Security in the Software Defined Data Center



Similar documents
Architecting and Building a Secure and Compliant Virtual Infrastructure and Private Cloud

Shifting Roles for Security in the Virtualized Data Center: Who Owns What?

VMware vcloud Networking and Security Overview

Keith Luck, CISSP, CCSK Security & Compliance Specialist, VMware, Inc. kluck@vmware.com

Software Defined Data Centers Network Virtualization & Security. Jeremy van Doorn Director of Systems Engineering EMEA, Network & Security

VMware vcloud Networking and Security

How To Build A Software Defined Data Center

How To Protect Your Virtual Infrastructure From Attack From A Cyber Threat

(R)Evolution im Software Defined Datacenter Hyper-Converged Infrastructure

White Paper. Juniper Networks. Enabling Businesses to Deploy Virtualized Data Center Environments. Copyright 2013, Juniper Networks, Inc.

Netzwerkvirtualisierung? Aber mit Sicherheit!

Intro to NSX. Network Virtualization VMware Inc. All rights reserved.

Sichere Virtualisierung mit VMware

How Network Virtualization can improve your Data Center Security

Private Clouds. Krishnan Subramanian Analyst & Researcher Krishworld.com. A whitepaper sponsored by Trend Micro Inc.

How To Protect Your Cloud From Attack

VMware Software Defined Network. Dejan Grubić VMware Systems Engineer for Adriatic

Business Values of Network and Security Virtualization

Effective End-to-End Cloud Security

Secure Cloud Computing

E-Guide HOW THE VMWARE SOFTWARE DEFINED DATA CENTER WORKS: AN IAAS EXAMPLE

Public Cloud Service Definition

1518 Best Practices in Virtualization & Cloud Security with Symantec

VMware NSX A Perspective for Service Providers part 2

Use Case Brief BUILDING A PRIVATE CLOUD PROVIDING PUBLIC CLOUD FUNCTIONALITY WITHIN THE SAFETY OF YOUR ORGANIZATION

Advanced Security Services with Trend Micro Deep Security and VMware NSX Platforms

VMware vcloud Architecture Toolkit Public VMware vcloud Service Definition

VMUG - vcloud Air Deep Dive VMware Inc. All rights reserved.

IBM Cloud Security Draft for Discussion September 12, IBM Corporation

HAWAII TECH TALK SDN. Paul Deakin Field Systems Engineer

VMware Integrated Partner Solutions for Networking and Security

Journey to the Private Cloud. Key Enabling Technologies

Itex VMware NSX Network Virtualization Presentation

Trend Micro Deep Security

Agentless Security for VMware Virtual Data Centers and Cloud

The growing importance of a secure Cloud environment

Expert Reference Series of White Papers. vcloud Director 5.1 Networking Concepts

Virtualization, SDN and NFV

Cloud and Data Center Security

SDDC: A New Architecture for a New Era of Ed IT

vshield Administration Guide

Learn how to build Enterprise Hybrid Clouds for your customers using VMware vcloud

RE Think. IT & Business. Invent. IBM SmartCloud Security. Dr. Khaled Negm, SMIEEE, ACM Fellow IBM SW Global Competency Center Leader GCC

Devising a Server Protection Strategy with Trend Micro

Software Defined Environments

Trend Micro. Secure virtual, cloud, physical, and hybrid environments easily and effectively INTRODUCTION

VMware vcloud Air Security TECHNICAL WHITE PAPER

Securely Architecting the Internal Cloud. Rob Randell, CISSP Senior Security and Compliance Specialist VMware, Inc.

Cloud and VM Based Security

CloudCore. cloudcore infrastructure 4 100% SOLID STATE STORAGE 4 TRUE SCALE-OUT ARCHITECTURE 5 RAID-LESS DATA PROTECTION 5

What s New with VMware vcloud Director 5.1

VMware vcloud Director for Service Providers

雲 端 發 展 與 安 全 趨 勢. 陳 建 宏 Jovi Chen 技 術 顧 問 2011 Check Point Software Technologies Ltd. [Unrestricted] For everyone

Total Cloud Protection

VMware Solutions for Small and Midsize Business

Devising a Server Protection Strategy with Trend Micro

VMware's Cloud Management Platform Simplifies and Automates Operations of Heterogeneous Environments and Hybrid Clouds

Simplify IT. With Cisco Application Centric Infrastructure. Roberto Barrera VERSION May, 2015

Potecting your business assets in The Cloud, with. Secure Multitency Environment from CloudHPT.

