HP to scale up TippingPoint network security with SDN
The company's Sentinel software would run on an SDN controller and tap into TippingPoint's intelligence
IDG News Service - Hewlett-Packard plans to use its recently announced SDN controller to distribute its TippingPoint intrusion prevention system across networks, overcoming the scale limitations of dedicated appliances.
The research project, called Sentinel, is one of HP's first steps to use the distributed nature of SDN (software-defined networking) to change what networks can do. In this case, SDN can make it easier to provide protection against Internet malware throughout an enterprise or carrier network. Sentinel can scale up to handle thousands of endpoints, helping to keep enterprises secure as they embark on BYOD (bring your own device) policies, said Mauricio Sanchez, chief security architect at HP Networking.
"It's bringing that level of capability to the entire network and not just to the Internet gateway," Sanchez said. Leveraging its security capabilities along with SDN is one move by HP to compete with rivals such as Cisco and Juniper in the rapidly evolving SDN market.
TippingPoint keeps track of known sources of malware on the Internet, with a list of about 700,000 sites today, according to the company. It consists of software and an accompanying service, in which security researchers identify sites that contain hazardous code.
Currently, the TippingPoint software is deployed in appliances, which are installed as gateways between the public Internet and a private network. But those appliances can become bottlenecks because their performance is limited by the speed of their network links and hardware components.
Researchers at HP are now working on turning TippingPoint into an application that runs on HP's SDN controller, said Sanchez, a co-creator of the application. Because SDN separates the control of a network from its forwarding plane, it allows networking applications to be distributed wherever in the network they need to be. HP's controller is designed to host many different applications.
Sanchez demonstrated Sentinel at a media event at HP on Thursday. The software works by capturing and analyzing the DNS (Domain Name System) traffic that's generated when a user on the network tries to go to a website. If the site's DNS information matches that of any site on the TippingPoint list, Sentinel will take action over the network using the OpenFlow protocol, Sanchez said. It can redirect the user's request or take other steps, including sending a warning that the endpoint may have gone to that site because it was infected.
Because the Sentinel application has a real-time connection to the TippingPoint service, which updates its database at least every two hours, it has the latest information to secure the network. And because it only captures DNS traffic instead of the full flow of Web-browsing data, it can work efficiently, Sanchez said.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- A New Set Of Network Security Challenges IT faces conflicting mandates from the business. Employees demand access from devices beyond the firewall. On the other hand, risk management dictates corporate...
- Best Practices for Cloud-based Information Governance This paper explores the latest ideas on evaluating cloud deployment: public or private clouds, data location and privacy, data ownership and access, and...
- File Archiving - The Next Big Thing or Just Big This white paper from Osterman Research discusses best practices for archiving file-based content and offers some recommendations about how organizations should manage the...
- Mission Possible - How HP conquers the demon of explosive structured data growth Database is critical to business operations across the enterprise. As the data foot print grows, a myriad of challenges emerge.
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Network Security White Papers | Webcasts