Creative Commons
Supply chain - its a term and topic that is now discussed around dinner tables as families and friends discuss and debate COVID-19s spotlight on the US dependence on other countries to provide the essential products and materials we need in time of crisis. The other dinner table discussion seems to focus around cybersecurity. With a precipitous increase in attacks and exploits in this new remote work environment, IT pros and those working from the home office are equally concerned.
While the focus of supply chain discussions has largely been around medicines and emergency supplies, there is another conversation that has been simmering in the tech sector for a long time. Flare ups occur every time the press reports on a suspected exploit found in infrastructure. How dependent can supply chain infrastructures become on foreign suppliers (or suppliers with factories based in other countries) before they become overly dependent? And how can an IT infrastructure manufacturer (in this case server) assure that the components being used in a bill of materials (BOM) are genuine and contain no microcode or other components that can be used to exploit that equipment over time?We will address this over the next few paragraphs.
Supply chain concerns are legitimate
The supply chain can be used as another attack vector for bad actors to exploit data, be it hackers looking to hold IP and sensitive information for ransom, or nation states looking to wreak havoc or disable critical functions of our companies or government. Such actors can insert motherboard implants that can go overlooked or insert malicious microcode that can create a backdoor once a platform is in production. Additionally, components such as a baseboard management controller (BMC), the control plane of the server, can have built-in vulnerabilities. These are all exploits that are not just theoretically possible - they have, in fact, already happened.
We often talk about cybersecurity in terms of perimeter defenses such as firewalls, or access control from companies like Aruba. IT organizations that are more serious about security look to technologies like HPEs designed Silicon Root of Trust (SiROT) as the starting point where cybersecurity starts. While SiROT is a critical and fundamental element of a cybersecurity strategy, the reality is that cybersecurity starts in the supply chain ordering the parts and components that go into the server. From storage and memory to the CPU, to the inductors, capacitors and resistors that go on to the motherboard.
Strangely enough, securing the supply chain is not just about security. Its also about ensuring quality that is assured through authenticity. One of the challenges that exist today is ensuring the components that populate a server at the time it is stored at in a datacenter are the same components that were in that server at time of assembly. And that those parts are genuine manufacturers parts.
Supply chain is really complex
Per John Grosso, Vice President of Global Operations Engineering, Global Supply Chain at HPE, the average 1U or 2U ProLiant rack server has between 3,5004,000 components. That is, 3,5004,000 components that have to be tracked across hundreds of suppliers around the worldchecked for security and for quality purposes.
The HPE supply chain is complex.
Consider the very simplified graphic above. The team at HPE (or any manufacturer) must ensure quality and integrity from left to right. Meaning, every component coming from every supplier is authentic and untainted as it leaves the suppliers factory and arrives at HPEs manufacturing facility. The team then must ensure the servers are assembled with those very same authentic components and the integrity of the server is intact. After assembly, every server must be tested prior to shipping out to customers or distributors and resellers (in the case of the indirect sale, HPE must ensure that these servers are not modified or compromised in any way as they sit on warehouse floors, ready to fulfill orders). Upon arrival at a customers datacenter, HPE must ensure that server boots up with the hardware, firmware and software components that were installed when the server left the factory floor.
But, how does this happen? Grosso described his teams approach to driving integrity across the process, and its quite comprehensive. He uses a term called roving cyber validation, whereby team members embedded with suppliers perform regular audits and informal spot checks on a regular basis to ensure the genuineness of components. As components are shipped to HPE factories, random x-raying takes place to ensure no tampering took place during shipment.
As servers are assembled in HPE or partner facilities, a cryptographic manifest is built after assembly and validation of components is complete. This manifest is attested at the customer site at first boot at the customers datacenter, through HPEs Silicon Root of Trust (SiROT).
Supply chain management does not end at first boot. HPE (and other server vendors) must be able to ensure the integrity and quality of that server throughout its lifecycle. Through maintenance, upgrades and repairs, Grossos team is charged with ensuring the integrity of that server.
In the case of HPE, SiRoT and other utilities built into the companys integrated lights out (iLO) management platform can immediately detect, remove and recover a server from malware and ransomware (to learn more about this, check out my coverage here and here).
How does HPE do it?
During a time where buy American is starting to gain steam, its unrealistic to believe that the server supply chain can be brought on the shores of the US to guarantee security and quality. This may be an unpopular view, but its realistic. Given this reality, infrastructure companies need to be vigilant about these things. And this commitment to securing the supply chain must be viewed as a pillar of a companys strategy.
