NETWORK FUNCTIONS VIRTUALIZATION FOR SECURITY (NFV-S)



Similar documents
Wedge Networks: Transparent Service Insertion in SDNs Using OpenFlow

Delivering Managed Services Using Next Generation Branch Architectures

Virtualization, SDN and NFV

Unified Threat Management, Managed Security, and the Cloud Services Model

Management and Orchestration of Virtualized Network Functions

TRITON APX. Websense TRITON APX

Understanding the Business Case of Network Function Virtualization

VIRTUALIZING THE EDGE

Many network and firewall administrators consider the network firewall at the network edge as their primary defense against all network woes.

Getting on the Road to SDN. Attacking DMZ Security Issues with Advanced Networking Solutions

Panel: Cloud/SDN/NFV 黃 仁 竑 教 授 國 立 中 正 大 學 資 工 系 2015/12/26

SDN PARTNER INTEGRATION: SANDVINE

RIDE THE SDN AND CLOUD WAVE WITH CONTRAIL

Securing Virtualization with Check Point and Consolidation with Virtualized Security

Private Clouds. Krishnan Subramanian Analyst & Researcher Krishworld.com. A whitepaper sponsored by Trend Micro Inc.

WildFire. Preparing for Modern Network Attacks

The Virtual Ascent of Software Network Intelligence

Network Virtualization Solutions - A Practical Solution

Pervasive Security Enabled by Next Generation Monitoring Fabric

COUNTERSNIPE

The 5G Infrastructure Public-Private Partnership

IT Infrastructure Services. White Paper. Utilizing Software Defined Network to Ensure Agility in IT Service Delivery

IT Security at the Speed of Business: Security Provisioning with Symantec Data Center Security

NFV: Addressing Global Challenges for Telecom Service Providers

The Dirty Secret Behind the UTM: What Security Vendors Don t Want You to Know

ONOS [Open Source SDN Network Operating System for Service Provider networks]

Trend Micro InterScan Web Security and Citrix NetScaler SDX Platform Overview

BlackRidge Technology Transport Access Control: Overview

Network Function Virtualization Primer. Understanding NFV, Its Benefits, and Its Applications

Hybrid Cloud Architecture: How to Streamline Hybrid Cloud Migration

Driving SDN Adoption in Service Provider Networks

The Advantages of Security as a Service versus On-Premise Security

Network Functions Virtualization (NFV) for Next Generation Networks (NGN)

Reduce Your Network's Attack Surface

Transforming Service Life Cycle Through Automation with SDN and NFV

SOFTWARE DEFINED NETWORKING

A Presentation at DGI 2014 Government Cloud Computing and Data Center Conference & Expo, Washington, DC. September 18, 2014.

REMOVING THE BARRIERS FOR DATA CENTRE AUTOMATION

Public Clouds. Krishnan Subramanian Analyst & Researcher Krishworld.com. A whitepaper sponsored by Trend Micro Inc.

SDN and FTTH Software defined networking for fiber networks

Software defined networking. Your path to an agile hybrid cloud network

ADVANCED SECURITY MECHANISMS TO PROTECT ASSETS AND NETWORKS: SOFTWARE-DEFINED SECURITY

Top 10 Reasons Enterprises are Moving Security to the Cloud

U s i n g S D N - and NFV-based Servi c e s to M a x i m iz e C SP Reve n u e s a n d I n c r e ase

Definition of a White Box. Benefits of White Boxes

Deploying Firewalls Throughout Your Organization

WHAT S NEW IN WEBSENSE TRITON RELEASE 7.8

Firewalls. Securing Networks. Chapter 3 Part 1 of 4 CA M S Mehta, FCA

The Role of Virtual Routers In Carrier Networks

The Mandate for a Highly Automated IT Function

Horizontal Integration - Unlocking the Cloud Stack. A Technical White Paper by FusionLayer, Inc.

