Wednesday, October 21, 2009

What is Consumer SOA? "COSA"

So what is Consumer Oriented Service Architecture (COSA)?

SOA is a well known and established technology area with innovation driven by technology vendors like BEA/Oracle and SoftwareAG for leveraging/wrapping legacy applications and rapidly integrating technology across platforms, partners, and customers but COSA is a new concept.

The term itself was coined by Oracle Product Manager Vikas Jain in his blog
http://ws-security.blogspot.com/2009/10/consumer-oriented-service-architecture.html
But the idea is well established and was driven by those delivering services not by technology vendors.

As Vikas points out "While SOA concentrated on how to make the service architecture better, it left out on the consumer focus. The consumer focus becomes especially important when services are exposed to partners."

Vikas goes on to define the key challenges and requirements for a COSA solution such as Consumer Identification, Throttling so that the right customers get the right SLA, Contracts & Policies, Reporting, and Provisioning.

Today media vendors and social media vendors are leading the charge and paving the road with innovative technology vendors like Vordel, Sonoa Systems, Layer7, and Intel.

MTV Networks is a great example with their work with Sonoa Systems:
http://www.sonoasystems.com/about-us/news-and-events/mtv-networks-selects-sonoa-for-api-infrastrcture-feed-management

It is also demonstrated by the participation of Steve Riley, Evangelist and Strategy for Amazon at the Vordel User Conference.
http://www.vordel.com/news/press/16_09_09.html


Intel is targeting Oracle Fusion customers with http://www.intelforfusion.com/

Layer7 is also making waves with their announcement around integrating Oracle Service Bus with their hardware XML Gateway. http://www.layer7tech.com/main/products/osba.html

Tuesday, October 6, 2009

F5 Announces Plans to Unify Access Management for Web Applications

Solution Will Combine F5`s BIG-IP System with Oracle Access Manager to Enhance
Single Sign-on Capabilities and Simplify Access Control

SEATTLE--(Business Wire)-- F5 Networks, Inc. (NASDAQ:FFIV), the global leader in Application Delivery Networking (ADN), today announced that it plans to integrate F5 BIG-IP access solutions with Oracle Identity Management software to centralize web application authentication and authorization services, streamline access management, and reduce infrastructure costs.

Details
Advantages of combining F5 and Oracle solutions will include:

* Tight integration of the F5 BIG-IP system with Oracle Access Manager, enabling reduced TCO, lowered deployment risk, and streamlined operational efficiencies for customers.
* Integration with Oracle Access Manager Single Sign-On (SSO) to promote a superior end-user experience and enhanced user productivity. This integration will enable organizations to adopt an access management and SSO strategy that allows rapid ROI.
* A unified point of enforcement to simplify auditing and control changes in configuring application access settings.

F5, a member of the Oracle PartnerNetwork, will provide additional information about the planned solution in Booth #1421 at Oracle OpenWorld, taking place October 11-15 at the Moscone Convention Center in San Francisco. To learn more about F5`s presence at Oracle OpenWorld and other industry events, please visit www.f5.com/news-press-events/events.

Availability
The combined solution is expected to be available within the first half of CY 2010.

Supporting Quotes
"Ease of implementation and TCO are very important to Oracle and its customers," said Brian Mozinski, Director, Product Management, Identity Management and Security at Oracle. "By integrating functionality from Oracle Access Manager and F5`s BIG-IP system, customers can further streamline their deployments of the Oracle Fusion Middleware 11g Identity Management Suite."

"Our goal is to help businesses maximize the value of their technology investments," said Muneer Taskar, Director, Sales at Persistent Systems, a technology company specializing in software product development services. "Integration and interoperability from vendors like Oracle and F5 make customer deployments simpler and less costly to deploy and manage. We look forward to adding this new access management solution to our product portfolio."

"Close working relationships with key identity and access management vendors like Oracle are very important to F5," said Jason Needham, Sr. Director of Product Management at F5. "Together, we can deliver significant value to our joint customers by enabling them to centralize and unify application access control services across increasingly diverse network environments. F5 is committed to providing innovative access management solutions and edge services-such as SSL VPN, acceleration, and other managed services-to maximize IT agility and deliver enhanced functionality, security, and ROI to customers."