Securing the supply chain for HPE appears to be equal parts organizational, technical and cultural. And based on conversations I was able to have with Grosso and Security CTO Gary Campbell, this is nothing new. Campbell says the seeds of todays focus on supply chain management were sewn about 10 years ago in a briefing he and Antonio Neri (now CEO) had with a large government customer.
In 2014, HPE started to develop a holistic security architecture that could help the company in its fight with the counterfeiting of products and overall security. Out of this effort, SiRoT was developed and implemented across the HPE portfolio.
Upon Neris appointment to CEO, one of his top priorities was to embed a security first mindset across HPE, understanding this could be a real value to companies of all sizes and a true differentiator in the market. It feels as though this message has permeated the company. Security is a key messaging pillar around every product the company introduces to the market, and its PointNext services has a very healthy consulting practice focused on cybersecurity.
One of the interesting things I learned from speaking with Campbell was the fact that HPE is the only server company to design and develop its own BMC. Why is this important? Think of the BMC as the control plane of the server. It is the lowest level management interface and provides the basis for all of the physical monitoring of a servers condition. A compromised BMC can lead to a compromised server, and as previously mentioned, there are many news articles about this very thing happening. By developing its own BMC, HPE not only ensures the security of its servers, it has the ability to enable greater controls through its iLO management technology.
Bringing in Grosso and centralizing the management of the product lifecycle under his direction was a smart move by HPE. This enabled a single view of the product, spanning design, NPI (new product introduction), supplier quality, factory output and customer quality. Why does this matter? It enables a critical input to the product requirements and development process, ensuring security is fleshed out and given appropriate consideration across all stages of product life.
To ensure the team was being complete in its thinking and efforts, a Supply Chain Center of Excellence (COE) was built with representation from across the company. Its charter included three areascapturing the needs (and feedback) of customers and the market, sharing of best practices across the various teams and ensuring consistency of security practices across all product lines.
Finally, to make sure product and supply chain security remains a priority to HPE, its board of directors (BoD) has a committee headed by Mary Agnes Wilderotter that receives quarterly reports on the status of end-to-end product security, including the supply chain.
Whats next?
Considering the typical server has 3,5004,000 components (upwards of 7,000 components for converged infrastructure), it is hard to envision shifting the supply chain entirely to domestic suppliers. However, companies like HPE continue to work on reducing their dependence on suppliers who may not be able (or willing) to deliver in a time of need or crisis. As Grosso says, his team never stands still.
Given the scrutiny the government has put on foreign suppliers over the last couple years and the bright spotlight COVID has put on supply chain, I do expect to see further development from companies like HPE in ensuring these risks around dependency are not only mitigated, but minimized or removed.
Closing thoughts
As an analyst who has experience as an IT executive, I can fully appreciate the approach HPE takes to supply chain security. I never considered the integrity of the servers coming into my datacenter (or the quality of their performance), because I never had to worry. The upfront work of companies like HPE simplified my life and allowed me to deploy and run infrastructure with one less thing to worry about.
While securing the supply chain may not be as cool to talk about as edge computing, data analytics or cloud-native application development, it is arguably the most important consideration in choosing infrastructure to enable these environments. Its something we should all thinking about, even after this COVID craziness passes.
Disclosure:My firm, Moor Insights & Strategy, like all research and analyst firms, provides or has provided research, analysis, advising, and/or consulting to many high-tech companies and consortia in the industry, including HPE. I do not hold any equity positions with any companies or organizations cited in this column.
