Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Sunday, February 14, 2016

Cisco to showcase Security Everywhere strategy at GISEC 2016

Cisco announced its participation in the Gulf Information Security Expo & Conference (GISEC 2016) which will be held at Dubai World Trade Centre from 29th to 31st March 2016.

The company aims to showcase and deliver its strategy of Security Everywhere – from the cloud, network and endpoints with new security products and features and a threat awareness service as organisations execute on their digital transformation.

According to Cisco, they will be extending Security Everywhere with new capabilities and services that deliver greater visibility, context and control from the cloud to the network to the endpoint, for organisations of all sizes. At GISEC 2016, the company will demonstrate and showcase how its products and solutions can support its customers safely and securely through digital transformation and how they can weave in the security techniques and deployment as part of it. The value of Cisco architecture is its emphasis on embedding security spanning the extended network – including routers, switches and the data center – closing gaps across the attack continuum – before, during and after – and significantly reducing time to detection and remediation.

Thursday, January 30, 2014

Globalstar's new service turns your WiFi device into a satellite phone

Globalstar satellite
Your choices for satellite communication devices are relatively limited, especially if you'd prefer to use your own gear while chatting in the wilderness. You're going get a much wider selection of hardware once Globalstar's Sat-Fi service goes live, though. The subscription offering revolves around a satellite hotspot (not yet pictured) that lets you make calls and send data on Globalstar's network using most any WiFi-capable device. You can share the connection between multiple gadgets, and you can even use an existing phone number. Just be patient if you're eager to sign up for an always-available data link. The company doesn't expect the FCC to approve the hotspot until some time in the second quarter of the year, and you'll have to wait until shortly afterward to use the service itself.

Monday, July 22, 2013

MIT researchers teach TCP new tricks with software named Remy

Remy automatically generates congestion-control algorithms for dramatically improved speeds and lower latency.

A sophisticated piece of software called Remy can be used to manage network communications with unprecedented precision, creating new protocols and controls on the fly in order to wring maximum efficiency out of a network.
Remy is the brainchild of MIT professor Hari Balakrishnan and graduate student Keith Winstein, who are scheduled to present a paper entitled “TCP ex Machina: Computer-Generated Congestion Control” at an Association for Computing Machinery conference this summer.

Black Hat: Top 20 hack-attack tools

pcoming Black Hat conference is a goldmine of tips for hacking just about anything.

Network World - Turn someone else’s phone into an audio/video bug. Check.
Use Dropbox as a backdoor into corporate networks. Check.
Suck information out of pacemakers. Check.
The Black Hat conference convening in Las Vegas next week offers hacker tools for all of those plus more.
Intended to provide good-guy researchers with tools to test the security of networks and devices, the free tools distributed at the conference can also be used by the bad guys to break into networks, steal data and thwart defenses designed to expose malware halt attacks.

Wednesday, June 26, 2013

SK Telecom launches the world's first LTE-Advanced network, and the Galaxy S4 LTE-A

SK Telecom launches the world's first LTEAdvanced network, and the Galaxy S4 LTEA
Just days after an LTE-Advanced variant of Samsung's Galaxy S 4 leaked, Korean carrier SK Telecom has officially announced it's launching the world's first publicly available LTE-Advanced wireless network. The Galaxy S4 LTE-A is also official (in red or blue) as the first device able to take advantage of the new technology for even faster data transmission speeds. According to the press release, SK Telecom plans to have as many as seven LTE-A devices available by the end of the year, all capable of up to 150Mbps. While SK Telecom is using Carrier Aggregation and Coordinated Multi Point technology to improve speeds right now, it will add Enhanced Inter-Cell Interference Coordination in 2014 to go even faster. After that, it suggest carrier aggregation will improve to support higher speeds and faster uploads in subsequent years.
To take advantage of the higher speeds, SK Telecom's Btv IPTV service will begin offering 1080p video streaming in early July. That will be accompanied by enhanced multiview baseball broadcasts, more free videos, an HD video shopping service with six channels on one screen in August and the addition of FLAC audio files via its music package. Right now, the company has Seoul covered in LTE-A, and plans to eventually offer it in 84 cities, all at the same price as existing LTE service. Check after the break for the press release with all the details, plus video of a speed test.
Update: We've just come across another juicy tidbit that makes the Galaxy S4 LTE-A all the more worthwhile... it'll ship with a Snapdragon 800 SoC that contains a 2.3GHz quad-core CPU. It goes without saying that this phone will be speedy on all angles.

Tuesday, June 25, 2013

Cisco delivers "monster" Catalyst switch in major product refresh

Programmable and optimized for 10/40/100G, Cisco Catalyst 6800 line still does not yet retire the decade-old Cat 6500

Cisco this week will significantly update its enterprise network line-up with programmable campus and branch switches and routers designed to tightly bind applications to network hardware and services.
The new products include the Catalyst 6800 backbone switching line, a new supervisor engine for Cisco’s 4500-E chassis-based access switch, a new high-end ISR branch router and application performance extensions to the ASR 1000 edge router.
Cisco 6800
Cisco 6800
“Cisco has…delivered a monster Catalyst,” says Bill Carter, senior business communications analyst at value-added reseller Sentinel Technologies in Springfield, Ill. “This gives customers a core switch with 10G/40G/100G with the feature set required in the campus.”
The company, which this week hosts itsCisco Live event in Orlando, says its new products fit within an Enterprise Network Architecture under which applications, network services software and hardware networking functions all work together.
Much of this synergy is facilitated by Cisco’s ONE API framework for programmable networking and associated ASICs optimized for Cisco ONE programmability. Cisco ONE and its onePK API set is Cisco’s response to software-defined networking (SDN), in which many of the functions of network behavior are divorced from hardware and centrally administered by software controllers.
SDN makes network functions less reliant on specific hardware and operating systems, and more accommodating to commodity switching and open source software. It threatens Cisco’s dominance and fat profits in routers and switches.
Cisco is combatting the SDN trend by attempting to tightly link software programmability of network infrastructure to custom-developed ASIC hardware and hardware-specific operating systems, and defending its incumbency and massive installed base. These new products are instantiations of that strategy.

Monday, June 24, 2013

Every Network Failure Should Be Used to Improve the Network

Some advice for rebounding from network failure.

Let's accept reality. A network is so much more than just the sum of its electronic parts, operating systems, and configurations. It is an extension of the past and the present of our company. Much like the growth rings of a tree, we can look at our company's network and see all the human history of our company.  
That is probably why post-mortems are so hard and completely avoided or unproductive. People often bring much "baggage"  to the post-mortem. Agendas, politics, silos, likes, dislikes, fears. The list goes on and on. How can the post mortem possibly get anywhere? 
But of course, we've all heard the expression "Nothing changes if nothing changes."
Do you know how muscles grow bigger and stronger? During a workout you develop microscopic tears in your muscle fiber. Your body works to repair the damage. Voila. Muscle growth. No judgement. No thinking "that shouldn't have failed." Just the focus on the response.
Think of your network. Don't you want that for your network? Seriously, imagine it. Take just one minute right now. Can you even picture what your network woud look like if "every network failure was used to improve the network"? You can help to do that. You can help make the difference.   
While "speak softly, and carry a big stick” (Theodore Roosevelt) might have been a great foreign policy position, it is really something to be avoided in the conference room during a post-mortem. 

Monday, May 20, 2013

What Can Be Done About the Cybersecurity Skills Shortage?


IBM paper suggests changes are needed in cybersecurity education to address this silent problem.


I’ve written countless times about the cybersecurity skills shortage but here’s a quick summary of a few ESG research data points that illustrate the scope of this problem: 1. 25% of mid-market (i.e. 100 to 999 employees) and enterprise (i.e. more than 1,000 employees) report a “problematic shortage” of IT security skills. 2. 36% of organizations increasing IT headcount this year plan to hire information security staff. Of all the IT headcount being added in 2013, hiring information security professionals is the highest of priority. 3. 83% of enterprise organizations say that it is “extremely difficult” or “somewhat difficult” to recruit and hire information security specialists. Those organizations having the hardest time include companies in rural areas, mid-market firms, and vertical industries like academia, and the public sector. I remain amazed and incredulous that the cybersecurity skills shortage gets so little attention but a few others are also screaming from the hilltops to get governments, the security industry, and educators to pay attention. For example, IBM recognizes that a dearth of cybersecurity skills presents a threat to its customers, its security business, and its services organization. Let’s face it; no one will build “smarter planet” applications if there aren’t a whole bunch of highly-skilled security professionals to keep them safe. IBM isn’t just assuming the role of Chicken Little and yelling about how the cybersecurity skills sky is falling. Rather, the folks in Armonk are actually trying to do something about it. For example, IBM just published a paper called, Cybersecurity Education for the Next Generation

Wednesday, April 10, 2013

Juniper to unveil programmable core switch for software-defined networking


Based on MX router, what becomes of Juniper's QFabric Interconnect, EX8200?

