<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>The Server Room Blog</title>
    <link>http://communities.intel.com/community/openportit/server/blog</link>
    <description>Server Room</description>
    <pubDate>Wed, 28 Oct 2009 15:04:59 GMT</pubDate>
    <generator>Clearspace 2.5.9 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-10-28T15:04:59Z</dc:date>
    <item>
      <title>You May be Attacking Someone, Thanks to Botnets</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/10/28/you-may-be-attacking-someone-thanks-to-botnets</link>
      <description>&lt;!-- [DocumentBodyStart:d3a864e3-03ae-4574-aa93-32f5ef440372] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Do you ever wonder where Spam comes from?&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I have no idea where the meat-like version of Spam comes from (nor do I wish to ponder that mystery). But it is pretty well established that a huge component of the e-mail and IM Spam that we all know and hate is generated by automated programs (bots) installed on thousands or even millions of unsuspecting systems.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;These bots are remotely controlled via command-and-control or even peer-to-peer networks (botnets) to do the bidding of the bot developer—such as propagate Spam or other malicious software or generate denial of service attacks against designated targets.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;And all of this could happen without most people even knowing their system is doing anything.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Botnets are the end result of many malware exploits—as viruses, worms, Trojans, drive-by or click-through attacks may deliver and propagate the bot payload. They are also a crystal clear example of how the objective of attacks have changed from hit-and-run high-profile grabs for fame to instead focus on stealth and establishing and retaining control of assets. Botnets are an ideal tool for the nefarious—they can command huge numbers of widely distributed systems at trivial costs.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;While it is hard to estimate how many systems are part of a botnet, the potential is staggering.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;For example, the much-publicized Conficker worm is estimated* to have placed more than 4 million unique IP addresses under the control of “bot-masters”. &lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;And this huge resource base allows the bot-masters to rent control of these resources to spammers or other agents looking for ways to generate attacks or other nuisances with low risk of being detected.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;In essence, they are allowing criminals and spammers to outsource the generation of their malicious activities. It is a frightening business model indeed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;It is also a difficult challenge for IT. Thanks to botnets, it is possible for an IT manager or CIO to get a call from out of the blue asking why their systems are attacking some other company or government entity’s systems.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Or discover a botnets of 100’s of computers with their company.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;These type of events can happen to the best IT departments (even Intel or the US Government). Clearly, IT needs tools to help prevent such scenarios, and the antivirus and intrusion detection/prevention industry is working hard to keep up with the rapid growth in the delivery vehicles for bot code.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;The other weapon for IT managers is traffic analysis – looking for strange patterns of activity (such as bursts of e-mail traffic from selected systems or floods of network traffic generated against specific targets) that falls outside of business norms to determine if there is another business being conducted with their assets.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;While being part of a networked world has wonderful, powerful benefits, it is not without enhanced risk. A botnet is &lt;em style="mso-bidi-font-style: normal;"&gt;not&lt;/em&gt; a network you ever want a member of. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;Intel technologies like Trusted Execution Technology (TXT) and instruction set optimizations such as STTNI can be part of these solutions.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Intel® TXT can be used in solutions that help protect systems from software attacks which provide the malware payloads to compromise systems.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;In fact, Intel TXT (to be available with Westmere server systems) provides an entirely new protection capability for most systems—providing evaluation of the launch environment and enforcing “known good” code execution. This is important because most malware tools execute only once the system is booted—so Intel TXT provides a valuable complementary protection. And to help with the growing burden of run-time malware and attack analysis, new (with Nehalem) instructions that accelerate string manipulation can boost content inspection software ability to detect anomalies.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;And research and development will ensure Intel continues to develop and deploy building blocks to help IT address today’s challenges and tomorrow’s. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-family: Calibri;"&gt;We can do that most effectively only if we’re trying to solve the right problems.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Are your systems under attack? (yes, they are). What types of solutions are most effective for you?&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Where is the greatest exposure? Is the pain in stopping attacks or cleaning up after them? This is certainly worth thinking about—before some Government agency comes calling asking why your systems are sending them so much spam!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="color: #1f497d;"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;*&lt;/span&gt;&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.confickerworkinggroup.org/wiki/pmwiki.php/ANY/InfectionTracking"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;http://www.confickerworkinggroup.org/wiki/pmwiki.php/ANY/InfectionTracking&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #1f497d;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="font-family: Calibri;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:d3a864e3-03ae-4574-aa93-32f5ef440372] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">bot</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">txt</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">malware</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel_txt</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">westmere</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security_technology</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">control</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">compliance</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">attacks</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">trusted_execution_technology</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">sttni</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">nehalem</category>
