ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cisco initiative tackles mobile working security threat

Published: 19 Nov 2003 12:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco Systems has teamed up with three top antivirus companies in a security initiative intended to ban insecure mobile devices from corporate networks.

The initiative, dubbed the Network Admission Control programme, would allow companies to set their network devices to refuse connections from any mobile PCs or devices that fail to meet corporate security policies, such as not having the latest software patches and antivirus updates. Antivirus companies Network Associates, Symantec and Trend Micro joined Cisco in making the announcement on Tuesday.

The plan is meant to combat one of the common weaknesses of company networks: workers who log on from outside a company using insecure PCs or who bring those computers inside the company and connect to the network.

"Currently, no check is made to see if the PC is compliant with corporate security policies," Charlie Giancarlo, senior vice president of product development for Cisco, said on a conference call on Tuesday. "The user might become infected at home or through a hotel Internet connection...[and] immediately spread a worm throughout a corporate networks."

The move by the companies is a reaction to recent computer worms and virus epidemics that have managed to spread into businesses due in large part to the insecure PCs mobile workers use. Both the Slammer worm in January and the MSBlast worm in August were able to get past corporate defences by hitching rides on the laptops of mobile workers who were lax with security.

"The explosion of wireless, mobile devices and pagers has made the corporation much more vulnerable to attack through the devices," said George Samenuk, CEO of Network Associates.

Other companies have reacted to the problems the worms have highlighted. Microsoft announced in October that it would augment its focus on securing its software through patching, because the earlier system of updates hasn't been able to stem the epidemics. Other companies, including Internet service providers, have blocked certain types of traffic for weeks at a time to stop threats.

Putting agents in place
Cisco's Network Admission Control programme would enable companies to install on every PC and mobile device a client, called the Cisco Trust Agent, which could attest to certain levels of security, such as whether the device has been recently patched or has the latest virus recognition files. Antivirus software makers would modify their products to provide information to the software that could be used by companies to determine how secure the PC might be.

Giancarlo stressed that completely locking out mobile users is not an answer. "Clearly, the solution is not to eliminate one of the most important aspects of these devices: their mobility," he said.

The secure connections that allow employees to connect to the internal corporate network from home, virtual private networks, are also seen as a major threat to businesses' security.

Cisco has already focused on delivering such connectivity in its products. Earlier this month, the company announced an upgrade to the Cisco VPN 3000 Concentrator to add secure network functionality, dubbed WebVPN, based on the Secure Sockets Layer protocol browsers widely use.

Cisco's concentrators are network devices that act as central connection points for virtual private networks and, as such, are an ideal place to put in additional network defences.

However, the technology won't work unless security software can tell the Trusted Agent application the current state of security on the computer or mobile device.

"This important problem can't be addressed individually," said John Thompson, CEO of Symantec. "Collaboration is a must."

The technology might also spur sales of PCs and devices that use trusted-computing hardware -- controversial technology that uses encryption, special memory and security software to lock away secrets on a PC from prying eyes. Adding further protections to the system that attests to the security of a computer owned by a company is a reasonable use of the system, said Bob Gleichauf, chief technology officer for the Network Admission Control program at Cisco.

"We need a trust boundary between the network and these devices, and the system needs hardware and software to do that," he said.

Cisco plans to introduce the technology in the middle of 2004.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 86 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Programme Manager

Qualifications: * Demonstrable expertise in project or programme management * Leadership qualities to support global initiatives within a matrix ...

NHS Programme Manager North West

My client seeks a Programme Manager to work with a major north west trust to manage a large scale logistical and IT project. You will have previous ...

IT Security Consultant required - Gloucestershire

To apply for this position you will come from an IT Security role and have experience of developing and enforcing IT security policies and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment