Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/17/2017
08:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

New IBM Mainframe Encrypts All the Things

Next-generation Z series features the elusive goal of full data encryption - from an application, cloud service, or database in transit or at rest.

In the first major mainframe announcement by IBM in a decade, the company today unveiled its next-generation Z series that supports full-blown encryption for data via applications, cloud, and databases rather than today's more common practice of pockets of crypto.

Encryption remains a high bar for many organizations to deploy en masse; it's more often deployed at specific layers or portions of the data flow. And yes, mainframes are still a thing: The majority of credit card transactions run on IBM mainframes today, and other financial, insurance, and travel transactions still rely on the big ol' iron. IBM enlisted experts and customers from 150 different companies in building the architecture of the new Z system, including ADP and Highmark Healthcare.

"The challenge everyone has is it was too expensive to encrypt all of this … not really [expensive] in money, but I mean in processing time," says Caleb Barlow, vice president of threat intelligence at IBM Security. Transaction-based systems can't afford degradation of performance or user experience, he says. "When you're moving money or visiting an ecommerce website ... the encryption and decryption" steps can slow the process, he says.

So in most cases, encryption happens between the Web browser and the application server, or in a storage array. After each step of the data flow, the data is decrypted, so it doesn't remain locked down.

The Z system keeps data encrypted across the board, from the network to the storage array, in what IBM calls "pervasive" encryption, explains Barlow.

IBM engineered encryption into the Z's postage-stamp sized silicon processor: there are 6 billion transistors there dedicated to encryption processing, he says. "The machine doesn't slow down when it's asked to encrypt and decrypt" data, he says. The only time it's decrypted is when an organization needs to work with the data.

The encryption engine supports symmetric and asymmetric encryption algorithms including AES, DES, TDES, RSA, DSA, ECC, and ECDSA, as well as CMAC and HMAC for message authentication, and SHA2 and SHA3 hashing algorithms.

The IBM Z, which sells for around $500,000 and ships this quarter, can run more than 12 billion encrypted transactions per day, and includes what IBM calls "tamper-responding" encryption keys that kills keys if there's a sign of an attack so they can't be stolen; it restores them when the coast is clear.

Mainframes, while less prevalent these days, are still juicy targets for attackers. Researchers at Trend Micro recently discovered IBM Z Series mainframes (aka OS/390 machines) and IBM iSeries (aka AS/400 mainframes) left exposed on the public Internet, half of which were in the US. Exposed File Transfer Protocol (FTP) ports were the culprit in many of the cases.

Trend Micro's researchers say mainframes are at risk of what they call "business process compromise" attacks, where attackers infiltrate an organization and modify its mainframe transaction processes in order to siphon money surreptitiously.

John Clay, director of global threat intelligence communications at Trend Micro, says many exposed systems discovered via Shodan scans are misconfigured in some way. "The nice thing in what we hope to see with the IBM [Z] announcement is that an organization using the Z can implement encryption of the data at rest or in transit so that with any type of compromise" the data can't be stolen because it's encrypted, Clay says.

But don't expect an all-encrypted data world anytime soon. "It's going to take a while to get these systems in place," Trend's Clay notes. But it could bring about a "sea change" in the encryption space, he says.

The Ponemon Institute's recent Global Encryption Trends Study found that in the past 11 years, the ratio of organizations with enterprise-wide encryption strategies has doubled, from less than 20% to over 40%. They mostly employ an ad-hoc encryption strategy to date: 61% of organizations encrypt employee and HR data; 56%, payment data; 49%, financial records; and 40%, customer data, according to the report.

Related Content:

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Charlie Babcock
100%
0%
Charlie Babcock,
User Rank: Ninja
7/18/2017 | 1:37:45 PM
Mainframes a bridge too far for hackers
Mainframe operating systems have many built in security measures, and have proven a bridge too far for hackers, so far. That's why they're still in use at major banks and insurance companies. Adding encryption of all data will lock in that reputation for security and keep mainframes running applications into the next century.
For Cybersecurity to Be Proactive, Terrains Must Be Mapped
Craig Harber, Chief Technology Officer at Fidelis Cybersecurity,  10/8/2019
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17593
PUBLISHED: 2019-10-14
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
CVE-2019-17594
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17595
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-14823
PUBLISHED: 2019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to...
CVE-2019-17592
PUBLISHED: 2019-10-14
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.