vDefend Security Stack: Broadcom’s VCF Update
The vDefend security stack is Broadcom’s answer to AI fueled attacks that laugh at yesterday’s fragmented private cloud defenses. Umesh Mahajan, VP and GM of Application Networking and Security at Broadcom, joins Alan Shimel on Techstrong TV to unpack the latest vDefend and Avi load balancer release.
About Umesh
Umesh has been on Techstrong TV several times and leads Broadcom’s Application Networking and Security division. Consequently, he brings a deep view of how VCF customers actually deploy and scale integrated network security today.
Inside the vDefend security stack
AI powered attacks now blend infiltration, lateral movement and zero day behavior in one campaign. As a result, one size fits all firewalls miss too much. Meanwhile, CISOs need zero trust, hypervisor based segmentation and behavioral NDR in the same platform. In addition, virtual patching gives teams a distributed shield against known CVEs before their own patches land.
The release makes the vDefend security stack easier to roll out step by step. It also adds an air gap option for sensitive sites and migration tools from legacy firewalls. Therefore, the Security Services Platform gives operators east west visibility, threat and posture scoring, guided recommendations and a lighter footprint option.
Why this matters now
Meanwhile, Avi extends web application firewall coverage into full WAAP. In addition, it adds API discovery, spec conformance checks and OWASP API top ten protection. Consequently, throughput jumps to 75 gig DFW per host, 17 gig IDS per host and 12 terabits per second on Avi. All of it lands under one console with AI assistants.
Explore more cybersecurity coverage and the latest Techstrong TV interviews. Furthermore, the conversation previews Broadcom’s presence at VMware Explore in early September and where customers can find full release collateral.
For more information please visit broadcom.com
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest is Umesh Mahajan.
Excuse me. Umesh has been a guest several times on our show here, so we're lucky always to have him, and he's a great guy to talk to. He's VP and GM of Application Networking and Security over at Broadcom.
Umesh, welcome back to Techstrong TV. I hope all is well with you. Yes.
Thank you, Alan. Good to be back here talking to you. Absolutely.
So Umesh, we're going to focus in today on the recent vDefend and Avi, AVI load balancer announcement and what it means to the people out here, what is some of the new capabilities on it. Okay? Mm-hmm.
So if you don't mind, I'm going to jump right into it. Yes. Great.
So as AI-fueled cyber attacks become more sophisticated, and it seems like they're getting more sophisticated every day, why are fragmented security approaches no longer sufficient for private cloud environments? Yeah. So if you look at it, the real attacks come over the network packets.
Attackers are able to bypass the perimeter firewall, and the different kind of attacks need different layers of protection. One size doesn't fit all, like let's do a five tuple kind of protection. That no longer works.
First of all, you've got to deal with zero trust. Zero trust is infiltration. How do you stop that, the initial infiltration?
That means intrusion detection, malware prevention. Then there's the lateral movement, because the attacker may not hit your crown jewels immediately, but they compromise an application, certain host. Now they want to jump around to find the crown jewel.
There you need macro and micro-segmentation so that the lateral movement is not allowed. And this works best when it's hosted in the hypervisor. The firewall runs in the hypervisor.
You can't compromise it. You can't turn it off. And finally, you have the zero-day attacks.
These are the kind of behavioral attacks, attacks which haven't been seen. You can't put a signature, you can't put a five tuple. This kind of behavioral change is happening.
So you have to use AI and anomaly detection to figure out what these attacks are happening, and it's known as NT NDR, and we have this feature set in our stack. If you think about it, you need the full security stack over there to prevent these different kind of attacks from happening. Because with AI, they are not going to stop at one mode of attacking.
They're going to try once, two, three, all of the above. You need a full integrated stack. And then finally, the customers have to patch their own workloads to their own applications because they will have the vulnerabilities too, and they're open to attacks.
So we have this very nice feature called virtual patching in a distributed fashion, where we can stop the attack in a kind of virtual shield. We can come up with a signature based on the CVE and stop the initial infiltration from happening. So that's a powerful feature we have, and customers are really enthusiastic about it.
