Network Security: Coming Of Age

author-image
DQC News Bureau
New Update



Network security solutions are coming of age in the Indian IT market, owing
primarily to business houses of various sizes understanding its importance.
While organizations are adopting a proactive approach towards embracing security
measures as a business imperative, vendors in this space are witnessing an added
momentum in their business growth.

Advertisment

Sharing her views over the market scenario, Nupur Singh Andley, Associate
Research Manager-Connectivity, Springboard Research said, “The market for
enterprise network security equipment in Asia Pacific will be around $1.3
billion by the end of 2010 and is expected to reach $2.1 billion by 2013.” She
continued, “Furthermore, the anticipated post recession demand for enterprise
telecom networks and datacenter is likely to propel the adoption of high-end
network security solutions.”

Market trends

According to Cisco's recently released annual security report for the year
2009, the number of vulnerabilities and threats remained relatively consistent
in 2009 compared to previous years, but the exploit and attack threat levels
have increased by 57 percent. New attacks rely on social media users'
willingness to respond to messages that supposedly originate from known and
trusted users. It is easier and often more lucrative to trick a social media
user in order to launch an attack or exploit or steal personal information.

Sharing a similar viewpoint, Vishal Dhupar, MD, Symantec India said,
“According to industry analysts, the network security appliance market is
growing at a CAGR of about 14.5 percent worldwide. New analysis from Frost &
Sullivan finds that the market, covering 14 Asia-Pacific countries was worth an
estimated Rs 8,870 crore in 2008, growing 17.9 percent from the year before. A
modest CAGR of 7.5 percent is expected from 2009 to 2015, to gross revenue of
just over Rs 14,696.08 crore by end of 2015.”

Advertisment

The recent trend in the market, as a result of the impact of the social
media, has been that security vendors are collaborating more closely on the
disclosure of vulnerabilities working around developing patches and workarounds
before the exploitable information is widely available. “The latest trends are
driven by the fact that endpoint IT is now slowly moving to consumer devices and
most services are now Web based with quite a few of them capable of being moved
into a cloud delivery model. Also organizations will move from thick endpoint
security clients to thin dynamically downloadable secure connection clients,
which run on the endpoints and speak to the cloud security services,” said Jatin
Sachdeva (CISSP, CISA), Information Security Specialist, Cisco.

Threat analysis

Looking closely into the threat analysis perspective, network attackers are
now targeting primarily improper protection in IT infrastructure, unprotected
information, poorly enforced IT policies and weak managed systems. Additionally,
the 'insider threat' to data is also rising, both from malicious internal
sources looking to steal information and well-meaning insiders mishandling
information. “Today's organizations need to manage risk proactively, protecting
not just the infrastructure that data resides in, but also the information. The
dynamic nature of threats from a multitude of sources now means organizations
have to effectively reduce risk and ensure data is protected at all times, no
matter where it is used or stored,” Dhupar added.

The adopters

The earliest adopters of network security have primarily been the banking
and finance verticals, closely followed by the ITeS and BPO sectors. Traditional
enterprises, namely, retail, health and education are now gradually catching up
with the market tempo. “The SMB segment contributed slightly more than one-third
to the total revenues for the network security market in 2008. This percentage
is expected to rise over the next few years as more and more SMBs are beginning
to install at least first-layer perimeter defense on their corporate networks as
converged or integrated security appliances have made network security
affordable for smaller businesses. By 2015, SMBs will account for approximately
45 percent of the revenues,” said Rana Gupta, Business Head-India & SAARC,
SafeNet.

Advertisment

In the slowdown phase, the enterprise segment became tighter over their IT
budget. Still, the BFSI sector remained the leading adopter of network security
solution revenues in 2008, followed closely by service providers and the
government sector. “As per the survey conducted on network security equipment
user organizations across Asia Pacific, one-third of Asian respondents cited
that their network security budgets formed more than 20 percent of their
networking budgets, especially in markets such as China, India, Malaysia and
Philippines, indicating their growing business activities. The survey also
indicated that BFSI and public sectors are amongst the strongest spenders (more
than 20 percent of their networking budgets were spent on network security
equipment, according to 35 percent and 40 percent respondents, respectively) on
network security equipment in the region,” Andley concluded while speaking over
the vertical trends in the network security space.

