This page was machine-translated and may differ from the original. View original

VMware Unveils Service-Defined Firewall to Reduce Attack Surface in On-Premise and Cloud Environments

Google 우선 소스Published2019.03.11 09:50
| Through internal firewall solutions
| At the network and host level
| Protects normal activities and reduces the attack surface


On the 11th, VMware unveiled 'VMware Service-defined Firewall,' which reduces the attack surface in on-premises and cloud environments.

VMware Service Definition Firewall

VMware Service-Defined Firewall is characterized by combining high application visibility, an understanding of known good application activity, and intelligent, automated, adaptive firewall capabilities to support safer protection of applications, data, and users.

VMware announced a new security approach at the 'RSA Conference 2019' held in San Francisco, USA. VMware's security strategy focuses on reducing the attack surface rather than tracking unknown threats, shifting from the existing security model focused on 'chasing bad' to 'ensuring good', and focusing on the applications themselves rather than the infrastructure. By implementing inherent security in an infrastructure stack that includes VMware technology, enterprises can protect the normal operation of applications and significantly reduce risks to critical applications, sensitive data, and users.

Tom Gillis, VMware Vice President and General Manager of Network and Security, said, “The inherent security implemented by VMware leverages the unique characteristics built into the virtualization platform,” adding, “The newly unveiled VMware Service-Defined Firewall focuses on defending internal networks and verifies applications performing normal activities rather than tracking threats.”

Existing solutions used methods to install agents in the guest environment, but these agent-based solutions added complexity and had limitations in that the agent could be bypassed if an attacker obtained root privileges and controlled the host. As applications recently run in distributed environments, there is a growing need for distributed security as well.

VMware Service-Defined Firewall operates in bare metal, virtual machine, and container-based application environments, and will also support hybrid cloud environments such as VMware Cloud on AWS and AWS Outposts. Additionally, enterprises can use the VMware Service-Defined Firewall solution as a standalone firewall solution.

The characteristics of VMware service-based firewalls are as follows.

Application Authentication Cloud
VMware Service Defined Firewall can gain a high level of understanding of applications and hundreds or thousands of microservices through changes over time on the host. The Application Authentication Cloud leverages the intelligence of millions of virtual machines worldwide to accurately build an information map of the application's planned healthy state. Once the application's healthy state is authenticated, this solution can generate adaptive security policies capable of Layer 7 functionality and health checks.

Protection from guests
VMware Service Defined Firewall solutions leverage inherent capabilities to inspect guest operating systems and applications without remaining in the guest environment, ensuring that even if an attacker gains root access, they cannot breach the security network of the Service Defined Firewall. VMware Service Defined Firewall solutions present a new approach to network firewalls and host IPS, such as detecting and blocking suspicious traffic on the network while the OS and applications are running.

Firewall distribution within the software
The traditional approach to hardware firewalls involves diverting traffic for scanning from a virtual environment to a hardware appliance using hairpinning (or NAT loopback, a method of accessing services from an internal network using public IP addresses). For modern applications involving services and components running across heterogeneous clouds and multiple servers, this approach is difficult to scale and inefficient. The software-based VMware Service-Defined Firewall runs at the point where applications operate across the cloud and supports consistent policies without complex traffic hairpinning across the cloud environment.

Meanwhile, VMware collaborated with global security company Verodin to demonstrate the effectiveness of service-defined firewalls. VMware utilized Verodin’s Security Instrumentation Platform (SIP) to verify whether the VMware service-based firewall could effectively identify and defend against known and potential threats, and succeeded in detecting and defending against 100% of suspicious attacks in detection and prevention modes.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자