What Security Trends Stood Out at RSA 2011?

635 views
•
February 16, 2011
by
RSAC Cybersecurity
YouTube video player
What Security Trends Stood Out at RSA 2011?

TL;DR

RSA Conference 2011 brought thousands of international security professionals, practitioners, and vendors together to examine emerging technologies and build business relationships. Major points of interest included cloud encryption, virtualization management, high-speed network capture, mobile device security, startup innovation, and the conference’s growing role as a central meeting place for the information security community.

Transcript

This is, this is Yunaz Ozkan, and, uh, and I'm, uh, at RSA Conference right now, uh, twenty eleven. So this is a great conference. Everybody's here. Uh, it's the place to be for all security professionals, and there are literally thousands of people, vendors, security practitioners. Uh, everybody who is in the industry is here. So it's internationa... Read More

Key Insights

  • RSA Conference 2011 was an international gathering of thousands of security professionals, practitioners, and vendors. Its concentration of participants made it valuable for discovering specialized technologies, exchanging industry information, meeting decision-makers, and bringing together people who would otherwise be separated across three continents.
  • Cloud security was a prominent subject at the conference. Special interest group meetings included the Cloud Security Alliance, which attracted considerable attention because many participating parties were interested in its platform and the broader question of how information placed in cloud environments could be secured.
  • The Innovation Sandbox was a startup competition featuring ten finalists from the information technology security sector. It gave attendees an opportunity to examine unusual products, speak directly with vendors, and compare proposed solutions addressing current problems in areas such as virtualization, privileged access, encryption, and cloud storage.
  • Virtualization security requires attention to its management layer. One solution discussed at the conference segregated that layer and applied privilege escalation management, addressing concerns about securing virtualization and virtual desktop infrastructure deployments while controlling the administrative access that could affect those environments.
  • Cloud encryption can reduce the need to trust a provider with readable data. A proxy-based approach encrypted information before upload, allowing the provider to receive encrypted values and associated metadata without seeing the sensitive underlying content itself, including the actual names or Social Security numbers.
  • High-speed network monitoring was served by several specialized vendors. Ozkan counted at least six companies offering ways to capture traffic across ten-gigabit fiber links, tap the data, process it, and forward it to analysis tools without breaking or disrupting the operating network.
  • RSA Conference functioned as a business meeting place as well as an educational event. Company teams and vendor management could gather in person, conversations occurred throughout the corridors, information was exchanged, and visible handshakes suggested that commercial agreements and working relationships were being advanced.
  • Mobile device security was becoming an important concern because security professionals themselves widely carried Android devices, iPhones, tablets, BlackBerrys, Nokias, and other gadgets. Their prevalence among conference attendees indicated that these technologies were widespread and that securing them would become increasingly significant.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What were the main security trends at RSA Conference 2011?

The main areas highlighted were cloud security, virtualization protection, endpoint concerns, high-speed network capture, encryption before cloud upload, and mobile device security. Interest in the Cloud Security Alliance showed the importance of securing cloud platforms, while Innovation Sandbox vendors presented approaches for controlling the virtualization management layer and protecting information from cloud providers through proxy-based encryption.

Q: How can data be protected before it is uploaded to the cloud?

Data can be passed through a proxy that acts as an encryption device before the information is uploaded. Under the approach discussed at the conference, the cloud provider receives encrypted values and can see metadata or field labels, but it cannot read the underlying sensitive content. This reduces the need to trust the provider with unencrypted information.

Q: How can the virtualization management layer be secured?

The virtualization management layer can be segregated and protected through privilege escalation management. This approach focuses on controlling the powerful administrative access associated with virtualization infrastructure. It was especially relevant to concerns about virtual desktop infrastructure deployments, where weaknesses in the management layer could affect multiple endpoints or systems governed through the same environment.

Q: What was the Innovation Sandbox at RSA Conference 2011?

The Innovation Sandbox was a competition unique to the conference in which ten information technology security startup finalists presented their solutions and competed to be recognized as the best. It also allowed attendees to approach vendors directly, discuss unfamiliar technologies, and explore products related to virtualization management, cloud encryption, and other active security challenges.

Q: How were vendors capturing traffic on ten-gigabit fiber links?

Specialized vendors offered systems that could tap traffic moving across ten-gigabit fiber links, capture and process the data, and pass it to analysis tools without breaking the network. Ozkan counted at least six companies addressing this same requirement, making the expo useful for comparing several competing solutions to a highly specific network-monitoring problem.

Q: Why was RSA Conference valuable beyond its formal sessions?

RSA Conference brought vendors, customers, practitioners, and management teams into one place, enabling meetings that might otherwise require people to travel across three continents. Conversations took place in corridors and during evening activities, information was exchanged, and business relationships were advanced. The event therefore served as both a technology conference and a central industry meeting place.

Q: How could attendees follow RSA Conference 2011 digitally?

Attendees and remote followers could search Twitter using the RSAC hashtag to see what was happening at the conference. A mobile application was also available for BlackBerry, iPhone, and iTouch users. It provided access to the complete conference agenda and could update the user’s calendar, making it easier to organize participation throughout the event.

Q: Why was mobile device security becoming more important?

Mobile device security was becoming more important because thousands of attendees, including information security professionals, were carrying Android devices, iPhones, tablets, BlackBerrys, Nokias, and other gadgets. Their visible use showed that these devices were already widespread. The contrast between asking how to secure them and relying on them throughout the conference made the issue especially notable.

Summary & Key Takeaways

  • RSA Conference 2011 attracted thousands of security professionals, practitioners, vendors, and international visitors. Beyond its formal sessions, the event functioned as a broad industry meeting place where participants exchanged information, met management teams, explored commercial relationships, and observed the increasing influence of cloud computing, virtualization, and mobile devices on security priorities.

  • The Innovation Sandbox featured ten information technology security startups competing with their proposed solutions. Technologies discussed there included segregating the virtualization management layer to control privileged access and using proxies to encrypt information before uploading it to cloud services, limiting cloud providers to metadata rather than the underlying sensitive values.

  • The expo floor contained roughly two hundred to three hundred vendors, ranging from major companies to smaller specialists. Ozkan found at least six companies offering capture solutions for traffic carried over ten-gigabit fiber links. The conference also supported participation through its RSAC Twitter hashtag and a mobile application that managed agendas and calendar updates.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