It is expected that the banking sector will continue to be the biggest
spender on network security moving forward, mainly due to rising regulatory
compliance. “Following the loss of public confidence in the banking system after
the financial debacle of September 2008, the last thing any CIO would want is a
security breach to further dent the confidence of existing and potential
customers,” Gupta added.

The tech outlook

Moving on to the technological front, USB authentication token devices are
one of the latest in the line offering monitoring access during the entire
period a person is logged on, rather than only at the point of sign-on. In the
second place, built-in biometrics is another perimeter in the field of
technology. Built-in biometric fingerprint scanners add a layer of protection by
directly linking the fingerprint image to the system BIOS making it harder to
break into the system.

Advertisment

Today's organizations need to manage risk proactively,
protecting

not just the infrastructure that data resides in, but also the information

Vishal Dhupar, MD, Symantec India

The SMB segment contributed slightly more than one-third
to the total revenues for the network security market in 2008. This
percentage is expected to rise over the next few years

Rana Gupta, Business Head-India & SAARC, SafeNet

Although self-encrypting hard drives are not the latest in technology, it
continues to feature as a top option for the CIOs setting up the IT framework.
The recent trend has been toward automatically encrypting all data so that the
user does not have the option to forget it or avoid it when pressed for time.
“Technologies like VoIP, IPSec and SSL VPN, security, storage and others will
start moving and end-customers will start using the same in their day-to-day
life just like mobile phones, which have become a part of our life. So it will
be the telco, ISP and end-customers, who will drive the networking market to new
dimensions,” said Rishi Samadhia, Executive Director-Channel, ZyXel Technologies
India.

One of the latest advancement in terms of technology has been the
security-aware Web browsers and applications in the extended validation secure
sockets layer (SSL) server certifi­cates, which provides visual cues for secure
and non-secure sites. Mobile device security is, however, the latest in the pack
as there has been a widespread adoption of smart­phones and personal digital
assistants PDAs. However, many organizations have not yet addressed security
adequately for these devices which often carry sensitive data and files on
unencry­pted SD cards and other media.

Advertisment

Wireless LAN

Wireless LAN (WLAN) security, of late, has come into focus with major
projects across the nation taking off primarily in the hospitality and real
estate segment. Wireless networks are becoming faster, more affordable and
easier to adopt. “With 3G and WiMAX technology setting in, telecom operators now
need to carry not just voice but also data, which opens a whole new ground for
network security threats from hackers, viruses, Trojans, and more. Also, as more
users with varied data-capable devices access these networks to carry their data
and voice across multiple networks, there is more traffic and hence higher
probability of security attacks coming in from online sources,” said Tushar
Sighat, VP-Operations, Cyberoam India.

WLAN security has improved immeasurably with the adoption of IEEE 802.11i,
but vendors are still faced with several security gaps. In addition, the
consumers are now demanding more elaborate guest authentication, intrusion
detection, site planning, and network manage­ment. “In wireless front, the next
big thing which would be high in demand is 802.11n products as now 802.11n
technology is ratified by IEEE,” Samadhia concluded.

“Motivated by the need to reduce IT costs while increasing employee
produc­tivity; enter­prise-wide WLAN solutions are becoming increa­singly
viable. Proliferation of mobile computing devices has boosted employee demand
for access to their organization's network beyond the tether of their office
workstation,” Gupta added.

Advertisment

Future trends

Virtualization of security infrastructure is gaining popularity in the Asian
market as it helps reduce costs and address system manageability issues.
Besides, managed security services outsourcing has made significant inroads in
the Asian market as enterprises are striving to reduce capital and operational
expenditures.

However, the enhanced usage of enterprise mobility solutions and
Internet-based applications are fueling the adoption of network security
equipment market in the region with the widespread adoption of social networking
and cloud computing tools and applications by enterprises. “With quick rebound
of world economy lead by countries like India and China, the next few year's
rates are expected to be much better than the last two years. Network security
should continue to grow above 25 percent this calendar year and move to 30
percent levels in the next year,” said Sriram S, CEO, iValue InfoSolutions.

In the coming days, technologies like tokenization and fraud detection could
easily change the way that cloud security is defined. Customers could model user
behavior and everything could be managed and measured in real time in the cloud.
“Vulnerability assessment tools could continuously look for new vulnerabilities
which can be fixed before zero day attacks. Also, heuristics can be used to
model behaviors and build new rule sets in real time to stop new attacks. All
this can theoretically be performed by a security service in the cloud,” Gupta
concluded.

Advertisment



avishekr@cybermedia.co.in