iTnews
  • Home
  • News
  • Technology

Analysis: How secure is an optical-fibre network?

By Dave Bailey
Aug 7 2009 7:06AM
Follow google news

What IT leaders should consider.

Analysis: How secure is an optical-fibre network?
Many countries are looking to roll out optical-fibre connectivity to support next-generation broadband access, giving download speeds of 100Mbit/s with low latency and greater upload capacity than is associated with conventional asymmetric digital subscriber line (ADSL) technology.

Carriers, ISPs and large corporations, especially financial services firms, use a large amount of optical-fibre connections and the security of those connections needs to be locked down.

Such concerns are addressed in a recent report on optical network security by IDC research analyst Romain Fouchereau. Entitled: Fibre Optic Networks: Is Safety Just an Optical Illusion?, the report discusses what firms need to consider when thinking about how to secure fibre-based networks.

The report references several examples of optical network hacking - perhaps the most serious commercial example was when US security forces found a device illegally installed on carrier Verizon's optical network. The placement appears to have been designed to eavesdrop on a mutual fund company, shortly before it released its quarterly financial figures.

"Remember this happens more than organisations want to admit, and there's a lot of hacking that goes unnoticed," said Fouchereau.

Firms spend huge amounts of money to protect their networks.

"It's a pity if all this money is going down the drain because they're not protecting the fibre part of the network transmitting all the data," said Fouchereau.

The report details the three main methods used for siphoning off data from optical fibre connections.

The first technique, and the crudest, involves physically cutting the cable and splicing a device into the fibre that can be used to pick up the data, and transmit or re-route it somewhere else.

"This is the oldest and most traditional way of collecting data from fibre networks," said Fouchereau, explaining that there was a possibility of alert IT administrators seeing that something was happening and taking remedial action.

The other two methods involve devices for collecting light emitted by optical fibres, allowing hackers to reconstruct the data. Bending the fibre and picking up stray light emission is one possibility. The other is more elaborate, said Fouchereau, and involves putting a photosensor around the cable and measuring scattered light, to rebuild the data.

Fouchereau advises IT leaders to take fibre network security very seriously.

"It's like you put an alarm in your house and then leave the back door open. It doesn't make much sense to protect one side of the network without protecting the rest," said Fouchereau.

To lock down optical networks and reduce the risk of data theft, Fouchereau points to a handful of security vendors who have products for end-to-end data encryption. These appliances can encrypt using key sizes of 128- or 256-bits using Advanced Encryption Standard (AES) with maximum data transmission rates.

But Rob Bamforth, Quocirca principal analyst for communications, said that while taking data from optical-fibre data transmission was more than just a theoretical possibility, there are still challenges for would-be hackers.

"How accessible is the fibre?" he said.

"Many companies, especially carriers, put systems in difficult to reach places, for example buried alongside gas mains."

Another problem for hackers, said Bamforth, was that optical fibre can be enabled with different types of equipment. "This can vary quite significantly, so some knowledge of the specific systems used would be required," he said.

Bamforth pointed out that even hackers would look at return on investment for their activity.

"If the effort is too great for the value returned, they'll move on to a more vulnerable target," he said.

"But it might be wise to iron out simpler-to-attack vulnerabilities elsewhere first".

Bamforth said that firms should wrap full encryption and authentication around the things they really want to protect.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:
anhowisnetworkopticalfibresecuretechnology

Related Articles

  • Black Hat founder: SSL is broken Black Hat founder: SSL is broken
  • Adobe releases Flash 10.1 and patch bundle Adobe releases Flash 10.1 and patch bundle
  • Google posts Chrome security fixes Google posts Chrome security fixes
  • Report: Apple's iAds catches interest of antitrust regulators Report: Apple's iAds catches interest of antitrust regulators
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
AI is delivering business value today
Partner Content AI is delivering business value today
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Software AG squares up to SAP with IDS Scheer buy

Software AG squares up to SAP with IDS Scheer buy

Report: Apple's iAds catches interest of antitrust regulators

Report: Apple's iAds catches interest of antitrust regulators

Analysis: How secure is an optical-fibre network?

Analysis: How secure is an optical-fibre network?

Google adds search support for mobile application stores

Google adds search support for mobile application stores

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.