SAN FRANCISCO – VMware announced several advancements in its NSX SDN and Carbon Black security platforms at this week’s VMware Explore 2022, including a centralized cloud console for networking and security in the hybrid, multicloud environment.
“Project Northstar will be the hub that allows you to create seamless and secure connectivity across private and public [clouds], and have a true cross-cloud service delivered in a multicloud infrastructure,” explained Tom Gillis, SVP and GM of VMware’s Networking and Advanced Security business group.
Announced in technology preview today, the project offers a centralized console for consistent software-as-a-service (SaaS) consumption of VMware’s networking and security offerings including network and security policy management, network detection and response (NDR), NSX Intelligence network visibility and analytics, advanced load balancing, and HCX workload mobility for private cloud and VMware Cloud deployments.
“We've taken the management plane for this virtual networking infrastructure, and we're delivering it as a service,” Gillis said.
With the introduction of vSphere 8, VMware now has the ability to run the networking and security services on data processing units (DPUs, also known as SmartNICs) connected to the host hypervisor to offload the CPUs. This address the needs of network-intensive and latency-sensitive applications.
“That makes a very strong economic argument for using the SmartNICs, plus it gives you that operational efficiency and that you can run very high levels of throughput from any given node,” Gillis touted.
Lateral Security Is the New BattlegroundFor years, organizations have deployed security solutions on the endpoints and next-generation firewalls at the perimeter, but ransomware attacks are still happening with increased frequency and severity.
The cause behind all this is “attackers have a motivation to get in your network and stay in,” Gillis argues. “This is why we say that lateral security is the new battleground.”
The company’s recent Global Incident Response Threat Report found that lateral movement was seen in 25% of all attacks.
“VMware has a unique vantage point that gives us an intrinsic advantage in understanding the inner workings of these applications so we can spot these lateral movements of attackers,” Gillis said.
For traditional virtual machine-based applications, the vendor offers an “end-to-end view” with the Carbon Black endpoint security services; while for container-based modern applications, “the API is the new endpoint, so you need to be able to understand, observe, and protect those internal APIs to stop the lateral movement of these attacks,” he added.
To extend the API security and analytics capabilities, VMware introduced Project Trinidad, which deploys sensors on Kubernetes clusters and uses machine learning with business logic inference to detect anomalous behavior in east-west traffic between microservices.
“We've brought advanced machine learning business logic inference, an API called sequence modeling into our service mesh capability that allows us to understand and protect those APIs and see all of the connections in every conversation,” Gillis explained.
Additionally, at this year’s event, the vendor also announced the expansion of network detection and visibility to its Carbon Black Cloud endpoint protection platform; introduced Project Watch, a multicloud networking and security capability that provides advanced app-to-app policy controls; and unveiled the NSX Advanced Load Balancer with new bot management capabilities.
Read all of SDxCentral’s VMware Explore 2022 coverage here.
Comments