Cisco boffins found startup to kill firewalls

The perimeter is obsolete.

Five former Cisco engineers have co-founded a startup called Rohati Systems whose products take dead aim at traditional perimeter firewalls.

A traditional firewall and its access control list "is not capable of doing its job today from an access-control perspective," says CEO and president Shane Buckley. "Nowadays, your IP address just doesn't represent who you are."

Rohati will mark its debut this week with a network-based entitlement control device designed to limit access to applications, such as Microsoft's SharePoint collaboration suite, based on the user's authentication.

Called the Transaction Networking System (TNS), the appliance is intended to reside close to the data assets it protects, usually in the datacentre. It checks whether users should be permitted to access application data stored there based on user credentials that might include Kerberos, VPN SSL or Microsoft authentication protocol NTML.

TNS functions at the application layer to establish Layer 7 access-control lists to limit who has what access to data, Buckley says. Use of the TNS begins by putting the device in monitor mode to let it watch the users accessing the data, capturing all the transactions, such as opening and closing files.

"This way, the appliance is learning all the transactions in the network," Buckley says. This enables the appliance to build a policy that managers can refine, such as permitting or denying, or allowing reading, writing or deletion. Now in beta and expected to ship in July, the appliance makes use of the OASIS standard called the eXtensible Access Control Markup Language (XACML) for the data-management policy.

"The appliance has a set of policies on who can have access to what based on directory attributes," Buckley says, adding that one advantage is that no changes to existing applications or new client software is required.

TNS competes most directly with entitlement software from CA, Oracle, IBM Tivoli Software and Securent, which was acquired by Cisco last November for $100 million.

Every time a user goes to access an application, a check for authorisation will be made by TNS, but speed shouldn't be an issue, Buckley says, because the two models of the product, the TNS-100 and the TNS-500, scale between 4G and 40Gbps, are built on Infiniband technology and support as many as 6 million connections. In the future, the TNS is likely to be developed to do more than provide access control to applications.

"Because we control the application, this gives us the ability to do things like content cloaking, blocking out sensitive content to the viewer," Buckley says. Content filtering of various types could also be integrated into the basic architecture.

Rohati, which joined the Jericho Forum, the group dedicated to encouraging alternatives to traditional perimeter firewalls for e-commerce, is targeting TNS for organisations that allow business partners to share network resources with internal users.

JDS Uniphase, among others, is said to be a beta tester. TNS 100 starts at $20,000 (approx £10,000) and TNS 500 starts at $85,000(£42,000).


Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Related Security news

Black hole discovery could boost quantum computers

String theory of gravity connected to entanglement

Onapsis to launch ERP vulnerability testing suite

The software searches for vulnerabilities, looks for compliance problems and creates reports

Women are better at protecting corporate secrets

Defcon social engineering contest finds most people give up secrets to strangers

Facebook introduces new security measures to kick out spammers

Users will be able to use IP info to confirm if their account has been hacked in to and reset passwords



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *