NETWORK SECURITY: Better Safe, Than Sorry

author-image
DQC News Bureau
New Update

With information becoming the lifeblood for every organization, maintaining
its security is a daunting task for IT managers and solution providers who cater
to the needs of these companies. IDC states that network security is a prime
concern area for CIOs this year.

Advertisment

With a CAGR of about 25% till the year 2010, the network security market
stands at approximately Rs 500 crore in India. The SMB segment has shown an
above average growth of about 31 percent as compared to enterprise growing at
the rate of about 20-30 percent.

According to a Frost and Sullivan report, the Indian security market was
$29.9 million at the end of 2003. It says this can swell up to $1.42 billion by
the end of this decade, according to conservative predictions.

"The
threat is not from viruses alone. Malware has found various entry
points, which is a challenge for vendors"

Niraj
Kaushik


Country Sales Manager, Trend Micro

Advertisment

IDC says the worldwide information security market was worth $6.7 billion in
2000. It is projected to more than triple to $21 billion by the end of 2005.
Remote LAN, Internet, extranet/intranet and wireless access services will drive
the need for advanced information security services, as technologies for
circumventing network security systems continue to keep pace with the
technologies designed to defend against them.

Also, companies seeking to outsource work insist on security certification or
adherence to security laws, standards and business practices prevalent in their
respective countries. Not surprisingly, leading Indian software services
companies, IT-enabled services companies and BPO outfits are going in for
security certifications like BS 7799 or ISO 17799.

SECURITY ON TOP OF AGENDA

With IT spends shrinking, security still commands the prime position. Unlike
their predecessors, the new breed of enterprises looks at network security
setups as investments, rather than expenses. Looking at this trend, new products
are being launched daily and worldwide countries have decided to frame network
security policies for their data.

Advertisment

HOW
SECURITY BREACHES AFFECTS COMPANIES

l

Insecure
wireless networks
:
Intruders can use the network to access systems at the central data
center
lBreaching
privacy regulations
:
Sharing personal information such as credit card numbers and e-mail
addresses can be a breach of security
lUser
error damages business
:
Wrong information supply can put a business in danger
lDisgruntled
staff attacks
:
Employees can make user Ids and passwords vulnerable by sharing them
lEmail
and Internet abuse
:
Email and the Internet at work can be very vulnerable security
loopholes

l

Hacking:
Hackers can disrupt or break into an online business. They can
also deface the site and send malicious information to readers

With all these new development, the network thread is also growing leaps and
bounds. In former times, it was a virus, which was a reason of data loss. Now it
is a completely new breed of threats; malware that not only destroy the native
data but also make your systems vulnerable for the other attacks.

The latest buzzword in this malicious business is compromised PCs. Worms hit
PCs, open up gateways and spammers use the resident database of these machines
to spam more people.

Advertisment

While all this might paint a gory picture about network security, vendors are
pleased that corporates are finally sitting up and taking notice of the landmine
they are sitting on. The tools of surveillance and analysis have now become
small, cheap and mobile.

"Currently,
worm intrusion, spam, spyware, Instant Messengers and P2P are the
major security concerns"

Mark
Stevens

CSO, Watchguard

Security systems have moved from simple firewalls to intrusion detection
systems (IDS) to intrusion protection systems (IPS). The key to security,
according to vendors, is proactive security systems that not only make networks
secure at the entry level, but also cover all the corners of security ends
comprehensively.

Advertisment

Security now isn’t just a product, and it isn’t just a service. It’s a
condition that is expected to be embedded in the process of creating value.
Today’s information security encompasses diverse issues. Right form the
firewalls, intrusion detection systems and security management tools as part of
security services to managed security services, security companies are
reinventing themselves to cater to the new breed of security threat.

CIOs have understood the requirement to communicate the security issues in
the organization as the most important issue. In

order to have an effective information security posture organizations are
aligning their information security with their business objectives.

SHIFT IN SECURITY CONCERNS

Till some time ago, only the network access point needed protection to
prevent any breaches. But now, the demand is for a

360-degree solution that gives seamless security to the entire network.

Advertisment

Says Niraj Kaushik, Country Sales Manager, Trend Micro India, "The
threat is no longer from the viruses alone. Malware has found various entry
points, which is a challenge for vendors. The nature of attack has become
drastically harmful." Vendors now have to provide not only the security
systems that detect and fight these attacks, but also proactively prevent
similar mishaps.

Neel Ratan, ED, Pricewater housecoopers says that there are three prime
concerns that envelop security need for any organizationpeople, process and
technology. According to him, most of CIOs have a stronghold on the latest
security issues and are putting security policies in place. He also feels that
the newer standards of computing such as grid and high-performance computing (HPC)
will only complicate security concerns and standards.

Newer breed of malware is also different, it gains entry not from only two
points but from multiple holes. Worms might be residing in your systems without
any effect or intrusion, it just lay bare the IP of the computer and thus the
network on which one is working. A single worm can lay bare the complete network
of the organizations. With such magnitudes of vulnerabilities to the
organization, they are implementing security policies and placing CSOs to take
care of the security issues.

Advertisment

"Managed
security services will be a huge service model as the security
threats will scale up the technology ladder"

Anjan
Bhattacharya


Business Manager,  SDG Software India

LATEST OFFERINGS
UP FOR SALE

Firewall, a standard device for network security has metamorphosed from
being a device that prevents a specific type of information from moving between
the outside network and the inside network and vice versa. Fixed with a router
or server, it has graduated to a fifth-generation product.

It is now a kernel proxy, a specialized form that works under the Windows NT,
which evaluates packets at multiple layers of the protocol stack by checking
security as data is passed up and down the stack.

