SlideShare uma empresa Scribd logo
1 de 15
SENETAS

“FIBRE OPTIC CONNECTIONS ARE SECURE - RIGHT?”




                                                1
Senetas Europe
High Performance Encryption Solutions

   Securing Data In
       Transit
          Graham Wallace
          Ian Greenwood
Company overview
• Senetas Europe,
  based in Basingstoke
  is a wholly owned
  subsidiary of
  Senetas Corp. Ltd.
  Australia
• An Australian ASX
  listed engineering
  company
• Developing high
  speed network
  encryption
  technology since
  1997
• Currently sold to
  more than 35
  countries globally
Senetas Security Products Portfolio
Technology Differentiators

• Layer 2 encryption for
  performance & simplicity

• Constant low latency (<7us)
  even on voice/video links

• Retains full network bandwidth

• Ideal for 1GB/10GB datacentre
  fibre links
Tapping Optical Fibre
    The Fact and the Theory
Why would someone tap an optical
                   link?
• Live networks and back-up systems
  run remotely on high speed optical
  fibre
• Optic Fibre NOT secure
• Readily available fibre tap device
  bought on Net
• Intrusion undetected by
  information sender or receiver
• 480 million km of fibre deployed
• IDC estimates that only 30% of the
  digital universe is subject to security
  applications.
How - Clip on Coupler
• We can already prove
  that fibre can be tapped.
• What is contentious is
  whether this risk can be
  mitigated against
  without the need for
  encryption.
How - Light Touch Techniques
• The effect of this technique is similar to splicing.
• The extent to which the fibres are polished will decide
  on the tap ratio. This can be as low as 1% but up to
  20% would be likely to be undetectable.
How - Light Touch Techniques

             The polished evanescent wave coupler is
             based on bringing the cores of two fibres
             close together by removing part of the
             cladding and optically contacting the
             polished faces. By this process, the two
             cores behave as if they are contained within
             the same cladding.
Evanescent Wave Coupler - Jigs
Patents for fusing fibres
• Once you can splice there are a number of patented
  techniques for fusing more than one fibre WITHOUT
  breaking the original.
• You can check out:
   – US 4989939
   – US 5410626
   – US 6862385
Main Message
‘If your data is worth millions then it’s worth spending
thousands to get it’

•   We do not suggest this is a trivial enterprise
•   Nor could it be done by novices
•   But we do suggest that this kind of attack is
      possible for moneyed and motivated people
Senetas CN range of Encryptors summary
• Encrypts ALL the contents of Ethernet and Fibre Channel frames
• Full duplex line-rate encryption up to 10Gbps < 7 microseconds
  latency
• All Senetas solutions centrally managed by CypherManager
• Certified - FIPS 140-2 level 3, Common Criteria EAL4+, CAPS IL3
  baseline
• Ideal for Point to Point fibre links and MPLS Services
• Flexible licensing from 10Mbps to 10Gbps



                           EAL4
                           +
Securing Data in
     Transit
Thank you for your
    attention.
  Any Questions?

Mais conteúdo relacionado

Mais procurados

Arch Rock Overview
Arch Rock OverviewArch Rock Overview
Arch Rock Overviewpauldeng
 
Mobilize employees with the cisco mobile workspace solution
Mobilize employees with the cisco mobile workspace solutionMobilize employees with the cisco mobile workspace solution
Mobilize employees with the cisco mobile workspace solutionCisco Mobility
 
Cisco CCNA Certification Exams
Cisco CCNA Certification ExamsCisco CCNA Certification Exams
Cisco CCNA Certification Examscerts trainer
 
Beyond BYOD: Uncompromised Experience for Any Workspace
Beyond BYOD: Uncompromised Experience for Any WorkspaceBeyond BYOD: Uncompromised Experience for Any Workspace
Beyond BYOD: Uncompromised Experience for Any WorkspaceCisco Mobility
 
Stop Doing These 5 Things with Your SD-WAN
Stop Doing These 5 Things with Your SD-WANStop Doing These 5 Things with Your SD-WAN
Stop Doing These 5 Things with Your SD-WANJuniper Networks
 
Steve Chung Ruckus Wireless Presentation CommsDay 2014
Steve Chung Ruckus Wireless Presentation CommsDay 2014Steve Chung Ruckus Wireless Presentation CommsDay 2014
Steve Chung Ruckus Wireless Presentation CommsDay 2014Veronica Kennedy-Good
 
