Akamai-HQ.jpg
– Akamai

In the most recent move towards platformization, Akamai today announced the launch of the Akamai Guardicore Platform, which combines microsegmentation and zero-trust network access (ZTNA), multifactor authentication (MFA), DNS firewall and threat hunting into one zero-trust platform.

“Analysts have predicted that organizations will be looking for more integrated solutions from a single vendor rather than continuing to purchase and manage multiple point products,” Dan Petrillo, director of security strategy at Akamai, told SDxCentral in an email. “These components combined provide organizations with the right solution to adhere to the core principles of zero trust including treating all entities as untrusted by default, enforcing least privilege access, and maintaining comprehensive security monitoring.”

Petrillo added the solution aims to help minimize their attack surface and reduce data breach risks by verifying every access request, regardless of its origin.

A unified platform simplifies ZTNA implementation

ZTNA and microsegmantation are two key products and a starting point for organizations to transition to a zero-trust architecture, Petrillo noted. “Depending on their security priority, a business normally starts a transformation with one or the other.”

However, deploying ZTNA and using next-generation firewall (NGFX) to segment their internal networks and workloads is a complex and inefficient approach. Organizations need a unified ZTNA and and microsegmentation solution, he added.

“With a unified zero-trust platform, businesses can start with either solution but over time they get benefits from a single agent, console and policy. This reduces the complexity of managing disparate solutions and accelerates the time it takes to get to a zero-trust architecture,” Petrillo said.

He touted that a unified zero-trust platform can address the ZTNA deployment challenges by

  • Enhancing app visibility: Organizations often lack a complete picture of the business applications. Microsegmentation labeling enhances visibility, enabling quick identification of private apps and their users.
  • Streamlining access control: Traditional ZTNA requires manual firewall rule adjustments to ensure application accessibility. A unified zero-trust solution simplifies this by creating a  microsegmentation policy instantly with a single click.
  • Improving troubleshooting efficiency: The unified solution offers visibility of the entire path, from the user's device to the application and even down to the application's process level. This allows the networking teams to quickly investigate and resolve any application access issues.

Akamai uses genAI for zero trust

The Akamai Guardicore Platform uses generative artificial intelligence AI (genAI to streamline the zero-trust implementation for tasks including natural language communication with network logs, AI labeling for asset inventory, AI queries for simplified vulnerability assessments, and AI-driven policy recommendations.

For example, the genAI features allow security teams to ask natural language questions of their network through AI assistant, instead of manually poring through logs for use cases like compliance scoping and incident response.

“We are utilizing the Azure OpenAI infrastructure, which offers managed dedicated instances of OpenAI’s LLMs. We then train these models internally,” Petrillo said. “The LLM prompt is fed with up-to-date information that is specific to the customer environment to ensure it provides relevant information based on the input prompt.”

Addressing ransomware and zero-day exploits

A recent Akamai report showed ransomware attackers are shifting their attack techniques away from phishing to emphasize vulnerability abuse and becoming more aggressive in their methods of extortion and zero-day and one-day vulnerabilities.

“When a vulnerability is announced, it’s a race against the clock to identify and protect potentially compromised systems,” Petrillo said, adding the segmentation function can be used to “ringfence” potentially compromised systems, preventing any communications with those systems until a patch is issued or another fix is worked out.

However, this feature alone can’t adequately find all of these compromised systems. That's why Akamai is harnessing the power of genAI to solve this problem through its genAI-powered chatbot, he added.

“A single query can surface all communicating machines in your environment that may be vulnerable, allowing security teams to quickly create and enforce policy to protect those machines before the vulnerability can be exploited,” Petrillo said.