VMware’s security chief says extended detection and response (XDR) is “the next frontier for us,” as the virtualization giant continues to grow its security business.

XDR is “something that we can do really, really uniquely to stop these very sophisticated attacks,” said Tom Gillis, SVP and GM of the company’s Network and Security Business Unit, during a press conference before the company’s Security Connect event.

“The way you keep your data center safe, keep the bad guys out knowing that they're probably going to get in, is a series of steps,” he explained. “It starts with segmentation, tightening them up to per-application segmentation though the distributed IDS and signature-based analysis to stop known threats, non-signature-based analysis to stop the unknown threats, and the new frontier is combining both host and network together. Those five steps yield state-of-the-art security that can be operationalized at scale.”

XDR combines elements of security information and event management (SIEM); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); and network traffic analysis (NTA) in a cloud-based platform. This centralizes security data, threat hunting, and incident response. Several vendors, VMware included, also add cloud threat detection and response as an XDR capability.

VMware’s XDR Strategy

VMware first started talking about its XDR strategy at last year’s VMworld, and executives provided more details about its approach ahead of the company’s annual security event.

Traditionally, security operations teams replied on SIEMs, which dump a ton of security data into a data lake and then run analytics on top of that. But this results in a lot of noise and makes it difficult to separate out the real threats from false alarms, said Patrick Morley, SVP and GM of VMware’s Security Business Unit. “The dream on XDR is how do we get the right level of telemetry, and take it from the right sources — not every source but the right sources,” he said.

Before joining VMware, Morley spend 12 years as CEO of Carbon Black, which provided cloud and endpoint security. VMware paid $2.1 billion for the security company in 2019 and in short order made it the center piece of its security business. Since then, VMware acquired other security vendors including network detection and response firm Lastline and Avi Networks that, among other things, brought in a load balancer and web application firewall.

On the cloud-native and application security side, VMware bought Kubernetes security startup Octarine last year, and more recently API security vendor Mesh7.

All of these acquisitions play into VMware’s larger security strategy, and they also feed into its XDR play.

XDR’s ‘5 Core Pieces’

“There’s different definitions, but I think of XDR with five core pieces,” Morley said. This includes host, cloud, network, identity, and workload data, he said. Even though it’s not one of his five, email data is also important “because that’s still where most of the attacks are coming from,” Morley added. “And for VMware, I would argue that we participate in three and a half of them.”

This includes host, network, and cloud via its NSX networking and security products along with Carbon Black. And while VMware doesn’t have a specific identity platform, “with some of the tools and products around Workspace One we provide a lot of information about identity,” Morley said.

It’s still too early to say who will win in the XDR market, and customers will likely chose an XDR vendor based on their specific threat landscape, said Zeus Kerravala, principal analyst at ZK Research.

VMware “has as compelling a set of products to provide XDR as any XDR vendor does,” he said. “Nobody really does all of it, and a lot of this comes down to, from an organizational perspective, where you think your biggest source of breach comes from? For instance, if you think it’s network, then you’d probably want to use a Palo Alto or Fortinet or Cisco,” because these three vendors approach XDR from a network-centric perspective, Kerravala said.

However, if you are most concerned about attackers accessing corporate systems via workloads in the data center or in the cloud, “then maybe you lean towards a VMware,” he said.