VMware today announced the general availability of VMware Live Recovery, which offers disaster and ransomware recovery capabilities for VMware Cloud Foundation environments.
Businesses today face unprecedented challenges in cybersecurity, Mark Chuang, head of product marketing for VMware Cloud Foundation at Broadcom, told SDxCentral. Sophisticated cyberattacks with fileless malware and long dwell times make reinfection during recovery a risk. Other challenges include manually integrating and testing multiple point products for recoveries such as on-premises backups and cloud storage, relying on completely manual ransomware recovery runbooks, and juggling multiple management consoles and licensing across on-premises and cloud for different solutions.
To address these multifaceted challenges, the vendor launched VMware Live Recovery, which leverages Broadcom Carbon Black for some ransomware detection and recovery capabilities. VMware acquired Carbon Black in 2019 for about $2.1 billion and later used its technology for Advanced Security for VMware Cloud Foundation. After Broadcom closed its $69 billion acquisition of VMware, Carbon Black was moved to operate as an autonomous business unit within Broadcom. While it no longer reports to VMware, the collaboration continues.
VMware Live Recovery has three key components:
- Next-generation antivirus technology from Carbon Black with behavioral analysis for fileless malware identification and containment. Chuang said the protection strategy is dual-layer, using a next-generation antivirus and running that live in production while doing regular backups.
- An isolated recovery environment that uses VMware's public cloud capacity to create a quarantined and controlled space for workload validation. When customers power up the backup at the restore point, VMware will put the Carbon Black sensors into the isolated environment and inject them into the virtual machines automatically to observe the behavior of the backup copy and look for suspicious behaviors, Chuang said.
- Virtual machine network isolation for each workload during the validation in the isolated recovery environment to prevent lateral movement and reinfection of the production site.
In addition to the ransomware recovery, the new solution also added new features to the disaster recovery use cases such as customizable recovery point objectives as low as one minute, available with vSphere Replication, and the extension of on-premises disaster recovery to the public cloud paired with full-featured cyber recovery.
VMware Live Recovery offers unified managementTraditionally, organizations had to stitch together multiple products to cover modern cyber recovery and traditional disaster recovery needs. VMware Live Recovery unifies these critical capabilities in a single solution.
The solution has two underlying technologies, including VMware Live Cyber Recovery (formerly VMware Cloud Disaster Recovery/Ransomware Recovery) and VMware Live Site Recovery (formerly VMware Site Recovery Manager).
“It is about providing unified protection for both the ransomware recovery use case and the traditional disaster recovery use case. We're able to provide this protection for workloads that are running on premises as well as in the public cloud,” Chuang said. “And one of the new aspects of this solution is a unified management experience.”
The VMware Live Recovery offers a centralized management interface that allows organizations to view and manage their deployment of protected workloads across use cases and regions.
It also simplified consumption via a single subscription for both ransomware and disaster recovery capabilities with flexible licensing for workloads running on-premises, or virtual machines running on VMware Cloud on Amazon Web Services (AWS) and Google Cloud VMware Engine, according to Chuang.
Comments