About F5 Networks
F5 Networks is the global leader in Application Delivery Networking (ADN), focused on ensuring the secure, reliable, and fast delivery of applications. F5`s flexible architectural framework enables community-driven innovation that helps organizations enhance IT agility and dynamically deliver services that generate true business value. F5`s vision of unified application and data delivery offers customers an unprecedented level of choice in how they deploy
ADN solutions. It redefines the management of application, server, storage, and network resources, streamlining application delivery and reducing costs. Global enterprise organizations, service and cloud providers, and Web 2.0 content providers trust F5 to keep their business moving forward. For more information, go to www.f5.com.

About the Oracle PartnerNetwork
Oracle PartnerNetwork is a global business network of more than 21,000 companies that deliver innovative software solutions based on Oracle software. Through access to Oracle`s premier products, education, technical services, marketing and sales support, the Oracle PartnerNetwork program provides partners with the resources they need to be successful in today`s global economy. Oracle partners are able to offer their customers leading-edge solutions backed by Oracle`s position as the world's largest business software company. Partners who are able
to demonstrate superior product knowledge, technical expertise and a commitment to doing business with Oracle qualify for the Certified Partner levels. For more information, go to http://oraclepartnernetwork.oracle.com.

F5 and BIG-IP are trademarks or service marks of F5 Networks, Inc., in the U.S. and other countries. Oracle is a registered trademark of Oracle Corporation and/or its affiliates. All other product and company names herein may be trademarks of their respective owners.

This press release may contain forward-looking statements relating to future events or future financial performance that involve risks and uncertainties. Such statements can be identified by terminology such as "may," "will," "should," "expects," "plans," "anticipates," "believes," "estimates," "predicts," "potential," or "continue," or the negative of such terms or
comparable terms. These statements are only predictions and actual results could differ materially from those anticipated in these statements based upon a number of factors including those identified in the company's filings with the SEC.

F5 Networks, Inc.
Alane Moran, 206-272-6850
a.moran@f5.com
or
Connect Public Relations
Holly Hagerman, 801-373-7888
hollyh@connectpr.com

Wednesday, September 30, 2009

Symark is now BeyondTrust

BeyondTrust PowerBroker® Joins Oracle Extended Identity Management Ecosystem

“ONLY 47% OF COMPANIES
IMPLEMENT AN IT REGULATORY
COMPLIANCE PROGRAM.”
- DELOITTE SURVEY, 2009


Information technology and intellectual property are the lifeblood of a typical enterprise
these days. Safeguarding these precious assets is imperative to every organization, and
the number one priority needs to be protecting the organization from itself. Specifically,
protecting administrative, database and superuser passwords, such as root, on Unix/
Linux servers represents the most critical access points to business-critical IT assets and
resources at their most fundamental level. Addressing this dilemma, in addition to the
time consuming tasks of managing multiple identity management solutions, can be an
impossible task for enterprises. That is why BeypndTrust chose to partner with Oracle, in
order to offer a single source solution for all enterprise identity management needs.
BeyondTrust PowerBroker, now part of the Oracle® Extended Identity Management
Ecosystem, provides enterprises with a comprehensive privileged access control application
to implement highly flexible policy language to enforce across multiple Unix/Linux
platforms and operations throughout the enterprise. Features include:

SELECTIVELY DELEGATE ROOT & OTHER SPECIAL ACCOUNT PRIVILEGES
PowerBroker enables users to perform specified administrative tasks without disclosing the
account password to them, dramatically strengthening enterprise security. Additionally,
PowerBroker secures and manages third-party application account privileges, such as Oracle
database accounts, which commonly store business critical information.

HIGHLY CONFIGURABLE SECURITY & ENFORCEMENT POLICIES
PowerBroker offers a dynamic policy scripting language to arm administrators with the tools
to create and manage detailed policies seamlessly, which grant specific access to perform
tasks. Enterprises can granularly restrict per user, group, netgroup, host, day/date/time, to/
from specified hosts, and based upon AD, NIS, NIS+ or LDAP data.

SECURELY LOG, REPORT & PRODUCE RELIABLE AUDIT TRAILS
PowerBroker logs every requested task, including all environmental information, and
encrypts logs to prevent modification. PowerBroker protects enterprises from common
violations of many U.S. and Canadian government compliance regulations and industry
standards such as SOX, PCI, HIPAA, GLBA and FISMA.