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...Cisco Canada
 
Porque cambiar de IPSec a SSL VPN
Porque cambiar de IPSec a SSL VPNPorque cambiar de IPSec a SSL VPN
Porque cambiar de IPSec a SSL VPNaloscocco
 
The Ruckus Edge: Networking Solutions
The Ruckus Edge: Networking SolutionsThe Ruckus Edge: Networking Solutions
The Ruckus Edge: Networking SolutionsPurdicom
 
Planning For Success - Wireless Network Design, Analysis, and Troubleshooting
Planning For Success - Wireless Network Design, Analysis, and TroubleshootingPlanning For Success - Wireless Network Design, Analysis, and Troubleshooting
Planning For Success - Wireless Network Design, Analysis, and TroubleshootingSavvius, Inc
 
Panduit Enteprise Network Infrastructure Security Solution
Panduit Enteprise Network Infrastructure Security SolutionPanduit Enteprise Network Infrastructure Security Solution
Panduit Enteprise Network Infrastructure Security SolutionPanduit
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityRobb Boyd
 

Mais procurados (20)

Arch Rock Overview
Arch Rock OverviewArch Rock Overview
Arch Rock Overview
 
Mobilize employees with the cisco mobile workspace solution
Mobilize employees with the cisco mobile workspace solutionMobilize employees with the cisco mobile workspace solution
Mobilize employees with the cisco mobile workspace solution
 
Cisco CCNA Certification Exams
Cisco CCNA Certification ExamsCisco CCNA Certification Exams
Cisco CCNA Certification Exams
 
Beyond BYOD: Uncompromised Experience for Any Workspace
Beyond BYOD: Uncompromised Experience for Any WorkspaceBeyond BYOD: Uncompromised Experience for Any Workspace
Beyond BYOD: Uncompromised Experience for Any Workspace
 
Physically securing the wireless installation
Physically securing the wireless installationPhysically securing the wireless installation
Physically securing the wireless installation
 
Beyond BYOD
Beyond BYODBeyond BYOD
Beyond BYOD
 
Stop Doing These 5 Things with Your SD-WAN
Stop Doing These 5 Things with Your SD-WANStop Doing These 5 Things with Your SD-WAN
Stop Doing These 5 Things with Your SD-WAN
 
Steve Chung Ruckus Wireless Presentation CommsDay 2014
Steve Chung Ruckus Wireless Presentation CommsDay 2014Steve Chung Ruckus Wireless Presentation CommsDay 2014
Steve Chung Ruckus Wireless Presentation CommsDay 2014
 
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...Cisco connect winnipeg 2018   optimizing your client's wi-fi experience v4 - ...
Cisco connect winnipeg 2018 optimizing your client's wi-fi experience v4 - ...
 
Spectralink airheads 2013
Spectralink airheads 2013Spectralink airheads 2013
Spectralink airheads 2013
 
CISCO
CISCOCISCO
CISCO
 
Porque cambiar de IPSec a SSL VPN
Porque cambiar de IPSec a SSL VPNPorque cambiar de IPSec a SSL VPN
Porque cambiar de IPSec a SSL VPN
 
Airheads barcelona 2010 securing wireless la ns
Airheads barcelona 2010   securing wireless la nsAirheads barcelona 2010   securing wireless la ns
Airheads barcelona 2010 securing wireless la ns
 
The Ruckus Edge: Networking Solutions
The Ruckus Edge: Networking SolutionsThe Ruckus Edge: Networking Solutions
The Ruckus Edge: Networking Solutions
 
Planning For Success - Wireless Network Design, Analysis, and Troubleshooting
Planning For Success - Wireless Network Design, Analysis, and TroubleshootingPlanning For Success - Wireless Network Design, Analysis, and Troubleshooting
Planning For Success - Wireless Network Design, Analysis, and Troubleshooting
 
Paul Ho - Wireless Infrastructure for Mobile e-Learning
Paul Ho - Wireless Infrastructure for Mobile e-LearningPaul Ho - Wireless Infrastructure for Mobile e-Learning
Paul Ho - Wireless Infrastructure for Mobile e-Learning
 
