Forward Networks moved into the security space today with three new features to help security teams contain and prevent incidents.

This isn’t a pivot for the SDN pioneer, but rather an “expansion of the field of view,” said CTO and co-founder Brandon Heller. The company’s software, which creates a digital twin of the network and allows operators to verify intent and predict network behavior, “has always been used for security,” he added. “We’ll always be networking at our core, but there’s a lot of value for the security side. It’s an expansion of who we’re targeting with our capabilities, based on the same data, because we’re able to do a lot more by doing an extra 10% to make this data more visible. ”

The SolarWinds breach, discovered late last year, was the No. 1 motivator for this shift, he explained.

“It was on everyone’s mind, everyone was asking us about it, every boardroom, the question of: Are you sure you can trust your network? Is it as locked-down, zero trust as can be? The second thing is: We have all this data and we had customers that are already using our product for these purposes, but not necessarily with an optimized interface or a UI that makes it real easy,” Heller said.

Forward Networks’ 3 New Security Features

The first new feature, called Blast Radius Identification and Isolation, uses data already collected by the Forward Enterprise platform to help security operations engineers identify the reach of a compromised host via one mouse click. Once the exposure is identified, isolating the devices is a much simpler and faster process.

The second feature, Zone-to-Zone Connectivity Matrix, continuously captures firewall configuration information to provide real-time zone-to-zone connectivity. A graphical matrix “tells you whether given zones are fully connected, partially connected, or fully isolated,” said Chiara Regale, VP of product for Forward Networks. Full isolation may be intentional — for example, due to a firewall rule to harden security posture — but it may also mean a routing connectivity error, she explained.

The platform’s Path Analysis, Network Query Engine, and network-diff capabilities allows engineers to determine the cause of an unintended connectivity.

“Once the security engineers see that a given matrix is the source of truth for their security posture, or PCI compliance, for instance, they can translate this connectivity or lack thereof into policies that we, the platform, can automatically validate every time there is a change in the environment,” Regale said.

This allows security and network engineers to verify their network segmentation, Heller added. “It’s a really quick way to understand the segmentation that you really have in the network, and then check that it matches those expectations,” he said. “So this is a way of verifying that your zero-trust posture is actually implemented in a way such that the traffic is going to the right places.”

The final new feature uses information from the NIST National Vulnerability Database and the specific device and configuration data collected from the network to automatically analyze the network for vulnerabilities and then display this information in an actionable format. “What we do with this feature, we provide a dashboard where we list all the CVEs that are affecting the platform and the network, and the CVEs are described in terms of severity,” Regale said.

Additionally, Forward’s API integration with ServiceNow can automatically generate tickets.

How Forward Validates Zero Trust

The new features work together with Forward’s networking platform to validate organizations’ zero trust architectures, Heller said.

“Zero trust is all about defense in depth,” he said. “It’s about reducing all the trust and dropping the level of connectivity to the absolute minimum, because that’s the best you can do. And it isn’t just eliminating broader access for attacks that can get through, but it’s also about limiting the damage for the kinds of attacks like SolarWinds that are very hard to defend against.”

After the attackers compromised SolarWinds’ network — this likely happened in January 2019, according to SolarWinds CEO Sudhakar Ramakrishna — they inserted malware into the vendor’s Orion software update that was pushed to about 18,000 customers beginning in March 2019. This allowed them to remain in organizations’ environments for almost a year before FireEye discovered the breach in December 2020.

“SolarWinds reminded everyone you can’t trust anyone,” Heller continued. “This was software people trusted. Imagine you’ve installed software in your computer, it’s been fine for years, and then it gets a backdoor that no one in the world is aware of for months. It’s doing whatever it wants.”

This shows the importance of limiting network access proactively, “because if you have to be reactive about it, it’s too late,” Heller said. “What’s unique about verification, is it enables proactive defense of a security posture. It’s the only way you can be sure that you’ve locked down network connectivity to a level to where only the minimum [access] you need is present.”