home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Powered by InformationWeek Business Technology Network
InformationWeek 500 Conference -- September 14-16, 2008 Registed Today!

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






Basking in Glory-SNMPv3

One Brick at a Time

Although the original SNMP is the foundation of today's enterprise network management systems, it has some shortcomings. First and foremost, SNMP lacks an effective security model--an essential component in any critical network service. Second, SNMP agents suffer from an ironic paradox: Although SNMP allows managers to Get and Set MIB variables from afar, there is no standardized way to manage SNMP agents themselves via SNMP. Other flaws have come to light only after nearly a decade's use: SNMP cannot accurately describe relationships among managed objects, nor can it address an object within an object, perform more efficient Get operations, issue clarified Set operations or handle larger counters to accommodate gigabit technologies.

SNMP also suffers from a different problem. While it effectively provides the plumbing for network management and offers an extremely flexible and extensible MIB language, MIB support has proven to be its greatest weakness. Network management platforms must manage MIB extensions from literally hundreds of vendors--many variables of which are either redundant or at least similar. A handful of MIB standards, including MIB, MIB2, RMON and RMON2, have attempted to standardize common data types, but network management platforms face the Herculean task of correctly interpreting and associating large volumes of device-specific information. SNMPv3 addresses protocol-level improvements over previous SNMP implementations, but the operation of the MIB has changed little.

However, SNMP implementers should not despair. A separate initiative by the DMTF (Desktop Management Task Force) is attempting to standardize and associate these various data types into more useful information through CIM (Common Information Model) as well as DEN (Directory-Enabled Networking) initiatives (see "Hyping the Common Information Model," www.network computing.com/912/912ws1.html).

When the revolutionary SNMP first emerged, it faced a dilemma: how to create an effective network management system using the fewest hardware resources possible. At the time, CPUs and memory were at a premium, especially in the firmware of infrastructure devices. Community strings--passwords encoded in plain text in each packet--granted a modicum of security, but more important, they provided a protocol that was inexpensive to implement in silicon.

Today, plain-text community strings are under an even greater threat. Since packet sniffers and protocol analyzers are inexpensive and readily available to users at large, traffic traveling across the enterprise network must assume it's crossing a potentially hostile environment. Unfortunately, SNMP, which still relies on community strings, can perhaps better be defined as "Security's Not My Problem."



Efforts during the past five years to improve SNMP's security model arrived at an impasse, with competing versions of SNMPv2 (v2* and v2u) vying for approval while a compromise version called v2c omitted security enhancements, defaulting back to community strings. None had a clear advantage. In contrast, the recently proposed SNMPv3 standard promises finally to deliver a vastly overhauled security model and other protocol enhancements. Last winter, SNMPv3 moved from the inner workings of an IETF working group to the level of proposed standard. Unlike the stalemated SNMPv2 effort, SNMPv3 already has drawn a high level of commitment from the network management community, as well as from infrastructure vendors.


Print This Page


e-mail E-mail this URL





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights