Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Gaining Competitive Advantage Through Enterprise Planning
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Mobile Security
Vendor Influence Curves And How You Can Get The Best Value Out Of Your Network
Hardcat at Concentrics Research LLC
Kaspersky® Internet Security 7.0 protects computers and laptops from all internet threats
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Five former Cisco engineers have co-founded a start-up called Rohati Systems whose products take dead aim at traditional perimeter firewalls.
A traditional firewall and its access control lists "is not capable of doing its job today from an access-control perspective," says CEO and President Shane Buckley. "Nowadays, your IP address just doesn't represent who you are."
Rohati will mark its debut this week with a network-based entitlement control device designed to limit access to applications, such as Microsoft's SharePoint collaboration suite, based on the user's authentication.
Called the Transaction Networking System (TNS), the appliance is intended to reside close to the data assets it protects, usually in the data center. It checks whether users should be permitted to access application data stored there based on user credentials that might include Kerberos, VPN SSL or Microsoft authentication protocol NTML.
TNS functions at the application layer to establish Layer 7 access-control lists to limit who has what access to data, Buckley says. Use of the TNS begins by putting the device in monitor mode to let it watch the users accessing the data, capturing all the transactions, such as opening and closing files.
"This way, the appliance is learning all the transactions in the network," Buckley says. This enables the appliance to build a policy that managers can refine, such as permitting or denying, or allowing reading, writing or deletion.
Now in beta and expected to ship in July, the appliance makes use of the OASIS standard called the eXtensible Access Control Markup Language (XACML) for the data-management policy.
"The appliance has a set of policies on who can have access to what based on directory attributes," Buckley says, adding that one advantage is that no changes to existing applications or new client software is required. TNS competes most directly with entitlement software from CA, Oracle, IBM Tivoli Software and Securent, which was acquired by Cisco last November for US$100 million.
Every time a user goes to access an application, a check for authorization will be made by TNS, but speed shouldn't be an issue, Buckley says, because the two models of the product, the TNS-100 and the TNS-500, scale between 4G and 40Gbps, are built on Infiniband technology and support as many as 6 million connections. In the future, the TNS is likely to be developed to do more than provide access control to applications.
"Because we control the application, this gives us the ability to do things like content cloaking, blocking out sensitive content to the viewer," Buckley says. Content filtering of various types could also be integrated into the basic architecture.
Rohati, which joined the Jericho Forum, the group dedicated to encouraging alternatives to traditional perimeter firewalls for e-commerce, is targeting TNS for organizations that allow business partners to share network resources with internal users.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Progress Software Selected for ACORD Standards Framework 2008-10-16 09:45:00+10
Tandberg Data lifts RDX® QuikStor™ capacity to 500GB and offers continuous data protection 2008-10-16 09:23:00+10
Kroll Ontrack Offers More Complete Data Recovery Solution with SSD And Flash Capabilities 2008-10-16 09:00:00+10
Infohrm Launches 4G SaaS-based Workforce Planning, Reporting, and Analytic Solution 2008-10-16 08:04:00+10
Polaris Installs Massive Generators 2008-10-15 11:30:00+10
Dude! You Say I Need an Application-Layer Firewall?!
Proxy firewall technologies have proven time and again to be more secure than “stateful” firewalls. They will also prove to be more secure than “deep inspection” firewalls. High-performance proxy firewalls are available today which are easily capable of handling gigabit-level traffic. Discover more by reading on.










