A switch to security

 

Connecting state and local government leaders

The Avocent SwitchView SC540 is a secure keyboard-video-mouse switch that locks out rogue USB devices but will work with Common Access Card readers.

The government tries hard to maintain security — which, if you think about it, is an almost impossible task. When you have a huge organization with millions of employees who range from mail carriers and astronauts to scientists and soldiers, you will have a few security holes. To compensate, the government assigns access based on employees’ security classifications, so a top CIA agent can see more information than a data-entry clerk at the Social Security Administration.

GCN LAB SCORECARD

SwitchView SC540

Pros: Complies with HSPD-12; denies access to USB devices other than CAC readers and input devices.
Cons: Expensive dual Digital Visual Interface connections that most users probably don’t need.

Performance: A
Ease of use: B+
Features: A
Value: B
Government price: $908

GCN Lab home page

At least, that’s how it’s supposed to work. The problem with security is that it sometimes runs counter to efficiency. For example, if you force everyone who needs to access a building to go through several security checkpoints, even your valid users will be late to work from time to time. Such bottlenecks also occur with network security.

Consider what can happen when several networks meet at the same desktop. One of the most efficient setups for users with multiple computers is to run them all through a keyboard-video-mouse (KVM) switch, so all the devices can share one monitor and keyboard. Otherwise, those standard-size government desks will get crowded fast with several monitors and input devices for each computer.

The problem with KVM switches in terms of security is that they bring together several systems at one point. If some of those computers are connected to a secure network such as the Defense Department’s Secret IP Router Network and others are connected to the Sensitive but Unclassified IP Router Network, you have a potential problem. And even if all the computers are connected to the same network, the KVM could still act as a means of access for malicious users.

Avocent’s SwitchView SC540 can solve the security problems associated with connecting computers via a KVM switch. When we unpacked the test unit for the lab, it looked similar to many other nonsecure KVM devices we have tested in the past, save for some green security tape at the top and sides of the unit. The message on the tape warns users that if the switch is opened, it will stop working. In addition, the LEDs on the front of the unit will flash if the box has been tampered with.

Of course, we wanted to open it right up to test this feature but decided to go green and avoid creating unnecessary waste.

The self-destruct mechanism is a somewhat over-the-top security program to prevent James Bond-style tampering or bugging of the device. But the switch also incorporates more mundane security methods that are more likely to prevent a breach.

One security feature revolves around the way the SwitchView SC540 handles its four USB ports. Given that most PCs have dropped PS/2 ports in favor of USB, it makes sense that a device designed to link computers to a single monitor and keyboard would allow USB access.

But in some switches, that approach created a problem: A USB key drive inserted into the switch could pass credentials to connected computers. If the operating system viewed the removable device as an authorized part of the KVM switch, it could circumvent the computer’s or network’s security policy. Essentially, it let the KVM act like a USB hub, thereby overriding agency policies that only allowed the use of approved USB devices or none at all. Most home users probably welcomed the extra USB ports, but it meant that government adoption was problematic at best.

In contrast, the SwitchView SC540 does nothing when you insert a camera cable, key drive or other storage device into one of the USB ports. It doesn’t pass any information to connected computers. It only allows keyboards and mice to connect, and they worked fine in our testing.

However, one type of USB device does work with the SwitchView SC540: Common Access Card readers. That exception was added to help agencies comply with Homeland Security Presidential Directive 12, which requires a system of common access for government networks. When you plug a reader into the USB port, you can use a CAC with connected computers. We had several CAC readers in the lab, and all of them worked fine with the SC540 on all connected PCs.

The switch has a couple of other features that help agencies comply with security demands. For example, all keyboard data buffers are cleared after commands are sent. That way, you could put computers linked to secure and nonsecure networks on the same switch, and no data from the keyboard could be accidentally or purposely passed between them. And of course, the computers on the network attached to the SC540 don’t actually touch other than through the keyboard and mouse, so no data can be transferred between them.

The SC540 model is a bit expensive, with a government price of $908. There are less expensive four-port switches out there, though most don’t have the robust security of the SC540. One reason for the high price is the switch’s support for dual Digital Visual Interface inputs for each of the four computers that can be connected. So you have eight DVI ports, though only four selectable inputs. The feature is designed to accommodate users who have multiple monitors for each PC on their desktops, but that’s a small percentage of the government population.

There are other models in the SwitchView line that offer more traditional inputs while retaining the security features we tested. Most users will probably want to choose one of them. However, if you use multiple monitors, the SC540 is the perfect choice.

Avocent, 866-277-1924, www.avocent.com

NEXT STORY: How NIST put DNSsec into play

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.