SAN FRANCISCO – As cyberthreats become more sophisticated, the need for artificial intelligence (AI)-driven, cloud-based and unified security and networking platforms is growing, and the secure access service edge (SASE) market continues to evolve to meet those needs, according to Palo Alto Networks SVP Kumar Ramachandran.

How AI is transforming SASE

The increasing prevalence of technology vulnerabilities and the diminishing reaction time for security vendors and customers highlights the need for tools like machine learning (ML) and AI, Ramachandran noted.

Recent statistics showed a 161% increase in usage of tools like Cobalt Strike, which enable large-scale attacks, while at least 100 new URLs are created daily using generative pre-trained transformer (GPT) technology, he added.

“The reality is that you have to have a deep data science investment, which brings [us] to … the usage of AI and ML,” Ramachandran told SDxCentral.

The volume of data required to address various use cases can be massive. For example, stopping threats that emerge within 15 minutes requires a departure from the old model of waiting for signatures to be generated and published, he explained.

To address this, Palo Alto Networks processes over 236 billion threats daily, amounting to more than a trillion threats per week. This vast and diverse data set is utilized to train its ML models. “Today 95% of zero-day threats we stopped using in-line ML that is operating at a scale that no other vendor comes anywhere close to matching,” Ramachandran touted.

“And it really speaks to the power of the fact that when you have a unified platform, then you have this kind of data, and then you can train your AI systems,” he said.

SASE as a managed service in the AI world

The SASE-as-a-managed-service trend addresses the transformation of people and processes, Ramachandran said.

“When I move to a model where AI and ML is enabling lots of functionality, how should we organize my people — like my people are used to manually doing a whole bunch of activities, and they were used to having that manual comfort,” he added, noting that organizations need a managed service partner to guide them through operating at scale.

Additionally, in the process of network and security transformation to SASE, sometimes teams are still organized in a siloed model when they are about to start on the first transition project, and a managed service partner can help map out from current to end state and evaluate tools or capabilities through a collaborative and integrated approach.

To this end, Palo Alto Networks partners with Accenture, NTT and AT&T to offer managed SASE services.

The operational visibility of SASE

Another trend in the industry is the operational visibility of the SASE platform, Ramachandran pointed out. “In the end, in all these things, architecture matters tremendously. When a customer makes a SASE transformation, we become part of that mission-critical infrastructure.”

SASE solutions must be highly available and reliable, as their downtime directly impacts customer operations. “If the SASE solution is down, the customer stops. That's different from deploying public firewalls in your data center and having redundancy [where] you're responsible for managing the availability of those devices that [are] on-prem,” he added.

That’s why Palo Alto Networks is building Prisma SASE on a native multi-cloud platform that leverages multiple regions of Google Cloud Platform (GCP) and Amazon Web Services (AWS). This unique approach allows the SASE solution to remain operational even if one service from GCP or AWS fails.

“We're the only vendor on planet earth that actually publishes five-nines of availability, so our SASE solution is the strongest link in the customer's access chain from user to application,” Ramachandran claims.

SASE approaches maturity

As the SASE market matures, customers start to look for the right architecture, design and vendor, Ramachandran said.

At last year’s RSA conference, customers came to Palo Alto Networks’ booth asking about the definition of SASE, including why they should make the technology transformation to SASE and its use cases. But this year, “What they're trying to understand now is: Hey, what is the right architecture for me? What is the right design? What's the right solution,” he said. “And our response to these customers is that the unified platform is the one that can get you the right kind of data and deliver incredible security.”

“Customers are coming off the pandemic, and then they're navigating uncertain macroeconomics. What customers are looking for, really, are vendor solutions that are operating at scale, that have full platform capabilities and are operationally easy to manage,” Ramachandran concluded. “We're definitely seeing a huge push in the SASE world, where customers want to come in and say: Listen, I don't want this point product only for secure web gateway, for my CASB [cloud access security broker], for my VPN, for SD-WAN – give me a platform approach,” he said.