Network Management
With the growing complexity of IT infrastructure, the need for an integrated solution tomanage heterogeneous components is becoming pressing. These heterogeneous compo- nents include routers, switches, databases, servers, applications, gateways, and other com- puting and communication resources. As IT networks have become more open, the overall security risk has been enhanced due to vulnerabilities in each of these components. As a result, security-related monitoring and management can no longer be limited to pure security devices (e.g., firewalls) and must include other networking components that pose a security threat (Exhibit 86). We believe the solutions for security and network management are in the early stages of convergence, with emerging solutions providing an integrated view of the entire IT infrastructure. IDC estimates that the combined market for management software will grow to $1.8 billion in 2005 from $359 million in 2000, a 37% CAGR. While network management software is the dominating component of this market, we believe that security management software will become an increasingly important portion going forward.
Exhibit 86 ◆ Unified Monitoring and Management of Security and Non-Security IT Components
Source: RBC Capital Markets
Due to the highly specialized and closed nature of security solutions, management of security components has been separated from the management of other IT components. The security landscape is still evolving and has not consolidated to the same extent as the networking infrastructure landscape. For example, there are more than 20 intrusion detection vendors, more than 30 firewall vendors, and more than 10 anti-virus vendors in the market. A high degree of fragmentation has been a major inhibitor toward a common security framework. Furthermore, unlike the networking world, in which Internet Engineering Task Force (IETF) standards such as Simple Network Management Protocol (SNMP) and the associated Management Information Bases (MIBs) have driven inter-operability, the security industry has no such framework. Mitre Corporation sponsored an equivalent initiative, Common Vulnerability and Exposures (CVE), in the security market in late 1999. CVE, which was formulated to facilitate sharing of data across multiple vulnerability databases, is yet to get widespread support within the security community. Additional security frameworks have come from Network Associates (Active Security), Symantec/Axent (Smart Security Architecture), and IBM (First Secure). However, these companies have been focused primarily on vendor-specific solutions. A notable success has come from Check Points Open Platform for Security (OPSEC) alliance. More than 300 vendors whose products are able to inter- operate within the OPSEC framework have embraced OPSEC. Part of the OPSEC success
Routers Firewalls Content Filters Intrusion Detection VPNs Anti-Virus Telecom Equipment ERP Systems Databases Servers Switches Traffic Management INTEGRATED MANAGEMENT
is also attributable to Check Points dominance of the firewall market; firewalls are one of the earliest and one of the most essential security components.
Outside the security industry, other vendors such as Computer Associates and BMC Software, Inc. (NYSE: BMC; Neutral) have expanded their network management product lines to include security management solutions. However, when it comes to security, products from these vendors are point solutions bundled together (e.g., separate software modules to mange firewalls, content filtering, intrusion detection) rather than integrated security solutions. We believe that demand for integrated security management solutions is strong in the enterprise and the MSS markets, both of which deal with a diverse set of network devices and solutions. We believe that there are four paths toward integrated security management solutions. First, existing security management vendors could expand their products to include traditional networking devices. In our opinion, Check Point/OPSEC has the best chance to successfully undertake such an initiative. However, we believe this scenario is unlikely, given OPSECs sharp focus on security. Second, traditional network management vendors could expand their products for better and easier integration with security specific solutions. Vendors such as Computer Associates, BMC Software, and Hewlett Packard fall into this category. Until now, these vendors have left tighter integration of security solutions up to the end user. Third, new architectures for security integration and middleware could emerge. Vendors in this category include e-Security, Intellitactics, and OpenService, which provide an agent-based, integrated architecture to accommodate both security and non-security solutions. Finally, we are likely to see additional mergers between networking and security vendors such as the acquisition of WebTrends by NetIQ and the acquisition of Network Security Wizards by Enterasys.
From Network Security to Network Integrity
One way to ensure the health of IT infrastructure is to prevent it from contamination by keeping unauthorized users away, seeking out and patching vulnerabilities, and deploying various security solutions as preventive measures. This approach works to some extent but is neither fool proof nor 100% effective. The problem of good network health is compounded due to constant evolution in the IT infrastructurechanging network configurations, product revisions, patches across numerous heterogeneous components, and dynamic organizational requirements. Tripwire, Inc. has a unique approach that complements the preventive solutions and attacks the issue from network management, risk mitigation, and security perspectives (Exhibit 87).
Exhibit 87 ◆ Data and Network Integrity
Source: TripWire Inc.
Ris M na em nt
In rne Net ork
Data & Network Integrity
Tripwire approaches the problem as an integrity issue versus a security issue. This approach assumes that, despite best efforts, the integrity of ones data and IT infrastructure will invariably deteriorate over time. The scope of this assumption is not only restricted to the security solutions but is applicable to any kind of IT deployment. This integrity-based approach monitors for a variety of changes (e.g., size, access flags, configuration data, and read/write times) in all kinds of files related to network infrastructure. Any changes are analyzed and reported, with unexplained deviations marked as drifts from a good state to indicate deterioration in integrity. Once such deterioration is identified, the files can be restored to their original good state. This approach is a catch all for any contamination that originates either inside or outside an organization and is either intended or unintended. This approach allows quick identification of abnormalities and enables a quick recovery via deployment of back-up files. We expect this approach to become increasingly popular for managing IT infrastructures, either as a stand-alone solution or as an embedded component in a broader infrastructure management package.
u