Project Northstar – Tom Gillis, VMware
Tom Gillis, senior vice president and general manager of the Network and Advanced Security Group at VMware, explains how Project Northstar will finally unify the management of networking and cybersecurity in the multi-cloud age.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Tom Gillis who is senior vice president and general manager for the networking and advanced Security Group at VMware Tom. How you doing? I'm good.
How are you Michael? Well, you guys just launched this whole project North Star initiative. So I was hoping you would kind of explain what that's all about given the fact that we are seeing more convergence between networking and security these days but everybody's got in North Star.
Where's your email? Yeah sure thing. So really our North Star is pointed around, you know, stitching together the multi-cloud universe and so what we see more and more is customers are saying I've got, you know, very large five o'clock data center is lots of workloads, but I've got, you know increasing number or public Cloud workloads.
Maybe I've got an on two different public clouds, maybe even three public clouds. And I want to pull this together in a single coherent system. And so project Northstar is designed to do exactly that project North Star is the policy and the security analytics hub.
That allows us to create one Global setup policies and then we can still customize them in localize them at you know, your East Coast Data Center your West Coast Data Center your instances running on Amazon or instances running out on say Google and pull all this together with a single pane of glass. So yeah, it's a pretty big it's a big project for us and it's one of the customers have been waiting for for quite a while actually. How is the relationship between networking and security people involving these days because it seems like to me at least that more of the security operational functions are moving towards the networking guys and the security guys or focusing more on policy, but maybe it's not that neat.
Well, let me put it this way. The the big Trend that we see in security is is you know with the principles of zero trust you have to assume the attackers are already in they've already penetrated your network. So now the name of the game is how do you stop them from moving laterally throughout your infrastructure and stealing all your data or worse, you know sort of creating a ransomware situation that later.
Al movement is very difficult to detect if you don't have you know tight integration and cooperation between that routine and security team. So so, you know used to be you could deploy firewall and a firewall would live in one place at the perimeter. Okay.
And so the networking guys all they had to do is was provide routes that would allow you to to plug the firewall in and the security team could be completely separate and independent. But when we look at the distributed nature of these attacks, we really need to be able to put security not just that the perimeter you want to put security everywhere. So integrating security and networking together into one functional team, that's the future and this is even more relevant when we talk about public clouds where you don't have a physical box to put it in right?
So this is all distributed software that we need to work together to make sure that we're deploying in a sensible way. Do you think that the rise of multi-cloud computing therefore is forcing a lot of people are revisit these issues because we're not adding a lot of more security people heck we can't even find enough networking people. So do we need to find a smarter way of going about doing all this?
Yeah. So I think there's a tale, you know and a dog and I think that the the dog here is the, you know, sort of shocking and steady increase in both frequency and severity of ransomware. I mean ransomware is a giant giant giant problem.
The reason is giant giant problems. It's a really good business because most people pay their handsome so you can expect that Trend to only continue, you know, we expect ransomware to just get worse not better. Um, and so so, you know as we think about how we're going to stop this ransomware, it comes back to identifying lateral movement of attackers, you know, the idea that you're going to keep all attackers out is naive.
So assume that they're already in your network. How do you stop them from moving around and that's where this distributed security becomes so important once you have deployed a distributed distributed security architecture. You want that to work on every cloud so multicloud is kind of the second phase of this if you will, right?
Like let's let's think about an advanced security solution. And then let's put that everywhere our workloads are which is private Cloud public Cloud, you know Etc. We've been talking about micro segmentation for a while.
Now. What's the challenges that organizations have when it comes to implementing that and adopting it because you would think it might be a little more widespread than it is at the moment. So clearly there's work to be done.
Yeah. So microsegmentation is something we came up with, you know, almost almost a decade ago, like like eight years ago and micro segmentation stops what I call the obvious problem, right? So it's obvious that a web server in a development environment should not connect to a database and a production environment ever under any circumstances.
So don't allow that to happen. So microsegmentation is about shutting down application Pathways that shouldn't exist. And the challenge with it is is you would ask the question.
Well what application Pathways should exist and you know, one of the things that's interesting is if you ask a developer tell me what ports and protocols you need to have open for this application. You know what the answer is. All of them right because developers oftentimes don't know that's not the way they're thinking and frankly.