Limiting the Spread of Threats: A Data Center for Every User

I D C T E C H N O L O G Y S P O T L I G H T. S e r ve r S e c u rity: N o t W h a t It U s e d t o Be!

Securing the Cloud with IBM Security Systems. IBM Security Systems IBM Corporation IBM IBM Corporation Corporation

Network Services in the SDN Data Center

STRATEGIC WHITE PAPER. Securing cloud environments with Nuage Networks VSP: Policy-based security automation and microsegmentation overview

VMware vcloud Air Networking Guide

Data center fo the future software defined DC

Secure Clouds - Secure Services Trend Micro best-in-class solutions enable data center to deliver trusted and secure infrastructures and services

A Cloud WHERE PHYSICAL ARE TOGETHER AT LAST

SOLUTIONS. Secure Infrastructure as a Service for Production Workloads

JUNIPER. One network for all demands MICHAEL FRITZ CEE PARTNER MANAGER. 1 Copyright 2010 Juniper Networks, Inc.

VMware vcloud Air. Enterprise IT Hybrid Data Center TECHNICAL MARKETING DOCUMENTATION

CoIP (Cloud over IP): The Future of Hybrid Networking

VMware vcloud Powered Services

VMware Solution Guide for. Payment Card Industry (PCI) September v1.3

Cisco Prime Network Services Controller. Sonali Kalje Sr. Product Manager Cloud and Virtualization, Cisco Systems

Mitigating Information Security Risks of Virtualization Technologies

vcloud Air - Virtual Private Cloud OnDemand Networking Guide

VMware Software-Defined Datacenter

Do DevOps on VMware vcloud Air Your Way, Without the Rework! Ashok Aletty, vcloud Air Solution Architect

SOFTWARE DEFINED NETWORKING

Virtualization. as a key enabler for Cloud OS vision. Vasily Malanin Datacenter Product Management Lead Microsoft APAC

Building an Internal Cloud that is ready for the external Cloud

VMware vshield App Design Guide TECHNICAL WHITE PAPER

Advancing Security with Software Defined Datacenter. Karen Law Senior Systems Consultant VMware Hong Kong Ltd

Software-Defined Storage Extending the Power of Your Datacenter Eric Tsai Senior Technic Architect Presale Division Enterprise Group Taiwan

White Paper. SDN 102: Software Defined Networks and the Role of Application Delivery Network Services. citrix.com

Comprehensive security platform for physical, virtual, and cloud servers

The Benefits of SD-WAN with Integrated Branch Security

SOFTWARE DEFINED NETWORKING: INDUSTRY INVOLVEMENT

Virtualization Essentials

How To Protect Virtualized Data From Security Threats

Transcription:

Security in the Software Defined Data Center Francesco Vigo Senior Systems Engineer, VMware fvigo@vmware.com Ugo Piazzalunga Technical Manager, SafeNet ugo.piazzalunga@safenet-inc.com

Agenda Software Defined Data Center (SDDC) Network & Security Virtualization Impacts on security, compliance, audit Partner Ecosystem - Safenet

Workloads Virtualized 25% 60% >90% 2008 2012 Future

Time to Provision New Services Weeks Days/ Hours Minutes/ Seconds 2008 2012 Future

Storage/ Availability Servers Networking Security Management/ Monitoring VDC Software-Defined Datacenter Services Weeks Days/ Hours Minutes/ Seconds 2008 2012 Future

Software-Defined Datacenter All infrastructure is virtualized and delivered as a service, and the control of this datacenter is entirely automated by software. Standardized. Holistic. Adaptive. Automated. Resilient.