10 Strategies to Optimize IT Spending in an Economic Downturn. Wong Kang Yeong, CISA, CISM, CISSP Regional Security Architect, ASEAN

The Hillstone and Trend Micro Joint Solution

Intel DPDK Service Offerings

The Distributed Cloud: Automating, Scaling, Securing & Orchestrating the Edge

SDN and NFV in the WAN

OpenNaaS: an European Open Source framework for the delivery of NaaS An enabler for SDN and NFV

CoIP (Cloud over IP): The Future of Hybrid Networking

Software Defined Network (SDN)

The New IP Networks: Time to Move From PoC to Revenue

Scalable Network Monitoring with SDN-Based Ethernet Fabrics

How To Switch A Layer 1 Matrix Switch On A Network On A Cloud (Network) On A Microsoft Network (Network On A Server) On An Openflow (Network-1) On The Network (Netscout) On Your Network (

Lot 1 Service Specification MANAGED SECURITY SERVICES

Business Case for Virtual Managed Services

Asia Pacific Partner Summit 2015

Branches as Nimble as the Cloud: Unleashing Agility with Nuage Networks Virtualized Network Services EXECUTIVE SUMMARY

Security Overview and Cisco ACE Replacement

Leveraging SDN and NFV in the WAN

Driving Success in 2013: Enabling a Smart Protection Strategy in the age of Consumerization, Cloud and new Cyber Threats. Eva Chen CEO and Co-Founder

What is SDN all about?

Customer Benefits Through Automation with SDN and NFV

Software Defined Networking (SDN) Networking excellence Maniyan Sundaresan

Use Cases for the NPS the Revolutionary C-Programmable 7-Layer Network Processor. Sandeep Shah Director, Systems Architecture EZchip

NEC s Carrier-Grade Cloud Platform

Extreme Networks: A SOLUTION WHITE PAPER

Juniper Solutions for Turnkey, Managed Cloud Services

SDN Security Considerations in the Data Center. ONF Solution Brief October 8, 2013

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

Security MWC Nokia Solutions and Networks. All rights reserved.

Product Factsheet MANAGED SECURITY SERVICES - FIREWALLS - FACT SHEET

The Promise and the Reality of a Software Defined Data Center

Taking the Open Path to Hybrid Cloud with Dell Networking and Private Cloud Solutions

Who moved my cloud? Part I: Introduction to Private, Public and Hybrid clouds and smooth migration

Foundation for High-Performance, Open and Flexible Software and Services in the Carrier Network. Sandeep Shah Director, Systems Architecture EZchip

CLOUD & Managed Security Services

How To Protect A Virtual Desktop From Attack

Strategic Direction of Networking IPv6, SDN and NFV Where Do You Start?

FROM A RIGID ECOSYSTEM TO A LOGICAL AND FLEXIBLE ENTITY: THE SOFTWARE- DEFINED DATA CENTRE

Networks that know data center virtualization

ALCATEL-LUCENT ENTERPRISE DATA CENTER SWITCHING SOLUTION Automation for the next-generation data center

Why Choose Integrated VPN/Firewall Solutions over Stand-alone VPNs

Chapter 11 Cloud Application Development

+ web + DLP. Secure 1, 2, or all 3 with one powerful solution. The best security you can get for one or for all.

Application Defined E2E Security for Network Slices. Linda Dunbar Diego Lopez

Transcription:

NETWORK FUNCTIONS VIRTUALIZATION FOR SECURITY (NFV-S) 2014/03/03 Wedge Networks Whitepaper Document: WEDGE-NFV-S.V1.0 Wedge Networks www.wedgenetworks.com

(This page intentionally left blank for presentation purposes) Page 1

TABLE OF CONTENTS TABLE OF CONTENTS...2 TABLE OF FIGURES...3 INTRODUCTION...4 The New Paradigm in Providing Network Security...4 The Benefits...5 Wedge Networks Cloud Security Platform : Network Security Services...5 Expandable Platform Future Services...6 Built-In Market-Ready Security Services...6 ABOUT WEDGE NETWORKS...7 Page 2

TABLE OF FIGURES FIGURE 1: THE OLD WAY OF PROVIDING SERVICES VS. THE NEW WAY... 4 FIGURE 2: WEDGE NETWORKS CLOUD SECURITY PLATFORM ARCHITECTURE... 5 FIGURE 3: WEDGEOS OPEN SERVICE BUS... 6 Page 3

