Light Reading

AT&T's Amoroso: Perimeter Security No Longer Enough

Ray Le Maistre

The days of networks being adequately protected by "perimeter" security infrastructure are over, according to AT&T Chief Security Officer Ed Amoroso.

In a special video presentation recorded by AT&T Inc. (NYSE: T) for Light Reading's recent Mobile Network Security Strategies event in London, Amoroso provided a detailed insight into the different stages "we're going through as a community -- a mobility community, telecom community, and as users."

In the past, perimeter security that was built using devices such as firewalls and intrusion detection systems "sufficed," and served us well as a community, notes the AT&T expert, but in those days mobility wasn't an issue.

The mass use of mobile phones led to the concept of network-based security, though this was driven more initially by the exploits of "advanced hackers" breaching perimeters and "being able to muck around with things inside the enterprise." This resulted in security strategies that involved thwarting attacks before they reached the edge of the enterprise network.

Now we're in a new phase, says Amoroso, where mobility-enabled cloud is enabling user-defined services for individuals and companies, and "mobility is how we breathe life into that." And the key issue now is "how can we not be a tether" -- there is no point in constraining smartphone users and tethering them to the enterprise if perimeter security strategies are no longer working, he states.

AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.
AT&T's Ed Amoroso has a firm grasp on the security challenges faced by mobile network operators.

As we enter the era of the mobility-enabled cloud, the technologies that will be important, and which will enable user freedom in a secure environment, are:

  • Encryption: "Why not encrypt everything?" asks Amoroso. That comes with the burden to get public key infrastructure and single key infrastructure correct, but "that's very difficult to do."

  • Containerized technology: Enabling secure authorized access whereby a "session" protects the integrity of an access (for example, an employee accessing an online paycheck stub) and then provides the ability to wipe data from a device once it has been accessed and used, so that evidence of the session no longer exists on the device.

  • Proxy: A mediation layer between the cloud and users, where certain types of things can be mediated. Amoroso certainly believes denial of service should be included in that proxy.

  • Run-time virtualization: This is probably more important than anything, believes Amoroso. As you virtualize an entity into the cloud -- an app, for example -- then you need to virtualize security in a virtual environment, not try to protect it with old-fashioned security devices. The idea that network operators will dynamically provision security along with the other objects that are being provisioned into the cloud is "really exciting," says the AT&T security chief.

    "Put all those things together and I fundamentally believe you can protect the mobility-enabled cloud environment better than we can protect information inside perimeters today," proclaims Amoroso. "That's a controversial statement… [but] -- there will be those that believe compliance is most important but we need to get everyone on board here -- perimeter is not working today, advanced persistence threats are making their way through, denial of service attacks render edge computing difficult to maintain."

    He adds that embedding security into the object's run-time systems is something "we hope that compliance officers and regulators will become comfortable with, because the whole idea here is to make computing safer. It's not about checklists -- it's about using the checklists to make computing support the different missions that are important to all of us. That's our vision for the future -- this futuristic prediction that's becoming real now, going from perimeter, through network-based, to a mobility-enabled cloud where we feel more comfortable pushing our information out into something more ubiquitous and more separated and hopefully protected by run-time virtualized security functionality."

    Amoroso goes on to discuss further mobile cloud security and analytics issues with his colleagues Gus De Los Reyes, executive director, security R&D at AT&T, who runs the security research group, and executive director of technology security Brian Rexroad. Find out what they had to say, and see the full presentation by Amoroso by watching the video, AT&T's Ed Amoroso on Mobile Security.

    You can also find out what else happened at the Mobile Network Security Strategies event in London by checking out our dedicated industry show site.

    — Ray Le Maistre, Circle me on Google+ Follow me on TwitterVisit my LinkedIn profile, Editor-in-Chief, Light Reading

    (0)  | 
    Comment  | 
    Print  | 
  • Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
    From The Founder
    The comms industry is rallying to the cause of open, independent interoperability testing.
    Flash Poll
    Live Streaming Video
    CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
    Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
    LRTV Interviews
    AT&T's Chiosi on the Potential of Open Source

    10|6|15   |   06:27   |   (0) comments

    AT&T Distinguished Network Architect Margaret T. Chiosi talks to Light Reading's Carol Wilson about the potential for open source technology to liberate communications service providers.
    LRTV Interviews
    Network Security in a Gigabit World

    10|6|15   |   05:52   |   (0) comments

    Masergy's James Harrison talks about some of the network security and data center issues network operators need to consider as they expand their broadband services portfolios.
    LRTV Documentaries
    Telefónica: In Search of Virtual Simplicity

