Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Symantec Adds Crypto to Backup

Touts backup server encryption as the cure to users' tape traumas

Dec 12, 2006 | 07:40 AM

By James Rogers
DarkReading

Symantec today unveiled backup encryption software that it claims will keep IT managers and CIOs out of the storage snafu hall of shame. (See Symantec Expands Data Encryption.)

The vendor is touting its clumsily titled Veritas NetBackup Media Server Encryption Option (MSEO) as a way for firms to encrypt backup data before they shift it off to tape. In doing so, Symantec joins the growing list of vendors looking to tap into users' growing tape paranoia. (See On the Brink of Storage Disaster, Security Smorgasbord on Show and CA Faces Backup Flaw.)

Lost tapes are now almost as much of an IT security cliché as lost laptops thanks to a string of high-profile incidents involving the likes of Time Warner, Los Alamos National Lab and NASA. (See Tape Security Trips Up Users, Can't Quite Kick the Tape Habit, Los Alamos Fallout Continues, NASA Goes to the Dark Side, and Search Results Get Safer: AOL Edges Google.)

Although Symantec describes the software as running on a media server, the vendor is not referring to video and broadcast products from vendors like AVID and Ciprico. (See Storage Grabs Video Limelight, AVID Intros Open Storage, and Ciprico Unveils Enhancements.) Rather, Symantec means a traditional server which backs up data from client devices such as desktops, laptops, and other servers. This, in turn is connected to a tape library or tape drive where the data is stored.

The idea behind today's announcement is that users can encrypt data on the server rather than on the client device, which is the approach taken by IBM's Tivoli Storage Manager. Symantec told Byte and Switch that doing the encryption on the backup server is more efficient than on the client because the server typically has extra CPU cycles, which frees the client up for other operations.

At least one analyst agrees with this approach. "The benefit of moving [the encryption] onto the media server is that it's dedicated to backup, so it will have a lot more capacity than the server you are looking to protect," says Stephanie Balaouras, senior analyst at Forrester Research. IBM, for its part, was unavailable for comment.

Symantec also claims that it is the first backup software vendor to offer encryption on the media server, although Vormetric's CoreGuard offering also encrypts data on the server. And it's an OEM'd version of this product that forms the basis of Symantec's MSEO, although one analyst told Byte & Switch that this could make life easier for IT managers.

MSEO at least removes the hassle of running Vormetric on your server and ensuring that it links up with other backup products and client devices, according to John Oltsik, senior analyst at the Enterprise Strategy Group. "It makes sense to let Symantec do the integration for you," he said.

Users deploying the software, though, will still need to allocate CPU power to it, which makes it slower than using a dedicated encryption device from NetApp/Decru or NeoScale. (See NeoScale Claims Speedy Encryption, Decru Selects Mu, Decru, Sepaton Team, and NeoScale Faces Up to 4-Gig Encryption.)

"There is some processing power that's needed, but the price of the encryption drive is prohibitive for some customers," says Mike Adams, manager of Symantec's NetBackup group.

Pricing for Symantec's MSEO starts at $5,000 for every Windows or Linux client per server, and $10,000 for each Unix client. Key management costs an additional $10,000. Pricing for NeoScale's recently launched 4-Gbit/s CryptoStor FC 712 encryption device, in contrast, is around $45,000.

Encrypting at the tape drive level can also prove expensive. An encrypted Fibre Channel version of Sun's T10000 drive, for example, is priced at $42,000. (See Sun Encrypts Tape Drive and Sun Fills in Storage Crypto Details.)

The cost benefits touted by Symantec, though, depend on the number of client devices used, warns Balaouras. "If you're talking about a number of licenses, it could quickly add up," she says.

The analyst told Byte & Switch that, despite the cost, some of the key management features offered within MSEO could benefit users. (See What's the Key to Excellent Encryption?.) The software, for example, can centralize key management to a specific device and automatically track which key has been used for each tape.

"Traditionally that has been the advantage of going with the more expensive encryption devices like NeoScale or Decru that are very strong in key management," says Balaouras.

MSEO will be available next month.

— James Rogers, Senior Editor, Byte and Switch

  • Avid Technology Inc. (Nasdaq: AVID)
  • Ciprico Inc. (Nasdaq: CPCI)
  • Decru Inc.
  • Enterprise Strategy Group (ESG)
  • Forrester Research Inc.
  • IBM Corp. (NYSE: IBM)
  • NeoScale Systems Inc.
  • Symantec Corp. (Nasdaq: SYMC)
  • Time Warner Inc. (NYSE: TWX)
  • Vormetric Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)