NEC upgrades to HYDRAstor grid storage system

NEC Corp. today unveiled several upgrades to its flagship HYDRAstor grid-storage system , adding write-once, read many (WORM) capabilities and the ability to encrypt data in transit. NEC officials said that the upgraded software will increase performance by 67%, while boosting security by improving HYDRAstor's ability to archive mission-critical data. "Over 70% of even high I/O data from source applications such as databases have not been touched after 6 months. The upgraded system also provides deduplication capabilities for more third party backup applications. A lot can be off loaded onto more efficient platforms," said Gideon Senderov, director of product management for NEC's IT Products Group.

The new RepliGrid in-flight data encryption capability protects data as it's being transmitted between HYDRAstor grids and data centers, he added. The new HYDRAlock WORM capability allows administrators to lock out any changes to documents or other records, maintaining a chain of custody for regulatory purposes, Senderov said. NEC also announced that it will allow users to license additional physical capacity that can be activated without adding additional components. A new quota management system allows administrators to set limits to the maximum effective capacity allocated for each file system and its associated application. For example, can now license as little as 12TB of capacity in a 24TB configuration and then pay a fee to activate additional capacity as needed.

The quota management system also offers threshold notifications as well as the ability to set aside a capacity reserve for other applications, such as critical archive data. The upgraded system can deliver up to 1.8TB per hour per accelerator node and up to 90TB per hour for the largest supported configuration of 55 accelerator nodes and 110 storage nodes, according to the company. Previously, the HYDRAstors grid architecture had a default capacity of 256 petabytes for all applications. "We are really looking forward to taking advantage of the new in-flight encryption and quota management functions," said Scott Ashton, a LAN/WAN specialist at TLC Engineering for Architecture Inc., an Orlando, Fla.-based engineering firm. "We've really seen the return on our initial investment as we've been able to take advantage of each new upgrade with HYDRAstor since our early adopter installation in 2007." NEC said that the performance boost comes from software enhancements and more efficient inter-node data transfer and communication protocols. Accelerator nodes are the controller blades with the CPU processing power and storage nodes are the system blades with disk storage capacity. NEC today also introduced lower-capacity, or "entry-level" models of HYDRAstor offering raw storage capacities of 12TB (or over 150 TB effective capacity); 24TB (or over 300 TB effective capacity) and 36 TB (or over 450 TB effective capacity). "A highly resilient storage solution primed for archiving, that self-evolves with the ability to intermix several generations of technology, offers global deduplication, great scalability, and automates provisioning, migration, workload balancing and system management will be the key features of a storage solution that the market will demand," said Dave Russell, a vice president at researcher Gartner Inc.

The new application-aware deduplication feature allows newly-supported third-party backup applications such as IBM's Tivoli Storage Manager and EMC's NetWorker, as well as previously previously supported Simpana from CommVault and NetBackup from Symantec, to take advantage of the data reducing feature. With the exception of WORM capability, the customers can install the latest HYDRAstor upgrades for free. The WORM upgrade costs $14,000 per accelerator node.

CA to buy NetQoS for $200 million

CA Monday announced plans to acquire NetQoS for $200 million, adding application-aware network and systems management products to the software maker's broad enterprise IT management portfolio. The added technology will also boost CA's efforts to manage advanced infrastructures that feature virtual systems and cloud computing environments, the vendor says. "NetQoS technology complements CA's Wily products and will help network and systems engineers better design their infrastructure to ensure application issues don't occur from the start," says Roger Pilc, senior vice president and general manager of CA's infrastructure and automation business unit. "The technologies will help network and systems management be more application aware." The deal, anticipated to close in CA's fiscal third quarter, would augment an already full software lineup grown via previous acquisitions of Wily Technology, Concord Communications and Aprisma. Hottest tech M&A deals of 2009 CA executives say the pending acquisition offers little overlap by way of products and will help CA products diagnose the root cause of application errors within the network and systems infrastructure.

CA executives say NetQoS products, designed for network managers responsible in part for application delivery, will add to the company's Wily products that detect performance problems in the application environment. Customers can visualize the links and relationships between the delivery technologies and the business applications and services with Wily, and understand the real-time application and service activity across those links and relationships with NetQoS traffic flows," says Jasmine Noel, co-founder and principal analyst at Ptak, Noel & Associates. NetQoS tools are able to detect application performance problems using network-centric measures such as traffic flow. "The acquisition is good because NetQoS has a focus on application delivery, so when combined with Wily, it offers a good one-two punch. With some areas of overlap in the former Concord eHealth and Aprisma Spectrum tools, CA's Pilc say the company will work to address issues after the deal closes. NetQoS technology will target network engineers who focus on application delivery where the management of traffic flows is the primary task, rather than the management of thousands of network devices." CA also expects the NetQoS technology to play a bigger role in its virtual and cloud management offerings.

