Feeds

SAN security under the spotlight

If you've networked your storage, you'd better start thinking about security

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

Having got standards programmes underway for SAN interoperability and management, the Storage Networking Industry Association (SNIA) is turning its attention to the next key part of the puzzle: storage security.

"Three things kicked it off," says Mike Alverado of Neoscale, who chairs SNIA's Storage Security Industry Forum , which held a technology demonstration at Storage Networking World in Orlando last week.

"First, storage over IP, as IP networks are assumed to be insecure. Second, the development of near-line applications means that storage can now be in an insecure remote location - tapes can be stolen, too.

"The third thing is that storage consolidation on the SAN gives you a place to where all data is shared, and the business managers don't like that because they like their data to be private. So IT is throwing a party and no-one wants to go."

The challenge is that application-level security, network security and storage-level security must all work together. For example, encryption of SAN block traffic relies on the application to do authentication.

Alverado says that security has to be integrated within management frameworks too, so the SNIA storage management initiative (SMI) includes fleshing out and refining the security model.

"The concerns are the effect of security on throughput, and the business value of adding security - it too easily becomes a technical issue or just insurance," he says. "You cannot view it as insurance, it has to be built in."

The industry has already voted to adopt the existing CHAP authentication protocol for Fibre Channel, he adds. The SSIF is also working on a security protocol analogous to the IETF's IPsec, provisionally titled FCsec.

Security for virtualized datacentres

More from The Register

next story
It's Big, it's Blue... it's simply FABLESS! IBM's chip-free future
Or why the reversal of globalisation ain't gonna 'appen
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
Microsoft and Dell’s cloud in a box: Instant Azure for the data centre
A less painful way to run Microsoft’s private cloud
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
CAGE MATCH: Microsoft, Dell open co-located bit barns in Oz
Whole new species of XaaS spawning in the antipodes
AWS pulls desktop-as-a-service from the PC
Support for PCoIP protocol means zero clients can run cloudy desktops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.