      <pubDate>Wed, 28 Oct 2009 15:04:59 GMT</pubDate>
      <author>james.j.greene@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/10/28/you-may-be-attacking-someone-thanks-to-botnets</guid>
      <dc:date>2009-10-28T15:04:59Z</dc:date>
      <clearspace:dateToText>1 month, 1 day ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/you-may-be-attacking-someone-thanks-to-botnets</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12758</wfw:commentRss>
    </item>
    <item>
      <title>Data Center Security</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/09/19/data-center-security</link>
      <description>&lt;!-- [DocumentBodyStart:66d56c57-3ef6-4f61-bb1d-4c77bd3da9f4] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;Even the name is a sort of a misnomer.  Not that there isn’t a lot of physical security around most data centers.  The doors are locked and not even regular employees have access.  This is necessary, and if someone gained physical access they could really mess things up. But, this is not where the big risk typically occurs.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;The growing challenge is data security – i.e. protection from threats that come across the wire.  With ubiquitous networks, and data moving everywhere, protecting the crown jewels is a full time job.  Hackers, malware, employee abuse, and other threats can lead to data exposure that is potentially devastating, and almost undoubtedly embarrassing for the IT manager.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;Gartner recently declared IT security the number one worry of fortune 1000 companies. This is not surprising when a report from Symantec showed exponential growth in internet security threats.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;There is no silver bullet, and there is no system that can never be defeated.  We need to do the best we can with the tools we have.  Doing anything less could be seen as negligent.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;Like security in the physical world, data security is a combination of business process and technology.  Neither can be effective alone.  Business processes must make clear what roles deliver data access, data steward ship, data ownership, and data disposal.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;&amp;lt;sidebar&amp;gt;Data disposal is going to be one of the biggest challenges to the promises of cloud computing.  If we consider a hosted app like “gmail” to be part of the cloud, then we either must accept privacy policies like “all data belongs to the host” or try to stick to using internal systems. &amp;lt;/sidebar&amp;gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;The other half of the security solution is technology.  Intel, and others, are delivering new technologies to the server to assist with security enforcement.  New string accelerator functions dramatically speed content scans for malicious data.  Technologies like execute disable &amp;amp; SM range registers provide improved protection against buffer and cache attacks.  The next generation of Intel server processors will introduce new features that can validate that code is un-altered and remove much of the overhead from encryption.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt;"&gt;Security can not be an occasional focus any longer.  Every security manager will need to be up to date on the state of technology and tools, and have the social skills to drive good data practices into the work environment.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:66d56c57-3ef6-4f61-bb1d-4c77bd3da9f4] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">data</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">center</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">data-center</category>
      <pubDate>Sat, 19 Sep 2009 21:09:36 GMT</pubDate>
      <author>ken.r.lloyd@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/09/19/data-center-security</guid>
      <dc:date>2009-09-19T21:09:36Z</dc:date>
      <clearspace:dateToText>2 months, 1 week ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/data-center-security</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12580</wfw:commentRss>
    </item>
    <item>
      <title>IDF: Something for Everyone</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/09/15/idf-something-for-everyone</link>
      <description>&lt;!-- [DocumentBodyStart:0fe9f5b3-ef70-45fe-833a-eb8c172b1f11] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;It has been a couple of years since I’ve had the opportunity and pleasure of attending an IDF, but I remember the experience well.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;While I had been in the technology industry for many years and was familiar with major tradeshows like Comdex, Interop, CeBit, etc, I recall being amazed that a single company could be the catalyst for such a huge event.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;But as I experienced it, it made more sense: after all, Intel sells a very broad line of products to a huge array of customers.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;And our products are among the most technologically advanced and complex in the world—yet they are only critical components to solutions that require a wide range of complementary parts—system boards, test tools, compilers, software, BIOS and integrators—to name just a few.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;And IDF is the critical venue to galvanize this huge and surprisingly efficient cadre of fellow travelers that will help build upon and deliver our technologies to the world.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;It is where we educate, communicate and differentiate, and it is a great showcase for Intel.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;This year, I’m excited to be able to participate.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;As I wrote a few weeks ago, I’m looking forward to being able to use this showcase to help establish Intel’s focus on server security. We’ve got a couple of key new features—Intel® Trusted Execution Technology (&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://developer.intel.com/technology/security/"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;TXT&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;) and Advanced Encryption Standard new instructions (AES-NI) for encryption processing—that promise to make secure processing for servers more complete and efficient.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;You can get a &lt;/span&gt;&lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/server/blog/2009/09/11/what-is-cryptography-aes-and-aes-ni"&gt;&lt;span style="font-size: 12pt; font-family: Calibri;"&gt;glimpse&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt; of what Leslie Xu and Michael Kounavis will cover for AESNI. I’ll be working with Mahesh Natu and some friends in the fellow traveler community to help introduce TXT for servers. Like many others, we’ll be using this opportunity to: conduct training for developers (session ECTS002); show the technology in action in a really cool Server Zone demo (Booth #517), and generally help build awareness for TXT and security in general.