Juniper Networks is readying a new programmable core switch to address software-defined networking in campuses and data centers.
Sources say it is called the EX9200 and is based on the MX router. It comes in three configurations: 4-slot, 8-slot and 14-slot chassis, the same form factors as the company's successful MX 240, 480 and 960 routers for enterprises and service providers.
Juniper MX routers
Credit: Juniper
Sources say that the form factor of Juniper Networks' new programmable core switch is based on the company's MX family of routers, shown here.
An overview of it can be found here. Juniper confirmed it will be unveiling a "new, advanced switch" and offered an embargoed briefing, but Network Worlddeclined.
The EX9200 is based on custom silicon -- the Juniper One programmable ASIC. The MX 240, 480 and 960 are based on Juniper's I-Chip and Trio chipsets. The EX9200 will support 240G/slot, and 40xGigabit Ethernet, 32x10G, 4x40G and 2x100G interface line cards.
Programmability features, in addition to the Juniper One ASIC, include an XML- and Netconf-accessible automation toolkit, and Puppet, Python and OpenFlow interfaces.Puppet is an open-source operations management software system; Python is a programming language; and OpenFlow is a popular controller-to-switch protocol and API for SDNs.
SDNs are a way to make network more programmable through software so that they can be reconfigured quickly and functionally extended more easily.

Monday, April 1, 2013

How the world's largest cyberattack slows down your Internet use


A fight between anti-spam group Spamhaus and a Dutch web-hosting company has escalated into a large-scale DDoS attack


Websites take longer to load. Netflix cuts out. Normally you can blame those annoyances on a slow Internet connection speed, but this week, it's the result of the largest global cyberattack in history.
The European nonprofit spam filtering company Spamhaus reportedly is fending off DDoS, or distributed denial-of-service attacks, that briefly took the site offline (it is now back up) and is causing widespread congestion on the Web.
Spamhaus creates blacklists of servers that spammers use to send messages for e-mail providers, so providers can then filter spam for their users. The company had recently added the Dutch website hosting company CyberBunker and its ISP, A2B Internet, to its list.
The attack began March 18. Spamhaus was overwhelmed with traffic in a clear DDoS attack, and turned to the security team at CloudFlare to get the site back up and running. CloudFlare disclosed the technical details of the attack on March 20.

DDoS attack against Spamhaus overhyped, says website watcher Keynote


While agreeing DDoS speed was high, Keynote Systems says news media went too far in saying there was a 'slowdown' on entire Internet

 Much of the news reporting about the massive denial-of-service attack against anti-spam service Spamhaus over the past week or so went way too far in describing it as creating a slowdown on the Internet itself, says one company monitoring website performance.
The massive distributed denial-of-service (DDoS) attack on Spamhaus -- which has many enemies as it seeks to stop Internet spam -- was a stunning event in that at some point the DDoS attack reached 300 billion bits per second, which likely does make it the most intense DDoS attack in history in terms of sheer speed. But when many in the media somehow ended up reporting that this DDoS attack last week caused a global slowdown, that was simply wrong, says Keynote Systems, which does global monitoring of websites for performance.
The hundreds of websites that Keynote monitors showed no performance changes that were out of the ordinary at all, says Aaron Rudger, senior market manager at Keynote, which went back and closely compared U.S. Web performance to European performance to see if it could find evidence to support all these Internet slowdown assertions heard in both the European and U.S. the media.
Several news stories from the United Kingdom suggested that the whole Internet was ready to collapse. That idea was widely echoed in the U.S. news media as well.

VCs Jumping Back Into Security Investments


FireEye, Imperva, Palo Alto Networks and SilverTail success stories driving more interest in funding security startups.

It’s a herd mentality out on Sand Hill Rd. Over the past few years, VCs shied away from many infrastructure and security companies, preferring to bet on cloud computing, mobile computing, and social networking startups.
Now that these markets are saturated and somewhat stagnant, VCs have returned to the information security market like the swallows of Capistrano. According to PWC and the National Venture Capital Association, security funding in 2012 was up 60% over dollars committed in 2010. Judging by the crowds at the RSA Conference in February, I’m sure that VC investment will grow precipitously in 2013 as well.
Yup, security-focused VCs are busier than a Sommelier at Madera in Menlo Park. Why the change of heart? Money. The Sand Hill Road phat cats are willing to bet on security because they see:
• IPO success stories. Imperva, PAN, and Qualys have all gone public over the last few years while FireEye is warming up in the on-deck circle. Few, if any, other technology sectors share this kind of success.

Network Security Trumps Server Security in the Enterprise


Purchasing behavior and security organization focus has broad market implications

There is a historical conundrum in cybersecurity about where to concentrate security skills, controls, and oversight. Hackers penetrate networks in order to compromise hosts and steal data. Given this obvious workflow, should CISOs focus security resources on networks, hosts, or a balanced combination of both?
ESG recently posed this question to 395 security professionals working at mid-market (i.e. 100 to 999 employees) and enterprise (i.e. more than 1,000 employees) organizations. The results are extremely interesting:
• 58% said that network security processes, skills, and technical controls are “much more thorough” or “somewhat more thorough” than server security processes, skills, and technical controls.
• 37% said that network security processes, skills, and technical controls are no more or less thorough than server security processes, skills, and technical controls.

Saturday, January 26, 2013

After selling Linksys, Cisco aims to reach consumers through carriers


Though it's pushing off its big consumer unit, Cisco is following service-provider networks into homes

IDG News Service - Cisco Systems' sale of its home networking business to Belkin International marks the end of a 10-year odyssey through the world of consumer products, but the company plans to keep reaching consumers through their carriers and cable companies.
Belkin announced on Thursday that it would buy Cisco's Home Networking Business Unit, including its Linksys brand, for an undisclosed sum. The privately held maker of networking gear, peripherals and accessories plans to fold Linksys' employees and products into its operations while keeping the Linksys brand alive.
The deal, which is expected to close in March, has been in the cards since Cisco'sshutdown of its Flip video camera business in early 2011. The company made that move as it kicked off a major reorganization in response to disappointing business results. Since then, Cisco has been sharpening its focus on enterprises and service providers, and the writing has been on the wall for the consumer business. Next Thursday, the company will shut down the short-lived home telepresence service it offered in conjunction with its already-discontinued Umi device.

Tuesday, January 22, 2013

Virtual Networks in Windows 2012 and Azure VMs


Today's Foundational Building Blocks for a Microsoft-based Private and Public Cloud Environment

This article addresses a key function built-in to Windows 2012 that on first blush may seem like a complex technical networking feature, but that functionality has GREAT implications when extending your on-premise Windows to the cloud (like Azure VMs).  You don't recognize the value of Virtual Networking in Windows 2012 utnil you truly start to see where the functionality is CORE to an organization that in a few years (or sooner) have servers on-premise as well as in the cloud.  Given the direction of most organizations networks, that is basically ALL organizations in a very short period of time.  AND, this functionality built in to Windows completely changes the competitive advantage Microsoft has when it comes to having servers both on-premise as well as in the cloud.
So here’s the deal…  With Windows 2012, Microsoft included a thing called “Network Virtualization” that basically allows you to create a Virtual Local Area Network (VLAN) without having to buy VLAN hardware, setup complicated appliances, use a 3rd party product (ie: Cisco, Brocade, etc) to create these virtual networks.  The benefit of VLANs is to isolate traffic, so if you have your finance department that wants to be the ONLY ones to access a finance server / application, you can create a VLAN between finance users and the VM/app!  This becomes important when virtual servers are in play because if you have say 10 virtual guest sessions running on a single host server, and 12 VMs on another server, and say 8 on a third server, but a VM on each “host” should be “grouped together” so the finance department can access the 3 VMs without anyone else in the org accessing those servers, you would create a VLAN between the finance users and the VMs on each host server, makes sense…

Monday, January 21, 2013

Random security predictions for 2013


Lots of malware and industry activity but continuing intransigence in Washington

It’s January 15 which means I probably should have posted a blog on my security predictions for 2013. Here is a somewhat random list of things I believe will happen this year:
1. Visible increase in hacktivism. Hacktivists have a lot to build upon in 2013 including the tragic death or Aaron Swartz, some notable 2012 successes by Anonymous (ex. OpVendetta), the trial of PFC Bradley Manning, etc. There is also a growing trend toward global hacktivism against domestic organizations and the U.S. government. I expect at least one major hacktivism incident per month this year.
2. Continued cybersecurity waffling on Capitol Hill. It took the financial sword of Damocles to get Democrats and Republicans to compromise on legislation to avoid falling off the fiscal cliff at the eleventh hour. Regrettably, cybersecurity legislation lacks a similar trigger. Given the volume of cybersecurity breaches, we should hear a lot of rhetoric from both parties but Washington has bigger fish to fry and legislators aren’t anxious for geeky debates about things they don’t understand. The wild card is a major cybersecurity incident. If this happens, expect lots of finger pointing and a reactive bill that serves as the cybersecurity equivalent of the USA Patriot Act. In short, we can expect inaction or bad action from Washington and nothing more.

Big Data Security Challenges


Collecting massive amounts of security data is easy. Data analysis and visualization? Not so much.