INTRODUCTION Network Functions Virtualization will deliver many benefits for network operators and their partners and customers whilst offering the opportunity to create new types of ecosystems which will encourage and support rapid innovation with reduced cost and reduced risk. -NFV Introductory Whitepaper, SDN and OpenFlow World Congress, Darmstadt, Germany The New Paradigm in Providing Network Security Information security is mission critical for any organization. The rapid shift to cloud, mobility, and consumerization of IT has exposed many new security vulnerabilities, leading to another generation of even more sophisticated and severe security breaches. At the same time, security solutions have been slow to react to this fundamental change and often become unwieldy in today s networks. Many of which are composed of proprietary hardware appliances. locked into racks and difficult to change driving up both the CAPEX and OPEX and leaving networks exposed. Adding new network functions (security functions or other) typically entails the integration of more of these hardware appliances with space and power constraints becoming an increasing issue, along with time to market concerns for these new functions. As a result, Network Operators are now endorsing Network Functions Virtualization (NFV) for the agility and adaptability to meet new service delivery requirements. However, current generations of network security functions virtualization are simply repackaged VM systems with third party pieces cobbled together in piecemeal fashion. They cannot satisfy the automation, scalability, and robustness of today s network security operations. Network Functions Virtualization for Security (NFV-S) virtualizes the network and brings advanced network security capabilities into virtualized functions - all in a complete, standardized and elastic solution. It enables seamless automation and orchestration across multiple cloud platforms and unleashes untapped potential of network security functions that can scale up and down with network resources as required. The Old Way The New Way FIGURE 1: THE OLD WAY OF PROVIDING SERVICES VS. THE NEW WAY Page 4

The Benefits NFV-S is a new approach through which Network Operators can quickly build, deploy and scale new network security services. It markedly reduces the typical lengthy timeframe to roll out innovative new services and provides the following benefits: All-Software Platform - Runs on standard of-the-shelf hardware without reliance on any specialized hardware ASICs or accelerators; doing away with the need for proprietary hardware appliances. Elastic, Auto-Scaling Platform - Built to utilize multi-threading functions, cloud infrastructure and virtualization. NFV-S can quickly, automatically and dynamically start new instances using the multi-cored or cloud capabilities of the underlying runtime environment. Elastic auto-scaling performance provides robustness and can use local resources or federated clouds, ensuring that network peaks are adequately handled. Comprehensive Security Functions - Powered by both a Patented Deep Content Inspection Engine and Deep Packet Inspection Engine, all current and future network security functions can be implemented with high performance and robustness. It is pre-bundled with a set of award winning security applications such as email security, web security, web application firewall, DLP, APT defense, content filtering, and mobile data security. Wedge Networks Cloud Security Platform : Network Security Services FIGURE 2: WEDGE NETWORKS CLOUD SECURITY PLATFORM ARCHITECTURE The Wedge Networks Cloud Security Platform (hereinafter, Wedge Platform ), powered by the WedgeOS, provides a smooth transition with automatic provisioning and dynamic service chaining in cloud environments that run on x86-based servers. Customers can mix & match Page 5

servers from different vendors and computation services from different cloud providers, allowing them to unleash the potential of the NFV-S enabled Wedge Platform. Expandable Platform Future Services FIGURE 3: WEDGEOS OPEN SERVICE BUS With its Open Service Bus feature, WedgeOS provides standardized interfaces through which most existing network security functions can be easily plugged into, allowing provision of these services at the network layer. Standardization also enables future technologies and services to be integrated as they develop. Built-In Market-Ready Security Services Current security services available on the Wedge Platform are already deployed in both operator and enterprise environments. These include: Anti-Malware Anti-Spam Data Loss Prevention URL Filtering Mobile Devices Security Educational Institution Security IDS/IPS Web Application Firewall Next Generation Firewall Advanced Persistent Threats Page 6

ABOUT WEDGE NETWORKS Wedge Networks is transforming the way security is delivered. Powered by the innovative WedgeOS the Wedge Networks Cloud Security Platform is designed to combat the shifting threat landscape associated with the consumerization of IT. Unlike first generation security products, cloud-assisted appliances or even dedicated security clouds, the Wedge Platform enables inline inspection of both inbound and outbound traffic embedded within the cloud layer across all platforms and device types without latency. The Wedge Platform is deployed globally, delivering security protection for tens of millions of users in Fortune 500 companies, government agencies, Internet service providers, and across all industry verticals. Wedge Networks is headquartered in Calgary, Canada and has international offices in Sunnyvale, USA; Beijing, China; and Manama, Bahrain. Contact Wedge Networks For more information 238, 3553-31 Street NW Calgary, Alberta Canada T2L 2K7 Office: (403) 276-5356 Fax: (403) 276-5568 Info@wedgenetworks.com Page 7