Thursday, 16 June 2011

IPv6 Changes Security: Is Your Business Ready?

The Internet is running out of room and, as a result, it is about to undergo a major transition to expand the number of available addresses online. This transition is from today’s IPv4 IP protocol to the new IPv6 standard. Businesses need to know and understand this transition – because there will be new security problems in the interim period.

Even though the promise of IPv6 is one of more security, IPv4 has earned its bones over the past few decades, and we’ve familiarized ourselves with what it can and cannot do. On the other hand, we have little to no experience with IPv6 in the real world. On paper, IPv6 looks great.But, I’m sure the Titanic did too. At best, IPv6 facilitates better security, it doesn’t guarantee it. 
Case in point: IPSec. Essentially, this secures IP communication by encrypting and authenticating IP packets. In IPv4, it was optional as a feature; in IPv6, it’s mandatory. Making a feature mandatory doesn’t mean it will find widespread support; the point is, IPv6 isn’t automatically more secure. It’s going to take a lot of pre-rollout preparation and an immense amount of security vigilance to get it right.
For businesses, there’s a lot to consider, and this will likely fall into the lap of the CSO. There are all sorts of pitfalls to avoid, and here are some to keep on top of at all times.

Buggy Programming. This is where things usually fall apart. In a transition this complex, on a scale this large, programmers are much more likely to make mistakes in the implementation, which could leave vulnerabilities wide open to hackers, negating the effectiveness of IPv6’s bells and whistles of security. The worst-case scenario is actually ending up with an IPv6 infrastructure that’s even more brittle than the IPv4 infrastructure before it, placing a business at even greater risk, by amplifying the attack space.

Transition Exploitation. This migration is going to take a while, and until then, businesses will be straddling a dual IPv4/IPv6 environment, each with its own specific set of security problems.This ups the workload for companies’ networking staff and increases the number of ways things could go wrong. This is where security vigilance is crucial; due to this hybrid interim, we’re going to encounter unusual situations where hackers can potentially take advance of an interaction between the protocols.

Ineffective Blacklists. While IP blacklisting has been successful in reducing the global volume of spam, there’s the concern that ISPs won’t be able to scale IP blacklisting to IPv6, given its sheer size. This represents the problem that some security techniques may not transition very well from IPv4 to IPv6, giving hackers even more room with which to mount their attacks.

DDos Attacks. Distributed denial of service (DDoS) attacks, which overwhelm a computer network or Web site to make it useless, will still pose a threat to businesses in IPv6. While IPsec can mitigate the effects of DDoS attacks to some degree, it does not prevent them, leaving resources at risk of being bombarded and brought to a complete stop. Broadcast amplification attacks, like “smurf” attacks, can do exactly that: keep you from your customer.

Evading Security Measures. Fragmentation attacks will still be a problem in IPv6, although architectural changes mitigate these attacks more efficiently. Fragmentation attacks can be used to evade, intrusion detection systems [IDS], intrusion prevention systems [IPS], and firewalls--often a business's only means for learning when they’re being attacked. Once they’re in, everything is fair game: client information, credentials, e-mails and trade secrets.

Masking Points of Origin. Spoofing attacks will still be a threat in IPv6, but the new IPsec mandate will better manage this threat for businesses. Spoofing allows hackers to conceal their identities, making it hard to track them down after an attack. It can also be used to fake an identity--to implicate an innocent person or company in an attack in which they had no real involvement. Attacks aren’t limited to those that try to steal information or destroy resources, they can actually attempt to tarnish the company’s reputation.

On June 8, World IPv6 Day, industry leaders like Facebook, Google (NASDAQ:GOOG), Bing, Yahoo (NASDAQ:YHOO) and Cisco (NADAQ:CSCO), among others, did a test run of their content over IPv6 for 24 hours. This served as an excellent benchmark for businesses, in order to gauge--at least somewhat--the impact it will have not only on their customer base, but their infrastructure.