According to ESG Research, 47% of enterprise organizations collect 6TB of security data or more on a monthly basis to support their cybersecurity analysis requirements. Furthermore, 43% of enterprise organizations collect “substantially more” security data then they did 2 years ago while an additional 43% of enterprise organizations collect “somewhat more” security data then they did 2 years ago.
Just what types of data are they collecting? Everything. User activities, firewall logs, asset data, vulnerability scans, DNS logs, etc. Most enterprises aren’t collecting, storing, and analyzing large volumes of network packets (i.e. Full-packet capture or PCAP) today but they will increasingly do so in the future. Once this happens, security data volume collection will take another quantum leap.
If this activity doesn’t signal the need for big data security analytics than nothing does. Nevertheless, CISOs’ need go beyond dumping a bunch of unstructured data in a Hadoop cluster.

Friday, May 25, 2012

The Four Lies of Networking


Commonly heard fallacies and half truths we've all encountered in networking.

Big Data and networking in general are all about numbers and statistics. We talk about our Petabytes of data, the number of packets per second and the Mbytes replicated in an hour. We want to know about the uptime percentages of our services and the time to repair on our circuits. We’re sold on loss ratios and round trip times.
And like statistics and their “Lies, damned lies,” as Mark Twain put it, networking has its own set of fallacies and half truths we’ve all run up against. Here are the four that bug me a bunch. I’d be interested in hearing which ones are on your hit list:

“Network performance is guaranteed by the SLA”

I love this one. Every one of the hundreds of IT managers I’ve spoken with in my 20 years of reporting on IT looked at SLAs as a necessary evil. You need something to hold your carriers accountable, but few expect the SLA to reflect the true conditions of the network and even fewer expected to collect on their agreements. SLAs will cover the carrier core not the last mile, where most of the problems occur. Some will promise zero percent packet loss, but that’s averaged over a months, not by minutes. Others might talk about 99.99% uptime in a year, which sounds great, but neglect to mention that equates to nearly an hour of downtime at any given moment. It’s for those reasons that finding a service provider with a straightforward SLA is so refreshing.

Cisco router rival invests in Cisco video foe


Juniper takes stake in Vidyo, maker of software-based telepresence for enterprises, clouds

Juniper has invested in Vidyo, a competitor of Cisco's in videoconfencing. Juniper is a strategic investor in Vidyo through its Junos Innovation Fund, which invests in software start-ups targeting emerging markets.
Terms of Juniper's stake were not disclosed but the Cisco rival joins lead investor QuestMark Partners and other existing investors Menlo Ventures, Rho Ventures, Star Ventures, and Four Rivers Group to raise Vidyo's funding to $97 million. Vidyo said Juniper's investment allows it to build up go-to-market activities and integrate its telepresence-style videoconferencing software with Juniper's routers and switches.
Vidyo has more than 1,850 enterprise, healthcare, education and government customers. Juniper views video as an expanding market, especially with mobile devices proliferating in enterprises, and is looking to have its products participate in it by integrating technology to improve the experience for business customers.

Wednesday, May 23, 2012

ALU expected to challenge Cisco, Juniper in core


Edge router rival ready for a core revival 10 years after dealing ACEIS

Alcatel-Lucent is reportedly ready to give Cisco and Juniper a run for the money in core routing. The company, which dukes it out with both in service provider edge routing, is about to pop a core router based on its 400Gbps FP3 processor, according to ITWire.
This would be ALU's second run at the core. Anyone remember the 7770 Routing Core Platform and7670 Routing Switch Platform with ACEIS? The 7770 was then respun into the 7770 Optical Branch Exchange.
Only the 7670 RSP appears to have survived from that fearsome foursome.
Ten Years After. Looks like the FP3 has inspired ALU to take another run at it. That, and its No. 2 or 3 position in edge routing. Observers are crowing about the potential of the FP3, according to the ITWire piece. Maybe it can correct the mistakes of the 7770 and ACEIS.
ALU will be re-entering a core router market that declined 7% in the first quarter, according to a bulletin issued this week from investment firm UBS. Cisco gained share in Q1, and now stands at 62% vs. 59% in 2011. Juniper's share declined by four percentage points, to 25% from 29% in Q1 of 2011. Huawei's share was flat at 10%.
UBS stated in its bulletin that ALU is "likely to enter mkt in 2012."
In the edge, the market grew 5% in Q1 to $1.6B, but shrank 6% from Q4 2011. Cisco had a 41% share in Q1, up 4% from last year, while Juniper grew share from Q4 but was down 3% from Q1 of 2011.  
ALU's share was up slightly in Q1 from a year ago, at 25% vs. 24%, but down from 26% in Q4.