LAS VEGAS – Oracle believes it may have found a solution for a gap it sees in cloud network security. It's called Zero-Trust Packet Routing Platform, and it is something the company is using as a standard policy that it wants to become an industry standard.
"The idea is to address a pretty large gap in security," Leo Leung, Oracle vice president of products and strategy, told SDxCentral. "You can call it cloud security, or large environment security. Typically, it goes down two dimensions. One is identity-based. So you're identifying the people and machines that have access to an environment. The other big realm is network security. The challenge with both of those is that they've been around for decades, they get better, but it doesn't stop some of the bad actors from finding other gaps."
This leaves a vulnerable area that's being exploited constantly by way of phishing, human error or insider corruption: trusted entities getting into a system where they're not supposed to be.
"They've (bad actors) found the gaps, and whether it's a phishing attack or something like that, they get an identity of someone who does have access to resources," Leung said. "And once they're in, they can do a certain amount of things. One of the biggest challenges to security is just that: a trusted entity inside the network is exfiltrating (the theft or unauthorized removal or movement of any data from a device) data. There's nothing that either network security or identity security can do to stop it without, you know, becoming so extreme that the entire system becomes unusable."
A twist on zero trustThe zero-trust technology Oracle is developing approaches this in a different way.
"Instead of putting a giant wall around the data and saying, 'Hey, nobody can access this data except for this one person,' it's going to attempt to define first how sensitive the data is," Leung said. "So we tag the data, whether it's PII [personal identifiable information] or data inside of databases, raw files, anything, with a specific code. Secondly, there is a policy that says 'Only these people are allowed to access data and do certain things with the data.'"
When a packet enters an IT system legitimately but is later seen to have moved to a place where it's not supposed to go, alerts immediately sound.
"So for example, this exfiltration thing could be prevented by this new standard, in that you can allow the inside user to access the data and move it from place A to B. But if that user goes in and tries to move the data from A to C, they will not be allowed. And you will actually use the network to block that," Leung said.
All this will be automated by Oracle using its smart NICs, included in every network node, as the security enforcers in this Zero-Trust Packet Routing Platform. Smart network interface cards, or smart NICs, are a method of offloading intensive packet processing tasks from servers.
Every piece of data, each packet that moves along in the network will have a unique identifier, Leung said.
"That little identifier is what triggers off the policy engine to do something – either notify or block the movement of the entity," Leung said. "Blocking happens through the network, at least within OCI. We'll do it through our smart NICs, so every machine in our cloud has a specific picture. These (NICs) become enforcement points for how traffic routes in our network."
The beginning of a new security standard?The standard will be composed of a policy engine that describes data to this unique identifier within packets. "It's early stage, but we think it could be pretty big when it comes to the security space," Leung said.
Oracle said it is collaborating with Applied Invention and other industry partners on the new standard, which will enable networks to collectively enforce the shared security policies and security architecture organizations already use without changing existing applications and networks.
Comments