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I’m really looking forward to the demo.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;It is one thing to offer a cool feature, but it is a whole new level of anticipation when one can so clearly visualize how this technology can be deployed to make users’ environments better.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000; font-family: Calibri;"&gt;I know that we’re eager to share our enthusiasm and engage the developers and customers that will make our technologies a success.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I’m also keen to get to see other great things coming out of Intel and our fellow travelers. What are you eager to see and hear about at IDF? &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:0fe9f5b3-ef70-45fe-833a-eb8c172b1f11] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">and</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">server</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">technology</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">txt</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">execution</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">idf_30in30</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">idf_2009</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">trusted</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <pubDate>Wed, 16 Sep 2009 06:41:58 GMT</pubDate>
      <author>james.j.greene@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/09/15/idf-something-for-everyone</guid>
      <dc:date>2009-09-16T06:41:58Z</dc:date>
      <clearspace:dateToText>2 months, 1 week ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/idf-something-for-everyone</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12561</wfw:commentRss>
    </item>
    <item>
      <title>Submarines, Stealth Fighters and Evolving Needs of Information Security</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/09/08/submarines-stealth-fighters-and-evolving-needs-of-information-security</link>
      <description>&lt;!-- [DocumentBodyStart:c291c538-602d-4d14-b012-7392f085c24c] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;New Server Security Technologies Are Coming &amp;amp; Why We Need Them&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;The other day I had the opportunity to talk with Jeff Casazza and &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://video.intel.com/?fr_story=8fe1a25e3a92d98b7b956fbd5c8be281ff47b0e0&amp;amp;rf=sitemap"&gt;James Green&lt;/a&gt;&lt;span style="color: #000000;"&gt; from Intel’s Server Platform Group.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;The topic? server security.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Our conversation was focused on the introduction of some new security technologies that are on their way and why we need them.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;During our discussion, I found myself thinking back to my days in the US Navy, where security was a core topic of everything we did. The introduction of submarines transformed naval tactics and the stealth fighter changed aviation tactics. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;So, why does IT put so much emphasis on information security?&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;… because the cost of a data breech is extremely high.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Imagine if a data breech of your IT systems resulted in losing employee social security numbers or customer information – the cost to recover that data (if possible) and the legal costs (penalties from regulatory agencies) is very, very high.&lt;span style="mso-spacerun: yes;"&gt;   &lt;/span&gt;Jeff and James mentioned that business models are also exposed if these types of information escapes happen – a company’s brand, business and employee relationships could be at risk given the nature of trust and integrity that circle throughout our business. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;Security always ranks high in importance, especially when we feel at risk.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;As I have transitioned into my new role inside &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/it"&gt;Intel IT&lt;/a&gt;&lt;span style="color: #000000;"&gt;, I have found a significant focus on &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/it/info_security.htm"&gt;security solutions&lt;/a&gt;&lt;span style="color: #000000;"&gt; especially as new threats (for profit attacks), new usages (client / server virtualization, cloud computing) and new collaboration tools (social media) challenge our existing paradigms of information security.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;During my discussion, I learned about two technology standards that Intel is implementing for servers that reduce security risks and address the changing nature of information security attacks happening today and expected tomorrow.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Stealth Fighters Attacking Your Data:&lt;/strong&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; The nature of security attacks have changed.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Previous generation hackers used to target broad wide spread attacks on corporations or the worldwide web trying to disrupt business, gain notoriety with the ability to affect tens of thousands of people.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;The newer generation attackers are seeking a smaller target .. a single laptop or a single server.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;These new for-profit attacks are aimed at both industrial (business) or government entities and only need a single penetration into your infrastructure to get enough information to create a serious issue for your business.&lt;span style="mso-spacerun: yes;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;Encryption:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; A solution to defend against the stealth fighter point attack on your data is increased encryption of data.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Data encryption is not new.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Secure Sockets Layer (SSL) encryption for communication over the internet, harddisk encryption and enterprise application encryption are all standard methods IT shops use to protect information.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Unfortunately, encryption is not free, and I’m not talking about purchase cost .. but rather &lt;/span&gt;compute cost&lt;span style="color: #000000;"&gt;.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Encryption is a &lt;a class="jive-link-external-small" href="http://www.cs.bc.edu/~straubin/cs381-05/blockciphers/rijndael_ingles2004.swf"&gt;compute intensive process that consumes processing cycles&lt;/a&gt;. Intel is planning on introducing &lt;/span&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;new instructions for &lt;a class="jive-link-external-small" href="http://software.intel.com/en-us/articles/advanced-encryption-standard-aes-instructions-set/"&gt;Advance Encryption Standards&lt;/a&gt; (AES-NI)&lt;/strong&gt;&lt;span style="color: #000000;"&gt; that are intended to dramatically improve the efficiency of encryption in a future version of it’s processor micro architectures.