Showing posts with label server. Show all posts
Showing posts with label server. Show all posts

Tuesday, December 31, 2019

Looking ahead to 2020, Rackspace CTO Joel Friedman offers his predictions

As the New Year 2020 begins, hybrid and multi-cloud will continue to gain traction, as will software as a service (SaaS). Security remains a tough nut to crack, and edge computing will gain ground, but Joel Friedman, Rackspace CTO, predicts more modestly than the current hype may suggest.


PREDICTION 1: HYBRID/MULTI-CLOUD REMAINS ASCENDANT
Smart organizations have locked onto the benefits of running apps and data in the places that make the most sense, whether that’s public or private cloud, colocation or, most commonly, a bespoke combination of these that can evolve as business needs and resources dictate. However, the complexity of managing multiple clouds across the dimensions of cost, security, governance, identity and DevOps patterns will continue to grow in 2020.


This complexity is related to the forced reliance upon a multitude of platforms, the rate of technological change, disruptions to traditional service delivery models and a real shortage of skill sets required to bring it all together. Due to these factors, it is likely that multi-cloud solutions will prevail, while the search for qualified external help will intensify.

Finding external help may prove difficult, as not only will managed service providers need to maintain a multi- or hybrid cloud instance, but internal and external vendors will need to work together to manage a multitude of issues around cost governance, security and tagging, to name a few. Fortunately, 451 Research has found these growing pains can be alleviated with clear communication and flexibility on each partner’s part.

PREDICTION 2: SAAS = PROBLEM SOLVED
On top of infrastructure, one of the cloud strategies I hear on repeat when working with customers is that “cloud first” starts with SaaS. They don’t want to reinvent the (inferior) wheel by developing applications for ‘solved’ problems. Mature SaaS offerings are a culmination of many iterations of customer mandated features, user experience analysis, and just as important, industry best practices around process workflows.

In many cases, organizations choosing to fit their internal process to best match their SaaS vendor’s implementation – as opposed to always opting for customizing the platform to suit legacy workflows. Furthermore, SaaS has a compounding effect with data; once data is in the system, other ecosystem players can offer turn-key integration and add-on services, further enhancing the value proposition of SaaS. 

While this isn’t necessarily a new trend, Friedman predicts this will be the norm in 2020 and expects to see more and more niche, and vertically-focused applications developing a SaaS model.


PREDICTION 3: SECURITY REMAINS A STRUGGLE
When it comes to security, many organizations remain burdened with legacy systems riddled with technical debt and corresponding security vulnerabilities. They understand the need to harness cloud-compatible security frameworks, operating models and tools to operate securely in cloud-native environments, but it can be slow and rough going.

Most industries simply have not reached the place where mature cloud security practices are being implemented, and this creates fertile ground for breaches. Too many are still attempting to apply traditional security controls and methodologies to cloud-native environments and deployments. 

This generally does not work well; not only is the security implementation likely to be ill fit, it also creates drag on the organization’s desired benefits of agility. This sometimes leads to fragmentation, where business units go around central security and implement on their own shadow security. The risks of this should be obvious.

In 2020, Friedman thinks that the cloud continues to present some growing pains to even the most digital-native and forward-thinking organizations. These organizations understand how the cloud can aid their business in moving fast, but they don’t yet have the maturity to implement real-time or just-in-time posture management and ‘least privilege’ protocols in the ephemeral, complex and constantly changing world of multi-cloud. 

While security teams straddle the old world of insecure legacy applications and platforms (those which cannot or should not be modernized), and the relative newness of cloud operating models, I unfortunately expect to see the breach headlines continue in 2020 along with all of the free credit monitoring can handle.

Even when the security teams agree in concept that it’s possible to be more secure in the cloud, many do not have cloud compatible security frameworks, operating models and tools to aid the business in operating in cloud-native environments securely.


PREDICTION 4: CLOUD CONTROL PLANE WILL BECOME THE NORM
There has been a trend over the past few years in which the management plane has been reversing from the datacenter to the cloud. For early cloud adopters, the datacenter was still the central control point. Organizations burst into the cloud or had back-end projects with no internet accessibility. As cloud grew in popularity, more and more greenfield projects became cloud-native.

