Storage networking vendor warns of security pitfalls

Poor security is one of the storage networking industry’s “”dirty secrets,”” the chief technical architect of a major manufacturer warned a trade show this week.

“”We haven’t delivered on network storage security, yet,”” said Val Bercovici of Network Appliance Inc., the keynote speaker at the SAN/NAS

Summit, a day-long show for storage area and network attached vendors. The show is held in several cities across the country. Bercovici’s comments came at the Toronto show.

“”Storage is becoming a network resource and you’d expect it to be protected like a shared resource. It isn’t,”” he told listeners. “”So my caution is, deploy this very carefully today. If anyone can compromise physical access to your disks you are completely insecure.””

“”If you have storage based on IP (Internet protocol) and Ethernet, you have some modicum of security because of existing standards,”” he said in an interview later. “”But a very popular way to deploy storage today is over Fibre Channel. It’s a great technology for sharing disk devices over servers, but essentially it’s a SCSI cable on steroids. You don’t log into your SCSI disk or your SCSI scanner. Unfortunately, you also don’t log into shared resources and shared storage over Fibre Channel.””

There are security standards being developed, he added, but in part because some vendors want to protect their market share. “”It’s nowhere near ready for prime time.””

That’s why securing physical security of storage network servers is paramount, he said. “”You can do a lot of damage by getting on to one node of a SAN,”” he said.

That’s not to say companies shouldn’t investigate how to implement networked storage, he also said.

“”You’re bleeding yourself slowly, and maybe quickly,”” by continuing to use direct storage where it isn’t necessary, he said.

In his address, Bercovici advised information technology managers searching for networked storage products to toss away product literature. Instead, he said, they should look for best practice white papers put out by manufacturers. Good ones, he said, have “”honest advice.””

“”They tend to be written by people such as engineers, with a few more morals and scruples than marketing people.””

After that, he said, question vendor technical reps about the products you’re interested in, and speak to their reference customers.

Would you recommend this article?


Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.

Jim Love, Chief Content Officer, IT World Canada

Featured Download

Howard Solomon
Howard Solomon
Currently a freelance writer. Former editor of and Computing Canada. An IT journalist since 1997, Howard has written for several of ITWC's sister publications, including Before arriving at ITWC he served as a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

Related Tech News

Get ITBusiness Delivered

Our experienced team of journalists brings you engaging content targeted to IT professionals and line-of-business executives delivered directly to your inbox.