{"id":46225,"date":"2021-11-03T13:31:10","date_gmt":"2021-11-03T05:31:10","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=46225"},"modified":"2021-11-03T13:31:14","modified_gmt":"2021-11-03T05:31:14","slug":"network-and-data-center-security","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/11\/03\/network-and-data-center-security\/","title":{"rendered":"Network and data center security"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Guy Matthews<br>Editor, NetReporter<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Surviving the pandemic has tested everybody\u2019s powers of endurance. For individuals, and for enterprises everywhere, it has been a troubling and disruptive time. For many businesses it has been a matter of adapting at light speed to ensure survival. It has also seen several tectonic shifts at the level of IT, either accelerating trends that were already in progress or creating fresh waves, the implications of which still unfolding.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cFirstly there was a shift towards the cloud and enterprise digitalization as people dispersed to work remotely,\u201d notes Mauricio Sanchez, Research Director, Network Security &amp; Data Center Appliance, SASE Market Research, Dell\u2019Oro Group. \u201cWe saw enterprises that hadn\u2019t necessarily been particularly digital, as far as their clients and workers were concerned, suddenly having to dial that in. Then there was the conversation about every business&#8217;s online digital experience from a security perspective.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was an uncertain time even for seasoned security practitioners, he says: \u201cThen this summer, ransomware hits the front pages with companies like Colonial Pipeline getting hit hard by a massive outage of their facilities. More recently we\u2019ve seen Russia\u2019s Yandex suffer one of the largest DDoS attacks in history. Cyber threats weren\u2019t slowed down by the pandemic. In fact, they have probably accelerated in many respects.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Figure 1: Out with the old<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1.jpg\" alt=\"\" class=\"wp-image-46226\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-1-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Changes in working patterns, in tandem with a rising tide of security threats, forced a lot of enterprises to think about their reliance on legacy network architecture, believes Sanchez: \u201cThe classic hub and spoke model that has worked for many decades was in doubt. It was a tried and trusted model, good at protecting the inside of the corporate network, with everything backhauled to that data center at the heart. A lot of enterprises have started to understand that this architecture no longer fits what&#8217;s needed, and that\u2019s led to a new class of architecture solutions matched by some new enabling technologies.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not least of these has been SASE, or the secure access service edge: \u201cWe see this as the next wave in networking,\u201d claims Sanchez. \u201cThe vendor community has responded to enterprise pressure with this intersection of networking and security, by providing a converged networking and security solution.\u201d &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Figure 2: SASE \u2013 a natural evolution<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2.jpg\" alt=\"\" class=\"wp-image-46227\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2021\/11\/figure-2-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">So what, wonders Sanchez, are the top security threats enterprises facing today? To help answer this he spoke to a panel of seasoned security professionals from around the world of commerce.&nbsp; &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gail Coury, Senior Vice President and Chief Information Security Officer with security vendor F5 Networks, sees the challenge as multi-faceted: \u201cAt F5 we have moved so many of our applications out of our data centers,\u201d she says. \u201cOne of our top goals is to be completely out of that business. If you look at how our workers do their work today, remotely from their home offices, they are very rarely getting on a VPN. But now we have an expanded attack surface, with some applications still in an on-premise data center, others protected by SASE, many in multiple clouds around the world helping us manage our employees and support our customers. We see threats to applications, threats to the end user, threats to the devices users are connecting from.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers are busily adapting to the new defensive measures that everyone is putting in place, believes Jordan LaRose, Director of Consulting and Incident Response with security vendor F-Secure: \u201cWe have new technologies to stop classical attacks, like ransomware,\u201d he says. \u201cIt&#8217;s funny that I&#8217;m saying ransomware is classical, as it&#8217;s only been around for a couple of years. But that&#8217;s how quickly the industry is moving nowadays. I\u2019d add that ransomware attackers are not just targeting computers anymore, they also target key servers, key users on the network, exfiltrating intellectual property, or blackmail information, or anything they see as valuable that they can take and base a ransom on. They&#8217;ll hold it hostage and say if you don&#8217;t pay us this money we&#8217;re going to leak this information to the public Internet. This is a big challenge for the industry because protection now needs to target the entire network.