Panduit Enteprise Network Infrastructure Security Solution
Panduit Enteprise Network Infrastructure Security SolutionPanduit Enteprise Network Infrastructure Security Solution
Panduit Enteprise Network Infrastructure Security Solution
 
TechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN SecurityTechWiseTV Workshop: SD-WAN Security
TechWiseTV Workshop: SD-WAN Security
 
KRISHNAMOORTHI_NW
KRISHNAMOORTHI_NW KRISHNAMOORTHI_NW
KRISHNAMOORTHI_NW
 
Ruckus brief customer_Medley
Ruckus brief customer_MedleyRuckus brief customer_Medley
Ruckus brief customer_Medley
 

Destaque

Why optical networks ?
Why optical networks ?Why optical networks ?
Why optical networks ?Gagan Randhawa
 
Security in Optical Networks - Useless or Necessary?
Security in Optical Networks - Useless or Necessary?Security in Optical Networks - Useless or Necessary?
Security in Optical Networks - Useless or Necessary?ADVA
 
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...The Rockefeller Foundation
 
Integración en-la-organización
Integración en-la-organizaciónIntegración en-la-organización
Integración en-la-organizaciónRachel Rivera
 
【Connected.T3】SORACOMで実現するプライベートIoTバックエンド
【Connected.T3】SORACOMで実現するプライベートIoTバックエンド【Connected.T3】SORACOMで実現するプライベートIoTバックエンド
【Connected.T3】SORACOMで実現するプライベートIoTバックエンドSORACOM,INC
 
How to Buy a Car for $1,000 - Gnomedex 2008
How to Buy a Car for $1,000 - Gnomedex 2008How to Buy a Car for $1,000 - Gnomedex 2008
How to Buy a Car for $1,000 - Gnomedex 2008Kevin Fox
 
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIAS
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIASPresentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIAS
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIASElias Said Hung
 
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She..."Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...Sherry Jones
 
2013 Medicines in Development: Older Americans
2013 Medicines in Development: Older Americans2013 Medicines in Development: Older Americans
2013 Medicines in Development: Older AmericansPhRMA
 
Do you hunger for games? Gamification in Information Literacy Instruction
Do you hunger for games? Gamification in Information Literacy InstructionDo you hunger for games? Gamification in Information Literacy Instruction
Do you hunger for games? Gamification in Information Literacy Instructionagcalabrese
 
User Experience Flight Check - WordCamp LA
User Experience Flight Check - WordCamp LAUser Experience Flight Check - WordCamp LA
User Experience Flight Check - WordCamp LAjharr
 
Integracion en la organizacion
Integracion en la organizacionIntegracion en la organizacion
Integracion en la organizacionRicardo Roldan
 
100万ダウンロードを達成するには(16班)
100万ダウンロードを達成するには(16班)100万ダウンロードを達成するには(16班)
100万ダウンロードを達成するには(16班)stucon
 

Destaque (18)

PACE-IT: Troubleshooting Fiber Cable Networks
PACE-IT: Troubleshooting Fiber Cable NetworksPACE-IT: Troubleshooting Fiber Cable Networks
PACE-IT: Troubleshooting Fiber Cable Networks
 
Why optical networks ?
Why optical networks ?Why optical networks ?
Why optical networks ?
 
Security in Optical Networks - Useless or Necessary?
Security in Optical Networks - Useless or Necessary?Security in Optical Networks - Useless or Necessary?
Security in Optical Networks - Useless or Necessary?
 
Limsahí
LimsahíLimsahí
Limsahí
 
ArcGIS 10.0 Course
ArcGIS 10.0 CourseArcGIS 10.0 Course
ArcGIS 10.0 Course
 
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...
Dispatches from the Frontline: Using Pro-Poor Foresight to Influence Decision...
 
Integración en-la-organización
Integración en-la-organizaciónIntegración en-la-organización
Integración en-la-organización
 
【Connected.T3】SORACOMで実現するプライベートIoTバックエンド
【Connected.T3】SORACOMで実現するプライベートIoTバックエンド【Connected.T3】SORACOMで実現するプライベートIoTバックエンド
【Connected.T3】SORACOMで実現するプライベートIoTバックエンド
 
How to Buy a Car for $1,000 - Gnomedex 2008
How to Buy a Car for $1,000 - Gnomedex 2008How to Buy a Car for $1,000 - Gnomedex 2008
How to Buy a Car for $1,000 - Gnomedex 2008
 
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIAS
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIASPresentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIAS
Presentación sobre EL CENTRO VIRTUAL DE ALTOS ESTUDIOS EN ALTAS ENERGIAS
 
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She..."Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...
"Epistemic Game Design for Collaborative Inquiry and Civic Engagement" by She...
 