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.5in;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Submarines Seeking Your Data From Under Your Hypervisor:&lt;/strong&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; Much of the anti-virus and security protection that resides on servers and client machines resides and is run through either the Operating System, Hypervisor or Application layer.&lt;span style="mso-spacerun: yes;"&gt;   &lt;/span&gt;New malware software and root kits are targeting systems at startup before the hypervisor and/or OS boot up undermining the protection you have at the higher levels of the application stack.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;A new server technology from Intel, called &lt;/span&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/technology/security/"&gt;Intel® Trusted Execution Technology&lt;/a&gt; (Intel TXT)&lt;/strong&gt;&lt;span style="color: #000000;"&gt; works to ensure your system can boot up to the secure, protected environment you have deployed through your software stack.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;In doing this, TXT ensures that your anti-virus software “perimeter” is secure and has not been compromised by a root kit “submarine”.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;TXT has been available in &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://developer.intel.com/technology/security/downloads/TrustedExec_Overview.pdf"&gt;Client Intel® vPro™ processor technology-based platforms since 2007&lt;/a&gt;&lt;span style="color: #000000;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; color: red; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;Tune into the upcoming Intel Developers Forum (&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/idf"&gt;&lt;span style="color: windowtext;"&gt;www.intel.com/idf&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #000000;"&gt;) to learn more about plans for securing your server’s data and many other technology innovations from Intel. &lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="color: #000000;"&gt;Chris &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:c291c538-602d-4d14-b012-7392f085c24c] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">data</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">secure</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">submarines</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">stealth</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualization</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">aes</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">encryption</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">server</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">regulatory</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">servers</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">txt</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">it@intel</category>
      <pubDate>Wed, 09 Sep 2009 05:08:46 GMT</pubDate>
      <author>christopher.p.peters@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/09/08/submarines-stealth-fighters-and-evolving-needs-of-information-security</guid>
      <dc:date>2009-09-09T05:08:46Z</dc:date>
      <clearspace:dateToText>2 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/submarines-stealth-fighters-and-evolving-needs-of-information-security</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12526</wfw:commentRss>
    </item>
    <item>
      <title>Security in virtual environment</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/08/24/security-in-virtual-environment</link>
      <description>&lt;!-- [DocumentBodyStart:7045425e-5071-4e05-be0c-0f32657eb11c] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;&lt;span style="font-family: 'Times New Roman', helvetica, sans-serif; color: #000000; font-size: 14pt;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Times New Roman', helvetica, sans-serif; color: #000000; font-size: 14pt;"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;I have written in the past about key IT considerations while &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-2355"&gt;implementing virtualization&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;One of the key elements that change going from a non-virtualized environment to virtual environment is the security model. The security model needs some additional considerations going to virtual environment.&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;I and a few of my colleagues who meet with IT end customers deploying virtualization on a regular basis have realized that there are some frequently asked questions/concerns and also misconceptions about protection in virtualized environment.&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;We also did a bit of research on types of documents available to help IT understand the topic of security model in virtualized environment better, but found most articles to be either outright dismissive of security concerns or took a very opposite theoretical and conservative view on lack of security.&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;So with the help of our architects we developed the below white paper with an intent to help IT managers, strategists and implementers understand resource protection in virtualized environment better. We also address some of the frequently asked questions and typical misconceptions with security in virtual datacenter.&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;The &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-3833"&gt;white paper&lt;/a&gt; essentially takes a balanced view and provides an overview of security model changes, challenges and considerations that organizations must address when implementing virtualization. It introduces hardware, software, and policy measures available to help address those challenges, including their strengths and limitations and then closes with a brief discussion of some key issues associated with security in emerging cloud computing usage models.&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="margin: 0in 0in 0pt; tab-stops: 435.75pt;"&gt;Let us know what you feel.&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:7045425e-5071-4e05-be0c-0f32657eb11c] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualization</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">datacenter</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <pubDate>Mon, 24 Aug 2009 17:20:56 GMT</pubDate>
      <author>radhakrishna.hiremane.shridhar@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/08/24/security-in-virtual-environment</guid>
      <dc:date>2009-08-24T17:20:56Z</dc:date>
      <clearspace:dateToText>3 months, 6 days ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/security-in-virtual-environment</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12469</wfw:commentRss>
    </item>
    <item>
      <title>Fall Intel Developer Forum Server Technology Blogs – What Do You Want To Hear About?</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/07/31/fall-intel-developer-forum-server-technology-blogs-what-do-you-want-to-hear-about</link>
