May 9, 2008

Toys for Geeks

One of the best things about working in a test lab like NSS is that we get play with all the latest, coolest stuff. Well, cool if you are a geek at heart, that is. It might not be an Aston Martin or a Playstation 4 but the new BP10K from BreakingPoint Systems does at least have white "go faster" stripes on the British racing green front panel....
And go faster it does. NSS has spent almost a year evaluating this equipment for use in its labs, and has been using it in earnest for the last few months. This has been a considerable commitment by NSS, given that our extensive methodologies consist of literally hundreds of different performance tests, and moving them to a new platform is no mean feat.

BreakingPoint has made this possible with a software architecture and GUI design that abstracts as much of the physical layer of the test rig from the logical requirements of the test. As just one example, converting an existing test between in-line layer 2 to routed layer 3 is the work of only a couple of mouse clicks - no need to go through hundreds of test scripts altering IP addresses and default gateways. And there are lots of new cool bells and whistles which will allow us to create incredibly complex tests.

But software isn't cool, is it guys? It's the hardware that gets us excited. And the BP10K can generate complex multi-protocol real-world traffic at line speeds - and that means at 20Gbps (40Gbps full duplex), with 7.5 million concurrent connections and rates of up to 750,000 connections per second from a single appliance with four fiber 10Gbps ports. And you can incorporate multiple appliances in a single test to scale up to hundreds of Gigabits.

In our lab, we have mixed 'n' matched BP10K's and the 2Gbps (4Gbps full duplex) BP1000's to provide us with a total of 60Gbps of traffic generation capability over both 10Gbps fiber and 1Gbps copper interfaces, and this will allow us to standardize on the BPS kit for our Layer 4-7 testing going forward.

All it needs now is a twin exhaust and flashy alloy wheels and we are all set...

-Bob Walder, CTO/Founder

May 8, 2008

RFI for leading network/test tools

NSS Labs continually evaluates and validates testing tools and best practices. This is a necessary step prior to selecting and implementing the best tools in our test methodologies, which result in our publicly published test reports. Our lab engineering team is thus requesting leading test tool, network infrastructure product and service providers to brief them on their offerings and roadmap. Best in class products will be selected for use in NSS Labs' next generation test facility. More info

May 7, 2008

Fastest Public Test of a Network IPS

As network traffic continues to grow, so too do the demands on network infrastructures. As a result, multi-gigabit network IPS devices are gaining traction, and providing essential protection in a switched core environment.

Yesterday, NSS Labs released a milestone report on what is the fastest independently verified Network IPS product on the market, to date - the IBM/ISS GX6116. (I say to-date because there are certainly a couple of 10Gig devices that have recently debuted, and we look forward to also testing these). What is notable here is that our tests are not based merely on RFC 2544 (UDP packet blasting), which can inflate a vendor’s performance metrics due to the stateless nature of UDP and typically large packet sizes used. (See our white paper on Pitfalls of Performance Testing). Rather, NSS Labs dedicates a lot of attention to creating real-world multi-protocol test suites across a wide range of use cases.

In our real world tests, we create a complex mix of protocols including HTTP, FTP, SMTP, DNS, etc and pass these through the device under (DUT) test at speeds up to 30 Gbps. This is a live test with deep packet inspection and default or recommended rules turned on. The Proventia GX6116 displayed excellent performance up to 6 Gbps coupled with extremely low latency under all normal traffic conditions.Security effectiveness was also impressive, with excellent coverage above 95% for the most critical vulnerabilities, out of a set of 579 – the largest set of exploits run in any public test.

Read the full report here: http://nsslabs.com/intrusion-prevention/iss-proventia-nips-gx6116.html

May 6, 2008

PCI Self-Assessment Questionnaires Embrace Use-Case Philosophy!

I have been meaning to comment on this for a while, but better late than never. Earlier this year, the PCI SSC released an updated, and well-thought out collection of self-assessment questionnaires to replace the previous, single questionnaire. This is a very welcome enhancement for a number of reasons, not the least of which is because it shows a clear support for a use-case-based approach - something NSS Labs has been working towards in its own testing.

In fact, we've written a white paper outlining how use cases can help IT Security and Compliance professionals evaluate products for appropriate usage in their environments. In short, know your environment, and specifically what you're trying to protect, and this will help you define more granular (and thus more useful) protection requirements for your control selections (i.e. security products).

There is no silver bullet or magic product, and in fact, as products are increasingly differentiating themselves, defining the requirements early on in the process is increasingly important. For buyers, this means being better prepared, and more discerning in the evaluation process. For vendors, this should be a welcome opportunity to claim some higher ground (in terms of positioning and differentiation) in some very 'mushy' crowded markets where customers turn quickly to price as a differentiator when they can't tell the difference in benefits.

May 5, 2008

Bankinfosecurity.com interview with Rick Moy on Product Testing

My interview with Tom Field of BankInfoSecurity.com at RSA about NSS Labs and how our product evaluations are helping the banking and payment card industry with security and compliance.

Listen to the interview
View page at bankinfosecurity.com

Apr 27, 2008

Interview with Martin McKeay at RSA

I had the pleasure of a brief chat with Martin of Networks Security Podcasts about what we do at NSS Labs. Martin is a prolific security blogger, podcaster, and QSA by day. Listen to the interview here: http://www.mckeay.net/2008/04/09/rsa-2008-rick-moy-nss-labs/

Apr 14, 2008

Rocking RSA

Last week's RSA Conference 2008 in San Francisco was one of the best one's I've ever been to. For purely selfish reasons! NSS Labs had a number of firsts.
  • It was our first time to have a booth at any trade show.
  • Over a dozen product vendors proudly displayed their NSS Approved logos at their booths. These large shiny plaques are about 5 times larger than the typical plastic sign you might otherwise see floating about.
  • Our debut was accompanied by the support of a broad ecosystem of test tool providers, security vendors, and others who shared our booth as partners.
  • We hosted two incredibly well attended Advisory Group sessions on testing and PCI.
  • We released a record number of product certification reports.
  • We threw the undisputed coolest party of all RSA and hung out with the heavy-lifters of the security industry, press, and analyst community. Where else could you get your groove on, and enjoy a shoe shine, shave and massage?
What could we possibly do next? I ask myself.