Volterra added capabilities to its VoltMesh service that provide globally distributed networking and security for cloud-native, API-centric applications.
VoltMesh is the startup’s distributed networking and security service. The updates integrate a load balancer, API gateway, web application firewall, and machine-learning based API security with the software-as-a-service (SaaS) platform.
This means DevOps and security operations teams can use VoltMesh to provide zero trust networking and security services at every globally distributed cluster, but with centralized management, visibility, and policy control, Volterra executives said in an interview with SDxCentral.
Cloud-native applications built on microservices increase the number of APIs per application. And this makes security controls like network microsegmentation obsolete because these apps communicate at the API layer, not the networking layer, said Volterra CMO Mark Weiner.
“Apps now are like jigsaw-puzzle pieces, and those pieces talk to each other using APIs — not just for external calls but for microservice one to talk to microservice five or seven,” Weiner said.
Plus, software-based app networking and security tools like Nginx (acquired by F5 Networks) and Avi Networks (acquired by VMware) were built for monolithic apps, not distributed clusters, he added. And using these tools for microservices-based apps creates performance, user experience, and security challenges.
Volterra’s App Security StrategyMicroservices-based apps require zero trust at the API layer, and this includes discovering all APIs and enforcing policy and control on them, added Ankur Singla, Volterra co-founder and CEO.
“The world is moving in this direction, and we are ready,” Singla said. “And what we want to do is to build in an approach where the developer team doesn’t have to make any changes. That is critical.”
VoltMesh enables this with its new API auto-discovery and control capabilities. It uses machine learning to automatically identify all APIs present in an application — whether they were inserted by the current developer team, or were legacy, or open-source software components — as well as learn normal user behavior. It then applies policy to safelist just those APIs that are required and automates zero-trust at the API-level.
Companies can deploy VoltMesh in clusters across multiple cloud providers. It can also be enabled within Volterra’s application delivery network.
The updated VoltMesh service is available as a free software download for base users with two multicloud clusters and a paid enterprise subscription for larger footprint and/or globally-distributed deployments.
Application and API-level security is an emerging technology but one that is becoming more important in companies’ security arsenals as applications and services move to the cloud and security needs to be embedded into the code itself.
To this end, Traceable, an application security startup headed by the former CEO of AppDynamics Jyoti Bansal, launched with $20 million in Series A funding earlier this summer. And Cisco’s Chief Strategy Officer Anuj Kapur said that application and zero-trust security startups tops his company’s mergers and acquisitions target list.
From Multicloud to Distributed CloudAs companies move from multicloud to distributed-cloud and edge environments with distributed applications, this increases the attack surface at the app layer, said Zeus Kerravala, principal analyst at ZK Research.
“You really can’t secure it at the network layer — even highly agile tools like Illumio operate at Layer 3, at the network layer,” Kerravala said. “But that’s like trying to secure a highway by putting up big guardrails and police roadblocks everywhere. It doesn’t help if people are dropping bombs from drones above. That’s what’s happening now. The network is providing the highway, and then a lot of connectivity is being done at the app layer through API-to-API communication.”
Volterra’s distributed cloud platform provides the connectivity and security at the app layer, and because it’s cloud native, DevSecOps teams can spin up security at the speed of containers, he added. This means that performance and latency doesn’t suffer like it would if companies tried to deploy virtual security tools like legacy firewalls in edge locations.
While enterprises could piece something together using Aviatrix’s cloud networking, Traceable’s application security, and Nginx’s load balancer, “Volterra brings all these together into a single shop,” Kerravala said. “They have their own network connectivity, they have security, but then they also have a lot of the Layer 4-7 services like load balancers and web gateways.”
As the big three cloud providers — Amazon Web Services, Microsoft Azure, and Google — push further into edge computing, and applications become increasingly microservices based, Kerravala said Volterra becomes an attractive target for larger networking and security companies. “Something like this would be a great acquisition targets for Cisco or even an F5 — someone that’s looking to move from multicloud to distributed cloud, which is the big trend happening here.”
Comments