Remote Support:
WebEx™ Communications, Inc. provides real-time collaboration services to a large and growing number of corporations. These corporations use WebEx applications for diverse purposes ranging from sales, marketing, training, project management and support.
WebEx customers span a variety of market sectors including technology, finance, manufacturing and healthcare. WebEx assigns data security the highest priority in the design, deployment and maintenance of its network, platform and applications, and its offerings meet the most stringent security requirements of corporations so they can use WebEx services effectively and routinely, secure in the knowledge that their sessions are safe and private.
The purpose of this document is to provide information on the data security features and functions available with WebEx Support Center Remote Support and inherent to the underlying WebEx communication infrastructure known as the WebEx MediaTone™ Network. This document will explain the following:
- MediaTone security
- The Secure WebEx Meeting Experience
- - Starting and joining a Support Session
- - In Support Session
- - Transport layer security
- - Firewall compatibility
- - Post Support Session
- 3rd party certification
You should be aware of the key roles available within Remote Support application, such as CSR and Customer/Attendee: - A CSR starts WebEx Support sessions. The CSR also controls the in-session experience and can trigger different features within Remote Support, such as desktop or application sharing, file transfer, and reboot.
- A Customer/Attendee has minimal responsibilities and typically grants only permissions for CSR actions.
The Underlying Infrastructure
The WebEx MediaTone Network
The WebEx MediaTone Network is a communications infrastructure purpose-built for real-time Web communications. It consists of a series of data centers located around the world, strategically placed near major Internet access points. WebEx routes traffic between the WebEx data centers using dedicated, high-bandwidth fiber.
Switched Architecture
WebEx uniquely deploys a globally distributed network of highspeed MediaTone switches. With this architecture, session data originating from the Presenter’s machine and arriving at Attendees’ machines is switched—never persistently stored—through the WebEx MediaTone Network. This is unlike other web meeting applications that use a store and forward server model that stores potentially sensitive content for an indeterminate period of time is on their equipment. WebEx sessions are thus completely transient and operate similarly to a voice conversation over the public phone network. In addition to unique security benefits, this architecture also enables an extremely scalable and highly available meeting infrastructure unburdened by the physical limitations of premisebased server solutions.
Data Centers
WebEx session content is switched using WebEx equipment located at WebEx owned and operated data centers worldwide. Current WebEx datacenter locations include: Mountain View, CA; Denver, CO; Reston, VA; London, UK; and Tokyo, Japan. Each facility is staffed, 24 hours a day, seven days a week. WebEx also maintains nodes in Melbourne, Australia and Bangalore, India. To gain access to any facility, one must first be on the approved access list managed by the WebEx Security team, described in the next section. Additionally, WebEx employs biometric security devices to control physical access.
Security Personnel
WebEx employs a dedicated security department, which reports directly to the WebEx CIO. The team includes a GIAC Certified Forensic Analyst, two CISSPs, a GIAC Certified Intrusion Analyst, and an ISSMP. WebEx spends significant resoures on training from vendors and industry experts, and the Security personnel regularly receive training in all aspects of enterprise security to remain at the forefront of security trends.
The separation of duties that exists between WebEx Security personnel and other WebEx personnel was a major factor contributing to WebEx obtaining both WebTrust and SAS-70 Type II certifications, as discussed later in this paper.
The Secure WebEx Support
Session Experience
WebEx Remote Support Site Configuration
The WebEx Site Administration module enables customers to enforce security policies across their WebEx site. For example, a customer may disable the CSR’s ability to Share Desktop on a per site basis. Settings established at this level propagate to all sessions created on the specific site. Other security related features of Site Administration Configuration include the following:
- Must unlist all Support Sessions.
- Require Customer to enter required information in pre-session form.
- Create disclaimer on customer’s pre-session/entry form.
- Require strong password.