SAN FRANCISCO – Zero-trust security models are the future, but they must be able to take into account context in order to not disrupt operations, a panel at this week’s VMware Explore 2022 event declared.

The panel, ominously titled “A Light in the Darknet: Stopping Cyberthreats with SASE,” tackled challenges in adopting a zero-trust policy for enterprises using secure access service edge (SASE) systems. Speakers noted that while zero trust is a goal, it’s difficult to implement due to its binary nature.

“Switching from having access to the entire network, you're behind the firewall, to a zero-trust framework is very disruptive to the end users. You're going from a blackness-type of scenario to a whiteness-type of scenario, which is hard to implement without trial and error and a lot of time,” Saqeb Akhter, a solution architect at VMware, noted.

Akhter’s colleague Clifford Lane, who is a principal systems engineer at VMware, explained that context awareness is what feeds into “information-driven analysis and response.”

“We're getting the necessary context to make a very nuanced and informed decision about the security posture that we must take with respect to the application that we're accessing, or the device that's going out and hitting other devices or communicating with other devices,” Lane said. “And that is what grants us that flexibility and that scalability.”

However, context is difficult to ascertain in legacy security environments that don’t have the ability to pull in that necessary data to make those decisions.

“Legacy environments find this very difficult to implement because it is not an easy thing,” Lane added. “For somebody that sits at the head of security to come up with a blanket policy that is going to cover all of those potential scenarios, especially with a lack of information, if they don't have that necessary context, they're left with creating a broad blacklist that is shutting out everything.”

Eddie Fox, CTO at managed network services provider MetTel, said that his enterprise customers are indeed asking for this and know they need better context to make their networks more secure.

“We have all this great information, and figuring out how to use it more contextually is a great way to put it, and our customers are asking for that,” Fox said. “The more contextually aware that we can be, the more secure we can be. It'll just make our lives easier to deal with.”

VMware Project Watch Ties Context to Zero Trust

Getting there will take some time. A number of cybersecurity firms are adding artificial intelligence (AI) and machine learning (ML) capabilities to their SASE platforms in an attempt to drive more contextual awareness.

VMware is attempting to bridge this gap with its Project Watch that was unveiled at the event. The project is framed as a multi-cloud networking and security platform that provides advanced app-to-app policy controls, with Akhter adding that it will also be part of VMware’s SASE platform.

The project is still in a technology preview, with Akhter noting the vendor is still working on its full scope.

“The tagline around it is that it's meant to be a contextual transactional firewall, don't quote me on any of those words,” Akhter said. “But the idea is that it's not a one or a zero. Every transaction that a user makes to an application, or an application makes to another application, should be looked at. They shouldn't just be allowed, and needs to be taken into account with context, location, etc.”

Read all of SDxCentral’s VMware Explore 2022 coverage here.