Noel says customers should not expect NetQoS tools to get lost in the shuffle as CA could have targeted plans for each product suite. "In terms of portfolio, CA now has two network performance management solutions, eHealth and NetQoS. But I think CA has specific targets for both solutions," she says. "CA's eHealth technology will target network engineers who spend most of their time managing performance of specialized network infrastructure. With its ability to track flows across virtual and physical elements, NetQoS tools could be coupled with Cassatt assets CA acquired earlier this year, the company says. NetQoS co-founder and CEO Joel Trammel says CA represented the best fit with his company's technology, and customers shouldn't expect any change in products or support as the deal unfolds. With no previous partnerships, the two vendors share some 200 customers and CA's Pilc foresees "very little modification in the NetQoS product set and its approach to customers going forward." That is why NetQoS executives found the deal to be synergistic. NetQoS has more than 1,000 customers worldwide and reported revenue of $56 million in 2008. "We sought out CA because we saw a clear fit with us and the company's success in acquiring Wily, Concord and Aprisma. Industry watchers expect the deal could benefit both parties going forward if CA sales teams focus on the NetQoS suite. "For a small vendor, being acquired could be good because a larger sales force means a bigger pipeline.

We were excited and see the clear fit between tying these acquisitions together," Trammel says. Or it could be bad if it gets lost in the portfolio. Do you Tweet? In the Swainson era, CA has handled its acquisitions fairly well, and with Wily as a tag-team partner I don't see NetQoS getting lost," Noel says. Follow Denise Dubie on Twitter here.  

Skype Founders Sue eBay: What's Going On?

The founders of Skype are suing eBay for copyright infringement, a move that could block eBay's deal to sell a majority stake in Skype to a group of private investors for $1.9 billion. The sale was seen as a big failure because the company was not able to further monetize the potential of the VoIP service in the years to come. eBay purchased Skype back in 2005 for $2.6 billion, but failed to acquire Joltid, the company supplying the core technology behind Skype, also owned by the founders of the VoIP software.

So eBay sold a 65 percent stake in Skype two weeks ago to an investment group for $1.9 billion, managing to get back some of the money it invested initially. At the core of the suit is a peer-to-peer technology called "global index", which is used by Skype's software to route calls over the Internet instead of traditional phones lines. But it's not all good for Skype, as Skype's original founders are now suing eBay, seeking damages for copyright infringement. This technology is owned by Joltid, which is still owned by the founders of Skype. Now moving to the U.S. courts, Joltid is seeking an injunction against Skype, which could affect Skype's operation.

As if it wasn't complicated enough, eBay licensed "global index" from Joltid for continued use in Skype, but Joltid terminated the license in March and have been battling eBay in U.K. courts ever since. The trial could jeopardise the closing of the Skype sale to the private investors, who are also named as defendants by Joltid. What's even more ironic is that that the money Joltid is using to sue eBay is probably the money they got from eBay when they sold Skype. While eBay is working on its own technology to replace Joltid's, Skype could be forced to close down its operation if Joltid wins the trial.

China's Alibaba expects India joint venture this year

Top Chinese e-commerce site Alibaba.com aims to announce an Indian joint venture this year as the company expands its global footprint, it said Friday. A deal in India, where Alibaba.com recently surpassed 1 million registered members, would be the latest in the site's efforts to grow abroad. "I've got a lot of confidence in India," said Jack Ma, CEO of Alibaba Group, the parent company of Alibaba.com. Alibaba.com is in talks with an Indian reseller about forming a joint venture, CEO David Wei told reporters at a briefing.

Alibaba.com is a platform for small and medium businesses to trade everything from lumber and clothes to iPods and PC components. Alibaba.com already works with Indian publishing company Infomedia 18, its likely joint venture partner, to promote its platform in the country. Its main member base is in China, but the site also has 9.5 million registered users in other countries and facilitates many cross-border trades. The site also has a joint venture in Japan and recently launched a major U.S. advertising campaign to attract more users there. Ma said Alibaba knows it needs to "do something" in Latin America as well. Ma and other top Alibaba executives visited the U.S. early this year for meetings with potential partners including Amazon.com, eBay and Google.

When asked if the company would also seek to expand in Eastern Europe, Ma said, "I will be there." Alibaba will not hold a majority stake in joint ventures it forms, instead taking a share similar to the 35 percent it has in its Japan operation. "Our global strategy means partner with local people," Ma said. "We want partners and we want partners to control their business." Users place total orders of more than US$200 million each day on the Alibaba.com international platform, Wei said. About 50 percent of those orders go to Chinese exporters, he said.

Half of new servers are virtualized, survey finds

More than half of new servers installed in 2009 will be virtualized, and that number will hit 80% by 2012, signaling huge growth in the hypervisor market, according to a report released at VMworld by TheInfoPro, a research company.

