ZDNet:  Reviews | Downloads | Tech Update | Prices
Page OneApplicationsNetworkingeBusinessHardwareCommentary



Hardware


Security driven two-headed hard drive
ZDNet (UK)
July 24, 2002, 7:08 AM PT


TalkBack!


A Japanese start-up has come up with a mutant piece of hardware that it says may deliver "perfect security" for Web servers: a two-headed hard disk drive.

Tokyo-based Scarabs has developed a prototype of the hard drive, which has a read-only head and a read-write head. The Web server can only read from the drive, theoretically making it impossible for attackers to deface the site or otherwise modify data.

For updating the site, an internal PC can be connected to the drive via the read-write head. "Each head works independently, so no synchronous control between two heads is needed," the company stated on its Web site.

Scarabs hopes to have a version of the device on the market this year.

The drive is an unusual response to the growing problem of online security, particularly with large businesses, whose Web servers are subject to a constant bombardment of attacks, according to security experts. UK systems integrator Mi2g recently said it had monitored more than 9,000 successful attacks on Microsoft Internet Information Server-based systems alone for the first half of this year.

Companies that rely on the integrity of their Web offerings, such as media companies, might find the hard drive particularly attractive. USA Today, for example, recently called in the police after discovering that vandals had posted several fake news stories on its Web front page.

Scarabs argues that its technology could help stem the problem, comparing the hard drive to one-way diodes in an electronic circuit. "The Internet should have one-way component like diodes, and the two-heads hard disk drive can be (that) one-way component," the company said.

The drive would be particularly suitable for public key servers and government information distribution sites, Scarabs says. A system with two of the drives could act as a super-secure proxy server, the company suggested.

The idea has been suggested before, as a way of speeding data retrieval, since the write-only head would not have to wait for the read-write head to finish its tasks, but has never been made a practical reality. Naoto Takano, chief executive of Scarabs, has said that he first came up with the idea of applying the concept to security three or four years ago.

At the end of last year, Scarabs built a prototype running with an NT server and has been using it to serve Webcam images since then. The drive currently costs more than $860 to manufacture, but Scarabs is working on a lower-cost implementation that would use a single head and two SCSI interfaces. Scarabs says it has approached several vendors and hopes to begin shipping the lower-cost drives this year. Industry experts say the technology looks interesting, but also has serious shortcomings.

"From a purely theoretical perspective, it's a good way to keep hackers from changing something on the site," said Alain Dang Van Mien, a research director with Gartner. "It could also protect from certain types of attack, but it would not keep hackers from getting information. From an integrity perspective it works, but from a confidentiality perspective, it's not enough."

The hard-drive solution would not protect against denial-of-service attacks, which simply aim to take a Web server offline, and do not require access to the hard drive.

In addition, Gartner's research has found that attacks on big businesses are increasingly coming from insiders, rather than random attackers on the Internet.

"They are coming from employees, contractors, people who know about the company," Dang Van Mien said. "These are not just teenagers who can get through your firewall."

E-mail this story! Printer Friendly

Also on ZDNet
Maximize Windows XP with this guide from TechRepublic.
Solve your computer problems with live tech help at ZDNet.
Beware the Deskstar: Check out IBM's new 120GB hard drive.
Compare specs on our editors' top five favorite cell phones.
Find a new job today in ZDNet's Career Center.


 TalkBack: Post your comment here
       And the applications for this device are...?  Robert Carnegie

       Re: And the applications for this device are...?  Jesse Ezell

       How about a harddrive with enforceable partitions?  Joseph Lindenberg

       Re: Security driven two-headed hard drive  Minh Truong

       Re: Security driven two-headed hard drive  Brian Goff

       The worst problems are read only...  Robert Crocker

       Re: The worst problems are read only...  Why Why

       Re: The worst problems are read only...  Chris Maxwell

       Non issue.  Martin Marvinski

       Re: Non issue.  Todd Thorner

       Re: Non issue.  Chris Maxwell

       Re: Non issue.  stephen mubita



 Search


 
 Tech Update

Sun's server road map

User guidelines for storage resource management

Itanium 2 versus Hammer--speed semantics

More hardware analysis...

 News in Brief

Near-naked Branson unveils cellphone  05:05PM

New drive combines CD burner, DVD player  04:15PM

Nortel to wire Club Med  02:43PM

Linux companies sign Brazil sales deal  01:10PM

German PC retailer calls it quits  12:06PM

More...

 Commentary

BERLIND BERLIND
Where TabletPC will succeed More...

CARROLL CARROLL
Who's afraid of digital rights management? More...

More Commentary...


ZDNet Tech Update
Featured Resource Centers

 News Tools

 News Archives

 News in Brief

 News for your PDA

 Contact Us

 Corrections
Newsletters
ZDNet News E-mail Alert
Security Update
OS Update




All newsletters
FAQ
Manage my newsletters


ZDNet
Services: IT Jobs | Wireless ISP Info | BizTech Library | 2GHz Notebooks | Bluetooth | Clearance Sale

      CNET Networks: Builder | CNET | GameSpot | mySimon | TechRepublic | ZDNet
About CNET Networks 

About Us | Feedback | Your Privacy | Service Terms | Advertise | ZDNet Jobs
 
Copyright © 2002 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc.