In a major move aimed at extending its Carbon Black extended detection and response (XDR) platform, VMware today introduced its new cloud-native detection and response (CNDR) capabilities to offer visibility and context into containers and Kubernetes environments.
“Containers and modern application frameworks are becoming more and more pervasive,” Jason Rolleston, VP and GM of VMware Carbon Black, told SDxCentral. The transformation has created a unique set of challenges for security operations center (SOC) teams, “because security people aren't necessarily application developers.”
Additionally, their ephemeral nature makes it hard to keep track of containers, which brings new threats and security blind spots. That’s why VMware integrated CNDR capabilities into its XDR platform, aiming to deliver runtime protection for Linux containers.
Rolleston highlighted how the enhanced XDR platform offers threat detection for containers and Kubernetes within a unified platform and dashboard. “For the SOC analyst, we're really providing you one place to go, to give visibility to everything. And then the new alerts that show up for containers show up in the same console that you would see endpoint alerts or workload alerts.”
In addition to its extended visibility, CNDR retains historical data in the cloud for anomaly detection, allowing teams to analyze alerts from previously existing containers.
This solution offers “really strong visibility across everything: deep context; historical data that tracks back what's happened over time, as well as connecting that to what's happening inside the containers; how the containers are interacting with each other. And then we're adding some anomaly detection. So we're looking at the actual behavior of those containers, and trying to identify things that look different from an anomaly perspective, but are in the context of security,” he said.
The new CNDR capabilities for containers and Kubernetes are slated for release within the next six months.
VMware pivots its container security to CNDRVMware has been offering container security capabilities for a few years based on its acquisition of the Kubernetes security startup Octarine. However, the vendor later found that this strategy was “the wrong approach”; not resonating as strongly as it had hoped with its core user base — the Carbon Black users, according to Rolleston.
To address the visibility needs of its Carbon Black users, the vendor made a shift toward CNDR. The functionality should provide complete visibility into the host, the Kubernetes and the container layers, he argues.
“We adjusted and said: Look, let's go full-on runtime visibility. We launched the stuff at the host level first, so that's the system running Kubernetes and running all the containers so you can see what was happening and how the containers were talking. We built out this network map [to] identify what was happening. And then further develop now to bring in EDR [endpoint detection and response], both for the container level and the Kubernetes layer,” Rolleston said.
Should container security be part of XDR or CNAAP?Many cloud security vendors offer container security as part of their cloud-native application protection platforms (CNAPP). But Rolleston argued it fits better within XDR frameworks.
CNAPP involves multiple security tools for the entire application lifecycle, and Rolleston said creating a unified platform to cater to all the requirements will be complicated, if not impossible. “I don't think anybody will build it. What I mean by that is it's so big, right?”
Rolleston argued the operational side and the development and product security functions require fundamentally different solutions. The operational team, he noted, is more concerned about runtime security, whereas the development team focuses on ensuring the security of the applications they are building. Even within VMware, these two teams operate independently, using different tool sets.
VMware’s approach is centered on catering to the needs of its core users — the SOC analysts, who are looking for runtime visibility and protection capabilities to identify threats or rogue or malicious processes within the container and Kubernetes environments.
“SOC is really all about identifying potential issues and responding to those issues and trying to resolve them. That's the operational security side of the house; as opposed to the DevSecOps, [which is concerned with] how do we get an application now that is safe. And those are two different jobs in essence,” Rolleston said.
That’s why VMware offers container security as part of its XDR platform. “Where we're focused is providing for the SOC analyst a tool that effectively detects threats across all those environments, a consistent way of seeing and identifying those threats, investigating those threats, getting highly contextual data that has network and endpoint natively married, that has the context of the container and the repository, having all of that stitched really well to help provide better detections but also much more rapid investigation and response,” he added.
Comments