quantum networking
– Getty Images

Palo Alto Networks has updated its firewall operating system with quantum-ready features, highlighting the ability to make legacy applications quantum-proof.

A new dashboard in the Palo Alto Networks operating system (PAN-OS), meanwhile, offers comprehensive insight and governance over cryptographic risk profiles with real-time inventory tracking, compliance validation, and inline remediation.

Additionally, it introduces quantum-optimized hardware to deliver high‑throughput processing of post-quantum cryptography (PQC).

Rich Campagna, senior vice president for network security at Palo Alto Networks, said the firm is working on the assumption that Q-Day, when a quantum computer becomes powerful enough to break encryptions, is three to six years away. This timeline is shorter than previous estimates as to when a quantum computer will be able to break current encryption methods.

Rich Campagna
Rich Campagna, senior VP, Network Security, Palo Alto Networks – Palo Alto Networks

“If that time horizon of three years becomes true, then most enterprises - especially the large ones - need to start now,” Campagna told SDxCentral, adding that while not universal, Q-Day awareness is spreading across a wider range of industries than before.

Like its namesake tool in Palo Alto’s Strata Cloud Manager platform, a quantum readiness dashboard is promised to provide PAN-OS users a full end-to-end view of what has and hasn’t yet been upgraded to quantum readiness.

“There's no other tool … that gives you that full kind of visibility into where you have PQC, all the way from the device and across applications, browsers, et cetera, running on devices, into the network and all the way to the backend applications themselves,” claimed the VP.

For Campagna and Palo Alto, the crux is that most endpoint devices, cloud applications, and browsers can already support quantum-safe algorithms, meaning enterprises need to only make them active for quantum readiness.

The more pressing problem concerns legacy applications, with Campagna estimating that around 3,000 internally developed legacy applications will need post-quantum support.

“That's a multi-year project for most organizations. So that's piece number one across the organization, in providing this assessment without any new infrastructure to deploy.”

To aid quantum upgrade for legacy apps, PAN-OS is introducing a cipher translation proxy, which can automatically convert classical traffic into post-quantum algorithms.

“The way it works is you take an application, or set of applications, and isolate them behind a firewall so they have no connectivity to anything other than the firewall itself.

“Those applications talk classical, not quantum safe, crypto to our firewalls, and then in the firewall, in real time, we translate that to quantum-safe encryption, so that the entirety of the outside world beyond this isolated segment sees this as quantum-safe cryptography.”

Though not named in Palo Alto’s announcement, the firewalls include algorithms approved by the National Institute of Standards and Technology (NIST), as deployed in recent Fortinet and F5 solutions.

Campagna reminded SDxCentral that these algorithms are still maturing and, therefore still susceptible to quantum decryption.

“There may be other flaws in these crypto algorithms as well that are discovered over time. Crypto agility represents this ability for a customer to simply swap out and switch cryptographic algorithms on the fly … in the platform.”

The path to quantum security is therefore not a finite one. As Palo Alto Networks evolves into an end-to-end platform through acquisitions like its CyberArk mega deal, there is the question of whether security firms need to acquire a quantum security practitioner as a major milestone on the road to Q-Day.

But with encryption and decryption a fundamental core of its business, Palo Alto is “very confident we've executed on a comprehensive solution directly in the management platforms that our customers already use,” said Campagna.

AI updates to PAN-OS

Dubbed PAN-OS 12.1 Orion, the new version of the firewall OS sees Palo Alto leverage its recent acquisition of ProtectAI, which saw completion this July.

A new Cloud and AI Risk Assessment process regularly evaluates cloud and AI assets to identify risks related to insufficient or missing security measures, indicating where additional safeguards are required to maintain strong protection.

Software firewalls, cloud-based firewalls, and instances of Prisma AIRS (AI Runtime Security) are deployed automatically, with the cloud infrastructure configured to direct network traffic, including through a secure multi-cloud network mesh.

Campagna mentioned the ProtectAI provision of being able to scan and look for weaknesses, both pre- and post-deployment, in any model within an organization.

The assessment, Campagna explained, covers various instances running in a public cloud environment: traditional assets, AI-focused ones such as large language models (LLMs), alongside low-efficacy controls like a cloud-native firewall.

“If we see new LLMs that have been popped up inside of, for example, one of the customer’s public cloud environments, we will start by scanning those models.

“Let's say they came out of Hugging Face as an open-source model that may potentially have vulnerabilities, then we'll initiate a continuous red team assessment against those models, which is essentially trying to go after the LLM just like an attacker would, and look for weaknesses.”

These findings are then translated directly into policies, which are implemented in real time in terms of control, across Google Cloud, Amazon Web Services (AWS), or other public cloud frameworks.

These can be deployed across virtual network (VNet) environments and virtual system components (VSCs), helping to form a secure multi-cloud mesh.

“It basically automates the entire process of deploying security into a cloud environment, starting from where it needs to be deployed, to deployment and scaling - if we see new east-west traffic that perhaps is suspicious, then deploying additional controls in place immediately.”

The updates come in response to the security concerns around LLMs, with security teams unable to keep up with what AI throws up next.

“Things are moving so quickly, and especially with AI, these are often top-down driven projects where it's just an unreasonable timeline [is given] when you get this new application at the door.

"Therefore, people aren't consulting with security teams - they don't want to wait for security teams.”