    10|5|15   |   07:30   |   (0) comments

    Francisco-Javier Ramon Salguero, head of Telefónica's NFV initiative, admits virtualization initially means greater complexity, but with the right abstraction layer, it is possible to create a services-driven network architecture. He explains how Telefónica's current trials and initiatives are aimed at doing that, and what his company and other carriers need to ...
    LRTV Interviews
    Gigabit Europe Takeaways

    10|5|15   |   03:47   |   (0) comments

    Participants from the inaugural Gigabit Europe event in Munich share their key takeaways from the conference.
    Women in Comms Introduction Videos
    Intel Urges Women to Take Advantage of Their Seat at the Table

    10|5|15   |   4:27   |   (1) comment

    Have inclusive and constructive conversations, attach a bigger meaning to your work and get involved in the cause, Intel's Monique Hayward advises women in comms.
    LRTV Interviews
    BT Updates on Plans

    10|2|15   |   03:16   |   (2) comments

    Peter Bell, CIO at Openreach, the access network division at UK incumbent BT, provides an update on the operator's trials and how Openreach is planning to deploy the broadband technology in its street cabinets.
    Telecom Innovators Video Showcase
    Sonus Shakes Up SD-WAN

    10|2|15   |   7:22   |   (0) comments

    Sonus CTO Kevin Riley sat down with Light Reading to discuss the trajectory of the company, its SDN ambitions and why Sonus is taking a market-disruptive approve to SD-WAN.
    LRTV Interviews
    CityFibre's Gigabit Vision

    10|1|15   |   03:18   |   (1) comment

    Mark Collins, director of Strategy & Public Affairs at competitive UK city network operator CityFibre, talks about his company's plans to help build Gigabit Cities.
    Telecom Innovators Video Showcase
    Automate, Scale & Create With Juniper's vCPE Solution

    10|1|15   |   6:34   |   (0) comments

    Join Kireeti Kompella, Juniper Networks CTO, and Steve Saunders, Light Reading Founder and CEO, as they discuss Juniper Networks' approach to NFV showcased with a turnkey vCPE solution, which demonstrates how service providers can use automation to rapidly deploy services.
    LRTV Interviews
    Gigabit Europe: Day 1 Takeaways

    9|29|15   |   05:47   |   (5) comments

    Light Reading's Ray Le Maistre and Iain Morris sup a beer and discuss some of the key takeaways from the first day of Gigabit Europe 2015.
    LRTV Interviews
    Gigabit in Europe

    9|29|15   |   04:24   |   (0) comments

    At the Gigabit Europe 2015 event in Munich, Heavy Reading's Graham Finnie talks about the availability of gigabit broadband in Europe.
    Women in Comms Introduction Videos
    AT&T's Band of Women

    9|28|15   |   4:36   |   (0) comments

    Brooks McCorcle, the president of AT&T's partner solutions divisions and a mathematician by trade, shares stats on AT&T's diversity and advice on how to create your own band of women at work.
    Upcoming Live Events
    October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
    November 5, 2015, Hilton Santa Clara, Santa Clara, CA
    November 17, 2015, Santa Clara, California
    December 1, 2015, The Westin Times Square, New York City
    December 2, 2015, The Westin Times Square, New York City
    All Upcoming Live Events
    Communication service providers realize that an ICT transformation is critical to their long-term survival, but most haven't yet committed to making it happen.
    Hot Topics
    Verizon's Go90 Is Live – Will Anyone Watch?
    Mari Silbey, Senior Editor, Cable/Video, 10/1/2015
    Eurobites: Dunroamin'
    Paul Rainford, Assistant Editor, Europe, 10/2/2015
    Sprint to Cut Up to $2.5B in 6 Months
    Sarah Thomas, Editorial Operations Director, 10/2/2015
    McKinsey: Women Less Likely to Advance at Work
    Sarah Thomas, Editorial Operations Director, 10/1/2015
    TiVo Takes Aim With Bolt
    Mari Silbey, Senior Editor, Cable/Video, 9/30/2015
    Like Us on Facebook
    Twitter Feed
    Webinar Archive
    BETWEEN THE CEOs - Executive Interviews
    With so many new and exciting communications technologies now under development, it's easy to get caught up in the industry's escalating hype cycle. That's why the ...
    Last week saw a big day in the 15-year history of Light Reading when Editor-in-Chief Ray Le Maistre and I were invited to interview the Deputy Chairman and Rotating ...
    Cats with Phones
    Hold My Calls, Indefinitely Click Here