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s a need, he says, for the tech industry to increase security even more, to cover not just an enterprise\u2019s \u2018crown jewels\u2019, but also to make sure that nothing unintentional goes in or out: \u201cSo not just your key database, but your CFO\u2019s laptop that he&#8217;s got sitting on his desk at home in Florida.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The nature of today\u2019s highly distributed organisations makes the job of security much harder, notes Vivek Bhandari, Sr. Director of Product Marketing, Networking and Security Business Unit with VMware. \u201cApps are everywhere, users are everywhere, we have all kinds of devices,\u201d he says. \u201cArchitectures are fundamentally changing with containerized applications, and with so many components spread across multiple clouds. It has created a field day for attackers because now the attack surface has exponentially grown. It&#8217;s become so much easier now for attackers to find their way in.\u201d &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another source of worry for Bhandari is the area of Zero Day exploits: \u201cCompared to the last two years, in 2021 alone we have seen more than two times the use of Zero Day exploits in the wild. This is something for which a lot of traditional security defences, that rely on signatures or known behavior, can&#8217;t react to. It\u2019s like somebody with a mask on masquerading as something they are not.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dr Ronald Layton, Vice President, Converged Security Operations with Sallie Mae Bank, wants to see budgets for security expand in line with those for other tech services: \u201cLaw enforcers should adopt a more collaborative approach, just like we do in the private market where we&#8217;ll pick the phone up and call a friend who&#8217;s the CISO and ask what they are seeing,\u201d he says. \u201cWe are all better when we collaborate, and the bad actors have picked this up rapidly. They&#8217;ve always been effective collaborators on the offensive side, better than on the defensive side which is where we all play.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Coury of F5 Networks finds it useful to leverage her experience as the former head of a business facing multiple security headaches: \u201cBefore I took the role of CISO at F5, I was general manager for one of our online security services business where we were protecting hundreds of customer environments against DDoS attacks,\u201d she explains. \u201cDDoS-as-a-service is something that the hackers have gone into. I also want to mention bot traffic and credential stuffing traffic that is focused on applications.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So what are the solutions out there that enterprises should be thinking about, in the face of all these fast evolving threats?&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bhandari of VMware is a believer in Zero Trust as a paradigm: \u201cWhat we&#8217;re beginning to see is organizations start thinking of securing end user traffic with solutions like SASE and ZTNA,\u201d he says. \u201cLook at all the stuff that&#8217;s happening within the cloud and across clouds, with almost every organization now shifted to a multi-cloud strategy where applications are hosted.&nbsp; We have to secure workload access as well, and it&#8217;s not only about user access.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Coury of F5 Networks wants more done to integrate security: \u201cI\u2019m talking about API security, and how micro services connect to each other. How do you secure the data?&nbsp; The data itself should be independently protected. How do you secure the user, how do you have positive strong identity, and then how do you make sure you authenticate the device? You must know that device is healthy before you allow that connection to occur, and this is all because we don&#8217;t have that perimeter anymore. This is why we have to change the way we think about security.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By way of conclusion, LaRose of F-Secure notes that he always says to clients who are either in the middle of or recovering from a cyber-attack, there is no silver bullet for security. &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThere&#8217;s no one piece of software that&#8217;s going to solve all of your problems,\u201d he concludes. \u201cI wish there was, it would make my job a lot easier. But, unfortunately, it&#8217;s all about understanding all of the different levels of technology, all the different levels of risk, and identifying the right solution for each one of those individual pieces.\u201d&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So what are the solutions out there that enterprises should be thinking about, in the face of all these fast evolving threats?\u00a0<\/p>\n","protected":false},"author":6,"featured_media":46228,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,54,96,2727,1656],"class_list":["post-46225","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-security","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/46225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=46225"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/46225\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/46228"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=46225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=46225"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=46225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}