2013 Medicines in Development: Older Americans
2013 Medicines in Development: Older Americans2013 Medicines in Development: Older Americans
2013 Medicines in Development: Older Americans
 
Icip workshop sme needs analysis
Icip workshop sme needs analysisIcip workshop sme needs analysis
Icip workshop sme needs analysis
 
Integracion en-la-organización
Integracion en-la-organizaciónIntegracion en-la-organización
Integracion en-la-organización
 
Do you hunger for games? Gamification in Information Literacy Instruction
Do you hunger for games? Gamification in Information Literacy InstructionDo you hunger for games? Gamification in Information Literacy Instruction
Do you hunger for games? Gamification in Information Literacy Instruction
 
User Experience Flight Check - WordCamp LA
User Experience Flight Check - WordCamp LAUser Experience Flight Check - WordCamp LA
User Experience Flight Check - WordCamp LA
 
Integracion en la organizacion
Integracion en la organizacionIntegracion en la organizacion
Integracion en la organizacion
 
100万ダウンロードを達成するには(16班)
100万ダウンロードを達成するには(16班)100万ダウンロードを達成するには(16班)
100万ダウンロードを達成するには(16班)
 

Semelhante a Senetas fibre optic connections are secure - right

Overview of Wireless Sensor Networks
Overview of Wireless Sensor NetworksOverview of Wireless Sensor Networks
Overview of Wireless Sensor NetworksDuncan Purves
 
Designing Local Area Network
Designing Local Area NetworkDesigning Local Area Network
Designing Local Area Networkzaisahil
 
Wireless connectivity for iot
Wireless connectivity for iotWireless connectivity for iot
Wireless connectivity for iotSubramanyam Arige
 
Agile Networking with OpenStack
Agile Networking with OpenStack Agile Networking with OpenStack
Agile Networking with OpenStack openstackcisco
 
Unveiling the Sydney IoT Landscape
Unveiling the Sydney IoT LandscapeUnveiling the Sydney IoT Landscape
Unveiling the Sydney IoT LandscapeAndrew Blades
 
Low Power Wireless Technologies and Standards for the Internet of Things
Low Power Wireless Technologies and Standards for the Internet of ThingsLow Power Wireless Technologies and Standards for the Internet of Things
Low Power Wireless Technologies and Standards for the Internet of ThingsDuncan Purves
 
Improving performance and efficiency with Network Virtualization Overlays
Improving performance and efficiency with Network Virtualization OverlaysImproving performance and efficiency with Network Virtualization Overlays
Improving performance and efficiency with Network Virtualization OverlaysAdam Johnson
 
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...Numenta
 
2018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 72018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 7FRSecure
 
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...Edge AI and Vision Alliance
 
[2014] Sigfox - Why all the fuss
[2014] Sigfox - Why all the fuss [2014] Sigfox - Why all the fuss
[2014] Sigfox - Why all the fuss Nicolas Lesconnec
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxssuser52b751
 
Neo4j @ elisa, Teemu Nykänen, Elisa
Neo4j @ elisa, Teemu Nykänen, ElisaNeo4j @ elisa, Teemu Nykänen, Elisa
Neo4j @ elisa, Teemu Nykänen, ElisaNeo4j
 
Low Power Wireless Sensor Network Technologies and Standards for the Internet...
Low Power Wireless Sensor Network Technologies and Standards for the Internet...Low Power Wireless Sensor Network Technologies and Standards for the Internet...
Low Power Wireless Sensor Network Technologies and Standards for the Internet...Duncan Purves
 

Semelhante a Senetas fibre optic connections are secure - right (20)

Overview of Wireless Sensor Networks
Overview of Wireless Sensor NetworksOverview of Wireless Sensor Networks
Overview of Wireless Sensor Networks
 
Designing Local Area Network
Designing Local Area NetworkDesigning Local Area Network
Designing Local Area Network
 