QUICK DEPLOYMENT & NON-INTRUSIVE
PowerBroker provides reliable, highly secure operations with minimal impact to existing
systems and network architectures. There are no required changes to the Unix/Linux kernel
or operating system or system reboots after installation. PowerBroker sessions are similar to
telnet sessions, requiring minimal system resources.






To learn more visit:

Thursday, August 27, 2009

Location, Location, Location!!!

Why IP Intelligence (Geo Location Data) is important for Authentication?

In the growing area of risk based authentication where organizations from banks to governmental departments are looking to share more information and services with people there is a much greater risk/fear of fraud.

Information Security vendors such as Oracle, RSA, Verisign, and others have complimented their existing Web Access Control technologies like Oracle Access Manager (OAM) with Risk Based Authentication solutions such as Oracle Adaptive Access Manager (OAAM) which assess the risk of fraud at the moment of a transaction and, based on policy, respond by allowing/denying the transaction or requiring secondary or “Step-up Authentication”.

In these scenarios, the more context available to the transaction the better risk analysis. Knowing that a banking customer who lives in Oslo, Norway is trying to send a wire transfer out of the account is actually logging in from Seattle, WA gives makes it simple to understand the potential risk.

IP data enables core risk assessments made within OAAM including; website visitor location (i.e. block high risk locations), network characteristice (i.e. is the visitor connected through an anonymzing proxy—intentionally masking their location), IP data provides an “IP fingerprint” of a visitor.

To help deliver this intelligence to customers Oracle partners with Quova as the preferred IP provider for OAAM. They provide specific ROI advantages over competitors.. Quova’s unmatched accuracy and depth of proxy intelligence data result in increased fraud catch and lower false positive escalations.

And Quova is the only provider that subjects its research process and data quality to annual independent audit by PricewaterhouseCoopers. Quova is widely recognized as the market leader and is in use throughout the anti-fraud marketplace. Quova for OAAM customers include; Monster.com, DFCU, ICICI Bank, National City Corporation.

To Learn more about Quova:
Contact Jon Heintschel
650-528-3739 or jheintschel@quova.com

To Learn more about OAAM
http://www.oracle.com/technology/products/id_mgmt/oaam/index.html

Or to learn about the Oracle Access Suite:
http://www.oracle.com/products/middleware/identity-management/access-management-suite.html

Saturday, August 1, 2009

Why the Public Sector needs Bio-Metric Solutions and how ORCL + Daon can help

Combing Oracle IDM Products with Best-of-Breed Biometric Infrastructure from Daon enables successful deployments across the Public Sector



Why are government organizations looking for this?

  • Stronger security to mitigate fraud & ID theft (more details below)
  • Strong Authentication without tokens (more details below)

Why has it not been adopted already?

  • Requirements for end-points to capture & verify biometrics
  • Complexity of provisioning & sharing biometrics across platforms and regions

So how can we be successful now?

  • Provisioning credentials & enabling cross platform SSO
  • Managing roles and fine grain entitlements

What is the real scoop on Fraud:

  • eCommerce Fraud Losses Projected to Grow to $3.6 Billion in 2008
  • Merchants estimate that 1.4% of their online sales will line the pockets of fraudsters
    Source: CyberSource eCommerce Fraud Survey, 2007
  • Société Générale €5 billion in trading loss due to unauthorized trades
  • Trader executed €50 billion of unauthorized trades and attempted to cover over his losses. When the bank discovered the fraud it had to unwind the position in 3 days, resulting in €5 billion in loss and triggering a world wide financial market sell-off.
    Source: CNN, January 2008
  • $17 Million remediation cost for 45 million stolen credit card numbers
    Breach of TJ Maxx’s IT systems led to the lost of 45 million credit and debit card numbers over a period of 18 months. Estimated revenue impact from negative press coverage was $4.5 billion.
    Source: Information Week, May 2007

So why is Strong Authentication not enough?

  • Tokens & Smart Cards require the device to be present, credentials still can be stolen and subject to man in the middle attacks and other Phishing or Virus/Malware breaches
  • Conversly, Biometric Credentials can not be stolen or replicated, user does not have to carry/track additional tools.
  • They can be verified for uniqueness against state, local, federal & international databases
    Rapidly identify potential threats or risky persons.

