Juniper Networks announced a new workload platform to connect and protect applications against malicious actions in real-time within zero-trust data center architecture. 

Kate Adam, senior director of security product marketing at Juniper, explained that the Cloud Workload Protection platform acts as a safety net for applications and their workloads. The agent operates in a “lightweight and serverless” manner that customers can essentially inject into production applications and individual containers.

This software agent provides application execution control and monitor, as well as automatic vulnerability remediation without admin intervention. Adam said that it offers a safety net to defend applications against exploits in the public cloud and on-premises environments, as well as within Docker, Kubernetes, and Amazon Web Services’ (AWS) Fargate container deployment services.

It also provides signatureless run-time application self-protection (RASP), memory-based attack prevention, vulnerability detection, comprehensive telemetry, optimized control flow integrity (OCFI) technology, and zero-trust microsegmentation.

“The most important feature of Cloud Workload Protection is the deterministic detection,” Adam said. The agent detects vulnerabilities in the application in real-time. “It uses deterministic detection to basically map out all the processes and function calls that an application should make according to the code,” she explained.

Developers inadvertently create code with some vulnerabilities, so having a safety net for applications can help prevent delaying a feature or service to end-users. “This feature allows companies to be extremely agile,” Adam added.

Integrates With Juniper vSRX Virtualized Firewalls 

The launch continues Juniper’s Connected Security strategy. This architecture involves enforcing security policies at every connection point across the network: switches, firewalls, routers, public and private cloud, and endpoints. It combines SD-WAN and security capabilities into a cloud-managed platform.

Cloud Workload Protection integrates with Juniper vSRX Virtualized Firewalls to restrict access based on risk, even as workloads and virtual environments change. These firewalls are designed to protect applications in public cloud environments. 

According to Adam, the platform will send an updated list of indicators of compromise (IOCs) at regular intervals (approximately every 5 minutes) to the firewalls, along with the IP address of potential attackers, the location of the vulnerabilities in the code, and the proof of exploit. In this way the firewalls can block any additional exploit attempt before it reaches the applications.

Adam expects they will further integrate the new agent with their other networking products, including the platform for data center network fabrics from the Apstra acquisition. 

The product will be available in September.