Container networking startup Tetrate is aiming to help enterprises simplify the management and consistency of security policies between different layers of the network stack.
Tetrate is launching a new capability within its Tetrate Service Bridge (TSB) platform — set for general availability on Sept. 18 — that enables the automatic generation of container network interface (CNI) policies from layer 7 application policies. The goal is to help enforce consistency between layer 4 and layer 7 (also referred to as L4 and L7) security policies to avoid potential conflicts that could lead to security issues. Layer 4 on the OSI stack refers to the transport layer, while layer 7 refers to the application layer.
The new capability in TSB follows guidance that has been defined in the zero-trust architecture model published by the National Institute of Standards and Technology (NIST).
TSB is a superset of capabilities that offers additional security and availability on top of the popular Istio and Envoy open-source service mesh technologies.
"TSB is a global management and control plane that federates and supervises many Istio instances," David Wang, head of product at Tetrate, told SDxCentral. "The real value of TSB, however, is helping multicloud, multi-team, multi-environment organizations like financial services, government and retail deploy, secure and run microservices more easily with Istio and Envoy."
Enforcing zero trust with L7 and L4A core element of zero-trust security is default deny, which means that all traffic is blocked by default until explicitly allowed. Working across different layers of the networking stack can potentially lead to conflicts and inconsistencies between access control policies.
Wang said that in the NIST guidance for zero-trust for cloud-native deployments, it recommends a reference architecture for implementing multi-tier policies. He noted that the reference architecture does not prescribe how the L4 policy should operate in harmony with the L7 service mesh policy. Wang emphasized, however, that it's crucial that the policies in both layers align as otherwise security breaches or outages can occur.
The new TSB automatic network policy generation feature facilitates the proactive reconciliation of L4 and L7 policies.
"Prior to this update — similar to open-source Istio and other service mesh solutions that operate at layer 7, TSB did not generate CNI network policies," Wang said. "The change in this release is that TSB now generates L4 CNI policies based on L7 policies."
The challenges of L4 and L7 policy consistencyAccording to Wang, L4 and L7 policies are supposed to work in harmony in different layers in the networking stack, operating on the same intent, protecting the same resources and setting comparable rules.
However, prior to the new TSB update, the reality was that L4 and L7 policies could drift into discord because many teams incrementally change these policies as needed.
"When policies mismatch, outages or security breaches can occur," Wang said.
To avoid the mismatch, organizations need to do some form of periodic reconciliation of L4 CNI policies with L7 service mesh policies. This task typically falls on operator manual effort. Making matters worse, Wang noted that operators often take a reactive approach, discovering policy mismatches or conflicts from outages or security breaches, then fixing the error retroactively. Until this update, he said that proactive reconciliation was out of the question because it took too much effort.
"After this update, having a TSB-generated L4 policy reference shifts the operator into a proactive, prevention mode," Wang said. "The availability of this reference L4 policy cuts down the mental effort required to reconcile L4 and L7 policies, reducing the likelihood of conflicting policies at different layers and making the system more secure and available."
Comments