Granted, many still integrate with on-premises or hosted private clouds for identity, business intelligence or other data enrichment requirements, but the hyperscalers have now moved past denying that hybrid cloud is real (in attempts to capture all workloads), and pivoted their strategy to capture those datacenter workloads where they stand and bring them into their ecosystem. 

This includes Snowball Edge, AWS RDS of VMware, Azure Stack/Azure Arc and Google Anthos. Expect to see more such services in 2020. And why shouldn’t we? Cloud providers have proven their effectiveness of securely operating at scale, and API-enabling everything.


PREDICTION 5: EDGE WILL GAIN MODERATE GROUND
Edge computing is a new frontier — no player is currently dominating this space, as it is a naturally fragmented market. When choosing locations over platforms to address local markets, data sovereignty, and other use case specific needs, I believe organizations may want to align in a technology-neutral and consistent manner. And based on the trends over the past year, containers and serverless seem like a natural beneficiary for edge.

As Kubernetes dominates in the container orchestration arena, serverless is another story in which, as of yet, there are no victors. AWS, Azure and Google Cloud Platform all have their own flavors of Function-as-a-Service (FaaS), which are embedded within their respective cloud ecosystems. Will OpenFaaS with kNative gain some ground based on open standards, addressing the often spoken lock-in avoidance and mobility potential? We shall see. 

Either way, Friedman predicts that 2020 will see lots of innovation and exploration in the edge space, but he suspects this is the year of gaining momentum and the floodgates won’t open until 2021.

Kaspersky Web Traffic Security now available in two deployment options to meet customer demands

Kaspersky released next version of Kaspersky Web Traffic Security, which now offers enhanced protection capabilities though integration with Kaspersky Anti Targeted Attack to improve early detection of sophisticated web threats. The product is now available in two deployment options, as a standalone application and a software appliance, to meet broader customer needs.


According to Kaspersky researchers, 717 million web attacks were revealed in the second quarter of this year. The attacks contain various kinds of malware including generic adware to ransomware and advanced threats that reach corporate networks through phishing, social engineering or unreliable web resource surfing.

Web gateway protection allows companies to block massive amounts of web threats before they reach endpoints. This decreases the number of alerts on endpoints that interrupt users and administrators, as well as ensures protection of devices which don’t have endpoint security product installed or updated.


To make the deployment and use of the product effective for companies with different needs, Kaspersky now offers two options: as a software appliance or a standalone application.

The software appliance is a ready-to-use solution for companies that need to quickly deploy and start using secure web gateway with a proxy server pre-configured. The appliance interface allows users to manage the incorporated proxy server, avoiding configuration hassle.

The Kaspersky Web Traffic Security standalone application allows resource economy and a more agile configuration for companies that need a more customized solution and careful integration of different cybersecurity products. The application does not necessarily demand a separate server, as the system requirements necessary to protect a particular bandwidth are met. It can be installed alongside other applications but configured separately from other gateway components.


The protection capabilities of Kaspersky Web Traffic Security are now empowered by two-way API-based integration with Kaspersky Anti Targeted Attack, which allows customers of both solutions to achieve earlier attack detection and automated responses to advanced web threats. 

Suspicious files are automatically sent to Kaspersky Anti Targeted Attack for analysis. The system reveals the nature and malicious activity that the advanced threat generates, including files, transmission of commands, payloads and stolen data, and blocks them at the early attack stage.


“Different deployment scenarios allow companies to choose the best way to secure corporate web traffic, depending on available resources or IT network architecture,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “It also brings new usage scenarios to our partners. For example, the new format of the all-in-one appliance can be used by managed service providers to add web traffic security to their portfolio. Thanks to the application’s ease of deployment, scalability and multi-tenancy, they can provide web traffic security as a service for additional protection to ever growing number of customers, without the hassle.”

Kaspersky Web Traffic Security is available in both deployment options as part of Kaspersky Security for Internet Gateway and Kaspersky Total Security for Business.

