subject: Controlling Enterprise Mobility in the Cloud [print this page] Controlling Enterprise Mobility in the Cloud
Independent of whether your corporation is an early adaptor or an early majority company, if you will be adopting cloud computing technologies in the foreseeable future, then an interesting question to ponder would be: "How would the adoption of cloud computing and SaaS applications impact the enforcement of corporate security policies for mobile users?"
The traditional approach to enforcing corporate access security is to require mobile users accessing the corporate LAN to launch either SSL VPN or IPSec VPN clients. With these technologies, tunnels are established at the application or network layer respectively to ensure confidentiality of data traversing these VPNs. The challenge of this approach is that mobile workers who use their corporate remote access devices to access the internet either don't launch their VPN clients, or their sessions are routed directly to internet through a split tunnel connection provisioned on access routers.
When remote users are accessing the corporate LAN through VPN, they are protected by firewalls with UTM (Unified Threat Management) functionality. This is not the case, however, when the users connect directly to the Internet. In this case, they are exposed to a multitude of risks, including viruses, phishing, and spyware.
A practical example of this risk would be the following scenario. Consider that you are using your corporate laptop to log from your home into the Dolphin Stadium and the Miami Dolphins team website to purchase tickets for the 2010 Super Bowl football game. What you don't know is that this web site has been hacked into (based on a real scenario*), and it downloads and installs a malicious code on your laptop. This code acts as Trojan and can install a keylogger code and disable the anti-virus application on your laptop. After purchasing your tickets to the Super Bowl, you decide it's time to get some work done and log into your Google Apps. Unfortunately, your password to Google Apps is captured by the keylogger and compromised at that time. This scenario could have been avoided with a mobile connection manager blocking the remote access to Google Apps after detecting that the Antivirus application is disabled.
As the control point in the cloud computing era is shifting from VPN to internet connection, the connection manager will be required to enforce corporate policies for endpoint security. The recently announced iPass Open Mobile Platform has been designed with this paradigm shift in mind. The Open Mobile Client is always running on the mobile device, which enables it to become the ultimate control point for all mobility purposes, regardless of whether the accessed applications reside in the cloud or on the corporate LAN.
The client in most cases is transparent to the end users, enforcing policies in the background. Policies may include optimal network selection, launching and passing on user credentials to VPN clients, and performing end-point integrity checks and remediation. The ECA (Event Condition Action) functionality on the Open Mobile Client empowers IT administrators to enforce corporate endpoint security policies. ECA is used to enforce both pre- and post-connect policies and spans across all integrated technologies (e.g. VPNs) and application (e.g. UTM apps running on the mobile device).
*Based on a real hacking scenario, please refer to the PC World website for the article "Super Bowl Related Websites Hacked." or http://www.pcworld.com/article/128750/super_bowlrelated_web_sites_hacked.html.
By Michael Segal, iPass.
iPass Inc. helps enterprises and individuals unify the management of remote and mobile connectivity. With iPass software and services, enterprise customers can create easy-to-use wireless and broadband solutions for their mobile workers, home offices, and branch and retail locations, complete with web-based management, security validation, and unified billing. Visit us at http://www.ipass.com, or blog at: http://www3.ipass.com/blog or find a hotspot at: ipass.jiwire.com