August 27, 2007

Intel's vPro chips in more security for businesses

Intel's latest vPro microprocessors provide expanded security capabilities with hooks for third-party PC defense and management tools

With the introduction of its latest vPro microprocessors on Monday, Intel contends it is injecting a heavy dose of new security capabilities for the benefit of business customers and third-party technology providers alike.

[ See also: Intel adds desktop NAC to latest chips ]

By wrapping a set of expanded security features around the vPro Core 2 Duo chips, the chip giant maintains it can help IT departments more easily protect and support their desktop systems, in large part by offering additional hooks for other vendors' PC defense and management tools. 

With the addition of features that extend malware behavior-detection further onto the CPU level and wall off virtualized software systems from attack, Intel says it can greatly enhance the chips' interaction with complementary security technologies.

By adding new capability for desktops to communicate directly with so-called network access control (NAC) systems, Intel contends it can offer full-fledged security management opportunities that circumvent the need for device-OS interaction.

"The time [available] to respond to vulnerabilities is down and the sophistication of malicious attacks is increasing," said Gregory Bryant, general manger of Intel's Digital Office Platform Division. "We're trying to make security more proactive by driving it into the platform itself."

Intel is also touting other systems management and power-efficiency features in the chips, formerly known by the code-name Weybridge, but its sales pitch for the new vPros is centered on its security tools.

Bryant acknowledges that it may take years for the processors to find their way onto a large share of enterprise desktops. However, the vPros' technologies are aimed at other emerging IT phenomena such as virtualization and NAC, he said, which will help the processors fall in line with those trends.

The vPros' augmented Time-based Systems Defense Filters promise to scan every outbound packet traveling over the processor and maintain logs of suspicious behavior to identify unwanted network activity.

The chips address security concerns with virtualized software systems -- including integration issues with traditional anti-malware technologies and the opportunity for data theft via external attack -- with the addition of a pair of features.

Intel's Trusted Execution Technology -- which was developed under the code-name LaGrande -- promises to wipe out any residual data that may be left available when a virtual system is improperly shut down and to detect any attempts to modify the software it is running on. When combined with the chips' Intel Virtualization for Directed I/O technology, the processors will specifically be able to detect and ward off emerging attacks that seek to inject themselves between hardware and software systems by isolating virtual machines and cutting off outside access to their memory, Bryant said.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.