If we just know the vulnerability, we can come up with a signature well before the customer itself can roll out their own patches, put the signature in place, and stop the attack from happening. So if you look at this, customers buy products from multiple vendors, security products one, two, three, four. " Maybe they got two of them to work, but typically, they have a tough time assembling them together.
With AI, you need the full stack, and that's why I think what we have with vDefend and Avi, we provide a fully integrated stack, and the firewall part runs in the hypervisor. But that's why we think we have a unique edge in this area. Excellent.
And with the AI attacks, just good solid cyber hygiene is still important, and that's defense in depth and having the complete stack. Mm-hmm. Let's move over to the vDefend updates.
Yes. First of all, let's define what do we mean by vDefend, and how do they strengthen protection across workloads? Okay.
So by vDefend, we mean our virtual, because we provide only in software, there's no hardware appliance with our security stack. And with vDefend, we provide the best security solution for VCF workloads or the VCF private cloud, right? Workloads are running on top of VCF.
That's where we want to provide a full security stack solution. So that's what we mean by vDefend. And in this announcement, what we've done is we are continuously making it easier and easier to deploy our stack, use it, understand it.
After talking to customers, we found what were their challenges, why can't they rapidly roll it out? Because they do want to rapidly roll it out, but they are afraid of making mistakes. So that's where I think our solution and many of our enhancements come in.
So we now can easily give out a threat assessment scoring and report, ATP 1, 2, 3, much like last year we rolled out DFW 1, 2, 3. Now we can rapidly roll out the advanced threat protection features so customers can deploy it. It's kind of a logical, systematic fashion.
They do one step, then they go to the next step, then they go to the third step. And finally, we also have air gap solution for security sensitive organization who don't want anything to happen in the public cloud or no connection to the public cloud. Those features also are being rolled out in vDefend.
And then I talked about operational simplicity, right? This is really, really important for our customers to have that Confidence that capability that they can operate a modern security stack like we defend. They can get the insights, recommendations.
They know how to navigate through a system properly. It's not just a documentation chat box, it's more runtime to what's really happening, who's talking to who, where is the firewall rule, all of the above. Just ask a few questions, two questions, and you start getting the answers.
And then as we are gaining market share in this area, we are working hard at work creating migration tools from other legacy agent-based or appliance-based firewalls to vDefend. All this is being announced and is coming out as part of vDefend in this latest release. Excellent.
Next, I want to talk to you about the vDefend SSP, the Security Services Platform. We touched on it a little bit, but- So- ... it's becoming increasingly critical.
Yes. So you know, I alluded to in the previous answer that customers want to move at speed. In order to move at speed, first of all, you have to know, you have to have visibility.
What is really going on? Who's talking to who? Is there any security in place?
Am I even little bit protected or I'm fully protected? You just ask this question and you're surprised by the kind of answers you get. Yeah, I deployed three rules, or some customer will have hundreds and hundreds of rules.
So the variation is so high, but they don't know, are they fully protected or what's going on. So that's where the Security Services Platform comes in. We want to provide them end-to-end full visibility, east-west application visibility, so that they really know where they are, and then based on the security policies they have already configured or not configured, we give them a security assessment and a score and even a threat assessment score.
So now they know where they stand. Now that they know the score typically is not that high first time we deploy the platform, then we come out with a report with all the recommendations. Hey, this and this application is talking.
Look, this leg is not protected. That other side, it can get out of your data center. So please do X, Y, Z, and that will raise your protection posture, security posture, and your score keeps going up in real time.
Very healthy, very easy way to see, are you on the right path? Are you on the right journey? And then we deploy, we allow our customers with the same tool, your practical, sensible one, two, three, four approach.
How would the systematically deploy our distributed firewall and advanced threat protection? And finally, what we did was, since customers really love this tool, and we allow it at different sizes and footprints depending on the scale, we introduced something, a lighter version of SSP, so that they can start with a smaller number of cores. They don't have a server available easily, which has a larger number of cores.
