News
2/3/2009
03:40 PM
George Crump
George Crump
Commentary
50%
50%

Archives Dirty Little Secret

If you have read this blog for any length of time, you know that I am a big believer in archiving. Moving data off primary storage and onto a disk-based archive just makes sense and saves dollars. That said, there is one downside to archiving; you have to really like your choice of archive solutions (software and hardware) because leaving IS painful.

If you have read this blog for any length of time, you know that I am a big believer in archiving. Moving data off primary storage and onto a disk-based archive just makes sense and saves dollars. That said, there is one downside to archiving; you have to really like your choice of archive solutions (software and hardware) because leaving IS painful.For example, if you have e-mail archive software A and want to switch to e-mail archive software B, you are facing a difficult if not impossible migration scenario. In reality, most companies either don't migrate and put up with what they have OR they run parallel systems until the archive under software A's management expires and in archive especially that can be a long time.

The situation is almost always the same for hardware. Some of the solutions that don't use proprietary access like Bycast or Permabit, which use standard NFS/CIFS access, are less difficult, but others can be a challenge, again often leaving the decision to run both systems in parallel or living with what is in place.

Both of these situations made it critical for customers when selecting an archive solution to be very sure of their selection before committing to it fully. The problem is, of course, that production archive solutions are very hard to simulate during evaluation. What is needed is a way out...

Most software solutions that have attempted this are very manual, put stress on the e-mail infrastructure, and do not provide message authenticity. Finally, software companies like Procedo are providing the capability to migrate between both archive software and archive hardware solutions, as well as filling the gap in standard file migration.

Migration of archives is a task that requires a lot of consideration, and the software application that performs this service needs to be aware of those considerations as well. For example, maintaining compliance and chain of custody of the archive during the migration is critical. You built an archive to be prepared for litigation; you don't want your archive migration to expose you to more.

Solutions like this also should provide a "fail-safe" option. If during the migration process you find a weakness in your new archive solution, you need the ability to opt out. Again, you can only test so much -- there is a big difference in evaluating an archive with a couple hundred GB's of test data and a multi-TB archive in production. Solutions like this could have value just in helping you securely evaluate a new archive solution.

Archive migration is one of the key missing ingredients in broader archive adoption. It enables the ability to change your mind and keep up with new innovations in archive software and hardware. This means choice and increased customer satisfaction. Once suppliers know you have a way out, they can't take you for granted.

To understand more about Primary Storage Optimization, register for our Webinar.

Track us on Twitter: http://twitter.com/storageswiss.

Subscribe to our RSS feed.

George Crump is founder of Storage Switzerland, an analyst firm focused on the virtualization and storage marketplaces. It provides strategic consulting and analysis to storage users, suppliers, and integrators. An industry veteran of more than 25 years, Crump has held engineering and sales positions at various IT industry manufacturers and integrators. Prior to Storage Switzerland, he was CTO at one of the nation's largest integrators.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5027
Published: 2014-12-26
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2062. Reason: This candidate is a reservation duplicate of CVE-2010-2062. Notes: All CVE users should reference CVE-2010-2062 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2010-1441
Published: 2014-12-26
Multiple heap-based buffer overflows in VideoLAN VLC media player before 1.0.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) A/52, (2) DTS, or (3) MPEG Audio decoder.

CVE-2010-1442
Published: 2014-12-26
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.

CVE-2010-1443
Published: 2014-12-26
The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format...

CVE-2010-1444
Published: 2014-12-26
The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted archive.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.