You’re going to have to hurry: the federal government is considering the end of 2012 as the deadline for converting to IPv6. Don’t take this change lightly; we’re talking about the backbone of e-commerce, and that can make all the difference between maintaining your bottom line--or not.

Wednesday, 25 May 2011

Event: Moving into the New Internet World - IPv6 with PROGRESO Networks



The existing Internet based on Internet Protocol version 4 is running out of available addresses due to massive web growth, particularly Mobile Internet in both developed and developing nations and APNIC has started allocating the last /8 available IPv4 addresses since 15 April 2011.

In order to avoid the IPv4 address shortage, the next version of IP address, IPv6, is the solution that will provide 340 undecillion of available addresses as compared to just 4 billion of addresses in IPv4. Moving from IPv4 to IPv6 will encourage economic growth, innovation and foreign direct investment through continued Internet growth.


EVENT HIGHLIGHTS

1.30pm                       Registration
2.00pm - 2.15pm       Welcome Speech & Company Introduction
                                 Mr Victor Tang, Director - PROGRESO Networks Pte Ltd


2.15pm - 3.00pm       Keynote Address -
                                 IPv6 Migration, Planning & Execution
                                 Prof. Dr. Sureswaran Ramadass, Director of National
                                 Advanced IPv6 Centre of Excellence (NAv6)


3.00pm - 3.45pm      Tea Break & Networking Session

3.45pm - 4.15pm      Speaker Slot

4.15pm - 4.45pm      Introduction of IPv6 Certification Courses
                                Mr Adil Hidayat, IPv6 Trainer, National Advanced IPv6 Centre of   

                                Excellence (NAv6)

4.45pm - 5.00pm      Q & A


WHO'S ATTENDING?
CEOs, CIOs, IT Managers and other corporate decision makers who need to acquire basic IPv6 knowledge and understand the opportunities that lies ahead with IPv6.



For event RSVP, please email to marketing@progreso.com.sg or call us at +65 6509 9600 for more information.
Limited seats available. Kindly Register by 24 JUNE 2011

Friday, 15 April 2011

Asia Pacific IPv4 Exhausted, Becomes First Region Unable to Meet IPv4 Demand

Asia Pacific Network Information Center (APNIC) today announced it has reached the last block of its available pool of IPv4 addresses. The day is marked as key turning point which initiates a major change in regional delegation policy. From today's announcement [PDF]:

This event is a key turning point in IPv4 exhaustion for the Asia Pacific, as the remaining IPv4 space will be 'rationed' to network operators to be used as essential connectivity with next-generation IPv6 addresses. All new and existing APNIC Members who meet the current allocation criteria will be entitled to a maximum delegation of a /22 (1,024 addresses) of IPv4 space.

APNIC Director General Paul Wilson explained the Asia Pacific region is the first to reach the point of being unable to meet IPv4 demand. This is due to the unprecedented fixed and mobile network growth the region is experiencing.


"Considering the ongoing demand for IP addresses, this date effectively represents IPv4 exhaustion for many of the current operators in the Asia Pacific region," Wilson said. "From this day onwards, IPv6 is mandatory for building new Internet networks and services."

Friday, 8 April 2011

The next generation internet: IPv6 Forum Launches the IPv6 Education Certification Logo Program


TOKYO - BEIJING - Penang - Malayisia - New Hampshire - USA - LUXEMBOURG, September 06, 2010 - The IPv6 Forum Ready Logo Program Committee releases a new program: the IPv6 Education Certification Logo Program. This program defines and certifies courses, engineers and trainers with Silver & Gold Logo levels and requires IPv6 implementation on the web site of the education program.