Wireless connectivity for iot
Wireless connectivity for iotWireless connectivity for iot
Wireless connectivity for iot
 
Agile Networking with OpenStack
Agile Networking with OpenStack Agile Networking with OpenStack
Agile Networking with OpenStack
 
Unveiling the Sydney IoT Landscape
Unveiling the Sydney IoT LandscapeUnveiling the Sydney IoT Landscape
Unveiling the Sydney IoT Landscape
 
Low Power Wireless Technologies and Standards for the Internet of Things
Low Power Wireless Technologies and Standards for the Internet of ThingsLow Power Wireless Technologies and Standards for the Internet of Things
Low Power Wireless Technologies and Standards for the Internet of Things
 
Improving performance and efficiency with Network Virtualization Overlays
Improving performance and efficiency with Network Virtualization OverlaysImproving performance and efficiency with Network Virtualization Overlays
Improving performance and efficiency with Network Virtualization Overlays
 
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...
FPGA Conference 2021: Breaking the TOPS ceiling with sparse neural networks -...
 
High Speed Data Cables
High Speed Data CablesHigh Speed Data Cables
High Speed Data Cables
 
2018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 72018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 7
 
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...
“Using a Neural Processor for Always-sensing Cameras,” a Presentation from Ex...
 
[2014] Sigfox - Why all the fuss
[2014] Sigfox - Why all the fuss [2014] Sigfox - Why all the fuss
[2014] Sigfox - Why all the fuss
 
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptxConnecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
Connecting_Things_2.01_Instructor Supplemental Materials_Chapter4.pptx
 
Emerging IoT in the Energy Sector
Emerging IoT in the Energy SectorEmerging IoT in the Energy Sector
Emerging IoT in the Energy Sector
 
subok
suboksubok
subok
 
Neo4j @ elisa, Teemu Nykänen, Elisa
Neo4j @ elisa, Teemu Nykänen, ElisaNeo4j @ elisa, Teemu Nykänen, Elisa
Neo4j @ elisa, Teemu Nykänen, Elisa
 
Low Power Wireless Sensor Network Technologies and Standards for the Internet...
Low Power Wireless Sensor Network Technologies and Standards for the Internet...Low Power Wireless Sensor Network Technologies and Standards for the Internet...
Low Power Wireless Sensor Network Technologies and Standards for the Internet...
 
Tech sem on zig 1
Tech sem on zig 1Tech sem on zig 1
Tech sem on zig 1
 
Tech sem on zig 1
Tech sem on zig 1Tech sem on zig 1
Tech sem on zig 1
 
Zigbee technology
Zigbee technologyZigbee technology
Zigbee technology
 

Senetas fibre optic connections are secure - right

  • 1. SENETAS “FIBRE OPTIC CONNECTIONS ARE SECURE - RIGHT?” 1
  • 2. Senetas Europe High Performance Encryption Solutions Securing Data In Transit Graham Wallace Ian Greenwood
  • 3. Company overview • Senetas Europe, based in Basingstoke is a wholly owned subsidiary of Senetas Corp. Ltd. Australia • An Australian ASX listed engineering company • Developing high speed network encryption technology since 1997 • Currently sold to more than 35 countries globally
  • 5. Technology Differentiators • Layer 2 encryption for performance & simplicity • Constant low latency (<7us) even on voice/video links • Retains full network bandwidth • Ideal for 1GB/10GB datacentre fibre links
  • 6. Tapping Optical Fibre The Fact and the Theory
  • 7. Why would someone tap an optical link? • Live networks and back-up systems run remotely on high speed optical fibre • Optic Fibre NOT secure • Readily available fibre tap device bought on Net • Intrusion undetected by information sender or receiver • 480 million km of fibre deployed • IDC estimates that only 30% of the digital universe is subject to security applications.
  • 8. How - Clip on Coupler • We can already prove that fibre can be tapped. • What is contentious is whether this risk can be mitigated against without the need for encryption.
  • 9. How - Light Touch Techniques • The effect of this technique is similar to splicing. • The extent to which the fibres are polished will decide on the tap ratio. This can be as low as 1% but up to 20% would be likely to be undetectable.
  • 10. How - Light Touch Techniques The polished evanescent wave coupler is based on bringing the cores of two fibres close together by removing part of the cladding and optically contacting the polished faces. By this process, the two cores behave as if they are contained within the same cladding.
  • 12. Patents for fusing fibres • Once you can splice there are a number of patented techniques for fusing more than one fibre WITHOUT breaking the original. • You can check out: – US 4989939 – US 5410626 – US 6862385
  • 13. Main Message ‘If your data is worth millions then it’s worth spending thousands to get it’ • We do not suggest this is a trivial enterprise • Nor could it be done by novices • But we do suggest that this kind of attack is possible for moneyed and motivated people
  • 14. Senetas CN range of Encryptors summary • Encrypts ALL the contents of Ethernet and Fibre Channel frames • Full duplex line-rate encryption up to 10Gbps < 7 microseconds latency • All Senetas solutions centrally managed by CypherManager • Certified - FIPS 140-2 level 3, Common Criteria EAL4+, CAPS IL3 baseline • Ideal for Point to Point fibre links and MPLS Services • Flexible licensing from 10Mbps to 10Gbps EAL4 +
  • 15. Securing Data in Transit Thank you for your attention. Any Questions?

