ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Enterprise listens to instant messages

Rupert Goodwins ZDNet.co.uk

Published: 15 May 2003 11:13 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Network architects and system designers are quick to think of services for corporates, but slow to remember that real people, not seats, use the networks. Instant messaging or IM is a case in point: originally a consumer-only Internet chatter tool, it rapidly spread from people's personal lives into their work environment. However, while the cost of deployment of public IM clients such as Microsoft (MSN) Messenger, AOL Instant Messenger (AIM) or Yahoo! Instant Messenger is low and configuration simple, IM has many security and management implications.

The obvious problem is sending messages in clear across public networks, or across a corporate LAN where not all messages should be visible to everyone. IM clients without encryption will be vulnerable to people running sniffer programs tuned to their protocols. Conversely, IM clients can often be set up to use unusual port numbers, making it a good channel for surreptitious communication between employees.

Another problem is that the mainstream free IM products are vulnerable to spamming messages containing links to dangerous places, and many can also receive files -- potentially tunnelling infected or malicious executables through your firewalls and onto your system. Or in reverse, IM has much potential for people moving confidential documents out of a company without being traceable. Finally, public IM systems have no effective user authentication -- and as with any software that can be exposed to the Internet, there are buffer overflow and other vulnerabilities to worry about.

Enterprise IM systems, around 20 of which have appeared over the past year, have different approaches to solving the above issues. Some enterprise IM systems, such as that from Bantu, have no resident clients. Bantu uses a mixture of server hosted services and Java applets to provide encrypted messaging across a wide range of clients. This centralised approach makes it much simpler to provide logging, authentication and quality of service controls. Others use existing tools, such as Reuters Messaging. Currently aimed at the financial community, this uses SSL for encryption and runs on Windows 2000 Server with added messaging components. Still others, including Yahoo's Enterprise Edition, use the same basic client-based technology as their consumer variants but add extra levels of protection and management.

Although IM's main selling point is messaging, it has knock-on effects. One is presence; when a user logs into IM it effectively alerts the network that they're around and provides a path to reach them. Another effect is that extra services naturally cluster around IM, such as voice messaging, videoconferencing, directory look-ups, calendaring and so on. Every enterprise IM system has a different range of options here, as the market is still immature, and the promise of proper open standards to allow network administrators to mix and match data from different applications with IM is largely unfulfilled.

Things are slightly better with the messaging protocols themselves. There are two sets of open standards battling it out with the proprietary systems -- SIP/SIMPLE and XMPP. SIP is the Session Initiation Protocol from the IETF, and provides a way for two agents on a network to establish a connection with each other. SIMPLE, the Sip Instant Messaging and Presence Leveraging Extensions, adds IM functionality around SIP to make a standardised approach to buddy-based IM. XMPP is the Extensible Instant Messaging and Presence Protocol; it does much the same job, but comes from the open source Jabber project and is based around XML. SIP/SIMPLE seems to have a better chance of becoming the one standard, due mostly to industry support from people like IBM and Microsoft, but some companies such as Antepo are hedging their bets and providing servers with support for both protocols. Additionally, most enterprise IM systems allow some degree of communication with standard clients from the big three consumer systems.

Microsoft has released some messaging components for its servers, but a major update is somewhat overdue. The company is dragging its heels over its real-time communications (RTC) server, codenamed Greenwich. A beta did emerge earlier this year, but shortly afterwards the Greenwich team leader hopped ship to Reuters and nobody's talking about release dates yet. Its existing Messenger service has also come under fire, as a number of security lapses in the related Passport identity mechanism has led to Gartner recommending no Passport corporate use until November.

These are early days for corporate IM, even though the consumer side is so widespread -- IDC claims that 70 percent of employees use the technology already. There are many points of differentiation between suppliers, and with competition so intense those looking to install an enterprise-class IM solution should feel comfortable demanding compliance to their management, security and productivity requirements at a price per seat that almost guarantees a return on investment.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
29 out of 53 people found this useful


Full Talkback thread

1 comment

  1. Im interested in who the major players are in ent... andrew went

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Messaging Engineer (Exchange 2003/07, OCS/LCS) BANKING

Highly Prestigious Investment Bank is hiring a Senior Level Messaging Support Engineer to join a small team in supporting the global messaging & AD ...

Encryption Analyst

A fantastic opportunity has arisen for an Encryption analyst the ideal candidate will have exposure to ICSF, TKE/ DKMS etc. Apply now Rate excellent ...

Messaging Engineer Poole, Dorset

Messaging Engineer CSS Poole We are looking for a Messaging Analyst to work in the Messaging and Collaborative Services team. They should have ...

Vista Upgrade Blog

Windows XP SP3 Installed

I have downloaded and installed Service Pack 3 for Windows XP Professional on my Fujitsu Lifebook S6510. Everything went smoothly, and it seems to work just fine. I don't see anything... More

Post a comment

Vista vs. XP: The Final Retreat

I suppose that most people are getting tired of reading about Vista vs. XP. I know that I am getting tired of writing about. I'm getting even more tired of fighting with it. So this... More

Post a comment

Vista Memory Leak?

I'm wondering if anyone else has seen anything that looks like a memory leak in Vista? I've been running Vista Business on my Lifebook S6510 for several weeks now, and overall I'm... More

Post a comment

Discussions

ben.d.robinson ben.d.robinson

Firefox

Monday 12 May 2008, 1:07 PM

2 comments
Brian Murray Brian Murray

and the next step ....

Monday 12 May 2008, 11:25 AM

1 comment

Featured Talkback

"We don't recommend specific technologies — we promote the use of technology per se." What sort of nonsense is this?? Every Becta endorsed IT supplier to schools is a Microsoft shop. Every single one.

By: 1000193068

Read full story:
Becta takes Microsoft to the OFT