Vulnerabilities / Threats

7/17/2017
08:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New IBM Mainframe Encrypts All the Things

Next-generation Z series features the elusive goal of full data encryption - from an application, cloud service, or database in transit or at rest.

In the first major mainframe announcement by IBM in a decade, the company today unveiled its next-generation Z series that supports full-blown encryption for data via applications, cloud, and databases rather than today's more common practice of pockets of crypto.

Encryption remains a high bar for many organizations to deploy en masse; it's more often deployed at specific layers or portions of the data flow. And yes, mainframes are still a thing: The majority of credit card transactions run on IBM mainframes today, and other financial, insurance, and travel transactions still rely on the big ol' iron. IBM enlisted experts and customers from 150 different companies in building the architecture of the new Z system, including ADP and Highmark Healthcare.

"The challenge everyone has is it was too expensive to encrypt all of this … not really [expensive] in money, but I mean in processing time," says Caleb Barlow, vice president of threat intelligence at IBM Security. Transaction-based systems can't afford degradation of performance or user experience, he says. "When you're moving money or visiting an ecommerce website ... the encryption and decryption" steps can slow the process, he says.

So in most cases, encryption happens between the Web browser and the application server, or in a storage array. After each step of the data flow, the data is decrypted, so it doesn't remain locked down.

The Z system keeps data encrypted across the board, from the network to the storage array, in what IBM calls "pervasive" encryption, explains Barlow.

IBM engineered encryption into the Z's postage-stamp sized silicon processor: there are 6 billion transistors there dedicated to encryption processing, he says. "The machine doesn't slow down when it's asked to encrypt and decrypt" data, he says. The only time it's decrypted is when an organization needs to work with the data.

The encryption engine supports symmetric and asymmetric encryption algorithms including AES, DES, TDES, RSA, DSA, ECC, and ECDSA, as well as CMAC and HMAC for message authentication, and SHA2 and SHA3 hashing algorithms.

The IBM Z, which sells for around $500,000 and ships this quarter, can run more than 12 billion encrypted transactions per day, and includes what IBM calls "tamper-responding" encryption keys that kills keys if there's a sign of an attack so they can't be stolen; it restores them when the coast is clear.

Mainframes, while less prevalent these days, are still juicy targets for attackers. Researchers at Trend Micro recently discovered IBM Z Series mainframes (aka OS/390 machines) and IBM iSeries (aka AS/400 mainframes) left exposed on the public Internet, half of which were in the US. Exposed File Transfer Protocol (FTP) ports were the culprit in many of the cases.

Trend Micro's researchers say mainframes are at risk of what they call "business process compromise" attacks, where attackers infiltrate an organization and modify its mainframe transaction processes in order to siphon money surreptitiously.

John Clay, director of global threat intelligence communications at Trend Micro, says many exposed systems discovered via Shodan scans are misconfigured in some way. "The nice thing in what we hope to see with the IBM [Z] announcement is that an organization using the Z can implement encryption of the data at rest or in transit so that with any type of compromise" the data can't be stolen because it's encrypted, Clay says.

But don't expect an all-encrypted data world anytime soon. "It's going to take a while to get these systems in place," Trend's Clay notes. But it could bring about a "sea change" in the encryption space, he says.

The Ponemon Institute's recent Global Encryption Trends Study found that in the past 11 years, the ratio of organizations with enterprise-wide encryption strategies has doubled, from less than 20% to over 40%. They mostly employ an ad-hoc encryption strategy to date: 61% of organizations encrypt employee and HR data; 56%, payment data; 49%, financial records; and 40%, customer data, according to the report.

Related Content:

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Charlie Babcock
100%
0%
Charlie Babcock,
User Rank: Ninja
7/18/2017 | 1:37:45 PM
Mainframes a bridge too far for hackers
Mainframe operating systems have many built in security measures, and have proven a bridge too far for hackers, so far. That's why they're still in use at major banks and insurance companies. Adding encryption of all data will lock in that reputation for security and keep mainframes running applications into the next century.
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12716
PUBLISHED: 2018-06-25
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its l...
CVE-2018-12705
PUBLISHED: 2018-06-24
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
CVE-2018-12706
PUBLISHED: 2018-06-24
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
CVE-2018-12714
PUBLISHED: 2018-06-24
An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial o...
CVE-2018-12713
PUBLISHED: 2018-06-24
GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that already exists, as demonstrated by the gimp_write_and_read_file function in app/tests/test-xcf.c. This might be leveraged by attackers to overwrite files or read file content that was ...