market trends

You are currently browsing the archive for the market trends category.

A recent report from IDG Connect, iPad for Business Survey 2012 (needs registration to download) offers a fascinating insight into iPad take-up in the enterprise environment. The iPad for Business Survey focuses on professionals and their relationship with the iPad. Is it primarily a business tool, or an extension to personal usage? Who pays – user or employer?

Survey results show some interesting variations form continent to continent. If 2011 was the year BYOD took off, 2012 is shaping up to be the year corporate IT starts getting the tools to manage and discriminate professional and personal usage on unmanaged personal devices.

Google started it. When Google launched the Chrome browser some three years ago, one of the key security features was automatic updating. New code releases are downloaded in the background while the browser is running, and applied the next time the user re-starts the browser.

Google argues that this boosts security, compared with the splash screens and user dialogs of other browsers. Faced with the choice of (1) waiting for update code to download, waiting for the update to install, and waiting for the browser to restart, or (2) clicking “Cancel” and continuing to the page they wanted to reach when they launched the browser, many (too many) users choose option 2. The result? Out-of-date browser versions with unpatched security vulnerabilities.

Microsoft has now announced the introduction of silent updating for Internet Explorer, and Mozilla expects to bring out silent updates for Firefox in an as-yet unspecified future release.

Not everybody’s happy. Enterprise IT operations, particularly end-user support teams, will be in the front line when users find themselves unable to access a business-critical application which turns out not to be compatible with the latest version of the user’s favorite browser.

As long as users were primarily sat in front of corporate-issue MS Windows desktops, updates were under the control of the IT department. New browser releases could be tested against business applications for compatibility before being deployed to the desktop. In the age of BYOD, however, support and maintenance of the end-point environment is in the hands of the user; you can’t impose a locked-down corporate configuration on a device owned by the employee.

AirShip, the enterprise browser, has been designed to give control back to the IT department. The AirShip browser can be installed on a range of end-point technologies. It supports concurrent execution of multiple browser configurations, centrally managed and deployed to end user devices. With AirShip, the user connects to enterprise applications using the optimum browser release and configuration as defined by the system administrator. And AirShip can happily coexist with industry-standard browsers, so end-users can enjoy the latest release of their favorite browser for personal use while AirShip delivers a managed environment for professional use.

Launched on the US market mid-November, the Amazon Kindle Fire tablet has yet to cross the Atlantic. With its 7” display, a mere 8GB storage capacity, and WiFi but no 3G connectivity, it’s unlikely to be seen as an adequate alternative for a BYOD iPad in the corporate environment.

What’s got us interested in a device that clearly targets the consumer market (why else launch it just in time for Christmas?) is Silk, the native web browser. To quote from Amazon’s web site:

“Amazon Silk is a revolutionary, cloud-accelerated browser that uses a “split browser” architecture to leverage the computing speed and power of the Amazon Web Services cloud. Supports Adobe® Flash® Player.”

That last sentence is clearly targeted at the iPad; if you’ve been following us you know how to solve that problem. So what about this “revolutionary, cloud-accelerated browser”, then?

On closer inspection, it turns out that Amazon has adopted very much the same approach to browser architecture that we’ve been offering for nearly three years. Silk, like CommonIT’s AirShip product, selectively executes browser components in the cloud, streaming the result to the device. When we originally developed this approach for the Virtual Browser product, the objective was to deliver a highly secure web browser by isolating browser execution from the end point device. We quickly saw that this also offered the opportunity to boost browser performance compared with a natively executed browser, especially on older or less powerful devices such as battery-powered mobiles and tablets.

Amazon has taken the same approach for performance reasons. Amazon, of course, has a cloud ready to use for this. So the cloud-based browser, an approach originally developed by CommonIT, is now going mainstream. It’s nice to have company! But if what you need is a browser for enterprise deployment, offering centralized management, multi-platform support (user and server side), directory integration, multiple concurrent browser configurations… there’s still only one solution.

gPartner positions itself as a new generation of consultant, distributor and integrator for the SaaS market. Based in Paris and Lyon (France), gPartner is one of Google’s leading partners in the French market for the Google Enterprise family of products and services, with the expertise to integrate Google technologies in the core of the enterprise IT environment.

