It will find application in data centers and the cloud.
/ фото
What is this technology
VMware has presented a new firewall that protects the network at the application level.
The infrastructure of modern companies is built on thousands of services interconnected in a common network. This expands the vector of potential hacker attacks. Classic firewalls can protect against external attacks, however powerless if an attacker has already penetrated the network.
Cybersecurity specialists from Carbon Black , indicate that in 59% of cases, attackers do not stop at compromising a single server. They look for vulnerabilities in related devices and "move" across the network, aiming to gain access to more data.
The new firewall uses machine learning algorithms to identify anomalous activity on the network and alerts the administrator in case of danger.
How it works
Firewall consists of two components: the NSX platform and the AppDefense threat detection system.
The AppDefense system for building a behavioral model of all applications running on the network. Special machine learning algorithms analyze the operation of services and create a "white list" of their actions. Information from VMware's database is also used for its compilation. This is generated based on telemetry provided by the company’s clients.
This list serves as so-called adaptive security policies, based on which the firewall identifies anomalies in the network. The system monitors application behavior and sends a notification to the data center operator if deviations are detected. VMware vSphere tools are used to monitor activity, so the new firewall does not require specialized software to be installed on each host.
As for , is the platform for managing software-defined networks in data centers. Its purpose is to connect firewall components into a single system and reduce maintenance costs. In particular, the system allows the same security policies to be applied across different cloud environments.
You can see the firewall in action in .

/ фото PD
Opinions
The solution is not tied to the architecture and hardware of the target system. Therefore, it can be deployed on a multi-cloud infrastructure. For example, representatives of IlliniCloud, cloud services to government institutions, state that the NSX system helps them balance the load on the network and acts as a firewall in three geographically separate data centers.
Representatives from IDC , state that the number of companies working with multi-cloud infrastructure is steadily increasing. Consequently, solutions that simplify management and protect distributed infrastructure (such as NSX and the firewall built on it) are likely to gain popularity among clients.
Among the downsides of the new firewall, experts highlight the need to deploy software-defined networks. Not all companies and data centers have this capability. Additionally, it remains unclear how a service-defined firewall will affect the performance of services and network bandwidth.
VMware has also tested its product only against the most common types of hacks (such as phishing). It is unclear how the system in more complex cases such as a process injection attack. Currently, the new firewall cannot take measures to protect the network independently; it can only send notifications to the administrator.
Similar solutions
At Palo Alto Networks and Cisco, next-generation firewalls are also being developed to protect network infrastructure across the perimeter. Such a level of protection is achieved through deep traffic analysis systems, intrusion prevention systems (IPS), and virtual private network (VPN) virtualization.
The first company a platform that ensures the security of the network environment through several specialized firewalls. Each of these protects a dedicated environment—there are solutions for mobile networks, cloud, and virtual machines.
The second IT giant offers hardware and software tools that analyze and filter traffic at the protocol and application function levels. In such tools, security policies can be configured, and an integrated database of vulnerabilities and threats for specific applications can be accessed.
It is expected that more companies will offer firewalls that protect networks at the service level in the future.
What we write about in the First Blog on Corporate IaaS:
And in our Telegram channel:
Source: habr.com
