AIOps: Performance and Capacity Management

AIOps: Performance and Capacity Management

AIOps: Performance and Capacity Management

Members of this community will discuss end to end near-time collection, curation and reporting for simplified performance, cost and capacity management

 View Only

Tighter Network Security Challenges

By Felicia de Groot posted 02/04/26 11:53 AM

  

Written by Jack Opgenorth on February 5, 2026

Security is at the forefront of every Business in the Information Age. Most everyone has received that awful notification that our personal information has been ‘compromised’. The ITRC statistics are frightening (ITRC Report). IBM and other IT providers continue to provide improvements in the solutions for protecting our digital assets. The cost of a security Breach now exceeds $10M in the US. While those costs are significant, implementation of security, like every other change, should be evaluated as part of the deployment. Incorrectly implementing new technologies can result in excessive and avoidable costs. 

In this brief, I’ll provide some ways to ‘identify’ z/OS traffic that is at risk, I’ll reference IBM’s technology for implementing and managing ciphers, and I’ll introduce a few key performance metrics and resources that can ensure you are implementing tighter z/OS traffic security in a cost competitive way.

In a previous blog, I’ve covered the commonly used metric for IBM software licensing, and how you can track and report on your results using those measurements to help the business side of the house understand what’s behind the z/OS costs. There are numerous ways to reduce your mainframe costs that we have covered in the past. I’ll link to those resources throughout this blog.

Keep a Watchful Eye

Your primary TCPIP stack address spaces should be proactively measured for CPU consumption. I’ve seen similar patterns (Figure 1) using IBM Z IntelliMagic Vision in customer sites and have helped customers set up proactive dashboards along with implementing daily reviews of TCPIP address space consumption using change detection reporting, along with TCPIP traffic patterns, and zERT protocol activity as a way to keep your eyes out for changes.

Let’s be honest, which protocols and ciphers the security team is implementing has not been on every performance, capacity and system administration professional’s check box other than getting it done to Security’s satisfaction. Getting security to accept my latest password is hard enough on most days. Is it 15 characters? Do I use my password encryption for this site? That type of mindset needs to change when it’s for z/OS systemwide changes and the IntelliMagic team would welcome opportunities to help customers assess, review, and implement reporting that will enable a more proactive approach to implementing the best and latest security protocols, ciphers, etc. This includes evaluating test traffic before moving to production.

Looking at Figure 1 below is exactly why this is true. Unfortunately, the significant TCPIP CPU change (greater than 50% or 30 MSUs) in one customer’s environment is not a unique event. I’ve observed this type of scenario for customers running z14s and z15s.

image

Figure 1: Weekly average MSU Consumption for TCPIP Communications Across a Customer Environment

While methodical security changes might include planning for up-to-date technology, this may not always make it to the provisioning department and be given the importance that is warranted to make sure it’s budgeted (hardware and/or software). At every turn of the technology crank, security is a primary consideration. We are hearing about ‘quantum safe’, so this subject will continue to evolve. The intent of this blog isn’t to give you all of the resources on where to go, but to give you a couple of places to start. The IBM communications team has been sharing the results of options and considerations on this topic for a while.  Some of the key recommendations listed include things like using Crypto Express Adapters to reduce CPU, specifically GCP for z/OS network traffic, and reduce latency for network traffic.

A Crypto Express Example

The customer case in Figure 1 was on a z15 base processor, and they were able to implement Crypto-Express cards. The results from using this technology for the installation were impressive. The PCI Adapter utilization post implementation for the systems averaged around 3% (drilldowns by system show that it was 6% for one processor at peak demand), and it was well under 1% most of the time in Figure 2. The resulting MSU demand from the TCPIP stack in the environment saw a dramatic decline, which quickly proved the value of encryption co-processing technology. 

image

Figure 2: Implemented Crypto Express Adapters & ICF Configurations

image

Figure 3: MSU Consumption Pre & Post Crypto Express Card and ICF configurations

Budget for Security Technology

The evolution of zSeries technology will continue to advance security options. Organizations need to consider the processor generation they choose along with the requirements for encryption protocols and ciphers. The zSeries communications teams have done excellent work incorporating the processor intensive nature of encryption into coprocessors and adapters to minimize the impact to your communications software as it relates to encrypted network traffic. The rollout of processor changes in your environment can sometimes drive your technology into an N-1, or N-2 currency for processors. 

Maintaining the best security across a mixed environment may require some specific configuration differences in hardware, software, and encryption protocol choices. Transparency in usage, security protocols/ciphers and co-processor demand are just a few reports your team should have access to and regularly report out to leaders so that everyone is on the same page as you manage the complexity of these critical systems.

Next Steps

Since you may already be on z17, what’s the big deal? Some great recommendations have been made from Mike Fitzpatrick & Christian Nyamful in recent SHARE presentations (SHARE Conference sessions 10235 and 30335). Briefly, you need to be aware of what operations are accelerated in the hardware, and which operations are used within a given cipher suite. The provided links below should be bookmarked if this is your responsibility. A set of reports on your Network performance should be regularly reviewed. One example is provided below which contains a number of reports.

image
Figure 4: Dashboard reports should include: TCPIP CPU, Network Encryption, Network Health


Contact us for a consultation to learn how we’ve helped z/OS sites stay secure without breaking the bank.

0 comments
50 views

Permalink