Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/28/2014
08:28 AM
50%
50%

Securing The Distributed Network Perimeter

A variety of cloud and managed services can be used to lock down the rapidly expanding corporate network perimeter

The corporate network perimeter is not what is used to be.

A decade ago, companies focused on securing the perimeter, making sure that the inside of the network remained a safe, trusted environment, while attempting to create a digital wall to keep out the Internet vandals. Security professionals realized over time that defense in-depth should extend within the network because attackers inevitably get inside. In addition, with employees bringing in mobile devices and nomadic employees working from a variety of unsecured locations outside of the corporate network, the definition of the perimeter has changed.

Analysts and some security firms talked about the end of the perimeter, coining the abstruse term "deperimeterization." Instead of going away, however, an organization's security perimeter has simply become more distributed, says Jody Brazil, president and chief technology officer of FireMon, a configuration and policy management firm.

"Instead of thinking about a big circle around your entire enterprise, you need to start thinking about little circles around critical elements of your network -- a little circle around your data center, a little circle around your point-of-sale systems, and a little circle around your mobile users," he says. "Instead of one big perimeter, you end up with these smaller segmentations -- you can think of them as mini-perimeters."

Securing those mini-perimeters is a daunting task. Companies no longer have a single electronic wall dividing "us" and "them," but must place and maintain security controls across myriad branch offices and wherever their increasingly mobile employees roam.

Large enterprises have the resources to build the security infrastructure to deal with the distributed perimeter. Small and midsize companies often rely on services, traditionally from managed service providers, but increasingly from cloud security services as well.

Cloud security services can help companies deal with the increasing use of mobile devices and cloud services for business. Requiring a mobile user to connect back to the corporate firewall using a virtual private network may give a company greater control over their use of corporate resources, but at the cost of a slower connection and inefficiency that may dissuade employees from using the secure method of access.

[With cloud services collecting more data from businesses, firms should prepare for potential breaches that involve their providers. See Enterprises Should Practice For Cloud Security Breaches.]

Cloud security services aimed at offering clean networks to mobile users -- such as Zscaler and OpenDNS -- as well as more traditional endpoint security software that use the cloud to distributed threat intelligence, updates, and security policies, can help extend the perimeter to mobile devices.

"You have to carefully evaluate the operational concerns and security concerns before you move a business function to the cloud," says Nimmy Reichenberg, vice president of marketing and business development for AlgoSec, a security-policy management provider. "URL filtering is a good example of a function that makes sense to move the cloud."

Along with e-mail security and Web security, integrating identity and access management between the internal network and the cloud is another growth area of cloud security services, according to analyst firm Gartner. In 2013, cloud security services accounted for $2.1 billion in global revenue, in part because of the growth in IAM services.

Managing the devices that maintain the corporate network perimeter -- the firewalls and intrusion detection systems -- are not suited to the cloud, says Reichenberg. "I don't see the basic firewall management moving to the cloud any time soon," he says.

On the other hand, companies can outsource those functions to managed security services and improve their company's security posture, says Ben Feinstein, director of operations and development for the counter threat unit at managed security service provider Dell Secureworks.

"Most organizations still have a traditional set of network security controls that need to be managed and monitored, and a cloud service provider is not going to be able to do that," he says.

Managed security services offer a variety of levels of service, from threat intelligence that can help more technical security teams be more aware of the threats targeting their network, to more full-service offerings that can help nontechnical companies lock down their networks.

"Managed security service providers have a core competency and expertise around information security -- that is what they do, and they are experts," Feinstein says. "Also, they have global visibility across a number of different kinds of organizations, which allows them to have a better understanding of the threat landscape."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
FluBot Malware's Rapid Spread May Soon Hit US Phones
Kelly Sheridan, Staff Editor, Dark Reading,  4/28/2021
Slideshows
7 Modern-Day Cybersecurity Realities
Steve Zurier, Contributing Writer,  4/30/2021
Commentary
How to Secure Employees' Home Wi-Fi Networks
Bert Kashyap, CEO and Co-Founder at SecureW2,  4/28/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-36124
PUBLISHED: 2021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
CVE-2020-36125
PUBLISHED: 2021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.
CVE-2020-36126
PUBLISHED: 2021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow an authenticated user to read and write data not owned by them, including third-party users, application and payment term...
CVE-2020-36127
PUBLISHED: 2021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through the PUK signature functionality, an administrator will not have access to the current p12 certificate and password. When accessing this functionality, the administrator has the opt...
CVE-2020-36128
PUBLISHED: 2021-05-07
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its ...