MANUFACTURING
Force10 Extends Industry-Leading Resiliency with Security Suite
- Written by: Writer
- Category: MANUFACTURING
Force10 Networks announced a suite of technologies designed to increase network resiliency and protect against the rapidly growing threat of denial of service (DoS) attacks. The Force10 Dynamic Security Suite provides a secure and resilient networking infrastructure that enables network operators to sharply limit the productivity and management costs associated with the attacks that are increasingly disrupting carrier and enterprise networks. To protect against denial of service attacks and other disruptive traffic, the Force10 Dynamic Security Suite builds upon the E-Series' distributed architecture and combines Force10's DoS Guard technology and Hot-Lock access control list updates. Working together, these three features bring greater security and resiliency to the network, increasing network stability and reducing costs associated with managing the network. "Security and resiliency go hand-in-hand as two of the most essential characteristics of today's high performance networks," said Mark Bieberich, senior network infrastructure analyst at Yankee Group. "Systems like the Force10 E-Series that prevent disruptive traffic from wreaking havoc on a network provide a savings advantage in terms of operating and management costs, but more importantly provide highly sought after network stability." DoS attacks cost businesses millions of dollars a year in lost productivity and service and support costs. The Computer Security Institute (CSI) recently released a study that identified DoS attacks as the second most costly web-based security breach to U.S. businesses, behind theft of proprietary information. CSI also found that the rate of attacks increased 250 percent last year, making DoS the fastest growing cyber threat. Security and resiliency are built-in features of the Force10 E-Series architecture. The unique architecture distributes routing, switching and system management functions between three distinct processing units to ensure that no single function consumes more than its fair share of processing capacity. With three processing units on the route processor module, the Force10 E-Series delivers a new level of technical quality that eliminates network instability and ensures maximum network uptime. "Instability and security vulnerabilities are not an option in high performance networking environments," said Andrew Feldman, vice president of marketing for Force10 Networks. "The Force10 E-Series brings a new level of security and resiliency to networks that demand constant availability while decreasing network complexity and operating costs." As the second component of the Dynamic Security Suite, Force10's DoS Guard technology adds another layer of protection against disruptive traffic. DoS Guard automatically filters traffic destined for the route processor module that exceeds pre-set thresholds, eliminating traffic spikes caused by denial of service attacks and ensuring that network operators have constant access to the management interface. By preventing denial of service attacks from overwhelming the processing units, the Force10 E-Series eliminates the outages that are required to reboot the system following an attack on the network, increasing stability and reducing operating costs. The third technology in the Dynamic Security Suite is Force10's Hot-Lock technology, which provides a powerful tool for combating network attacks and reducing traffic disruptions. Uniquely designed to allow network operators to update access control lists (ACLs), a collection of ordered policies that govern traffic and user access, without exposing their networks to malicious and unfiltered traffic, Force10's Hot-Lock technology increases network security. Comprehensive network security requires the administrator to update ACLs frequently to prevent new or pending attacks from affecting the network. During ACL modification, traditional solutions disable ACLs, temporarily creating a security hole that leaves the network vulnerable. A change that takes a few seconds translates into millions of packets passing unchecked through the network at Gigabit or 10 Gigabit speeds. Force10's Hot-Lock technology updates ACLs in a single action, eliminating the security holes generated during typical two-step ACL updates. This process enables network operators to dynamically apply new or modified ACLs directly to the network without disabling them, preventing traffic disruptions typically introduced when modified ACLs are reapplied to the network. The Force10 E-Series combines unmatched scalability with best-in-class resiliency to give network administrators a new level of network and application predictability. The built-in redundancy that characterizes the Force10 E-Series simplifies network topology, management and troubleshooting while line-rate Gigabit and 10 Gigabit throughput, regardless of traffic conditions, enables predictable performance.