By Richard Adhikari TechNewsWorld
04/15/08 5:00 AM PT
Virtualization and other measures can complicate enterprise security, so Apani Networks has launched EpiForce VM, software that works across platforms to isolate servers and other endpoints into logical security zones.
Crystal Reports - Discover the Latest Innovations. Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.
As corporations implement compliance with various regulations such as Sarbanes-Oxley, they find that they end up with different zones within their network that can't talk to each other.
This makes it difficult to implement an enterprise security solution. Adding virtualization to the mix complicates things further.
Apani Networks has come up with a solution to this: EpiForce VM.
EpiForce VM
Launched at the RSA Security Conference held last week at San Francisco's Moscone Center, EpiForce VM is a software-based solution that lets enterprises isolate both virtual and physical servers and endpoints as well as business-critical data into logical security zones regardless of what platform they run on or where they are physically on the network.
"We don't care if you're running on legacy systems or Windows or Solaris or a virtual platform, you should be able to isolate your servers and PCs into zones of like-minded computers," Ryan Malone, Apani's vice president of marketing , told TechNewsWorld.
"We control communications between zones and within the zones themselves," he added, saying that this is "an alternative to traditional network segments and virtual local area networks."
How It Works
EpiForce VM came out of research done at the National Security Agency. It is IPSec-based and is deployed at the network layer so "it is transparent to your existing network, to your applications and to your users," Malone said. IPSec, or Internet protocol security, is a suite of protocols for securing IP communications by authenticating or encrypting each IP packet in a data stream, or doing both.
So, all communications between zones is controlled by authentication of all machine-to-machine traffic and encryption based on policies set by the user and accessed on demand.
All machines in the same logical zone, whether they run the same operating system, or are physical or virtual, will remain connected regardless of their physical location. "You can take a physical machine and convert it to a virtual machine, or physically relocate a machine, and it will still be connected to others in the same logical zone," Malone said.
That's because EpiForce VM uses IPSec agents. "Instead of having links between IP addresses (a server's or desktop's location on the Internet), we have IPSec agent to IPSec agent, so we can have persistent connectivity," Malone explained.
Managing EpiForce VM
The application comes with its own centralized console and 30 canned reports.
Alternatively, it can be integrated into existing network management applications. "If you have, say, HP (NYSE: HPQ) OpenView and you want to use Syslog to read your reports, EpiForce will write the reports to Syslog," Malone said.
Syslog is a standard for forwarding log messages in an IP network.
EpiForce VM will be available in the second quarter of this year, and will initially support VMWare ESX Server.
VMWare ESX Server users will be able to migrate virtual machines protected by EpiForce VM between physical hosts without disrupting existing security policies.
The OSS Cure for What Ails Hospital IT April 11, 2008
Years ago, Florida Hospital in Orlando faced problems with its IT system, much of which relied on proprietary software. Innovative projects were abandoned due to high costs, and disaster recovery time was unacceptably long. So the hospital turned to open source. It was difficult at first, but officials say things are becoming easier as OSS goes more mainstream.
Related Stories
Chertoff on Cybersecurity: 'Reverse Manhattan Project' Needed April 09, 2008
Homeland Security Secretary Michael Chertoff told IT security professionals that their help is needed to protect the United States from a catastrophic cyber attack. He suggested a "reverse Manhattan Project" to beef up the ability to detect and respond to an attack.
IBM Conjures Phantom to Fight Hacker Menace April 08, 2008
At the RSA 2008 conference, IBM revealed details about a project code-named "Phantom." Phantom will tackle security concerns for virtualized environments, which often require a different approach to security than physical servers. The undertaking is similar to VMware's VMsafe, which was launched earlier this year.
Live From RSA: Getting Ready for the Security Smackdown April 07, 2008
The halls are just starting to hum at San Francisco's Moscone Center, the venue for this year's RSA Security Conference, which runs through Friday. Among the upcoming highlights: A Security Smackdown to test experts' mettle and several security-related book signings.
Related News Alerts
More by Richard Adhikari
Steve Jobs Conquers the Decade - Now What? November 07, 2009
Apple CEO Steve Jobs has been named the chief executive of the decade by Fortune, and it's hard to call that a bad pick, considering the turnaround Apple has undergone since Jobs returned to the helm in the mid-'90s. What's next on the list for a tech leader who's already changed the way we use computers, how we listen to music, and how we use our cellphones?
Verizon Launches a Droid of a Different Color November 06, 2009
Motorola's new handset wasn't the only Droid that Verizon brought to market Friday. HTC's Droid Eris also made its debut. The phone closely resembles the HTC Hero, a handset Sprint started selling last month. The similarity in names for the two Verizon phones is no accident -- Verizon says the name "Droid" will be used as a brand within the carrier's lineup.
There's Something About Droid November 05, 2009
For Verizon, the Droid is an answer to AT&T. For Motorola, it's a path to relevance in the smartphone world. For the Android platform, it's the debut of a brand-new version of the operating system. And for some smartphone shoppers, it could be a tough choice between a Droid and an iPhone.