This is where it gets tricky

  • Capturing & Storing Credentials
  • High cost of having devices at the end-points to capture data
  • Tremendous disparity in capture/read devices & algorithms
  • It is difficult to future proof your deployment when devices, algorithms, and infrastructure continuously evolving
  • Risk of being out of date by the time of production deployment
  • Challenging to provisioning credentials and synchronize biometrics with apps & infrastructure
  • Challenge for using single biometric authentication for SSO

So how do you maximize the ROI?

  • Govt. & Ent. require solutions that compliment & enhance entire IT IDM infrastructure to justify investment.
  • Oracle IDM Solutions Provisioning Credentials
  • Oracle Identity Manager (OIM) enables automated provisioning or revocation of accounts based on biometric auth/enrolment
  • Oracle Role Manager (ORM) ties biometric attributes to user roles
  • Oracle Entitlements Server (OES) richly defines fine-grain applications entitlements to grant/limit access to specific functions, data sets, or transactions based on level of authentication, roles, and credentials.
  • Gain seamless authentication across applications with Oracle eSSO (OESSO)
  • Replaces name/pwd with a a single biometric authentication to increase security level & create single sign-on across web & desktop applications.
  • Oracle Adaptive Access Manager (OAAM) Ties biometric authentication with broader authentication context (like device identification and location) to validate the entire transaction and identify anomalies or malicious behavior over time.

Here is how the Daon solution fits in...


For more information on Daon please visit their website.

Wednesday, July 1, 2009

Security solutions for misuse of information & entitlements

After "Who has access to what?” the question is “What are they doing with it?”

Information security has followed a similar path of information technology. First it was about storing and organizing information in databases and securing that information. Then as applications and middleware evolved to deliver that information and application entitlements to users, Identity and Access management suites developed to securily enable access to them.

But once information and entitlements are in the hands of users it is open for misuse. There are many examples of this:


  • Accidentally emailing confidential information about M&A to the wrong internal user with the same name like John.Waters@xyzcorp.com instead of Jon.Waters@xyzcorp.com.
  • Copying sensitive financial or personal information out of a protected application into a file and posting it on an open file share or SharePoint portal
  • Sales person leaving the company who emails a list of accounts and contacts to themselves before going to work for a competitor.
  • NT Admin who misues the shared account because they know they are 1 of 30 people with the password and nobody knows who did what with it.
  • Former employees hacking into a company database because the password never changes as it is hard coded into applications.



The list of potential risks/attacks goes on and on. To help customers identify these and address them, Oracle has once again expanded the Extended Identity Management Ecosystem to include:


  • Privileged Account Management (PAM) – manage shared and cached credentials for privileged accounts

  • Data Loss Prevention (DLP) – network and endpoint content-aware monitoring, discovery and blocking

Which is complimented by Oracle IAM solutions that provide consistent Security Services & Policy across layers for


  • Compliance – Fine-grained entitlements and identity analytics based on consistent user roles

  • Reconciliation – Closed loop implementation & verification of policies across layers


Our DLP partners (including McAfee, Symantec, & ControlGuard ) integrate with Oracle IRM to:


  • Discover, classify, quarantine and seal (IRM-encrypt)

  • Intercept file copies to removable media, classify, quarantine, seal (IRM-encrypt) & release

DLP integration with Oracle IAM will enable :


  • DLP policies via OID or OVD group membership

  • Provision/de-provision DLP policies via OIM (groups)

  • Feedback/tuning of IAM

Similiarly Oracle PAM partners including Cloakware, Cyber-Ark, Liebsoft, and OpenTrust (formerly Symark) , deliver integrations that allows customers to:


  • Leverage OID/OVD as identity/credential store

  • PAM policies via OID/OVD groups

  • Provision/de-provision policies via OIM (groups)

  • Leverage Oracle database as secure policy store

  • Secure caching of credentials for unattended application restarts

To learn more about these partners please visit their page on OPN or click on their name above to reach their website directly.




{NOTE: Please click on the above images to see the slides in full size for reading the details}

Tuesday, June 30, 2009

Cloakware and Oracle Work to Integrate Cloakware Password Authority with Oracle Identity and Access Management

Integration Strengthens Access Rights Security with Privileged Password Management

Cloakware, the leading provider of privileged password management solutions announced today that it is working with Oracle to extend their suite of Identity Management solutions with Cloakware's flagship product, Password Authority. By combining these two best-in-class products, Oracle is now able to enhance their customers' security management, with a comprehensive solution to manage, protect and monitor access to vital data.