Dial-up protection systems such as the Remote Authentication Dial In User
Service (RADIUS) centralizes the management of user authentication by placing
the responsibility of authenticating each user in the central RADIUS server.
Another solution is the TACACS or terminal access controller access control
system that remote authorization system based on client/server configuration.

"There
are three prime concerns that envelop the security need for
any organization—people, process and technology"

Neel
Ratan


Executive Director, Pricewaterhousecoopers

The latest breed of proactive defense systems are IDS and IPS. IDS work like
a burglar alarm. It is either network-based, where the technology is focused on
protecting network information assets or host based. It is focused on protecting
server or host information assets.

IPS, on the other hand, is aimed at detecting certain symptoms of an attack
and the possibility to resist it before damage can occur. Apart from these there
are a large brigade of technologies, there are several other tools such as port
scanners, packet sniffers and other analysis tools to manage vulnerabilities in
the network.

Besides packaged security products, managed security is a new buzzword. If
you find it difficult to hire security experts, the third party security service
providers give 24x7 security services for the organization.

BUYING PATTERNS

With the evolution of technology and the needs of customers, the buying
patterns have also witnessed a sea change.

Kartik Shahani, Sales Director-India, McAfee Security says, "Spam will be a
great threat and solutions built to prevent it will be in great demand in the
near future."

"Spam
will be a great threat in the future and solutions to prevent it
will be in high demand"

Kartik
Shahani


Sales Director-India, McAfee Security

Mark Stevens, Chief Strategy Officer, Watchguard says that buying patterns
would entirely depend on the nature of the threats. Currently, he says it is
worm intrusion, spam, spyware, instant messengers and P2P that are the major
security concern areas.

Vendors have now become aware of these new challenges and are producing
specific products aimed at different verticals and segments of the clients. They
are also putting in place a multitude of SIs trained for the security solutions.

Another emerging trend is providing managed security services. Mark feels
that this part business will grow tremendously, especially as the SMB segment
scores up the business.

Anjan Bhattacharya, Business Manager, SDG Software India agrees with him. As
the security threats scale up the technology ladder, it will not be easy for
everyone to manage security issues.

Vendors are also feeling the change in the buying patterns and putting newer
products in market that are predictive, proactive and performance oriented.
Network Associates initiated a huge R&D regime to face the new buying
pattern and manage new products.

THE GROWING
SMB SEGMENT


SMB, the fastest growing client segment for this business, with their
increased usage of emails for communication and requirement of IT-enabled
services. With these increase, SMB is the cash cow for network security vendors.

BFSI and BPO are the current favorite customers for vendors. Most software
developing companies have also spruced up their network security majorly to
suffice with stringent client requirements. Manufacturing and telecom have also
picked up very well.

BENEFITS
OF A WELL-DOCUMENTED INFORMATION SECURITY POLICY
 

l

Increases
company’s credibility with partners and customers
lSupports
legal actions taken in case of security breach
lReduces
damages of security breaches resulting from accidental or deliberate
actions by employees or outsiders
lAnswers
frequently asked security related questions
lProtects
company directors from liability for unauthorized actions by
employees

l

Assures
staff that they are using information resources in a secure and
correct fashion

PK Gupta, Director Strategic Development, Legato Software feels that this
segment defines the real security demands. Major vendors now have end-to-end
security offerings with special pricing for this new breed of price conscious
clientele, that demand a non-technical approach towards network security.

Felix Mohan, CEO, SecureSynergy feels that vendors will not only have to
produce the new security systems that can detect and protect from the new line
of threats but also products that defines the ROI and TCO for the clients,
especially for the new SMB segment.

As security threats multiply, a simple rule of arithmetic suggests an
increase in price. But vendors are actually reducing prices to gap the
supply-demand equation.

Kaushik
says that this approach has not only reduced prices, it has also put in place
products that run on intuitive technology, which require lesser expert level
intervention and can he run by a non-techie person. This can come in handy for
the smaller companies requiring secure networks with good ROI and TCOs.

This attention to minutiae is what is keeping the customers coming back to
vendors for better upgrades for the network security. Maintenance of their
existing network is yet another burgeoning business opportunity which beckons
most solution providers.

Thus, security is never absolute, but vendors are aspiring to hit the
ultimate. There’s no such thing as complete safety or complete freedom from
doubt or fear people and organizations always face risks. Some risks can be
eliminated, some can be reduced, and some can be accepted with these solutions.
An organization is "secure" when it understands the risks, and is able
to manage them so that, the costs used to reduce risk are commensurate with the
expected business value.

SHWETA KHANNA

UNDERSCORING THE IMPORTANCE OF NETWORK SECURITY

l Verifiable digital
attacks worldwide caused economic damage of more than $16 billion by March 2003,
almost double the year earlier. Through 2005, 20% of companies are expected to
experience a serious Internet security incident, not limited to virus attacks.

l In 2003, the overall
rate of malicious software attacks through viruses and worms, increased by
nearly 20%. It was exemplified by the Slammer worm that infected 90% of
vulnerable systems within 15 minutes.

l According to an US FTC
survey, there were 27.3 million identity theft victims in the past five years.
9.9 million victims were in 2002-2003, causing losses amounting to $48 billion
to business and financial institutions.

l An Ernst & Young´s
computer security survey revealed that 90% of organizations said that IT
security is of high importance to them, with 78% identifying risk reduction as
the top factor influencing security spending.

l IDC sees the annual
worldwide spending on security hardware, software and services growing from $17
billion in 2001 to $45 billion in 2006.