See original here:
Do You Know Where Your Servers Come From? Heres Why Securing The Supply Chain Matters - Forbes
- Setting up a Virtual Server on Ninefold - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- ScaleXtreme Automates Cloud-Based Patch Management For Virtual, Physical Servers [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Secure Cloud Computing Software manages IT resources. [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Dell unveils new servers, says not a PC company [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Wyse to Launch Client Infrastructure Management Software as a Service, Enabling Simple and Secure Management of Any ... [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- As the App Culture Builds, Dell Accelerates its Shift to Services with New Line of Servers, Flash Capabilities [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Terraria - Cloud In A Ballon - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Ethernet Alliance Interoperability Demo Showcases High-Speed Cloud Connections [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- RSA and Zscaler Teaming Up to Deliver Trusted Access for Cloud Computing [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- [NEC Report from MWC2012] NEC-Cloud-Marketplace - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- IBM SmartCloud Virtualized Server Recovery - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- BeyondTrust Launches PowerBroker Servers Windows Edition [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Ericsson joins OpenStack cloud infrastructure community [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- ScaleXtreme Cloud-Based Patch Management Open for New Customers [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- RootAxcess - Getting Started - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- How to Create a Terraria Server 1.1.2 (All Links Provided) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Dell #1 in Hyperscale Servers (Steve Cumings) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Managing SAP on Power Systems with Cloud technologies delivers superior IT economics - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- AMD Acquires Cloud Server Maker SeaMicro for $334M USD [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Web Host 1&1 Provides More Flexibility with Dynamic Cloud Server [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Leap Day brings down Microsoft's Azure cloud service [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- RightMobileApps White Label Program - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- bzst server ban #2 - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- “Cloud storage served from an array would cost $2 a gigabyte” [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- More Flexibility with the 1&1 Dynamic Cloud Server [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Hub’s future jobs may be in cloud [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cloud computing growing jobs, says Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- TurnKey Internet Launches WebMatrix, a New Application in Partnership with Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cebit 2012: SAP Cloud Computing Strategy - Introduction - Video [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Dome9 Security Launches Industry's First Free Cloud Security for Unlimited Number of Servers [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Servers Are Refreshed With Intel's New E5 Chips [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Samsung's AllShare Play pushes pictures from phone to cloud and TV [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Google drops the price of Cloud Storage service [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Intel Server Technology: Powering the Cloud to Handle 15 Billion Connected Devices [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Swisscom IT Services Launches Cloud Storage Services Powered by CTERA Networks [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- KineticD Releases Suite of Cloud Backup Offerings for SMBs [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- First Look: Samsung Allshare Play - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Bill The Server Guy Introduces the New Intel XEON e5-2600 (Romley) Server CPU's - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Cisco servers have Intel Xeon E5 inside [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Cisco rolls out UCS servers with Intel Xeon E5 chips [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- From scooters to servers: The best of Launch, Day One [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Computer Basics: What is the Cloud? - Video [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- Could the digital 'cloud' crash? [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Dome9 Security Launches Free Cloud Security For Unlimited Number Of Servers [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Cloud computing 'made in Germany' stirs debate at CeBIT [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- New Key Technology Simplifies Data Encryption in the Cloud [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- Can a private cloud drive energy efficiency in datacentres? [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Porticor's new key technology simplifies data encryption in the cloud [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Borders + Gratehouse Adds Three New Clients in Cloud Sector [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Dell to invest $700 mn in R&D, unveils 12G servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Defiant Kaleidescape To Keep Shipping Movie Servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Data Centre Transformation Master Class 3: Cloud Architecture - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 1/3 - Video #310 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Cloud Computing - 28/02/12 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- SYS-CON.tv @ 9th Cloud Expo | Nand Mulchandani, CEO and Co-Founder of ScaleXtreme - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Oni Launches New Cloud Services for Enterprises Using CA Technologies Cloud Platform [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Advanced Technology - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Infrastructure - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- The Hidden Risk of a Meltdown in the Cloud [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- FireHost Launches Secure Cloud Data Center in Phoenix, Arizona [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Panda Security Launches New Channel Partner Recruitment Campaign: "Security to the Power of the Cloud" [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- NetSTAR, Inc. Announces Safe and Secure Web Browsers for iPhones, iPads, and Android Devices [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Amazon Cloud Powered by 'Almost 500,000 Servers' [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- NetSTAR Announces Secure Web Browsers For iPhones, iPads, And Android Devices [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Be Prepared For When the Cloud Really Fails [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Dr. Cloud explains dinCloud's hosted virtual server solution - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- New estimate pegs Amazon's cloud at nearly half a million servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Amazon’s Web Services Uses 450K Servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Saving File On Internet - Cloud Computing - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 2/3 - Video #311 - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Linux servers keep growing, Windows & Unix keep shrinking [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Cloud Desktop from Compute Blocks - Video [Last Updated On: March 16th, 2012] [Originally Added On: March 16th, 2012]
- Amazon EC2 cloud is made up of almost half-a-million Linux servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- HP trots out new line of “self-sufficient” servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Cloud Web Hosting Reviews - Australian Cloud Hosting Providers - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Using Porticor to protect data in a snapshot scenario in AWS - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- CDW - Charles Barkley - New Office - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Nearly a Half Million Servers May Power Amazon Cloud [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Morphlabs CEO Winston Damarillo talks about their mCloud Rack - Video [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- AMD reaches for the cloud with new server chips [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]