Tuesday, December 24, 2019

SolarWinds Backup for Office 365 delivers cloud-first data protection for Office 365 Exchange, OneDrive, SharePoint

SolarWinds, provider of IT management software, launches SolarWinds Backup for Office 365, designed to extend data protection services by helping ensure the retention and recoverability of Office 365 data.

Backup for Office 365 backs up and helps restore Exchange, OneDrive and SharePoint data, managed from the same web-based dashboard used to protect servers, workstations, and critical business documents. The need for effective and affordable tools to help MSPs reduce the potential impact of malicious external attacks or internal user error is growing. 


Related data retention, recoverability, and the ability to demonstrate regulatory compliance is becoming even more critical, as more businesses continue to adopt SaaS applications and shift resources to the cloud.

With Backup for Office 365, users are able to save administrative time by managing Office 365 backups alongside server and workstation backups, keep recoverable copies of Exchange data for seven years, and archive OneDrive and SharePoint data for one year. Backup storage in SolarWinds’ private cloud is included, with more than 30 data centers worldwide to help meet data locality requirements.


Users can often unwittingly (or purposely) delete important emails, or OneDrive or SharePoint files. If this happens, SolarWinds Backup offers the ability to search for, and recover what is needed. If employees leave and the company does not want to continue paying a subscription fee to store their email and shared documents, then the SolarWinds Backup for Office 365 offers an additional way to retain and access this data. If the enterprise must comply under regulations with data-retention requirements, SolarWinds Backup is designed to help retain and archive critical data.

With SolarWinds Backup for Office 365, users can manage Office 365 Exchange, OneDrive, and SharePoint backups from a single web-based dashboard. They can also view and manage backup status across customers, and several devices and data types. SolarWinds Backup also helps strike the right balance between automation and control. Users can manually select which accounts and mailboxes they want to protect, or automatically add newly created Office 365 accounts to the backup schedule.


“Backup for Office 365 has assisted us in making our clients feel more secure and comfortable with cloud solutions because they’ve regained control over their data backups,” said Kelvin Tegelaar​, CTO, Lime Networks. “This solution is easy to manage, is super-efficient, and gives our customers an extra layer of protection and continuity.”

“If you’re relying on storage to do the job of backup, you’re putting your data at risk. Anything from an overzealous email cleanup to a deliberate ransomware attack can leave you scrambling if your data isn’t safely backed up. Microsoft is focused on the availability of active email and data, but potential gaps exist around the recoverability of accidentally deleted or overwritten data that are only solved by an effective backup product,” said Mav Turner, group vice president of products, SolarWinds MSP. “Backup for Office 365 is designed for peace of mind; you retain control over the retention and recoverability of your customers’ data in Office 365 and can be ready to help them in their time of need. Your backups will run seamlessly in the background, and the only difference you’ll notice will be increased trust that your data is safe, no matter what.”

Friday, December 20, 2019

Emotet security attack causes shutdown of Frankfurt’s IT network

The city of Frankfurt, Germany, became the latest victim of Emotet after an infection forced it to close its IT network. But the financial center wasn’t the only area that was targeted by Emotet, as there were also incidents that occurred in Gießen and Bad Homburg, a town and a city north of Frankfurt, respectively, as well as in Freiburg, a city in southwest Germany.

The infection started after an employee of the Fechenheim (a district in Frankfurt) civil registry clicked on an Emotet-laden attachment from a malicious spam email, apparently sent by a city authority. Alarms were raised by the security system, prompting officials to restrict city services and take the IT system off the network as a precautionary measure.  


Germany has been a frequent target over the past few weeks by threat actors employing Emotet, and in general has been a target for malicious activity this year, according to data from the Trend Micro Smart Protection Network infrastructure. In fact, the German Federal Office for Information Security (BSI) issued a press release warning the public about malicious spam emails that carry Emotet.

First detected in 2014, Emotet has become one of the most notorious malware families of the past few years. Its original iteration was as an information-stealing banking malware — however, it has since undergone multiple evolutions, including acting as a loader for other malware families. It went into hiatus earlier in the year but came back after a few months with a vengeance. This recent spate of attacks on Germany is likely a continuation of Emotet’s comeback campaigns.