Notas do Editor

  1. Senetas Europe are a wholly owned subsidiary of Senetas Australia.Senetas in Australia have been very successful in designing and supplying encryptors into the Asian markets for over 15 years, 18 months ago Senetas Europe was established to engage with partners to address both the private and public requirements for encryption solutions.And it is with great pleasure that we have with use today SelexElsag our partner to supply CAPS approved into Government space and Tellemachus who specialise in addressing the security needs of organisations such as police forces.
  2. What we do.The range of certified encryptors cover speeds from 2Mbps through to 10 Gbps and a range of protocols from E1/T1 to SONIT/SDH.Our CAPS program is focused on the CN1000 1 and 10 gig Ethernet plus the Fibre Channel encryptors.Hopefully that gives you an idea of who we are and what we do, now we would like to show you why we do it.Introduce Graham Wallace.
  3. It is demonstrable that with a cheap clip-on tapping device we can extract sufficient light to accurately reconstruct the transmitted data packet.However, this device introduces a loss of anything from 3-6dB depending on the wavelength being tapped.It is therefore detectable using simple Optical Time-Domain Reflectometer(OTDR) devicesIt has never been our contention that this device is an appropriate tool for a serious cyber-thief.We believe only that it opens up the question of what is possible.Nevertheless there are scenarios we will consider which could use even this simple device.
  4. Guided Waves occur when light propagates along or is constrained by the physical boundaries of a waveguide. This is the case for a singlemode fiber where the denser core has refractive index n1 and the cladding is less dense with refractive index n2. When the core diameter is small enough that the number of possible totally internally reflected rays is reduced to one, thus allowing only a single mode of guided light, the concept of rays changes to modes which bend with or are guided by the core.
  5. Indeed from the patent if you have a jig design which is specific to the fibre and the percentage of tap you wish to use then the whole process seems straightforward enough regardless of location. It’s really just about preparation.
  6. I think that’s probably sufficient. I’d like to just revisit the main message slide I showed earlier and reiterate. We believe that serious cyber actors can tap fibre optic links without being detected or without being stopped in a timely fashion. Justification for encryption remains a function of data value and risk assessment but we would contend that the you cannot make that judgement based on the idea that optical fibres are secure.
  7. Senetas are the only vendor that offers a whole range of layer 2 appliance based solutions including Ethernet, fibre-channel, SONET/SDH and ATM from 10MB to 10GB throughput. 100Gb in development.Because the solutions running at layer 2 rather than layer 3 there is little or no overhead added to the data packets. The CN 10000 ethernet solution has ~ 7uS latency and 99.9% bandwidth availability. (Layer 3 solutions from vendors such as Check Point/Cisco use IPSEC and VPN’s which encapsulate the whole packet adding significant overhead, especially on small frame such as those required for voice and video traffic). The Senetas layer 2 technology utilises a ‘cut through’ implementation rather than the layer three ‘store and forward’ characteristics.In the same way a switch has less impact on data delay than does a router.We currently are “in evaluation” stage with CESG (CAPS) which is due to be approved in during 2012 and will be the only 1 and 10Gigabit layer 2 encryptors approved for HM Government. We already have FIPS140-2 and Common Criteria. The commercial and CAPS products are based an exactly the same hardware platform.