      <description>&lt;!-- [DocumentBodyStart:cc1a21dd-d91a-48fb-963b-394ebbac12e2] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;span style="color: #000000;"&gt;54 days to Fall IDF in SFO!&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Perhaps I should be a bit less enthusiastic, as during the course of the next two months, I will be extremely busy working on courses, presentation, demos, web updates and new collateral pieces highlighting Intel’s contributions to server and data center instrumentation, data center efficiency and eco-technology.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;In addition to those responsibilities, I have taken on ownership of driving a technology blogging program at IDF, with server technology experts sharing their insights here on Server Room – an opportunity that I am very excited about, but I need your help.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;span style="color: #000000;"&gt;My question to you today is – what would you like to see covered in the technology blogs from IDF?&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I am starting the process of recruiting “volunteers” to participate, and understanding what you want to see discussed will help me to get the right people to cover the topics that are compelling to you and hopefully facilitate an interesting dialog that will help you to better understand server technologies.  Since its easy to self-recruit, you will definitely see a blog from me covering instrumentation, Intel Intelligent Power Node Manager and other related technology news @ IDF.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;span style="color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;span style="color: #000000;"&gt;So what do you specifically want to see covered in the IDF blogs?&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I look forward to you inputs and hope to see you at IDF!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Dave&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:cc1a21dd-d91a-48fb-963b-394ebbac12e2] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">idf2009</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">node_manager</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel_developer_forum</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">server_platforms_group_marketing</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">server</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">server_technology</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel_intelligent_power_technology</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">instrumentation</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualizaiton</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">i/o</category>
      <pubDate>Fri, 31 Jul 2009 16:59:17 GMT</pubDate>
      <author>david.e.jenkins@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/07/31/fall-intel-developer-forum-server-technology-blogs-what-do-you-want-to-hear-about</guid>
      <dc:date>2009-07-31T16:59:17Z</dc:date>
      <clearspace:dateToText>4 months, 12 hours ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/fall-intel-developer-forum-server-technology-blogs-what-do-you-want-to-hear-about</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12404</wfw:commentRss>
    </item>
    <item>
      <title>IPsec Offload: Meet Microsoft* DirectAccess*</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/05/16/ipsec-offload-meet-microsoft-directaccess</link>
      <description>&lt;!-- [DocumentBodyStart:a016a7b3-5b08-4d36-8cfb-da6dada862b0] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Manageability, security, and performance are always hot topics in the computing world.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; At times the focus shifts between them as needs and technologies change, but these areas have remained key vectors of enterprise computing for a long time.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; However, in many cases these usability vectors conflict with each other.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; IT managers’ desire for security and manageability may lead to extra applications and process hoops for end users, which can decrease performance.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Increasing the ability to remotely and seamlessly manage a pc almost always adds security headaches that must be dealt with.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Enterprise IT design is always about finding the right tradeoffs and improving the process over time.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;One technology that has been around for quite a while to help improve security is IPsec (aka, IP Security).&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; IPsec is a set of protocols for securing and authenticating IP packets by encrypting their contents in an end-to-end manner.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Most people are familiar with IPsec as the underlying technology for facilitating Virtual Private Network (VPN) connections from the outside of an organization’s LAN to inside the network.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; IPsec secures the Int&lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;er&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt;net to Int&lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;ra&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt;net tunnel in this case.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Using IPsec to set up a VPN can be a bit of a pain because you have to key in an access code or password and it’s far from seamless.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; On the IT manager’s side, this setup does not eliminate security problems because the VPN tunnel only secures the network pipe &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;once it is established&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt;.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; There is nothing stopping the end user from browsing the web on their work computer or somehow exposing it to a virus &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;before&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt; connecting to the corporate network in a secured way.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; This has a few downsides from a manageability perspective.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; First, the security is compromised because of potential infections transferred from an insecure network to the corporate network due to lack of continuously active protection.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Second, the manageability of this solution is lacking because enterprise systems outside of the corporate network are not manageable until the user manually connects to the VPN gateway.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;So while using IPsec to help create a VPN connection provides functionality that is secure and provides outside-in access to the corporate network, it requires additional configuration by the end user, is not seamless for either user or administrator, and is generally provided by an additional application running on the system.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; This is all non-optimal.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Enter Microsoft* DirectAccess*.