A recent survey on IPv6 training and studies at universities and vendors has demonstrated that IPv6 training and courses are way too embryonic to have any critical impact. It is estimated that some 20 million engineers are working on the current Internet worldwide at ISPs, corporate and all other public and private organizations and they will need quality training on IPv6. This is a gigantic task since it’s the first upgrade of the Internet and most probably the last one for decades to come. The web site of the study can be seen here: http://www.training4ipv6.eu/

The IPv6 Forum Education Logo Program’s prime objective is to encourage and accelerate the education on IPv6 and promote thereby swifter adoption of IPv6 in the education curriculum and programs of the universities, research institutes, vendors and training specialists. This program is designed to increase practical engineering expertise and hands-on knowledge to tackle this large undertaking ahead of us extending thereby user confidence by demonstrating that IPv6 will be deployed by qualified engineers.


LATEST NEWS: 

PROGRESO Networks will be launching a full range IPv6 solution in the coming July 2011.  We offer the IPv6 forum certified course, consultancy services, deployment and migration services and products.  As a Singapore ATC(Authorised Training Centre) for IPv6, our courses will include the following:

- IPv6 Forum Certified Engineer (Silver Certification)
- IPv6 Forum Certified Engineer (Gold Certification)
- IPv6 Forum Certified Trainer (Gold Certification)

Contact us for more information on IPv6 solution:

Office No.: +65 6509 9600
Fax No.: +65 6509 9667
Info: ipv6@progreso.com.sg 

Thursday, 31 March 2011

fourDscape® Surveillance Technology helps First Responders Access Events in Real-time.

fourDscape® is a patented four dimensional, integrated visualization technology providing situational awareness and command & control in a single easy-to-use interface. fourDscape's browser/server architecture, has been designed to be a modular, open, and easy to use, and provides interactive visualization capabilities which make it an ideal technology to integrate into the data center and facilities environments.


The fourDscape® solution integrates user-generated data from disparate sources, including live smart sensors, into actionable information. The information can be displayed in a fourDscape® browser that effectively presents the data in a single visual scene or common operating picture, providing automated situational awareness for Incident Commanders, First Responders, Law Enforcement, Security Personnel and anyone else that is responsible for Securing and Protecting Infrastructure and/or Human Assets.

The layered system architecture works by refining raw sensor data as it propagates up each layer until it is visually represented in a fourDscape® browser as a temporally-spatially correlated set of dynamic objects in a 4D scene. This scalable, network-based architecture is capable of managing large arrays of surveillance, scanning and tracking sensor suites. The natural user interface delivers full contextual and interactive situation awareness and control.

fourDscape® is a modular system conceptually similar to internet browsers/servers, except that websites exist in 2D space, whereas 4D Portals utilize the entire expanse of 4D time and space. fourDscape® 4D browser users can navigate into the 3D virtual reality of a 4D Portal and move back and forth through the fourth dimension of time to effectively analyze many correlated real-time sensor datasets, both inside the data center and within the surrounding facility.

Related products: TailgatER Mobile Commander Visuality Solutions

Contact Us
Office No.: +65 6509 9600
Fax No.: +65 6509 9667
Info & Sales: sales@progreso.com.sg

Wednesday, 30 March 2011

S'pore Needs Science and Technology to Enhance Security

SINGAPORE: Home Affairs and Law Minister K Shanmugam said Singapore will need to constantly leverage on science and technology to enhance operational capabilities in homeland security.

One way is to work with youths and tertiary institutions to get them to take "a serious role" in helping to make Singapore safe against security threats.

A group of polytechnic and university students have topped the Novel Automobile Barrier Challenge, which was first launched in September last year. They beat 26 other entries to emerge as the top three winners.

The challenge requires participants to come up with a kind of barrier that will effectively stop a moving vehicle travelling at 60 kilometres per hour, from crashing into a building or a facility.

It is understood that this is the first time that the Home Affairs Ministry has organised such a challenge with a tertiary institution and it said it is the first of many to come.

The winning team from the National University of Singapore walked away with a cash prize of S$8,000. One of the team members, Mr Tan Chun Liang, who is a PhD student from the School of Design and Environment, explains how the barrier works.

Mr Tan said: "The design is extremely portable, and we actually designed it so it does not look like a barrier...car hits metal, metal hits ground and ground hits spike. Car stops."

Some of the other ideas received may also be adopted by the ministry but feasibility studies will still need to be conducted.