Slideshow: VMworld product roundup 

The benefits of virtualization and growing maturity of hypervisors is certainly contributing to increasing use. But the economic downturn is also forcing IT to cut back on hardware spending, and many are turning to virtualization to wring more power out of previous server investments.

In 2008, about 30% of new servers were virtualized, says Bob Gill, managing director of search research at TheInfoPro. The data includes all types of servers, although the trend toward virtualization is largely being driven by the x86 market.

"It seems to many people that the party is over, that everyone is virtualizing," Gill says. "But the simple fact is it's just starting to kick in."

The data is based on interviews with IT pros at 195 enterprises in North America and Europe, mainly Fortune 1000-size companies. About 10% of respondents report having more than 1,000 virtual machine instances, and about half have deployed at least 100 virtual machines.

VMware is still dominating the x86 virtualization market, according to IDC. In the first quarter of 2009, 50% of new virtualization licenses deployed on x86 servers were from VMware, and 24% were from Microsoft, according to IDC's Worldwide Server Virtualization Tracker.

The opportunity for Microsoft and others to take significant market share away from VMware may not come until next year, Gill says. That's because VMware's strategy has been to sell large blocks of virtualization licenses to customers, and many customers will have to work their way through excess VMware licenses before they consider switching, he says.

62% of respondents have tested a hypervisor other than VMware's and 30% said they plan to put a non-VMware hypervisor to use.

But that's not to say IT shops are dissatisfied with VMware. Only about one in ten respondents said they are considering switching away from VMware, and nearly every VMware customer expects that the company will still be on its technology roadmap in three years, the survey found. The reality is, many IT shops are choosing to use multiple hypervisors. Nearly one-third of respondents said they will support a mixed set of technologies for x86 virtualization.

"We're going to see a very messy, heterogeneous hypervisor world," Gill says.

Questions about performance and manageability are the greatest impediments to virtualization, but these concerns are not likely to stop the upward momentum.

Customers may choose to avoid virtualizing some transactional-heavy applications like databases, but "nobody ever said 100% of all servers will be virtualized," Gill said.

Korean 'journalists' booted from Defcon

Four South Korean journalists were booted from the Defcon hacking conference this week after conference organizers decided their story didn't quite add up.

Conference representatives released few details of the incident. They said Sunday that they'd ejected the journalists two days earlier after deciding that they simply weren't acting like press. They believe that one member of the group was a legitimate journalist, but that the other three were on some sort of intelligence-gathering expedition.

Hackers who the group interviewed at the show said that their questions seemed inappropriate, organizers said. The journalists attended one day of Defcon's Black Hat sister conference before being ejected on Friday.

Defcon did not release the names of the journalists or say who they claimed to work for.

This kind of incident happens nearly every year, said one of the show's senior organizers who goes by the name "Priest."

In the past, they say they've caught members of Mossad, the French Foreign Legion, and other organizations posing as press. By registering as journalists, they can get more time to query researchers and raise no suspicions by asking probing questions.

"When you think about it, being a member of the press is a pretty good cover because you can ask difficult questions, people love to see their names in print and in lights, so they're much more likely to talk to you, so you can get away with a lot more," Priest said.

The French Legionnaires were easy to spot, he said. "There's a certain body type you find with people who are in that type of work," he said. "Broad shoulders, narrow waist, not very tall. I'm looking at these guys, going, 'You're in far, far too good shape to be press.'"

The Legionnaires eventually admitted that they were not press and were allowed to stay at the show as regular attendees. They even went on stage for Defcon's annual "spot the fed" contest where people are invited to pick out government employees from a group of attendees.

Government employees posing as press often move very quickly to technical questions, rarely showing any interest in the motivation behind the research. They get "very technical very quickly," Priest said. "They're much more interested in what the latest is and what the greatest is and how they can use it."

Often they also ask about U.S. government systems or seem to be gathering intelligence on the presenters, he added.

And often attendees are happy to provide the information, thinking that it may be used in an article, particularly young, inexperienced hackers, Priest said. "You've got usually a very introverted individual, who usually doesn't have a lot of friends, and if you have someone paying attention to you... you're flattered; you're ego's being stroked; you're much more likely to try to impress that person."

Microsoft patches 9 bugs, leaves one open for hackers

Microsoft today delivered six security updates that patch nine vulnerabilities, fixing two bugs already being used by hackers but leaving one still open to exploit.

Of the six bulletins, three patched some part of Windows, while the remainder plugged holes in Publisher, Internet Security and Acceleration Server (ISA) and Microsoft's virtualization software. Six of the nine bugs were ranked critical, Microsoft's highest ranking in its four-step score, while three were tagged as "important," the next-lowest label.