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; In Windows* Server 2008 r2 for servers and Windows* 7* for clients Microsoft* will be supporting a seamless IPsec support layer called DirectAccess*.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; What this will provide is the ability to integrate the encryption/authentication of IPsec directly into the Operating System so the end user connects securely outside &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;and inside&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt; the corporate network to the systems and applications they need via IPsec.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Because this is integrated into the OS, the set up of the security and connection details are more seamless from both an IT person and end user perspective.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Initial configuration is obviously required, and each IT organization must set up the security policies to their own specifications, but once that is done the system is up and running.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Microsoft*’s implementation of this functionality at the OS level, &lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; so each application can have its own secure IPsec tunnel.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; This can provide secure access both outside &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;and inside&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt; of the corporate network.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Up until recently, using IPsec internally has not been of much focus, but recent estimates suggest 80% of successful attacks come from internal threats, so encrypting and authenticating internal data is now in focus for IT administrators.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Microsoft* DirectAccess* allows for this new seamless security model.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Now this all sounds well and good… but what’s the catch?&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Well, a key angle here to note is that IPsec is a &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;highly&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt; CPU intensive technology.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; Encryption and decryption of IP packets in real time can easily swamp a CPU core when attempting to push much more than a few hundred megabits of network data.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; For a typical end user system, a few megabits of data across a few IPsec connection applications will likely not cause much heartache, but for network servers that are hosting potentially &lt;/span&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 10pt;"&gt;thousands&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 10pt;"&gt; of simultaneous IPsec connections while trying to drive multiple Gigabits of I/O the performance results will be much more… uhh, what’s a nice way to say ‘unimpressive’?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;In order to solve this issue, Intel networking products offload the computationally expensive encryption engine (AES-128) onto the LAN Controller while the IPsec configuration, management, policy creations etc all remain in the OS to keep usability simple. Intel offers both dual port 1 and 10 Gigabit networking solutions that support not only solid performance on standard networking workloads and advanced virtualization features, but also the ability to offload IPsec in hardware to improve system performance under large IPsec I/O workloads.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;For companies looking to enable IPsec into their network environment using DirectAccess*, they have the potential to improve security, reduce complexity, and enhance manageability of their end clients.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; They just need to remember that in order to make this all work seamlessly on the server side without choking off processing performance, offloading the IPsec workloads to I/O hardware will be a requirement.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Intel® Ethernet® can deliver this support in adapter or down on motherboard form factors while supporting a wide range of Enterprise class performance and virtualization features.&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; So is this a way to improve security and manageability without impacting performance?&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; It seems that way to me.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span lang="SV" style="font-family: 'Book Antiqua','serif'; mso-ansi-language: SV;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;-----&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&lt;br/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span lang="SV" style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-ansi-language: SV;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;Ben Hacker&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span lang="SV" style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-ansi-language: SV;"&gt;&lt;span style="font-size: 10pt;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span lang="SV" style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-ansi-language: SV;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;&lt;span style="font-size: 10pt;"&gt;For more information on DirectAccess* --&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.microsoft.com/servers/directaccess.mspx"&gt;&lt;span lang="SV" style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-ansi-language: SV;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="font-size: 10pt;"&gt;http://www.microsoft.com/servers/directaccess.mspx&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span lang="SV" style="font-family: &amp;amp;quot;Book Antiqua&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; mso-ansi-language: SV;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:a016a7b3-5b08-4d36-8cfb-da6dada862b0] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">performance</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">manageability</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">servers</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">ipsec</category>
      <pubDate>Sat, 16 May 2009 15:18:18 GMT</pubDate>
      <author>benjamin.r.hacker@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/05/16/ipsec-offload-meet-microsoft-directaccess</guid>
      <dc:date>2009-05-16T15:18:18Z</dc:date>
      <clearspace:dateToText>6 months, 2 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/ipsec-offload-meet-microsoft-directaccess</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=12170</wfw:commentRss>
    </item>
    <item>
      <title>Identity Theft - It really makes me mad when my integrity is on the line</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2009/03/11/identity-theft--it-really-makes-me-mad-when-my-integrity-is-on-the-line</link>