Dr Lee Fook Kay, Chief Science and Technology Officer with the Home Affairs Ministry, said: "We have barriers but a lot of the barriers are fixtures that we put in the building. Those which are more portable are not so effective, so that's why we are reaching out to the students to see whether they can come up with good solutions. And I think students also tend to look at the economical way of looking at the problem. So they may not be very expensive solutions but they work.

"If you look at events, people do put barricades but some of these are pretty heavy to transport and they are quite a burden. So the ideas that the students have come up with are really very novel. They are deployable and very portable. Students tend to really think out of the box."

A Memorandum of Understanding with NUS is also on the cards to facilitate sharing of information and ideas in science and technology.

Mr Shanmugam said: "MHA aims to stay ahead of evolving security threats, and ensure that the Home Team is always prepared in the face of an ever-changing security environment. A strong partnership with our educational institutions facilitates capability, expertise development and promotes mutual interest."

Mr Shanmugam added that such partnerships will take Singapore's homeland security capabilities to the next level.

-CNA/ac (


PROGRESO Networks Homeland Security Solutions:

Encryption Solution Military Solutions Video Surveillance

Contact Us
Office No.: +65 6509 9600
Fax No.: +65 6509 9667
Info & Sales: sales@progreso.com.sg

Thursday, 24 March 2011

Media Converters in the MAN and Beyond

Most Local Area Networks have migrated to a Gigabit or at least a Fast Ethernet backbone with switched 10/100 connections to clients, printers and file servers. Fast on the inside, but slow on the outside, many U. S. businesses rely on copper T-1 and T-3 connections, or fiber ATM / SONET circuits for WAN connectivity. These connections were designed for voice but were never intended to handle the exponentially growth of Internet and data traffic, applications or the protocols typically used in today's LAN. What's more, provisioning and maintaining these circuits, or upgrading from a T-1 to a T-3 connection is an expensive and time-consuming proposition for both the service provider and the customer. It also requires significant capital investment at both the Point of Presence (POP) and the customer premises.  Ethernet is the dominant LAN protocol with the highest market penetration. Ethernet equipment is readily available at reasonable prices, and provides a migration path from 10 Mbps to 100 Mbps to Gigabit Ethernet. And with the 10, 40 and eventually, 100 Gigabit Ethernet standard, the application space for Ethernet will logically expand from the LAN to the MAN, and eventually to the WAN.


Media Converters are Flexible

Connecting copper switch ports to modular media converters for optical access enables service providers to fully benefit from the flexibility and distance offered by media converters. Media converters support multiple types of media from copper to multi-mode and single-mode fiber, and support 10 Mbps, 100 Mbps and Gigabit Ethernet.  Single-mode converters routinely cover distances of 20, 40 and 80 kilometers with 1310 nm optics, and even up to 130 kilometers with 1550 nm optics.

Media converters can also greatly enhance the consistency of service. With modular media converters, the network administrator can troubleshoot one circuit while the other customers' connections remain up and running. On the customer side, a standalone media converter can be used to provision an optical demarcation point, resulting in more cost savings and simplicity because the Telco router can be eliminated. Behind the media converter on the network edge, a Layer 2 LAN switch can be used to interconnect the public and private networks. Advanced protocols such as 802.1q, 802.1p, Quality of Service, and Network Address Translation can be handled at the POP switching router.

Benefits of Media Converters in the MAN

Tried and proven in the LAN, Ethernet is well positioned to become the protocol of choice for the transport of data, voice and video also outside the LAN.

Protocol transparency — service provider supplies the customer a standard Ethernet interface

Bit rate transparency — customer can connect to the service provider network at 10 Mbps, 100 Mbps or Gigabit Ethernet

Ethernet simplifies the network design — a traditional Telco router can be replaced with a remotely managed media converter

Customers can use the bandwidth they need, when they need it, without the wait associated with legacy services

Using media converters with Ethernet-based services minimizes the cost of provisioning and maintaining optical circuits