2016 NetExIP-HyperIP Security Enhancement Update

NetEx/IP® and HyperIP® Today

Network Executive Software, Inc. (NESi) brings high performance file transfer technology to the industry-standard IP environment with its NetEx/IP and HyperIP software products.

NetEx/IP is many times faster than TCP over long distances, which makes it the ideal solution for moving massive amounts of mission- or time-critical data across the country or across the globe.  As proven by our long-term users, NetEx/IP has the highest throughput rates over long distances with no degradation of performance because of its efficient bandwidth utilization and mitigation of the effects of packet loss and latency. In fact, NetEx/IP and its predecessor product NetEx/HC (HyperChannel) have provided solutions for moving data for global corporations and US state and government agencies for more than 30 years.

For existing TCP applications, the premier solution is NESi’s low cost HyperIP.  HyperIP transparently implements NetEx/IP in the data path to provide all the NetEx/IP improvements, plus compression of data, on a virtual machine without having to modify existing applications or operating procedures.

The Challenge: Securing the Data

With an increase in hacking and breaches of sensitive databases in recent years, many corporations (especially those in the financial, government, or health sectors) and US government agencies are looking at ways to better protect data transiting between sites and the databases themselves.  Data security is also of utmost importance for those customers utilizing shared/public networks.

NetEx/IP Security Enhancements

NESi recognizes this concern for data protection and is therefore planning to enhance NetEx/IP and HyperIP over the next year with standards-based security technology like Transport Layer Security (TLS) to significantly increase the security of the data being moved across the computer room, the country, or globally.

TLS is a cryptographic protocol that secures data as it is transmitted, focusing on authentication, data integrity, and data confidentiality. With TLS, keys are generated uniquely for each connection and are based on a shared secret negotiated at the start of a session, providing security between two applications using NetEx/IP or HyperIP.  Adding TLS to our NetEx/IP products will also provide improved security for our BFX & PFX utilities, which interface upward to customer applications.

In addition to data security, adaptive block compression of data will also be added to NetEx/IP, thus decreasing WAN bandwidth usage and effectively increasing the application data throughput over the network.

Solving WAN Challenges of Workload Mobility Using HyperIP

IBM released a whitepaper on Leveraging the Cloud to transform Test and Development. As companies implement software in the cloud on an on-premise platforms for workload sharing, challenges emerge in the movement of that workload between the customer premise and the offsite destination of that data. Does development become hindered if I move that workload offsite or does it have to be in my LAN? Can I move it offsite so workload mobility, flexible system and software configuration, and continuous provisioning be leveraged as a cost effective solution? IBM’s Smart Cloud solution and HyperIP’s WAN Acceleration Virtual Appliance ensures that customers can leverage workload mobility over the WAN, without suffering the performance problems caused by the WAN.
Customers leverage many techniques for moving the workload between the test/dev environment and the customer’s developers. vMotion, Live Migration, FTP, RSYNC, TSM, ProtecTier, etc. All of these applications require the workload to traverse the WAN. TCP/IP has limitations on the movement of big data. HyperIP removes those limitations to significantly improve performance of workload mobility, in excess of 10-12x faster by providing a WAN Acceleration technology that removes packet loss, latency, and out-of-order packets from task. HyperIP then implements block-level data reduction algorithms to significantly reduce the time to move that workload to or from the cloud hosting facility. This all translates to cost effective network transfers and connectivity.

For more information on HyperIP and to request a trial, go to http://www.netex.com .

HyperIP Series – You Asked About WAN Acceleration of Encrypted Data…

A customer recently asked a question during a webcast, “How does HyperIP accelerate encrypted data?” The answer is, it depends.

In the case where the data was encrypted when it was written to disk, as is required in most financial institutions, encryption poses problems for WAN optimization controllers who need to inspect the data to perform their optimization techniques:

1. Compression and deduplication on the network can no longer be applied to a secured/encrypted packet, so data reduction algorithms are a moot point.

2. Data security is paramount, so movement or transport of that data over the IP network requires the datagram to be intact, not un-encrypted, then re-encrypted putting data security at risk. That now means data pattern caching in disk or memory is no longer applicable.

3. Payloads in the encrypted data block can be quite large requiring a data streaming technology to meet window requirements and aggressive RTO’s to be adhered to.

So how can HyperIP WAN Optimization Virtual Appliance from NetEx accelerate encrypted data?

If the data is encrypted prior to HyperIP compression won’t be possible but HyperIP will still be able mitigate network issues that degrade WAN performance. SSL data payload, certificates, and keys will all passed through HyperIP’s accelerated transport at or near wire speed. No matter the distance or latency, no matter the packet loss on the WAN, no matter the amount of network congestion or out–of-order sequence issues, HyperIP will maximize the throughput of the application.  This allows for complete data security, no modification of the SSL-encrypted block of data jeopardizing the integrity of the payload, transparent to both the application and encryption.

If the traffic is encrypted with a Taclane KG encryptor, HyperIP takes the unencrypted data from the source, optimizes the transport of that data to near wire speed, then compresses the data blocks to reduce traffic on the WAN, then hands that data to an encryption appliance. This is the preferred solution in most Department of Defense implementations, where specific encryption gear is required. This solution allows for complete WAN Acceleration of the block of data before it is encrypted. Global replication and backup of data now leverage HyperIP’s value and complete data security with government approved encryption on the WAN links.

See a success story about HyperIP in a DoD implementation:

Whether you are moving your secured data to a cloud storage provider, your own private cloud facility, a centralized data repository from remote offices, or an in-house DR facility, HyperIP can significantly improve the performance of your applications.