      <description>&lt;!-- [DocumentBodyStart:8892fb91-88ae-412d-a5dd-2f04431ef3e6] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;As usual, after swimming in the morning, I thumbed through my Blackberry.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; On the small glass screen, I saw the email from a friend,&lt;/span&gt; &lt;strong&gt;&lt;em&gt;&lt;span style="color: blue;"&gt;“Hi, For: Did you send this email to me?”&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="color: #000000;"&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I was very puzzled by what she meant that I quickly scrolled down to see the full text below her message:&lt;/span&gt; &lt;strong&gt;&lt;em&gt;&lt;span style="color: blue;"&gt;“Dear friend, I would like to introduce a good company who trades mainly in electronic products…&lt;/span&gt;&lt;/em&gt;”&lt;/strong&gt;&lt;span style="color: #000000;"&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I looked at the “From” line.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; It is from my personal email account!&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I knew immediately that some hacker hijacked my address book and used my email name to send out spam email.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; But how did that happen?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; How could I clean up this mess? I suspected that my not-so-strong password was hacked and I corrected it right away.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Since the send box identified who were the recipients. I then sent an email to explain the situation.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; My sister-in-law shot me an email afterward:&lt;/span&gt; &lt;strong&gt;&lt;em&gt;&lt;span style="color: blue;"&gt;“I though it was a little strange.&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/span&gt; &lt;strong&gt;&lt;em&gt;&lt;span lang="ZH-TW" style="font-size: 12pt; color: blue; font-family: PMingLiU; mso-fareast-language: ZH-TW; mso-ascii-font-family: Wingdings; mso-hansi-font-family: Wingdings; mso-bidi-font-family: Wingdings;"&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-size: 12pt; color: blue; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;”&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;This cyber identity theft really makes me mad at the intruder and myself not taking more precaution measures.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I use my web email account everyday, save my personal data in the “cloud”, and provide my VISA card number to purchase online.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; With the social media network, I may disclose even more personal information on the web.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; This incident wakes me up that I need to protect myself diligently by adopting caution behaviors such as using the strong password or making sure confidential data are encrypted.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; I also realize how much trust I have put in the datacenter and service provider that I may not even realize until I am personally affected.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Do the servers enforce strong passwords only?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; How do I know the communication between my personal computers and the servers are secured?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Can the service provider be trusted?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; It takes both the consumer end and the service providers together to create a secured environment.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; Service provides have the fiduciary duty to protect their customers and their investors by focusing on datacenter security issues.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; It may take only one security compromise to shake up the trust of the customers.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;I have been with Intel’s server group for the last 13 years and experienced many server technologies from form factor to power saving that have transformed the datacenters.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; With our upcoming server platforms, we will be placing more focus on helping datacenters to secure their infrastructure.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt; We would like to see a day that no one will need to send an email to their friends to say:&lt;/span&gt; &lt;strong&gt;&lt;em&gt;&lt;span style="color: blue;"&gt;“I didn’t send that spam!”&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt; &lt;span style="color: #000000;"&gt;&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;&lt;span style="color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="font-size: 12pt; font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;What is your story and resolution regarding security issues in cyber space and datacenters&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: Arial; mso-fareast-font-family: PMingLiU; mso-fareast-language: ZH-TW;"&gt;?&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:8892fb91-88ae-412d-a5dd-2f04431ef3e6] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <pubDate>Wed, 11 Mar 2009 17:56:27 GMT</pubDate>
      <author>heung-for.cheng@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2009/03/11/identity-theft--it-really-makes-me-mad-when-my-integrity-is-on-the-line</guid>
      <dc:date>2009-03-11T17:56:27Z</dc:date>
      <clearspace:dateToText>8 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>4</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/identity-theft--it-really-makes-me-mad-when-my-integrity-is-on-the-line</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=11957</wfw:commentRss>
    </item>
    <item>
      <title>Live from "Intel Premier IT Professional Event"-Denver</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2008/06/26/live-from-intel-premier-it-professional-eventdenver</link>
      <description>&lt;!-- [DocumentBodyStart:1fda3084-afcb-4858-9ee3-c0c705f4950e] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;I'm blogging here today from the Intel Premier IT Professional (IPIP) event in Denver, Colorado. This is a really amazing setting at the Center for the Perfoming Arts in downtown Denver. There are some 200 industry professionals here networking and sharing best practices around client and server technologies with some of the main topics including Intel's technology roadmap, security, client and server virtualization. For those who couldn't be here, check the &lt;a class="jive-link-external-small" href="http://ipip.intel.com"&gt;IPIP Website&lt;/a&gt; for event details and to download the presentations. In addition to updates on this blog, Josh Hilliker and I will have an event wrap-up on &lt;a class="jive-link-external-small" href="http://www.blogtalkradio.com/"&gt;Blog Talk Radio&lt;/a&gt;, stay tuned for the details. Check back to this blog for event updates as they occur. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Wm. Hank Lea&lt;/p&gt;&lt;p&gt;Community Manager&lt;/p&gt;&lt;p&gt;Open Port-The Server Room&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;2pm- Event Update&lt;/strong&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here's some cool video of XEON 7300-series(4P)running a database transaction application:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;!