They can start from small, and then dynamically, they can expand to a bigger footprint in future as they bring in more and more hosts and workloads under the Security Services Platform. Thank you. Next up, I want to talk about something that people don't often think of around when we talk about security, but the Avi Load Balancer, it also has some security capabilities in there.
What are you doing around-- I understand part of the release is enhancing those as well. Yeah. So, the load balancer is typically a forward proxy, it's full proxy.
And then, it deals load balances a lot of web application traffic at the front end, right? So that's a natural place for a load balancer to implement a web application firewall. We've had a web application firewall on Avi for many years.
Customers are embracing it. They're liking it. Security attacks are increasing, and WAF has suddenly become very interesting.
But now WAF is also used to protect Kubernetes-based web applications. And here, when it comes to Kubernetes, almost everything is API based. You talk API from one entity to another entity to another app.
That's where API protection comes into work. So we decided we have to have API protection in place. That's what we've implemented.
And WAF with API protection is called WAAP, and now we have that. Ours is fully defined, software defined, scale out models. It's differentiated from other WAF implementations out there.
We discover the APIs, we ensure that they conform to the specs, and then we have our well-known Avi analytic latency analytics. It works over here too, even in this mode for WAF and WAAP, and no other load balancer offers this. And finally, we all obviously protect the OWASP 10 API-based attacks, so we're fully compliant to the standards over here, and we have a unique differentiation of scale out with full analytics in place over here.
Excellent. One more question for you. So, IT teams, security teams, they're overextended to say the least.
They're battling AI and agentics, and frankly, they were overworked before AI came on the scene. How do these updates help these people in their day-to-day improve performance, simplify security deployments, make operations more efficient? Well, if you get to the crux of the problem, what is happening is the sheer amount of traffic going in and out of these applications, the number of applications increasing, especially AI applications, huge amount of network traffic goes, and then they chit-chat amongst themselves Because you talk about AI servers and all that.
All the time, there's discussion on networking elements and optical interconnect because the normal interconnect can't handle it. The traffic is going up, it's just 1X, 2X, 3X, 4X. So what is happening?
The servers, the 10 gig servers are becoming 25 gig NIC servers, 100 gig NIC servers. Now in 100 gig NIC server, we can support 75 gig of DFW traffic, and we support under one cluster, VCF cluster, at least 1,000 ports. So that's a 75 terabit firewall controlled from one single entity.
So now that is huge scale and that is huge savings. The customer's operational team just goes to one location and low bill, they can control a 75 terabit firewall. On intrusion detection, we went from 3 gig to 9 gig per server, and now we are doubling it again to 17 gig per server.
So that is 17 terabytes per second for a 1,000 server VCF instance. Nobody in the market has a IDS/IPS appliance of this magnitude. So suddenly now you can handle so much IDS/IPS traffic, you can start using it for all your applications.
Similarly in Avi, we've doubled our throughput to 12 terabytes per second for load balancing purposes, and we leverage the QAT, which is an Intel assist to do encrypted traffic over there. So on the operational simplification, we have AI assistant for vDefend, which I talked about earlier. We also have AI assistant for Avi, and we are making it easier and easier.
As this throughput goes up massively, the security requirements go up drastically with AI-assisted attacks. We also have to make it simple, because otherwise our customers can't really move forward. We are taking care of all the three elements: increase security, increase scale, but at the same time keep simplifying the operations so that the customers can move at speed.
Excellent. " Sounds like a heck of a new release of packages out here. I hope to see you soon, and keep up the great work.
Okay, thank you very much. We are very excited about the release we've just done. Absolutely.
People who want to get more information, where should they go, Umesh? Well, I think we have our website where all our collateral is there, and then we will be at VMware Explore- Yes ... part of September.
So we are looking forward to meeting our customers over there, and otherwise all our collateral about these releases and features is up on our website. Excellent. " We're going to take a break.
We'll be back with more.