Network & Security Virtualization

Impeding the Journey to the Cloud Network and security challenges restrict options for applications in the cloud. DMZ PCI BCA VDI DR Dev Test Web AIR GAPPED PODS MIXED TRUST CLUSTERS ON-PREMISE PRIVATE CLOUD HOSTING & DEDICATED PRIVATE CLOUD PUBLIC MULTI-TENANT CLOUD efficiency, agility, savings Network Challenges Provisioning is slow Placement is limited Mobility is limited Hardware dependencies Operationally intensive Security Challenges Often restricted to perimeter Bolted-on Lacks visibility Location & hardware dependent Operationally intensive

The Solution Virtualize the Network Software Defined Data Center One Provisioning Programmatic is provisioning slow Placement any workload is limitedanywhere Mobility Move any is workload limited anywhere Hardware Decoupled dependent from hardware Operationally intensive efficient Network Virtualization Abstraction Layer Compute Virtualization Abstraction Layer Physical Infrastructure

What is Network Virtualization? Application Application Application Workload Workload Workload x86 Environment L2, L3, L4-7 Network Services Virtual Machine Virtual Machine Virtual Machine Virtual Network Virtual Network Virtual Network Server Hypervisor Requirement: x86 Decoupled Network Virtualization Platform Requirement: IP Transport Physical Compute & Memory Physical Network

Network Virtualization must Virtual Virtual Network Operations 1. Decouple 2. Reproduce 3. Automate Physical Physical Cloud Operations Hardware independence No change to network from end host perspective Operational benefits of virtualization

SDDC impacts On security, compliance, audit

Workloads Can Live Anywhere, but are managed centrally Between hosts, clusters Between data centers, clouds vsphere Host vsphere Host

IMPACT: Leverage Cloud asset inventory SDDC-Aware Legacy Software agent Network scanners Rely on multiple, inaccurate tools Cloud Asset Inventory? Cloud Asset Inventory Get all cloud asset info from cloud management solution

IMPACT: policies tight to workloads, not IP addresses Legacy 192.168.20.1 Bound to Physical Constructs 192.168.30.2? Identifier = IP or MAC Address SDDC-Aware Cloud Aware Identifier = VM, vapp, Org, Security Group

Enable Providers and Consumers Independently Consumers Consumption Model Request workloads and services Single Resource Model The Software-Defined Data Center Provider Provider Model Provisions workloads and services

IMPACT: Resource Isolation & Separation of Duties Infrastructure silos, separate failure domains Legacy Admins dedicated for each infrastructure service Single admin could manage it all, but is that desirable? SDDC-Aware Simplified infrastructure audit all in software, same management plane Single point of failure, platform security essential Does the entire data center or a complete service go down?

IMPACT: Visibility, Control, Efficiency At what cost? Software agents impact consolidation ratios. Security scans tax underlying resources. Legacy Network services lack visibility and control over virtual network Automation of network and security services is close to impossible since these services are still tied to physical infrastructure. SDDC-Aware How do you ensure that network and security services follow the workload, if workloads are dynamic? Should the individual who provisions network infrastructure also be allowed to secure it? Will this approach pass muster with your auditors?

vcloud Networking & Security Integrated Management with vcenter/vcd VMware Networking & Security vcloud Ecosystem Framework: Integrate 3 rd party services vshield Manager: Seamless integration with datacenter management VDC 1 VDC 2 3 rd party services Data Security: Protect against data leaks App: Isolate and protect applications and virtual machines VXLAN vsphere Edge Gateway: Secure the edge of the virtual datacenter and provide gateway services VXLAN: Foundation for elastic portable virtual datacenters

SDDC enables Best of Breed Software Defined Data Center Properties of virtual services: Programmatic provisioning Place any workload anywhere Move any workload anywhere Decoupled from hardware Operationally efficient Vendors provide best of breed services in these categories: Anti-Virus (AV), Anti-Malware Application Delivery Controller (ADC) Application Whitelisting Application Firewall Data Loss Prevention (DLP) Encryption and Key Management File Integrity Monitoring (FIM) Firewall (Host/Network) Identity and Access Management Intrusion Detection/Prevention System (IDS/IPS) Load Balancer Network Gateway (VXLAN) Network Port Profile Network Switch Policy and Compliance Solution Security Intelligence and Event Management (SIEM) User Access Control (closest to our SAM) Vulnerability Management WAN Optimizer Web Filter

Thank you!