Vulnerabilities / Threats

7/17/2017
08:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New IBM Mainframe Encrypts All the Things

Next-generation Z series features the elusive goal of full data encryption - from an application, cloud service, or database in transit or at rest.

In the first major mainframe announcement by IBM in a decade, the company today unveiled its next-generation Z series that supports full-blown encryption for data via applications, cloud, and databases rather than today's more common practice of pockets of crypto.

Encryption remains a high bar for many organizations to deploy en masse; it's more often deployed at specific layers or portions of the data flow. And yes, mainframes are still a thing: The majority of credit card transactions run on IBM mainframes today, and other financial, insurance, and travel transactions still rely on the big ol' iron. IBM enlisted experts and customers from 150 different companies in building the architecture of the new Z system, including ADP and Highmark Healthcare.

"The challenge everyone has is it was too expensive to encrypt all of this … not really [expensive] in money, but I mean in processing time," says Caleb Barlow, vice president of threat intelligence at IBM Security. Transaction-based systems can't afford degradation of performance or user experience, he says. "When you're moving money or visiting an ecommerce website ... the encryption and decryption" steps can slow the process, he says.

So in most cases, encryption happens between the Web browser and the application server, or in a storage array. After each step of the data flow, the data is decrypted, so it doesn't remain locked down.

The Z system keeps data encrypted across the board, from the network to the storage array, in what IBM calls "pervasive" encryption, explains Barlow.

IBM engineered encryption into the Z's postage-stamp sized silicon processor: there are 6 billion transistors there dedicated to encryption processing, he says. "The machine doesn't slow down when it's asked to encrypt and decrypt" data, he says. The only time it's decrypted is when an organization needs to work with the data.

The encryption engine supports symmetric and asymmetric encryption algorithms including AES, DES, TDES, RSA, DSA, ECC, and ECDSA, as well as CMAC and HMAC for message authentication, and SHA2 and SHA3 hashing algorithms.

The IBM Z, which sells for around $500,000 and ships this quarter, can run more than 12 billion encrypted transactions per day, and includes what IBM calls "tamper-responding" encryption keys that kills keys if there's a sign of an attack so they can't be stolen; it restores them when the coast is clear.

Mainframes, while less prevalent these days, are still juicy targets for attackers. Researchers at Trend Micro recently discovered IBM Z Series mainframes (aka OS/390 machines) and IBM iSeries (aka AS/400 mainframes) left exposed on the public Internet, half of which were in the US. Exposed File Transfer Protocol (FTP) ports were the culprit in many of the cases.

Trend Micro's researchers say mainframes are at risk of what they call "business process compromise" attacks, where attackers infiltrate an organization and modify its mainframe transaction processes in order to siphon money surreptitiously.

John Clay, director of global threat intelligence communications at Trend Micro, says many exposed systems discovered via Shodan scans are misconfigured in some way. "The nice thing in what we hope to see with the IBM [Z] announcement is that an organization using the Z can implement encryption of the data at rest or in transit so that with any type of compromise" the data can't be stolen because it's encrypted, Clay says.

But don't expect an all-encrypted data world anytime soon. "It's going to take a while to get these systems in place," Trend's Clay notes. But it could bring about a "sea change" in the encryption space, he says.

The Ponemon Institute's recent Global Encryption Trends Study found that in the past 11 years, the ratio of organizations with enterprise-wide encryption strategies has doubled, from less than 20% to over 40%. They mostly employ an ad-hoc encryption strategy to date: 61% of organizations encrypt employee and HR data; 56%, payment data; 49%, financial records; and 40%, customer data, according to the report.

Related Content:

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Charlie Babcock
100%
0%
Charlie Babcock,
User Rank: Ninja
7/18/2017 | 1:37:45 PM
Mainframes a bridge too far for hackers
Mainframe operating systems have many built in security measures, and have proven a bridge too far for hackers, so far. That's why they're still in use at major banks and insurance companies. Adding encryption of all data will lock in that reputation for security and keep mainframes running applications into the next century.
RIP, 'IT Security'
Kevin Kurzawa, Senior Information Security Auditor,  11/13/2018
Understanding Evil Twin AP Attacks and How to Prevent Them
Ryan Orsi, Director of Product Management for Wi-Fi at WatchGuard Technologies,  11/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17906
PUBLISHED: 2018-11-19
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
CVE-2018-9209
PUBLISHED: 2018-11-19
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
CVE-2018-9207
PUBLISHED: 2018-11-19
Arbitrary file upload in jQuery Upload File <= 4.0.2
CVE-2018-15759
PUBLISHED: 2018-11-19
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perfo...
CVE-2018-15761
PUBLISHED: 2018-11-19
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges...