Amid the rapid evolution of artificial intelligence (AI), Cisco is reimaging security architecture. Starting with protecting AI-scale data centers and clouds, the vendor unveiled Cisco Hypershield, designed to address three key security challenges in the highly distributed world – patching, updates, and segmentation.
The Cisco Hypershield is “probably the most consequential security innovation we have done in the 40 years that Cisco has been around,” Jeetu Patel, EVP and GM of Security and Collaboration at Cisco, told SDxCentral.
He added that as the time from vulnerability to exploitation continues to shrink, plus segmentation, vulnerability patching, and software updates become more challenging, protecting the data center is beyond human scale. “You have to reimagine the security architecture for the age of AI, and that architecture has to be hyper-distributed.”
That’s why Cisco Hypershield aims to provide capabilities, including:
1. Distributed exploit protection: As attackers are adept at weaponizing newly published vulnerabilities faster than defenders can patch, Cisco Hypershield automatically tests and deploys compensating controls into the distributed fabric of enforcement points, even when the patch has not been applied.
2. Autonomous segmentation: Recognizing that once attackers breach the perimeter, segmentation is key to stopping their lateral movement, Hypershield is designed to perpetually observe, auto-reason, and re-evaluate existing policies to autonomously segment the network.
3. Self-qualifying upgrades: Hypershield leverages a dual data plane architecture to allow software upgrades and policy changes to be placed in a digital twin that tests updates using the customer’s unique combination of traffic, policies, and features and then applies them with zero downtime.
Designed and built with AI in mind from the start, Cisco Hypershield doesn’t replace any existing data security solutions but uses a new architecture, Patel said. “What this is essentially is a distributed security model where the security controls that are put in front of anything,” including every application service in the data center, every Kubernetes cluster in the public cloud, and every container and virtual machine (VM).
This software security product is managed by the same management console as Cisco’s firewall infrastructure – Cisco Defense Orchestrator.
Core building blocks for AI-scale data center security
Cisco Hypershield is built with technology and powerful hardware accelerators that were originally developed for and are used extensively in high-performance computing (HPC) and hyperscale public clouds,m and make it now available for enterprises of all sizes, the vendor claims.
Patel explained three core building blocks of technology that make this product possible: eBPF, hardware acceleration including GPUs and DPUs, and AI.
eBPF is an open-source technology that allows for the execution of sandboxed programs within the Linux kernel, without requiring changes to the kernel source code or the loading of kernel modules. It is the default mechanism for connecting and protecting cloud-native workloads in the hyperscale cloud. Cisco recently completed the acquisition of Isovalent, which is the leading provider of eBPF for enterprises.
In addition to eBPF, Hypershield leverages hardware acceleration like DPUs to analyze and respond to anomalies in application and network behavior, and AI makes a hyper-distributed approach at scale possible.
“Security architectures were all built based on a perimeter-based security model,” Patel said. "In this hyperdistributed world, where I have thousands of microservices, they're running on multiple Kubernetes containers. Everyone is talking to everything. They're talking to each other through APIs. It's very hard to keep things secure unless the core mechanism with which you're keeping that entire infrastructure secure is reimagined and rethought to be highly distributed.”
Cisco Hypershield is expected to be generally available at the end of July 2024.
Comments