It's not the way we want them to think we want developers to focus on business logic not worrying about what ports and Protocols are being used. So we've we've spent you know, the better part of a decade building Ai and ml capability that can analyze your existing Brownfield applications and then automatically generate firewall rules to do the micro segmentation. So the tools are in place to do segmentation and do it and do it at scale and we do this for the largest customers in the world.
Right? So we're kind of way way past the point of credibility on this the so the good news is for those that haven't deployed micro segmentation. We can help you do that fast.
That's a good news. Here's the bad news. The bad news is that attackers are assuming you have segmentation in place.
And so what we're seeing happen is there's a significant rise and what the security guys call living off the land attacks where an attacker will either steal a credential or they will compromise a protocol to move through legitimate application Pathways that micro segmentation won't stop so microsegmentation is a foundational capability. If you don't have it in place, you're making it super easy for the attackers to do an Equifax type of Clean Sweep of your data center, which would not something anybody wants, but but it's not enough because we have to be able to stop these in line attacks that are that are using legitimate pathways. You talked about developers.
What's your sense of the current state of SecOps? We've been trying to get better at application security and sometimes I feel like application security winds up being a jump ball because the networking people think the app people are doing in the app people think the security people are doing it and then nobody does anything. So yeah, what do we need to do to kind of bridge that divide?
Yeah. Well, what's interesting is, you know, it's clearly the future, you know, you know the world we're moving into especially in a kubernetes space world. Security doesn't come in a box anymore security is going to be code.
Right and as is infrastructure as is the connectivity those Pathways that I was talking about. All of that stuff is going to be described in software. Predetermined pre-calculated and then when when you know, it's runtime you push a button and say go so that means no tickets to open no waiting a month for the fireball team to update those firewall rules.
Remember that no waiting, you know a month to get a DNS entry or VIP from a load balancer, right? You just push a button and and it works. That's the cloud operating model.
But what's interesting to me is that I think your point many customers say yeah, that's what we want. That's what I want. But but they struggled to get there and it's not the tools aren't in place, but they struggle with is what I call the layer 8 problem, right which is which is humans people.
And and probably the number one offender or the biggest challenge you have to overcome is the firewall team. Because firewalls have been working incredibly. Well like they're these are very very well engineered very high performance to build firewalls, right these things run and run and run.
They don't make mistakes. And so so we've been relying on these things for decades. But the fundamental architecture and design of a traditional firewall, even if you pull it out of the box and make it a VM, it's a scale up system that's designed to run at a perimeter.
It's not designed to run everywhere. And as I said like the name of the game these days you got to look everywhere. You can't just look at the perimeter and hope you're gonna catch all the all the ransomware.
So so changes in the wind changes in the air changes hard smart, you know administrators smart Architects are getting in front of this because this is clearly the future but we as an industry got a ways to go. Yes. Are we seeing a flattening of cybersecurity in the sense that we used to have a lot of different silos?
There'd be endpoint security. There'd be the network guys that they're with the firewalls app guys and Cloud networking security folks. And if everything becomes code, can we just flatten that so it can all just be centrally managed?
Well within security you see a similar, you know kind of you're moving from let's call it centers of excellence or you could call them silos, you know, and you flip at 90 degrees and say I need one cross-functional team that's gonna look about how I make security is code for this application and that's gonna have everything to do with code Integrity on the, you know, sort of very very upfront all the way to hardening and securing the runtime. None of that stuff should be figured out after the fact none of it, right? You should be you know, when you're building a checking in code you're scanning it looking for vulnerabilities.
That's all automated likewise when you're you know, turning it up a new cluster and putting in production. You can make sure that the crypto is in place that at the you know, malware detection is in place and that you're doing Advanced API security where we're looking at how apis reviews and making sure that they're not being abused with that legitimate application pathway that ransomware would take advantage of so, yes, the the world is changing but it's all moving in this direction that it has been for a while. Right which is is software.
And policy but that does entail across functional approach. You can't do that with the center of excellence model right The Silo model. We hear a lot about all things AI these days.
What's your sense of what's real about AI is it applies to security and network management versus what's in the more fanciful side of things. Yeah. It's funny.
I just gave a talk in another form on exactly this topic. So what is the role of ai ai is essential for any security solution? And you know, if you think about that East-West problem that I talked about This is a great example.
So You know, the the imperative of looking at lateral movement is not new. This is something security has known for you know, a decade or more and I would argue this is like one of the main value propositions of a Sim. So a Sim will look at everything.
