SASE
– Getty Images

NetWitness is launching secure access service edge (SASE) packet integrations with Broadcom’s Symantec, Netskope and Palo Alto Networks to support real-time enterprise network visibility for SASE deployments at the edge.

Traditional network edge security leaves blind spots for threat analysis, detection and response security tools, NetWitness claims. With integrations that interoperate directly with vendor’s SASE nodes, the provider emphasizes real-time packet inspection rather than relying on network logging alone.

SASE nodes are “the centralized choke point for where data is flowing into and out of those remote locations,” NetWitness CTO Ben Smith explained. “It's a very natural place for us to bring our network visibility set of eyeglasses, if you will.”

This integration allows NetWitness to create a copy of traffic flowing through SASE nodes. The copy is sent to one of the NetWitness’ devices and run through the NetWitness architecture to create metadata – additional context around those raw network packets.

For example, during a single network session, NetWitness can identify the type of connections happening within network traffic (e.g., whether a website being accessed is an unencrypted HTTP connection), and provide additional context around where the server that's hosting the website is geographically located so that network analyst teams can identify anomalies and risks in traffic behavior.

From an architectural perspective, Smith said the NetWitness integrations are not in line with vendors’ network infrastructure, which means enterprise customers interact with that metadata through the NetWitness user interface (UI) rather than directly with Symantec’s, Netskope’s or Palo Alto Network’s infrastructure.

“That's a common area of concern with any vendor," Smith told SDxCentral. "If a vendor’s solution stops working or it's not available, is that going to affect the day-to-day operation? Absolutely not. How we are architected is we sit off to the side, we're working with a copy of that traffic.”

Smith added that “depending on the integration,” NetWitness is able to expose metadata to other UIs, such as in the case of a customer using a different provider’s security information and event management (SIEM) platform, to create alerts or specific metadata within their SIEM dashboard.

These integrations with Symantec, Netskope and Palo Alto Networks will be available in the NetWitness Platform 12.3, which Smith said will be out “very shortly ... in weeks, not months, I think it's safe to say.”

Bringing SASE vendors better network visibility

NetWitness said that performing full-packet capture and log monitoring directly on SASE nodes and combining them with all on-premises, cloud and software-as-a-service (SaaS) sources maintains the network security elements SASE brings to the table.

As enterprise networks continue to sprawl across locations and devices, enterprises are grappling with new network edge security problems – a problem that Smith said SASE “by definition is designed to solve.” Organizations that have bought into the SASE vision are doing so in efforts to centralize remote locations, he added, and many are surprised to find how many “blind spots” there are in real-time visibility for their hybrid work environments.

Legacy network and security architectures were not designed for the hybrid work environment where data and traffic travel to dispersed locations across many different devices. This has led to visibility issues for network managers, who have traditionally relied on VPN and proxies to solve that problem. Routing all traffic to specific points increases network complexity and costs, and presents a “massive scaling issue.”

“The blind spots really have come up on the network side," Smith said. "We have not seen so many blind spots on the logging side. But it's that network-level visibility that organizations don't necessarily understand or appreciate. And up until now it's really been hard if you're a SASE provider to bring that type of real-time visibility to downstream customers."

NetWitness is more than just network logging

Traditionally, when organizations think about network security, they're focused on visibility, Smith said. And for most organizations, that visibility conversation often starts with logs and SIEM capability.

“But those of us in the industry realize that visibility is much more than logs,” he added.

SIEM software collects traffic logs from network devices and forwards them to a central logging system to be reviewed by network management teams. “If you think about logs as information that's going to be generated by static devices on a network by applications, databases, it's almost a good look,” Smith said.

Still, logs look back in time at network events that happened in the past. Total network visibility that looks at live network traffic – which can originate from a branch office, remote device or any other resource – is what Smith called “the single source of truth.”

“Looking at that network traffic is going to allow you to see down to the packet level, down to the session level, exactly what is transiting from point A to point B,” he said. “In the SASE architectural model where you have these nodes that all of these remote locations connect up into, that's a very natural place to point these lenses to get a sense of what's flowing in both directions through those nodes.”

In addition to network traffic, the same is true for data exfiltration, which Smith said is key in the midst of increasing data breaches. Real-time data transfer visibility will not show up in a log file, but is easy to see within the context of a network traffic session.

“The reason that we're so happy to be partnered with these other vendors is we think that this network-level visibility for the SASE use case is distinctive. It's different,” he added. “It's actually going to empower the security operations centers that are responsible for securing those organizations. It's going to empower them with that visibility, something that's more than logs, that network-level visibility. It's going to be a single source of truth for what's happening right now.”