Seeking new ways to accelerate customer migration to online services, gPartner has turned to commonIT. With our Virtual Browser solution, the enterprise retains full control over end-user access to Cloud services through full management of the browser. Whether the need is for access and content filtering for security reasons, support for diverse end-point platforms and application environments, or to deliver transparent connectivity for end-users, Virtual Browser delivers performance and affordability.

The partnership with gPartner reinforces our positioning in the Cloud Services Brokerage market segment, where Virtual Browser facilitates and accelerates enterprise migration to Cloud Computing.

In Gartner’s “Hype Cycle for Cloud Computing 2010″*, analysts David Cearley, Benoit Lheureux and Daryl Plummer present the “Cloud Brokerage”. This market is focused on technologies and services that improve security while reducing cost and complexity in cloud services access and management. This market presents a high potential and proliferates as cloud services consumers seek to simplify and improve their consumption of cloud services across multiple cloud services providers. In its “Hype Cycle” Gartner identifies commonIT as one of the seven sample vendors.

*Gartner, Inc. Hype Cycle for Cloud Computing, 2010, David Mitchell Smith, July 27, 2010.

The Cyberdefense security solution developed and introduced a few months ago by commonIT partner Hermitage Solutions is an outsourced SaaS-style “Security as a Service” offering. Targeting small and medium businesses, Cyberdefense offers a full range of security functions, resolving the increasingly complex technical challenges faced by SMBs with an end-to-end security solution delivering legal and regulatory compliance and even an insurance policy.

Hermitage Solutions has chosen our Virtual Browser technology as part of the Cyberdefense offering. Under an OEM agreement Hermitage and commonIT have integrated Virtual Browser as a component of the SaaS platform. The result for Hermitage is a simple, secure, and cost-effective response to customer needs for mobile and remote access. Cyberdefense users get remote Intranet and Windows desktop access (physical or virtual), using any available machine, easily and securely.

With the Cyberdefense offering Hermitage Solutions positions itself as a Managed Security Services Distributor (or MSSD), with Cyberdefense being offered through Hermitage’s reseller network.

The browser is an integral element in the corporate Cloud strategy. The broad take-up of web technology with standardized languages and protocols has resulted in the browser taking on the role of a universal client for end-user access to web-based and cloud-based resources. Browsers are free, and everyone knows how to use one. Pretty compelling arguments when budgets are tight!

But is using an industry standard browser really a zero-cost proposition for the enterprise? Let’s take a look at some of the issues.

Consumer-driven technology. The browsers we’re all familiar all obey one fundamental design principal: they must be as easy to use as possible for the greatest number of users. They must not hinder the user’s interaction with the web and the sites they want to visit – no matter what content those sites are hosting. In response to the Web 2.0 drive to increased user interactivity with rich internet applications, the browser transparently downloads and executes “helper” applications (Ajax, Flash, Java, ActiveX for example). In other words, the configuration of the browser is unstable and unmanageable. Is this really what you want from a key element of the corporate information infrastructure, the user interface to business critical applications?

Insecure design. Security professionals are increasingly aware that browsers are inherently insecure. The problems are threefold: (i) the browser, like any complex software environment, will always be exposed to bugs and vulnerabilities; (ii) the browser, connected to the internet, is inherently more exposed to external threats than software operating primarily locally on the machine, with local data; (iii) the browser’s self-modifying architecture (via plugins, for example – see above) multiplies the two preceding security risks.

No protection for confidential data. The end user connecting to enterprise Cloud services from home or from a cybercafé using the locally-installed browser is a threat to the enterprise. Business-critical processes and data may be exposed, via the browser, to a PC over which the enterprise has no control. Even if the user is sufficiently security-aware (and technically competent) to clear the browser cache and history at the end of each session – and how many of your users are? – sensitive data may still be stored locally (Flash cookies, to give just one example, without going into spyware and other threats).

If corporate IT management is to take full control of the cloud computing environment, we need to rethink the client-side connection. A new browser architecture is needed, secure by design, protecting corporate IT resources against web-based threats.

For more about the security issues of the browser and the Cloud, take a look at our White Papers.

Yes, Microsoft publishes yet another security alert for Internet Explorer. It allows an attacher access to any file on the system, and all versions of Internet Explorer are vulnerable — though the default configuration in the most recent versions of Windows (Vista, Server 2008, or 7) will block attempts to exploit the vulnerability. This leaves Windows XP deployments at risk; that’s 66% of the market according to NetMarketshare.

