F5 “Hacktivism” defense – RSA 2011
February 16, 2011 – San Francisco, CA – A recent telcon with F5 during the RSA Conference focused on an update on their product offerings and how they are addressing the challenge of “hacktivision” or the growing pro-active efforts from hackers to get access to data at client site.
A major discussion at the show was the cost of remediation for a data breech, and the larger number of data breeches that are taken place. A great deal of this trend is due to the fact that most companies have shifted to using contract, temporary employees or third party sub-contract firms rather than hiring full time employees that they support, train and trust. As a result, the qualification of these other workers who have access to the internal data at a company are in question as they were qualified under terms of another party that may not conform to “standard” policy. As a result of this trend and data breeches such as WikiLeaks, many in the IT industry are under the assumption that there are NO trusted employees and the traceability and audit trail for all IT activity needs to be created.
F5 Big-IP 3900 controller
F5 is the current industry leader in the area of Application Delivery Network appliance solutions. These are dedicated pieces of hardware with application software that operates at Level 7 of the TCP-IP stack. Their software supports their major ISV partners of SAP/Oracle/Microsoft Sharepoint.
F5 Viprion Module
The product delivers access policy decisions in the network flow, and acts as the main access control hardware for the network. For defense of events like WikiLeaks, the product is designed to not only administer and limit access to data on the network, but also create administration information such as tracking and alerts. At this time, the surveys from F5 have identified that most Distributed Denial of Service (DdoS) and electronic data breeches are created for political reasons not financial. The F5 products area designed to work up-stream from the data and perform its work at the edge of the network.
The products work on both the TCP and UPD channels and can create multiple Layer 7 applications to address access and delivery. The product can also be used to trap unauthorized access and for provisioning of network resources.
PC