Despite all the changes Emotet has undergone, spam mail remains the malware’s most prominent distribution method. The key strategy organizations can implement is to educate their employees regarding email threats and to encourage them to follow the recommended security best practices when accessing their emails. This includes always double-checking an email for any red flags, as well as refraining from clicking any links or downloading any attachments haphazardly.

Combating threats like Emotet calls for a multilayered and proactive approach to security that involves protecting all fronts — gateway, endpoints, networks, and servers. Trend Micro endpoint solutions such as Trend Micro Smart Protection Suites and Worry-Free Business Security can protect users and businesses from these threats by detecting malicious files and spammed messages, as well as blocking all related malicious URLs.

To bolster their security capabilities and further protect their end users, organizations can consider security products such as the Trend Micro Cloud App Security solution, which uses machine learning (ML) to help detect and block spam and phishing attempts. 

If a malicious email is received by an employee, it will go through sender, content, and URL reputation analysis, which is followed by an inspection of the remaining URLs using computer vision and AI to check if website components are being spoofed. The solution can also detect suspicious content in the message body and attachments and provide sandbox malware analysis and document exploit detection.

Thursday, December 19, 2019

Schneider Electric releases its initial integrated rack with immersed, liquid-cooled IT for data centers

Schneider Electric, vendor of digital transformation of energy management and automation, with Avnet and Iceotope, announces creation of commercially-available integrated rack with chassis-based, immersive liquid cooling. Optimized for compute-intensive applications, the solution combines a high-powered GPU server with Iceotope’s liquid cooling technology to increase energy efficiency. 


Avnet integrates the liquid-cooled server with Schneider Electric’s NetShelter liquid-cooled enclosure system for simple deployment into data centers or edge computing environments. The system is EcoStruxure Ready since the solution is available with next generation data center management software, EcoStruxure IT Expert and our digital service EcoStruxure Asset Advisor. 

This liquid-cooled solution is ideal for applications such as big data analytics, artificial intelligence, and machine-learning algorithm training development, where high compute demands more energy use. In a recent report published by Gartner, liquid cooling was identified as a technology to watch. 

Analyst Henrique Cecci advised data center operators “maximize cooling energy efficiencies by employing modern liquid cooling solutions.” Liquid cooling offers greater efficiency, lower operating costs, smaller footprint, increased reliability, and nearly silent operation despite the high-power density of the GPUs. 


Avnet, Iceotope and Schneider Electric plan to expand the offering as demand grows by welcoming other server OEMs into the partnership. 

“Schneider Electric is committed to making data centers more sustainable and liquid cooling is a very compelling approach,” said Kevin Brown, CTO and SVP of Innovation, Secure Power, Schneider Electric, who is presenting on liquid cooling at the Gartner conference. “This latest development marks a significant step toward industrializing chassis-based immersion solutions which offer the efficiency and effectiveness of tanks based solutions while providing the compatibility and serviceability of more traditional, ‘direct-to-chip’ liquid-cooling designs. Given the growth of compute-intensive applications, we believe this approach is very promising.”

“As a leading global technology solutions provider, Avnet has always excelled at adapting to changing markets, trends, and technologies,” said Scott MacDonald, global president, Avnet Integrated. “We do well at this by partnering with the world’s best technology designers and hardware manufacturers. In this case, we’re partnering with liquid cooling-specialist, Iceotope, and global infrastructure giant, Schneider Electric, to make the best possible liquid cooling solutions for our customers. We’re excited to integrate, fulfill, and support this solution that smartly addresses customer cooling challenges around rising chip densities, harsh IT environments, rising energy costs, water use restrictions, and space constraints.”


“Iceotope is thrilled to be making its innovative chassis-level, immersive liquid cooling technology available to the general market,” said David Craig, CEO of Iceotope. “We offer the only liquid cooling tech that scales easily from edge computing devices to large server farms in the cloud. And compared to direct-to-chip liquid cooling systems, our approach is more efficient, more reliable, saves more space, eliminates fans, and when deployed across the data center, it lowers cost.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...