Bernard Ourghanlian, Director of Security at Microsoft France, has an interesting (for us) take on the issue. Interviewed by journalists for French web media Clubic, he says “We would love to put Internet Explorer 6.0 behind us, but we simply can’t. For an enterprise, deploying a new navigator is a huge job. As long as Microsoft offers support for Windows XP (up to 2014), Internet Explorer 6.0 will also be supported.”

Putting to one side (for the moment) the fact that this new vulnerability is one more proof point for the session isolation we’ve developped with Virtual Browser, Ourghanlian’s words highlight a further problem with the management of desktop navigators as part of the enterprise infrastructure: deployment, updates, patching… all these tasks represent significant management and support overheads for the enterprise. The centralized architecture of Virtual Browser makes updates, whether to the browser or its plugins, trivial, and means that every user sees the updated browser, instantly.

There’s nothing new under the sun, they say; they could have been talking about browser security issues. There’s clearly a need for a revolution in the browser architecture — run-time environment, deployment, and support tools. That’s what we’re working on and where we’re going with Virtual Browser.

The latest release of Virtual Browser introduces several new features (like every new release — with thanks to Mathieu’s team!). One of these new features in particular adds a whole new dimension to the Virtual Browser solution. Virtual Browser now supports delivery of ICA and RDP remote desktop clients, alongside our already familiar browser support (IE, Firefox, Java, Flash, etc). With this release the end-user now has access not just to web-based applications but to any application which can be virtualised, as well as full-featured virtual desktops.

It’s worth taking a few minutes to understand where we’re going with this. Release 1.3 offers a single, secure, platform-independent client delivering installation-free end-user access to any web-based or virtualised application without the need to worry about (i) the configuration of the end-point device; (ii) the compatibility of end-point browser configuration and the target application/server; or (iii) the appropriate network configuration (VPN, etc) to access the remote application. The objective is to position the Virtual Browser solution as the universal client for access to cloud-based services.

The “Cloud” and “Cloud Computing” are still relatively new terms and there are varying definitions of what they comprise. For us, they cover the full set of web-enabled or virtualised applications, hosted in the enterprise (the private cloud) or by third-party service providers (SaaS). What we’re seeing today is enterprises migrating step-by-step to cloud computing models, with the infrastructure becoming decentralised — some of it moving to virtual environments (Citrix and others), some of it onto the Intranet, and some moving to the Internet, taking advantage of Cloud offerings vendors like Google, Salesforce.com and other SaaS providers.

In positioning Virtual Browser as the universal client for cloud access, we’re facilitating enterprise migration to cloud computing by resolving three key management issues:

  1. Security: encrypted traffic between the VB client and server, strong authentication, and support for multiple isolated user environments: Internet, Enterprise (internal) applications, on-line (cloud, SaaS) services, on both enterprise (managed) end-points and non-managed end-point devices.
  2. Single point of management and maintenance — configuration, updates, patching — of the client environment, on a centralised server environment, clustered for redundancy and scalability.
  3. Platform independence and compatibility: No matter what type of device the end-user is using or where they connect from, the application sees the same browser, eliminating compatibility issues and facilitating application development and support.

The SANS Institute, internationally recognized for its leadership in information security training and certification, has just published a threat report under the title “The Top Cyber Security Risks“. It comes as no surprise to us at commonIT that the report clearly identifies web usage as the key vector for attacks, whether at the client side or on the server.

The report leads by identifying two priorities that need addressing: unpatched client-side software, and vulnerabilities in Internet-facing web sites. Based on data collected between March and August of this year, the authors show that application vulnerabilities now far exceed those being discovered in the operating system, commenting that “browsers and client-side applications that can be invoked by browsers seem to be consistently targeted”.

A well-developed tutorial included in the report describes one specific way in which the enterprise can expose itself to web-based penetration. But the report is full of interesting data, and merits the time to read it for any information security professional.

And so to Virtual Browser. If we find the report particularly interesting and relevant, it’s not just for the quality of the data. It’s also because our Virtual Browser technology successfully addresses and mitigates the situations described, something no other technology on the market today is capable of. By putting the browser in a datacenter-hosted virtual machine and isolating browsing sessions from each other, the enterprise is fully protected whether the client side or server side is compromised. Virtual Browser — the enterprise browser solution, Secure by Design.

« Older entries