--[CodeBlockStart:2d5d89ef-bf55-4e8a-86dc-b4decc8d5661]--&gt;&lt;span&gt;&lt;embed height="344" src="http://www.youtube.com/v/5zlO7OdOHcs&amp;amp;hl=en" type="application/x-shockwave-flash" width="425"&gt;&lt;/embed&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:2d5d89ef-bf55-4e8a-86dc-b4decc8d5661]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;And another video showing the XEON 5400-series (2P) running the Black-Scholes Option Pricing benchmark:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;!--[CodeBlockStart:b28b3952-78c0-45fb-b369-911d259ef4b5]--&gt;&lt;span&gt;&lt;embed height="344" src="http://www.youtube.com/v/fcyg6eukAMU&amp;amp;hl=en" type="application/x-shockwave-flash" width="425"&gt;&lt;/embed&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:b28b3952-78c0-45fb-b369-911d259ef4b5]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;And a third demo showing the XEON 5400-series in a workstation configuration running 3D rendering application:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;!--[CodeBlockStart:f8c7a702-fc6a-4712-9288-36213481aba8]--&gt;&lt;span&gt;&lt;embed height="344" src="http://www.youtube.com/v/hf3ixt2pJT8&amp;amp;hl=en" type="application/x-shockwave-flash" width="425"&gt;&lt;/embed&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:f8c7a702-fc6a-4712-9288-36213481aba8]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:1fda3084-afcb-4858-9ee3-c0c705f4950e] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">45nm</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">data_center</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">energy_efficiency</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">innovation</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">josh_hilliker</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">manageability</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualization</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">workstation</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">xeon</category>
      <pubDate>Thu, 26 Jun 2008 20:59:18 GMT</pubDate>
      <author>william.h.lea@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2008/06/26/live-from-intel-premier-it-professional-eventdenver</guid>
      <dc:date>2008-06-26T20:59:18Z</dc:date>
      <clearspace:dateToText>1 year, 5 months ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/live-from-intel-premier-it-professional-eventdenver</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=11314</wfw:commentRss>
    </item>
    <item>
      <title>Virtual Appliances –  the next application development and deployment model?</title>
      <link>http://communities.intel.com/community/openportit/server/blog/2007/12/04/virtual-appliances-the-next-application-development-and-deployment-model</link>
      <description>&lt;!-- [DocumentBodyStart:f023d272-7c08-4f35-8b8d-09e83d403a47] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Server virtualization is becoming widely accepted and vendors and customers are beginning to explore usage models beyond support for legacy applications and server consolidation. Virtual Server load-balancing, disaster recovery (server and data center), dynamic creation and migration of virtual machines, to name a few, are fast becoming widely prevalent.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;One of the newest uses for server virtualization that is beginning to garner attention is &lt;strong&gt;application portability, packing and distribution, a concept that is becoming more concrete with the advent of virtual appliances&lt;/strong&gt;. Like the computer/HW appliances like TiVos, firewalls, IPS/IDS and NetApp filers, virtual appliances come pre-configured with applications and just enough operating software needed to perform their tasks, and delivered to the customer as a virtual machine file(s) ready to run atop a hypervisor. Every component of the virtual appliance is pre-configured and optimized and tested by the ISV who has the deepest understanding of the application, thereby eliminating interoperability issues and resulting in a better end user experience. Unlike hardware appliances which typically need specific hardware, virtual appliances run on top of any x86 hardware that has a hypervisor. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Could this be beginning of ‘Virtual-Appliance oriented architectures'? Too early to call, but in a virtualization-enabled world, the promise of an easy application deployment, distribution and maintenance/support is surely enticing. Just like any new technology or application model, there are a lot of challenges that ISVs and customers have to overcome with virtual appliances. We will get into details of these in the next set of blogs, but here is a quick summary of some questions customers and ISVs have to comprehend as they innovate in this space. We will also look at what Intel's doing here with its broad Virtualization Technology (VT) initiative.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;- &lt;strong&gt;Security&lt;/strong&gt; - Do you consider Virtual appliances as black boxes from a security perspective? Would you trust the ISV with both the app and the OS testing? Would there be any back doors? Will ISVs offload testing to third parties?&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;- &lt;strong&gt;Heterogeneous hypervisor environments&lt;/strong&gt; - How do you package the virtual appliances for deployment and distribution on multiple hypervisor environments? OVF is a clear direction here.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;- &lt;strong&gt;Performance of virtual appliances&lt;/strong&gt; - Are there issues with virtual appliances sizes as we deploy and distribute business applications in virtual appliances? How do you deal with dependent appliances? Would there versioning issues with virtual appliances? Will there be a need for multiple versions of virtual appliances executing side-by-side?&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;- &lt;strong&gt;Software licensing&lt;/strong&gt; - How does software licensing work in a virtual appliance model? How do you buy Microsoft OS licenses? Ubuntu, RedHat, etc are releasing stripped down versions of Linux for Virtual appliances usage. How would the Open source model evolve?&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;What do you think? You buy into the Virtual Appliance model? Will it work for you? Have you done anything with it yet? Let us know.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f023d272-7c08-4f35-8b8d-09e83d403a47] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualappliances</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtualization</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">licensing</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">virtual</category>
      <category domain="http://communities.intel.com/community/openportit/server/blog/tags">security</category>
      <pubDate>Tue, 04 Dec 2007 22:28:00 GMT</pubDate>
      <author>raghuram.yeluri@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/server/blog/2007/12/04/virtual-appliances-the-next-application-development-and-deployment-model</guid>
      <dc:date>2007-12-04T22:28:00Z</dc:date>
      <clearspace:dateToText>1 year, 12 months ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/server/blog/comment/virtual-appliances-the-next-application-development-and-deployment-model</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/server/blog/feeds/comments?blogPost=10788</wfw:commentRss>
    </item>
  </channel>
</rss>

