SAN FRANCISCO — VMware announced an extra layer of security for its Cloud Foundation software stack today at RSA Conference 2020 that includes Carbon Black technology as well as load balancer and web application firewall capabilities acquired from Avi Networks. The new VMware Advanced Security for Cloud Foundation also includes NSX Distributed Intrusion Detection and Prevention (IDS/IPS), and all three of these security updates integrate into vSphere.
In addition to the Advanced Security for Cloud Foundation, the vendor added features to VMware Carbon Black Cloud including automated correlation with the MITRE ATT&CK framework and soon-to-come prevention coverage for Linux machines. And finally it rolled out VMware Secure State auto-remediation capabilities to automate actions across cloud environments.
At a press briefing before RSA, VMware SVP and GM of Networking Tom Gillis said all of these capabilities contribute to what VMware calls “intrinsic security,” which is a theme that the virtualization giant has been leaning into over the past year since it’s concerted push into the security sector.
Intrinsic Security“Intrinsic security doesn’t just mean it’s built in,” Gillis said. “It means it’s built differently. And so, when we talk about intrinsic security, we focus on security that we can implement because we have an intrinsic advantage or capability with our [virtualization] platform, and that’s what’s different and unique.”
Specific to Carbon Black’s technology, which VMware acquired last year, intrinsic security means tighter integration into vSphere. Carbon Black’s workload protection technology no longer requires installing an agent to provide antivirus protection or endpoint detection and response. Instead, endpoint telemetry is managed and gathered via built-in sensors protected by the hypervisor, which can detect if an attacker tries to gain root access.
“With the acquisition of Carbon Black, we’ve done two things,” Gilles explained. “One is we have some vulnerability scanning that we have integrated into vSphere, so before you launch a server we check and make sure that that server is patched and current. And the big, big area of our integration with Carbon Black is being able to take what used to be an external agent and make it agent less. So building it in a way that it’s inserted and protected and managed from the hypervisor is extremely powerful. This is an example of that intrinsic security message.”
Security Via Software, x86 ServersThe second piece is the NSX Advanced Load Balancer/Web Application Firewall, which provides security via software and thus scale-out capabilities. This means it can ensure web servers have enough computation capacity for maximum security filtering even under peak loads, VMware says.
And finally, the third piece of the VMware Advanced Security for Cloud Foundation — NSX Distributed IDS/IPS — is a new capability of the NSX Service-defined Firewall, which VMware announced at last year’s RSA Conference. This piece provides intrusion detection across the different services that make up an application, thus making it easier to get deep visibility.
“Each piece of each service that makes up your application gets its own little mini firewall and IDS/IPS,” Gillis said. “This is the power of a distributed architecture, this is something that we could do uniquely, and something that is incredibly valuable to customers because it allows us to deliver better security.”
The distributed architecture of NSX Distributed IDS/IPS is important because it enables advanced filtering to be applied to every hop of the application, which VMware says eliminates the blind spots created when using traditional perimeter security products. Additionally, it auto-generates and enforces policies on an application-specific basis, thereby lowering false positives.
A distributed architecture across a large array of x86 servers is key, Gillis added. “This, we believe is the architecture for the data center of the future,” he said. “This is how the public clouds are built, and our customers at VMware they’re looking to VMware to help them deliver the public cloud experience in their private cloud infrastructure. In order to do that you need a public cloud architecture that is x86-based hardware and scale-out infrastructure software like the firewall load balancer and IDS/IPS.”
Carbon Black Plays Nice With Microsoft and LinuxIn addition its new advanced security suite for Cloud Foundation, VMware also introduced automated correlation with MITRE ATT&CK framework Technique IDs — a list of common tactics, techniques, and procedures (TTPs) — built into the VMware Carbon Black Cloud. This lets customers search for specific TTPs based on MITRE ATT&CK techniques within the VMware Carbon Black Cloud to discover potential threats and improve their security posture.
VMware Carbon Black will also soon integrate with the Microsoft Windows Anti-Malware Scanning Interface (AMSI) to provide additional visibility by decoding obfuscated commands. And finally, VMware Carbon Black will add malware prevention capabilities for Linux machines.
Secure State Automates Remediation Across CloudsVMware also rolled out new capabilities to its Secure State detection and remediation product. This includes a remediation framework to help customers automate actions across multi-cloud environments. The new service also provides pre-defined, out-of-the-box actions or lets developers create custom actions as code. All actions can be targeted to selectively remediate resources based on conditions such as cloud accounts, regions, or resource tags.
And to prevent new misconfigurations, security teams can build guardrails that auto-remediate violations. Users can programmatically execute all remediations as code using an API and integrate them within the CI/CD pipeline.
Comments