Optical Fibre networks
Hacking optical networks happens more than organisations want to admit

How secure is an optical-fibre network?

What should IT leaders consider when looking at optical network security?

Written by Dave Bailey

Many countries are looking to roll out optical-fibre connectivity to support next-generation broadband access, giving download speeds of 100Mbit/s with low latency and greater upload capacity than is associated with conventional asymmetric digital subscriber line (ADSL) technology.

Carriers, ISPs and large corporations, especially financial services firms, use a large amount of optical-fibre connections and the security of those connections needs to be locked down.

Such concerns are addressed in a recent report on optical network security by IDC research analyst Romain Fouchereau. Entitled: Fibre Optic Networks: Is Safety Just an Optical Illusion?, the report discusses what firms need to consider when thinking about how to secure fibre-based networks.

The report references several examples of optical network hacking - perhaps the most serious commercial example was when US security forces found a device illegally installed on carrier Verizon's optical network. The placement appears to have been designed to eavesdrop on a mutual fund company, shortly before it released its quarterly financial figures.

"Remember this happens more than organisations want to admit, and there's a lot of hacking that goes unnoticed," said Fouchereau.

Firms spend huge amounts of money to protect their networks.

"It's a pity if all this money is going down the drain because they're not protecting the fibre part of the network transmitting all the data," said Fouchereau.

The report details the three main methods used for siphoning off data from optical fibre connections.

The first technique, and the crudest, involves physically cutting the cable and splicing a device into the fibre that can be used to pick up the data, and transmit or re-route it somewhere else.

"This is the oldest and most traditional way of collecting data from fibre networks," said Fouchereau, explaining that there was a possibility of alert IT administrators seeing that something was happening and taking remedial action.

The other two methods involve devices for collecting light emitted by optical fibres, allowing hackers to reconstruct the data. Bending the fibre and picking up stray light emission is one possibility. The other is more elaborate, said Fouchereau, and involves putting a photosensor around the cable and measuring scattered light, to rebuild the data.

Fouchereau advises IT leaders to take fibre network security very seriously.

"It's like you put an alarm in your house and then leave the back door open. It doesn't make much sense to protect one side of the network without protecting the rest," said Fouchereau.

To lock down optical networks and reduce the risk of data theft, Fouchereau points to a handful of security vendors who have products for end-to-end data encryption. These appliances can encrypt using key sizes of 128- or 256-bits using Advanced Encryption Standard (AES) with maximum data transmission rates.

But Rob Bamforth, Quocirca principal analyst for communications, said that while taking data from optical-fibre data transmission was more than just a theoretical possibility, there are still challenges for would-be hackers.

"How accessible is the fibre?" he said.

"Many companies, especially carriers, put systems in difficult to reach places, for example buried alongside gas mains."

Another problem for hackers, said Bamforth, was that optical fibre can be enabled with different types of equipment. "This can vary quite significantly, so some knowledge of the specific systems used would be required," he said.

Bamforth pointed out that even hackers would look at return on investment for their activity.

"If the effort is too great for the value returned, they'll move on to a more vulnerable target," he said.

"But it might be wise to iron out simpler-to-attack vulnerabilities elsewhere first".

Bamforth said that firms should wrap full encryption and authentication around the things they really want to protect.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Virgin Media logoCommunications

Virgin Media challenges BT on superfast broadband uplink speeds

The network bandwidth "arms race" between BT and Virgin Media moves on to upstream speeds 15 Jul 2009

 

BT targets more than £1bn cost savings

Company chairman acknowledges "unacceptable" performance of Global Services division 15 Jul 2009

69 more towns to receive superfast fibre broadband

BT announces next round of high-speed service rollout 09 Jul 2009

BT fibre trials herald an era of innovation

A new era in communications began on Monday as BT went live with the first two operational trials deploying superfast fibre-optic broadband connectivity 09 Jul 2009

BT doubles fibre-to-the-premises rollout

2.5 million homes and businesses to get direct fibre connections 09 Oct 2009

BT's fibre-optic broadband rollout starts today

Openreach fibre product being trialled by ISPs in Muswell Hill, North London, and Whitchurch near Cardiff 06 Jul 2009

Top 10 most notable Black Hat/Defcon stories

Security woes from Las Vegas 05 Aug 2009

related whitepapers

today's top stories

Face facts: social media is the future

No organisation can afford to ignore the way business communications are changing 18 Mar 2010

Is the data watchdog about to pounce?

Experts believe the Information Commissioner’s Office is itching to use its new power to impose hefty fines for data breaches. Martin Courtney reports 18 Mar 2010

Lloyd’s of London gears up for regulation

CIO Peter Hambling tells Angelica Mari about how the insurance market has updated its IT infrastructure to comply with new regulations 18 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Smiths Group CIO Brian JonesAnalysis

Q&A: Brian Jones, CIO, Smiths Group

How should conglomerates be looking at the new IT technologies coming through? Brian Jones explains. 19 Mar 2010

Analysis

What security strategy should enterprises adopt after the recession?

Act now to put your your firm on higher growth path advise CISOs 19 Mar 2010

Primary Navigation