As more and more high-profile data breaches come to light, companies are realizing they need increasingly robust solutions to protect their vital data. A study conducted in January 2009 by the Identity Theft Resource Center of San Diego found that the percentage of breaches attributed to current or former employees more than doubled from 2007 to 2008. In light of findings like this, companies are struggling to balance individuals' access rights to secure information against risk and compliance requirements. Cloakware's patented white-box cryptographic techniques ensure defense-in-depth for end-to-end security of data and keys, especially where insiders have access to the execution environment. Working with Cloakware enables Oracle to offer its customers a solution to securely store and manage privileged passwords for human administrators and runtime applications without changes to the customer's existing infrastructure.

"Extending the Oracle Identity and Access Management Suite with third party platforms provides enhanced efficiency, a higher level of integration and increased effectiveness in terms of application-centric security and risk management," said Ron Huddleston, vice president, North America Technology Channel Sales, at Oracle. "Cloakware's Password Authority is a key part of this eco-system, augmenting our identity management suite."

Password Authority leverages multiple integration points into the Oracle Identity and Access Management Suite, including:

- Oracle Internet Directory (OID) - Password Authority can manage the passwords for accounts held in OID as well as for service accounts that authenticate against OID.

- Oracle Identity Manager (OIM) - Password Authority ensures that password management is synchronized with roles and access rules.

- Oracle WebLogic Server - Password Authority automates the run-time replacement of current passwords in connection strings/connection pools and the management of WebLogic administrator accounts.

- Oracle Database 11g Real Application Cluster (RAC) - Password Authority makes use of the Oracle database as its secure repository for all passwords, and is capable of supporting a geographically distributed database installation. Password Authority is also capable of maintaining and releasing Oracle Database passwords to humans and applications.

"Companies are now starting to understand the importance of employing strict standards to manage access to critical information and protect digital assets; the risks are too high to ignore," said David Canellos, senior vice president, sales and marketing at Irdeto and Cloakware. "By integrating Cloakware Password Authority with Oracle's Identity and Access Management Suite, customers will have a single solution to proactively address security deficiencies and reduce cost and risk in their IT infrastructure."

The combined solution will be demonstrated in Oracle's Hospitality Suite during the Burton Catalyst Conference in San Diego, July 27-31, 2009. The demonstration will highlight how Cloakware's latest product version, Password Authority 4.1, secures password storage, access and lifecycle management for shared privileged administrator and programmatic passwords within the Oracle Identity and Access Management Suite. For more information, please visit http://datacenter.cloakware.com.

Cloakware is a member of the Oracle PartnerNetwork.



About the Oracle PartnerNetwork
Oracle PartnerNetwork is a global business network of more than 20,000 companies who deliver innovative software solutions based on Oracle software. Through access to Oracle's premier products, education, technical services, marketing and sales support, the Oracle PartnerNetwork program provides partners with the resources they need to be successful in today's global economy. Oracle partners are able to offer their customers leading-edge solutions backed by Oracle's position as the world's largest enterprise software company. Partners who are able to demonstrate superior product knowledge, technical expertise and a commitment to doing business with Oracle qualify for the Certified Partner levels. http://oraclepartnernetwork.oracle.com

About Cloakware

Cloakware, an Irdeto company and part of the Naspers group, provides innovative, secure, proven software technology solutions that enable customers to protect business and digital assets in enterprise, consumer and government markets. Cloakware's two main product lines include: Cloakware Datacenter Solutions which help organizations meet governance, risk management and compliance (GRC) objectives for privileged password management while ensuring business continuity and the security of mission-critical data and IT infrastructure. Cloakware Consumer Product Solutions protect software and content on PCs, set-top boxes, mobile phones and media players. Protecting more than one billion deployed applications, Cloakware is the security cornerstone of many of the world's largest, most recognizable and technologically advanced companies. Headquartered in Vienna, VA and Ottawa, Canada, Cloakware has regional sales offices worldwide. http://www.cloakware.com/



Trademarks
Oracle is a registered trademark of Oracle Corporation and/or its affiliates.

Datasheet:
http://www.oracle.com/products/middleware/identity-management/docs/cloakware-datasheet.pdf