Will NFV/SDN technologies help the state of security? Or will we end up lost in the Clouds?
As NFV/SDN technology spreads, so does the lure of reduced expenditures for capital outlay and operating costs. The synergies available for early adopters are enticing. As Network Operators and Enterprise Services providers look to these technologies and the Internet of Things (IoT) with its imminent high volumes of end devices, the tantalizing revenue streams to be realized are not easily discounted.
Thus enters the age old antagonist of security practitioners everywhere: Deployment of new technologies require speed to market or they meet death. In the ensuring R&D, testing and roll-out, security it seems, is only an afterthought. It is an addendum on the official Requests for Proposal (RfP) process-often brought up only after bidders raise questions or flags about the risk or viability of a solution-Section CMXCIX – Please describe how you will address security and risk in the solution you are proposing and detail your companies security policies and procedures to minimize risk-in 500 words or less). en worse than the above scenario is this situation: The requester actually gets security needs correct and with the RfP, includes a 75+ page document of security needs and requirements. The hiccup comes when the bidders receive this document only a few days before the RfP submission period ends. Remember, it usually takes a company 3-5
working days to find the folks that can actually understand and comprehend a REAL security requirements document…the same underpaid boys and girls that then have the unenviable position of forming a response the entire bid rests on, in 24 hours or less with little to no knowledge of the hardware/software security capabilities.
Quick adoption of NFV/SDN will be key to some companies moving forward, it will mean their success or demise in rather clear terms. Those that get it right will likely reap wild benefits and those that are slow to adopt or adopt with a few small but critical errors may suffer a slow withering demise as they try to correct and become even less relevant. That Security will be part of the “Get it Right” this time around is the hope of myself and many others.
What will security look like in NFV/SDN deployments? What standards will apply? Is your use case and solution in a single physical country? Multiple countries? Data Center conveniently offshore to save on costs? Where are the customers? Same country or another? Does that “other” country or countries have strict and detailed sets of legal requirements for personal privacy and data security? Do they not allow or are they leaning towards data centers not being allowed in certain geographic regions because of governmental peering into data sets? (Or while there is no governmental driver, does your business environment drive such decisions?). These are all good questions and ones that need to be asked as companies drive at light speed towards adoption of technology which allows hardware and software to be built and utilized in a less specific use case and more generalist in nature.
All the above questions and more are being looked at by the various standards organizations at present and they are moving in their own ways towards developing answers to these questions (as well as those with other new technologies) but my fear is that with the current pace, it will come a bit late. It is my belief the real solution will only come if standards bodies can act quickly and efficiently to develop standards that are practical to implement and/or adhere in a much shorter time frame than is traditional. While this may seem difficult given that such organizations leverage the work of individuals, companies and governments with what results as “volunteer” time to develop these standards, it is not an unattainable goal and it is my hope that many of the security old timers may just be fed up enough with the current situation to jump in and assist so that the industry can get it right with security this time.
Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.