It looks all your net flow records and your syslogs and your you know web blogs and kind of munches them all together and says, let's see if we can identify the lateral movement of an attacker. And most of the customers I talked to were like, you know these Sim systems. Like if I didn't have to buy this, you know because a regulatory requirements I wouldn't because it really really expensive and they're really really noisy and they're really really hard to use and I'm not really sure I'm getting you know the value out of it that I should be and so so and it's not that the algorithms in a Sim are bad Sims relying on Sample data.
So Sam is gonna rely on Netflix will tell you server a talk to server B. So good. That bad which I worry about that right?
It's not enough context to know. Is that something we need to worry about? I feel a little bit like you ever watched Game of Thrones.
Mmm. So when I watch Game of Thrones, I'll get to like season 3. Someone gets killed.
I'm like that good guy back guy my happy my sad what you know, like like oh, it's too complicated. So net flow and Sample data are the equivalent of the Game of Thrones problem and that you need to have very very high fidelity data to figure out friends from Foe. And and you know, that's really where the industry is going is is you need to be able to ingest this huge quantity of data at the packet level and at the process level and then the anomaly stick out like a sore thumb thankfully, you know sort of advances in Big Data platforms industry why they're not security specific but just tools that allow us to ingest all this data and you know and process them on platforms like snowflake.
This is pretty amazing. Right and so so, you know, the tooling is in place to go do it now. We just got to put the systems in place to make it a reality.
All right. Well keeping on that theme winter is coming. So are the bad guys getting smarter or they're more of them or is it just that you know, they say complexity is the enemy of security and we may everyone worst enemies.
Yeah complexity is definitely the enemy of security and so as we move to a multi-cloud world the attack surface gets much much bigger much broader much more non-traditional, right? So so here's a great example API security. So people think about hey apis that I have for an application.
They're generally thinking about the north south or Internet facing apis, but what about all the internal facing apis the cloud native application can be made up of thousands of micro Services thousands of little tiny containerized Snippets of code each one of which has an API. So if you really want to understand the inner workings of an application, you've got to look at the API. The API is the new endpoint in a kubernetes world what we see it as happening is attackers are taking advantage of apis that are don't necessarily have a vulnerability.
But does your coded with security in mind, for example, if I wrote an API that said if you give me a name, I'll give you a credit card number that same API. If you gave me five names, I'll give you five credit card numbers. If you give me $50,000 names, I'll give you 50,000 credit card numbers.
Right? So attackers can take advantage of these apis and extract huge amounts of data without actually violating the terms of the API. And so so the the next Frontier, I really believe in the industry is to understand it Baseline the behavior of these apis and then look for normal behavior.
And then we can identify these attacks even though they're not exploiting a vulnerability. They're gonna be using an API either out of sequence or in a way that should never be used and we can stop that from within. Tom has a lot of people who are pessimistic out there when it comes to security because every day they wake up and another issue.
What's your sensor? We went in and are losing this battle right now. And you know, do we have accomplished for optimism somewhere?
Yeah. I mean look, I've been doing this for decades and I get this question all the time and and the fact of the matter is, you know, especially when you look at ransomware It's never gonna go away, right because it's a good business because most people pay their Ransom. And so so what we see is went like any other business the attackers are investing in tools to be more and more crafty to look like legitimate application traffic and do that East West movement so they can Harvest your data.
So so we'll never stop them coal. But what we can do is kind of like the vaccine right we can make the severity of the attack much lower and I think one of the other really interesting areas that we're focusing on is how can we automate the recovery of the attack? So using technology to speed up the recovery from ransomware?
We just recently introduced carbon black integrated into our VMware Cloud disaster recovery. And so what this means is when we take a snapshot we scan it and we tell you is this known to be clean or not. So in the event that that ransomware of attack does get through we're gonna go through and say, oh here's the last known verified clean snapshot and you've now defined your recovery point.
And I believe like over time we can actually start to drive that recovery Point down maybe even to zero. Which would effectively be an antidote to Grant somewhere. It's like yeah, you got Ransom, but don't worry.
I restored you right back to where you were before the attack happened, you know lose any data at all. So so I think it's one of these things we're going to continue to find ways to ameliorate and minimize and attenuate the threat but never eliminate it. Yes.
All right. So inoculations may not prevent you from getting sick, but they sure as hell can't be recover faster Tom. Thanks for being on the show.
Always a pleasure. Thanks, Michael. All right back to you guys in the studio.