"We got what we expected," said Andrew Storms, director of security operations at nCircle Network Security. "We got the 'kill bit' we were looking for in the ActiveX control and the DirectShow fix," he said, referring to two recent vulnerabilities that attackers have been exploiting for weeks.

In May, Microsoft acknowledged that hackers had begun exploiting a bug in DirectShow, one of the components in Windows' DirectX graphics platform. Last week, it owned up to another bug, this one in a video streaming ActiveX control used by Internet Explorer (IE) - and admitted it had known about, but not fixed, the flaw for the past 18 months.

Microsoft patched the already-public DirectShow flaw with MS09-028, and for good measure tucked in fixes for two more vulnerabilities also reported by researchers.

The "kill-bit" update in MS09-032 didn't actually patch the underlying ActiveX problem. Instead, Microsoft simply disabled the control, effectively shutting off any possible attack by modifying the Windows registry using the update. Microsoft offered the same protective measure via an automated tool last week, but that required users to manually browse to a support document, then download, install and run the tool.

Researchers unanimously voted those two updates as the ones to deploy immediately. "Microsoft did well to get out the two zero-days," said Eric Schultze, chief technical officer at Shavlik Technologies, "especially the ActiveX. It was a little much to ask them to get out the Office ActiveX fix, though."

Schultze was talking about a bug in an ActiveX control used by Office Web Components to display Excel spreadsheets in IE. Microsoft warned users of the vulnerability only yesterday. By today, Web attacks had rapidly increased. On Monday, however, Microsoft said that it wouldn't wrap up a fix in time for today's release.

Like the DirectShow ActiveX flaw that was patched today, Microsoft has released a "Fix It" tool that users can download and run themselves to kill the control. But, according to Schultze, Microsoft's not planning to push a kill-bit update to users for this second flaw. "Setting the kill bits actually impedes functionality," Schultze said. "Microsoft told me today that they're working on a file-level fix."

Other researchers speculated that Microsoft might depart from its usual once-per-month patch schedule to get such a fix out before Aug. 11, the next regularly-scheduled update. "Obviously, that would be much better," agreed Wolfgang Kandek, chief technology officer at security company Qualys.

The third critical update, MS09-029, also caught the eyes of Schultze and Kandek. Two vulnerabilities in Embedded OpenType (EOT) Engine leave all versions of Windows, including Vista and Server 2008, open to attack.

"It looks pretty easy to exploit," said Kandek. "If you view some text on a Web site in that font, you're compromised. And if the attack comes in an e-mail, there's no need to open an attachment, you can be compromised just by viewing the e-mail."

Schultze agreed. Calling the font vulnerabilities "nasty," he said that they could quickly be used up by hackers. "If there's exploit code available, which there isn't yet, these would be pretty easy to exploit," Schultze said.

Microsoft also delivered patches today for bugs in Publisher 2007, ISA 2006 and the client and server editions of its virtualization software. The ISA bug, described in MS09-031 intrigued both Kandek and Schultze, but not for the same reasons.

"You can gain full control of the server if you know the administrator password," said Kandek. "And in some situations, that password may be 'administrator' or 'admin' or even 'root'."

Shops with weak usernames may be at risk of information theft, added Amol Sarwate, the manager of Qualys' vulnerability research lab. "[Attackers] could install small malware and maybe sniff the Web traffic [through the server], access other systems on the same network or even redirect users to another Web site," Sarwate speculated.

Schultze dismissed those worries. "It looks like all the planets have to [be] aligned just right," he said, referring to the narrow scenario Microsoft spelled out. "I'd call that a real edge case."

The remaining two updates patched Publisher 2007 ( MS09-030) and Virtual PC and Virtual Server ( MS09-033). Neither drew much attention from Schultze, Kandek or Sarwate.

Storms, however, put a finger on the Publisher patch. "MS09-029 and MS09-030 are bucking the trend," said Storms, talking about the Publisher and OpenType bulletins. "Typically, Microsoft's newer software is more secure, but that's not the case here.

"The fact that we got them both in the same month is probably just a coincidence," Storms continued. "But it doesn't surprise me that researchers are looking at the newer software, because it's the newer software that's being deployed."

Schultze and Kandek noted that the OpenType vulnerabilities' appearance in all versions of Windows, up to and including the unfinished Windows 7, likely means Microsoft had overlooked the flaw for years. "It tells me that that particular component has received less attention," Kandek said, "and that Microsoft didn't change anything in the code from when it was first used in [Windows] 2000.

And the virtualization software bugs? Nothing much to worry about, said Schultze, since there's no chance that an attacker could escape the "guest" operating system to wreak havoc on the "host."

"But I think it's a sign of things to come," argued Kandek. "Virtualization adds to the attack surface rather than subtract."

July's updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.