Home > Security News > Storage security is an emerging issue
Security News:
EMAIL THIS

Storage security is an emerging issue

By the451, special to searchSecurity
12 Oct 2001 | the451

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Security, as related to storage, is a somewhat neglected area. But it's one that is likely to receive more attention in the future, particularly as IP-based storage area networks begin to be implemented.

Hackers typically aren't familiar with the inner workings of fiber channel. But IP is a different matter altogether, and the whole idea of storage pooling, whereby any host has access to data, presents a nightmare to security administrators.

"The SAN industry is relatively new," says Evaluator Group analyst Dennis Martin, "and some of the security issues are only now being considered." Storage devices, the fabric and network devices and the host server operating system all have their security issues.

The switch vendors have implemented such things as LUN masking and zoning, which enables the SAN to be split up into logical units and accessed only by designated servers -- but Martin says this has been implemented more from an interoperability standpoint than from a security one. There is not yet a proper concept of a "trusted switch," comparable to IP-based trusted servers, although Brocade and others are now working toward it.

Currently, of course, most SANs are behind the firewall. But one of the attractions of IP storage is that it will be able to connect to the outside IP-based infrastructure, including the public Internet, in order to join together remote "islands of information."

In theory, IP networks should be more secure than fibre channel, because more work has been done on security in the local and wide-area networking field. Both IP and fiber channel rely on trusted clients, however, and there are far more IP-based tools easily obtainable that the malicious population can use to gain access.

The earliest releases of SAN management software had no security components at all. That has now started to change. FalconStor, for instance, has added authorization policies to its IPStor product, and uses IPSec and VPN technologies to encrypt storage data as it travels over the network, so that SANs can be extended using shared networks, such as the Internet. IPStor utilizes key-based authentication to eliminate the possibilities of spoofing.

The Storage Networking Industry Association has set up a working group to look into these issues and will eventually come out with some specifications and standard practice recommendations. In the meantime, Martin is presenting a two-hour webcast on SAN security for the Evaluator Group on Nov. 13 to discuss the issues. It starts at 10am. Click here for more details.


the451 (www.the451.com) is an analyst firm that provides timely, detailed and independent analysis of news in technology, communications and media. To evaluate the service click here.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts