of Harvard Business School's Advanced Management Program, will also discuss her experience managing an international team focused on innovation in an age of high-speed change.