There are billions of reasons why network security needs to be pushed to the edge — more than 5 billion mobile technology users worldwide and more than 9 billion mobile-ready devices and IoT connections, by Cisco’s count. And all of these people and machines connect to enterprise networks.
As companies use more clouds and rely on a growing number of IoT devices and sensors, and as more employees work remotely using mobile devices, it’s easy to do business from anywhere. But this puts a strain on security because there are so many more network connections, and all of these connections need to be secure.
In other words, security needs to be anywhere and everywhere, too. It needs to be distributed, and close to cloud services, end users, and devices that are spread around the world to enable high-bandwidth, low-latency connections. Otherwise there’s a tradeoff between performance and security.
Considering all this, when Netskope last week announced that it was building an edge infrastructure to support its cloud security platform it seemed like an "ah-ha" moment. Of course, vendors should use distributed network infrastructure to support their security platforms, which is what Netskope is doing with NewEdge.
Why isn’t everyone taking this approach?
“It’s very, very hard,” Joe DePalo, senior vice president of platform engineering and operations at Netskope, told me. “Maybe 200 people in the world can build an edge infrastructure like this. We have the expertise and the IP.”
Netskope has a head start in this regard. But as networking and security become more closely intertwined, I’m betting that this will be the security architecture of the future.
Elastic Cloud GatewaysDoug Cahill, senior analyst at ESG, believes it will be as well. “We also think once these services are available, the deployment model is so much easier than the traditional network model,” he added. “You don’t have to redesign, rearchitect your network for a new type of security control because you are consuming a cloud service.”
ESG calls what Netskope and others are doing “Elastic Cloud Gateways.” These ECGs provide direct-to-cloud connectivity while also brokering access between end users, cloud services, and applications and inspecting the traffic that’s traveling between these channels. ECGs also converge different types of network security controls and gateways: web gateways, cloud access security brokers (CASBs), and software-defined perimeters. And then they fold in domain name system (DNS) security and data loss prevention.
“The ‘elastic’ piece is this notion that it’s truly cloud native,” Cahill said. “You can lift and shift a VM-based security tool to the cloud today, but it’s not cloud native.”
Cloud native is important because it provides scalability, but also because it’s the economic model that customers want, he added. “They want a consumption-based pricing model. As I have more users using cloud applications, I use more compute in the cloud, then I should be metering at the same relative level how I’m paying for my cloud security services.”
Another thing about this approach to security is that it needs to be deployed at the edge. “To yield the performance benefits, I’m not going to backhaul through the corporate network,” Cahill said.
In addition to Netskope, which started as a CASB, other security vendors including Zscaler are moving toward ECG. So is Palo Alto Networks with its new Prisma cloud security suite. “And we could consider Cisco’s Umbrella to be an example of ECG from OpenDNS,” which Cisco acquired in 2015, he added. “We see a lot of vendors heading this way, and we do see this as the way all should or will move in the future.”
Netskope Leads the PackFrom where I sit, Netskope is out in front of the competition with its ECG technology and in building out a distributed network to support its security cloud. “I think we are ahead of everybody, but it’s all going that direction,” DePalo said.
The vendor says it will deploy more than 50 points of presence (POPs) across the globe (25 are live now) this year, supporting hundreds of millions of concurrent connections. And it plans to add two new POPs per week and have more than 100 locations by 2020.
It’s putting POPs in carrier-based facilities, some larger colocation facilities, and mini edge data centers. As companies like Vapor IO, Packet, and MobiledgeX work to build out an edge infrastructure — Kinetic Edge Alliance, for example, is targeting the top 30 metro markets in the U.S., which cover about half of the population — other security vendors would be smart to take note and team up with these colocation providers and edge infrastructure companies.
When it comes to killer edge use cases, security sits high on the list. And security companies should start pushing their platforms to the edge. Otherwise they risk falling into irrelevance.
Comments