Ads by TechWords

See your link here
Receive the latest technology news and information.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 
Souped-up Security

Security and QoS Unite

Merging the two technologies gives users multiple lines of defense against network attacks.
 

Sign up to receive Networking and Internet Resource Alerts

sign-up

January 19, 2004 (Computerworld) -- Until recently, quality-of-service and network security technologies lived in separate worlds. But they have something important in common. Certain types of attacks on network security affect application performance -- and ensuring application performance is the main mission of QoS.
So the two technology camps have begun joining forces to stave off network attacks that degrade or halt network performance.
The enemies at the gate are worms, viruses, Trojan horse programs and denial-of-service attacks. These invasions rapidly replicate pieces of code or application service requests to the point where they overload a system's memory or CPU.
Firewalls and intrusion-detection systems (IDS) are typically used to identify unauthorized traffic based on known malicious bit patterns or limited parameters in an IP header. At the same time, sophisticated traffic-management capabilities -- available as appliances and as software capabilities in network routers -- recognize traffic based on application, protocol, user, media access control address, IP address and other granular variables.
Network implementers are recognizing common ground and the benefits of some integration work. For example, security and QoS products already tap common access control lists (ACL) for rules on how to treat traffic. And if further integrated, an IDS that discovers abnormal traffic patterns could alert a QoS system to treat that traffic according to those rules.
"The fact that firewalls, IDSs and QoS overlap gives you multiple ways to find and fight infections," says Joe Walton, a principal at VistaOne IT Services, a value-added network reseller based in Richmond, Va.
QoS's primary purpose is to manage the performance of multiple applications contending for bandwidth on a converged network link. To do this, QoS products identify what traffic is on the network, then classify and treat it according to the enterprise's network policy. For example, you could tune your network to "always allocate 20Kbit/sec. to Citrix," "limit streaming-media traffic to 128Kbit/sec." and "block all Kazaa traffic" to give the various traffic streams their appropriate due.
Once you have the power to identify and control traffic this way, you can apply QoS to also detect traffic anomalies, then set policies to automatically mitigate their effects. A firewall is a first line of defense, usually deployed at the WAN edge to permit or deny access based on ACLs. An IDS monitors packet streams in the background in search of traffic patterns that have already been identified as malicious -- then alerts you if it finds one.
QoS can do a little of each function, while also enabling network forensics and immediate treatment of suspicious traffic, says Walton. "QoS helps you track down where an infection originated within your internal network. Then you can go back and alert that site that they are infecting everybody," Walton explains.
The University of California, Irvine, uses Packeteer Inc.'s PacketShaper QoS appliance in part for this capability.
"PacketShaper identifies where [an unnaturally large volume of] connections are coming from," says Ted Roberge, manager of residential network services. "I can block or shape those IP addresses down to a tiny amount of bandwidth to minimize the impact on network and server resources."
Larry Roth, vice president of OnlyInternet.Net, an Internet service provider in Bluffton, Ind., has used Allot Communications Ltd.'s NetEnforcer QoS appliance in a similar manner: to fight viruses. "When Blaster came out on [TCP] Port 135, we put in rules and regulations for minimizing traffic that could use that port," explains Roth, who also uses firewalls and IDSs. "We saw an immediate 40% drop in Blaster being spread."
Oded Nahum, a senior systems engineer at Allot, says his company's gear has been used quite a bit by Internet service providers lately for handling network-aware viruses. "ISPs have such a broad reach, a virus can cause a lot of damage" if not checked, he says.
Interim Protection
QoS products often serve as "interim" defenses until viruses become known, IDSs are programmed to identify them, and patches are created and deployed on host systems.
Amir Khan, a director of product marketing at Cisco Systems Inc., says, "QoS plays a major security role here. When Kazaa [a peer-to-peer file-sharing application] hit enterprise networks, for example, it took many days to develop and implement patches."
Cisco's Network-Based Application Recognition classification engine, however, was able to flag Kazaa. Users could then decide to give it the lowest priority or drop it, he says.
Adding QoS to the security arsenal provides another line of defense against network attacks that affect performance. Meanwhile, further integration will enable QoS and security features to communicate with one another. When a network policy configured using one feature can trigger appropriate corresponding behavior in the other -- capabilities likely to become available next year - this integration and automation will enhance and simplify the network administrator's ability to implement policy-based rules to manage network behavior.
Wexler is a freelance writer in California's Silicon Valley. Contact her at joanie@jwexler.com.

Special Report

Souped-up Security
Stories in this report:
  • Souped-Up Security
  • Farming Out Security: How to Choose a Service Provider
  • Security and QoS Unite
  • Security Begins at Home (With Telecommuters)
  • The Almanac: Networking



  • Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story

    Special Reports

    IE9 to tap hardware to boost performance
    New attack fells Internet Explorer
    The 5 best and worst features of Google Chrome OS
    More top stories...
    Free Web apps to help organize your holidays
    Google's Chrome OS hits BitTorrent
    Global warming research exposed after hack


    Ads by TechWords

    See your link here


    Getting to know Windows 7? Don't stop now: From speeding up taskbar thumbnails to reining in UAC, here are 20 ways to make Windows 7 act the way you want.
    Is Motorola's new Droid good enough to vanquish iPhone envy? To find out, we took it on a 3-day trip.
    Sure, you could always use Linux as a desktop OS, but Corel Linux 1.0 was the first distro designed for ordinary users. It's been a long, strange trip since then.
    New touch-screen laptops from Fujitsu, HP and Lenovo take advantage of Microsoft Windows 7's touch-friendly infrastructure.
    Get the latest news, reviews and more about Microsoft's newest desktop operating system.
    General Mills, Genentech, San Diego Gas & Electric, University of Pennsylvania and Monsanto top the list.
    All Zones
    The SAS Zone
    Software Resource Center
    Mobile Security
    Disaster Recovery & Cost Savings
    Strategic Content Management
    Business Analytics Zone