“Anyone who has never made a mistake has never tried anything new.” — Albert Einstein

Serial Entrepreneur: Taher Elgamal (Part 8)

Saturday, March 31, 2007 | 1 comment

Check other articles in the series...

Taher addresses some of the unexpected impacts of the growth of the Internet, and the impact this had on network design. These thoughts lead into the development of Securify.

SM: What were you doing with Securify? TE: That was mid 1998, and it was an attempt to make networks work correctly knowing the entities you are connecting to. When the Internet came in, something extremely unexpected happened. Everybody, 100% of businesses got connected, and there are no two networks who are not connected to each other. The problem is none of these networks were not designed to be connected to anything. We ended up backing things into these networks, and trying to secure them. A lot of things ended up broken, and even today there are a lot of networks which are connected to the Internet which do not have proper security.

My original philosophy was to devise schemes to help businesses run networks the way they were intended to be, and then we could perhaps stop a lot of the bad, evil or unexpected things.

SM: What were you selling? Was it software? TE: Yes, but the original product was a suite of consulting services.

SM: So you actually worked on corporate networks and plugged their holes? TE: Yes. We had one of the best security consulting groups ever. It was the most unbelievable group of characters I would ever work with. That entire team is now CEOs – it was an unbelievable collection.

In order to build the product we had in mind, we needed to know what the networks looked like. In the mean time we built the technology which Securify still sells today which is a policy based method for managing events. The concept is if you determine something happening on the network should not be happening, you eliminate it. Most of the kernel security methods people use are negative things, which is the opposite way of looking at things. It is very difficult to manage security tracking down negative things because the evil things change every day and it becomes an arms race.

SM: What you were trying to do is preemptive? Can you give us some more on that, some logic for that approach? TE: Suppose you are listening on the wire in the middle of a network. What you listen to tells you that IP address x is asking to access the server at IP y, and the nature of the session looks like a web session. You then simply look at your policy for y and figure out if these two are allowed to talk to each other. If it is not OK then you stop something, or alert something. It turns out that in general, if that were the infrastructure of the networks, then networks would be a lot more secure.

Today what we do for the most part is listen in on traffic and try to see if it looks like some type of attack which we have seen before. The problem is you must see the attack first.

You really need to be ahead of the attack, and be trained on what to do first. That is the right security model. It is the security model from the old mainframe era. The best security model the entire industry has ever developed was in the mainframe era, and it has all been going down hill since then.













This segment is part 8 in a 13 part series
Jump to part: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13

Comments

[…] 1] [Part 2] [Part 3] [Part 4] [Part 5] [Part 6] [Part 7] [Part 8] [Part 9] [Part 10] [Part 11] [Part […]

Sramana Mitra on Strategy » Blog Archive » Serial Entreprenuer : Taher Elgamal (Part 13) Thursday, April 5, 2007 at 9:16 AM PT

You can leave a response, or trackback from your own site.


Free Updates

Subscribe to feed (learn more)

Or get updates by e-mail:

Recent Comments

  • I made the claim that Apple will blow past RIM in short order. RIM is a one-hit player in North America that will become a footnote. They'll struggle for years,… Realtosh on Still Bullish on Nokia
  • The potential from emergent markets in India, China and South America is undeniable particularly with the forthcoming oil boom in Brazil and the technical conve… David Bristow on Buying Opportunity with VMWare
  • One more thing. Apple was not working on iPhone 100%. They had and have many folks working on refreshes for all of their lines (iPods, Macs, laptops) plus th… Realtosh on Apple’s Uncharacteristically Sloppy Execution
  • Apple has looked a bit sloppy recently. What can Apple do to improve operations? Apple has been growing fast and aggressively, both in its' currents markets … Realtosh on Apple’s Uncharacteristically Sloppy Execution
  • Sramana, I liked the idea, although parts of it have an element of luxury in it. However,this vision that you have put forth does not seem to be India centri… Vishal on Vision India 2020: Lucid
  • great series! I am waiting for the healthcare essay!… ashwin on Vision India 2020: Preface