Blue Titan Partner Ties Web-Services Management To Security - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Hardware & Infrastructure
08:36 AM
Connect Directly

Blue Titan Partner Ties Web-Services Management To Security

Integrating an XML firewall from DataPower Technology increases security for the services built on its Network Director framework.

Blue Titan Software Inc. has integrated its Web-services software with an XML firewall to supply more security for the services built on its Network Director framework. The firewall is built into hardware instead of software to avoid adding any performance overhead.

Network Director can be used to set up a services-oriented architecture, where an application is available to be called by many different users over a network. Such calls and responses, when made over the Web, are accomplished via XML messaging. Network Director can route the messages, balance the loads, and line up needed resources, but it needed an addition to make sure the XML messages were safe and didn't contain hidden mischief, such as triggering an out-of-bounds inquiry at the destination computer.

By integrating Network Director's operation with DataPower Technology Inc.'s XS40 XML Security Gateway, Blue Titan can insure that the messages will be parsed in transit by the XML firewall and their contents as well as their headers inspected, says Sam Boonin, Blue Titan's VP of marketing.

DataPower's firewall "gets down into the XML message itself," says Kevin Anderson, senior marketing manager at DataPower, and can check the contents against the rules and policies that determine what the message should be permitted to do. If the message is headed for a human-resources department application, the firewall can make sure it's not going to try to launch an unauthorized SQL query against a database once it gets there.

"Obviously there's some long-term work these two products can do together, " says Tom Rhinelander, an analyst with the New Rowley Group. But the pairing requires a customer to want the firewall to be contained in a dedicated device. The XS40 XML Security Gateway in effect is a rack-mounted server requiring one slot of space in a data-center rack. Organizations that are used to configuring a general-purpose firewall in software might not warm up to a Web-services approach that requires one in a dedicated box, he notes.

Network Director has been enhanced to include management of the box as part of its framework for building networked services, Boonin says.

This approach, in fact, has already been implemented by other companies. Westbridge Technology is a Web-services management firm that approaches management issues from the security perspective. It offers a rack-mountable XML Message Server in hardware for swift parsing of XML messages.

Computer Associates also links management of networked services to security. Its Web Services Distributed Management product is linked to its eTrust security-product line, so its Web-services manager can retrieve the identity of a user and check whether access sought to a resource is permitted. "The two functions are interrelated," says Dmitri Tcherevik, director of Web services.

"A lot of companies haven't figured out how they'll roll out a services-oriented architecture," where a service created for one application can be called and used by a second or third or more applications, analyst Rhinelander says. Integrating Web-services management with an XML firewall reduces the number of decisions that have to be made to establish a services-oriented architecture, he says.

The DataPower XS40 XML Security Gateway is priced at $65,000 per appliance; Boonin says Network Director is typically priced around $250,000.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
State of the Cloud
State of the Cloud
Cloud has drastically changed how IT organizations consume and deploy services in the digital age. This research report will delve into public, private and hybrid cloud adoption trends, with a special focus on infrastructure as a service and its role in the enterprise. Find out the challenges organizations are experiencing, and the technologies and strategies they are using to manage and mitigate those challenges today.
COVID-19: Using Data to Map Infections, Hospital Beds, and More
Jessica Davis, Senior Editor, Enterprise Apps,  3/25/2020
Enterprise Guide to Robotic Process Automation
Cathleen Gagne, Managing Editor, InformationWeek,  3/23/2020
How Startup Innovation Can Help Enterprises Face COVID-19
Joao-Pierre S. Ruth, Senior Writer,  3/24/2020
Register for InformationWeek Newsletters
Current Issue
IT Careers: Tech Drives Constant Change
Advances in information technology and management concepts mean that IT professionals must update their skill sets, even their career goals on an almost yearly basis. In this IT Trend Report, experts share advice on how IT pros can keep up with this every-changing job market. Read it today!
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll