A guide: Using SmartNICs to implement zero-trust cloud security

In an age of zero-trust security, enterprises are looking to secure individual virtual machines (VMs) in their on-premise data centres, cloud or hybrid environments to prevent increasingly sophisticated attacks. The problem is that firewalling individual VMs using tools like software appliance firewalls or Connection Tracking (Conntrack) is operationally challenging to manage. It delivers bad performance, restricting VM mobility and consuming many CPU cycles on servers, which limits their ability to process applications and workloads.

As the need for VM security grows, IT managers end up spending on more and more servers, most of which are tied up with security processing rather than application processing. In this article, we will look at zero-trust security and how best to implement it in data centres.

About zero-trust security

Forrester Research first introduced the Zero-Trust Model for Cybersecurity in its 2013 NIST paper, “Developing a Framework to Improve Critical Infrastructure Cybersecurity.” In this model, all network traffic is untrusted, whether it comes from within the enterprise network or from outside the network. Before this model there was the concept of a trusted network (usually the data center network or enterprise LAN), and an untrusted network (essentially outside the data center or enterprise LAN). Typically, the trust was enforced by a perimeter security mechanism (Figure 1a).

Zero-trust advocated that (a) all resources be accessed securely irrespective of location, (b) adoption and enforcement of least privilege and role-based access, and, (c) inspection and logging of traffic. In traditional enterprise networks, these were implemented primarily by two main mechanisms:

  • Segmentation – Mostly network segmentation using VLANs. However VLANs just provide segmentation, not security
  • Perimeter security at the edge of the segments

This is depicted in Figure 1b.

Zero-trust in data centres

Large-scale data centres deploy a wide variety of services. A single user request can spawn many services within a data center, leading to both east-west traffic within the data center and north-south traffic between the data center and the Internet. For example, consider the process of ordering something on Amazon, where a front-end web server shows the product, but then services are required to accept and validate credit card information, issue a confirmation and send a fulfillment request. This means we must apply the zero-trust model within the data center as well.

There are three reasons why a zero-trust model using security appliances cannot be deployed in data centers, as shown in Figure 1b.  

First, operationally it is extremely cumbersome. The traffic from each server has to be backhauled to a security appliance, and all appliances must be properly configured. This leads to manual errors and operational challenges related to keeping the appliances up to date with changes in service requirements and/or changes in service deployments.

Second, it does not scale well and delivers inferior performance. Most of the security appliances today can handle traffic on the order of 200Gb/s. As servers start getting upgraded to and saturating 10Gb/s and higher network interfaces, a new security appliance must be deployed and provisioned for every 10-20 servers deployed. Actually, a pair of security appliances is needed for redundancy. With the security appliances becoming choke points, it also reduces the performance of the services.

Third, this creates silos within the data centre, making it hard to fully utilise the data centre infrastructure.

Zero-trust in virtualised or cloud-scale data centres

The challenges of using appliance-based zero-trust security are amplified in a virtualized data center as the number of VMs per server increases. There is an additional operational challenge in securing VMs, since they can be shut down and brought back up on a different server or sometimes in a different data center or even live migrated. This means the policies associated with a VM should move with it as well, or else all policies have to be programmed on all security appliances.

As a result, we have to think of a different deployment mechanism for zero-trust in data centres and in particular, virtualized data centers. This can be done by distributing security to each server using virtual appliances running alongside the VMs, by implementing security at the host/hypervisor level using Linux iptables, or at the vSwitch level using Open vSwitch (OVS) Conntrack.

This method (Figure 2a) presents the same problems of scalability and performance and the same operational challenges as the standard security appliance model. The virtual security appliance becomes the bottleneck. It is difficult to manage the policies one appliance at a time. When VMs move, it is extremely challenging to move the policies. In addition, the virtual security appliance is now consuming valuable server resources like CPU, memory and disk space that should be used to run VMs and deliver revenue-generating services.

Distributed security using Linux Bridge and iptables: This method (Figure 2b) solves some of the scale challenges because Linux iptables are available on all Linux hosts. However, by adding another layer of bridging between OVS and VMs, the performance suffers immensely. It is also a massive operational challenge to program taps and then policies for each Linux bridge. VM live migration and/or movement is still extremely challenging as the bridges, taps and policies have to be manually programmed.

Distributed security using OVS Conntrack: The basic solution for operational challenges is to add OVS Conntrack to OVS networking (Figure 2c). OVS has well-defined APIs for integrating with data center management stacks including OpenStack – e.g., OpenStack Security Groups are mapped to OVS Conntrack. This significantly reduces the operational complexity of deploying distributed security. Also, it removes the additional abstraction and provides a little bit better performance than using Linux iptables. However, this approach still does not address performance and scale. Deploying OVS with Conntrack in software results in very high CPU usage for that function alone.

To address these performance and scale issues, data center operators must find a way to offload OVS and Conntrack from the CPU cores. This allows them to provide a very high-performance distributed firewall on each server – close to the VMs – which can define policies and service granularity with a high number of connections being set up and tracked.

Offloading OVS Conntrack with a SmartNIC

The most efficient way to offload OVS and Conntrack is to use a SmartNIC and appropriate software. A SmartNIC is a network interface card that incorporates a programmable network processor which can run application software. By running Conntrack software in the SmartNIC’s processor, this chore is offloaded from the server CPU cores.

Offloading OVS Conntrack from the server CPU cores leads to far higher performance and scalability. Figure 3 (above) compares some representative performance metrics for the server CPU-based and SmartNIC-based implementations.

As can be seen in Figure 3, SmartNIC-based implementation delivers 4X the performance of a software-only, CPU-based implementation while consuming less than 3 percent of the CPU for a large number of flows.

Current implementations of software-only CPU-based Conntrack starts consuming more than 40 percent CPU at 100-500 unique flows and can go as high as 51 percent CPU utilization on a modern server with 48 cores. Clearly, using more than half a server to provide security is not a feasible solution when the central function of the server is to host VMs with applications/services that generate revenue.

Essentially, offloading OVS and Conntrack to a SmartNIC makes it feasible to implement security on a per-VM or per-container basis by removing the server usage penalty and expense, solving the scalability and performance issues, and, delivering better server utilization for application traffic as intended.

How to run Microsoft Outlook on Mac

When it comes to running Microsoft Outlook on a PC versus Mac, the choice between the two is often less a question of need and more a question of preference. It is essentially the specific functionality of these products that creates the user preference. Preference can, of course, be influenced by need, and every user […]

The post How to run Microsoft Outlook on Mac appeared first on Parallels Blog.

Why You Should Build Your Supply Chain from the Customer Up | @CloudExpo #SaaS #Cloud #Agile

Satisfying customers and winning their loyalty is the foundation that every successful business is built upon. Delivering a consistently excellent experience builds a level of customer intimacy that will set your business apart from the competition. Consider that 80% of your company’s future revenue will come from just 20% of your existing customers, according to Gartner.
The supply chain landscape is shifting, as customer expectations soar and new services and software bring greater complexity. There’s a great deal of pressure to maintain operational excellence, integrate disruptive new technologies, and innovate for a superior customer experience. Tying these disparate threads together requires responsive Supply Chain Orchestration (SCO).

read more

Marketing in the Digital Age | @CloudExpo #Cloud #Analytics #DigitalTransformation

In 2017, word-of-mouth marketing will be a lucrative strategy and should allow small businesses and startups to carve out powerful niches in a marketplace that’s noisier than ever.
When was the last time you paused to consider the noise on the internet? If you really take a look, it’s astonishing.
Data shows that every single day, 500 million tweets are sent out, 4 million hours of content is uploaded to YouTube, and 205 billion emails are sent. On top of that, roughly 3 million Facebook posts are shared every single minute. Then you have to consider that millions of new blog posts are published on a weekly basis.
In other words, the internet is anything but quiet. It’s loud – obnoxiously loud. For brands that want to stand out, the challenge of getting noticed is becoming more and more difficult.

read more

Is #Blockchain Enabler of Data Monetization? | @CloudExpo #BigData #FinTech

Special thanks for the help on this blog to the coolest, most hip group of industry experts that I have ever met: the Pathfinders. The Pathfinders is an elite forces group of master system engineers inside of Dell EMC who tackle our customers’ most difficult and inspiring challenges. I am honored to be part of that club! Suppose an autonomous vehicle learns of a more efficient route and wants sell this knowledge to other autonomous cars for a fee (using blockchain to handle machine to machine transaction). Suppose the autonomous vehicle could start to monetize itself; to self-fund its own operations and the acquisition of goods and services such as gas, repairs or vehicle upgrades (using blockchain to conduct commerce). Now suppose the autonomous vehicle could couple real-time analytics of vehicle performance and maintenance with real-time bidding for maintenance servicing and replacement parts (blockchain inserted again). Lastly, think “intelligent” vehicle depreciation and salvage value optimization where the autonomous vehicle continuously scours used car and auto parts markets for vehicles in need of older chassis, transmission and electrical components (again leveraging blockchain).

read more

Blockchain: Byzantine Generals and Achieving Consensus | @CloudExpo #Cloud #FinTech #Blockchain

When discussing disruptive technologies, the topic of blockchain inevitably enters the conversation. Gartner recently listed blockchain as one of the ‘Key platform-enabling technologies to track.’ Approximately $1.4B has been invested in blockchain just this year, according to PwC executive Seamus Cushley. IBM announced this week a Blockchain-as-a-Service Enterprise offering at their Interconnect Conference. While there is a lot of ‘hype vs reality’ discussions going on, there is no arguing that blockchain is being taken very seriously across industries and cannot be ignored.

read more

CA “Platinum Sponsor” of @CloudExpo NY & Silicon Valley | @CAinc #DevOps

SYS-CON Events announced today that CA Technologies has been named “Platinum Sponsor” of SYS-CON’s 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. CA Technologies helps customers succeed in a future where every business – from apparel to energy – is being rewritten by software. From planning to development to management to security, CA creates software that fuels transformation for companies in the application economy.

read more

Is Your IT Career Ready for the Cloud? | @CloudExpo #API #Cloud #Azure

The IT industry is undergoing a significant evolution to keep up with cloud application demand. We see this happening as a mindset shift, from traditional IT teams to more well-rounded, cloud-focused job roles. The IT industry has become so cloud-minded that Gartner predicts that by 2020, this cloud shift will impact more than $1 trillion of global IT spending. This shift, however, has left some IT professionals feeling a little anxious about what lies ahead. The good news is that cloud computing is relatively new by IT’s standards, which means it’s constantly expanding to encompass new career paths.

read more

Making a Difference in Tech: #YesWeCode | @DevOpsSummit @CollabNet

InformationWeek recently ran an article I wrote that describes CollabNet’s work with non-profit #YesWeCode. This Dream Corps initiative aims to help young adults find careers and success in the tech industry.
In the article, I address the growing need for new talent in the tech industry:
«The U.S. Bureau of Labor and Statistics estimates that there will be one million more IT jobs than computer science students in the U.S. by 2020. The software development field in particular is expected to see a much higher than average growth rate of 17 percent.»

read more

NGA wants to speed cloud deployment

Federal government has come to embrace the cloud in a big way, and many of its departments have already started moving their data and applications to the cloud. Though this is heartening from a technology and user perspective, what is painstaking is the process of approvals. Typically, it takes a minimum of six months for a cloud provider to get security clearance for its service. In fact, six months is when the approvals run at the fastest possible pace. Otherwise, clearance to use cloud service for federal government apps and data can take years. The National Geospatial Intelligence Agency (NGA) wants to change all this.

To those working in NGA this elaborate approval process feels like a super slow motion and this is why they’re doing everything they can to change it. According to Jason Hess, the cloud security head at NGA, many different processes are being put in place to reduce the time it takes for a cloud provider to get security clearance. Ideally, Hess wants all approvals to be cleared in a single day, so the cloud service can be up and running within 24 hours of its application. Currently, the NGA uses a combination of DevOps techniques to get approvals within seven days, but this hasn’t been easy by any breadth of imagination.

This is a big initiative, considering that the NGA is planning to move all of its data and applications to the cloud, in a big to “re-invent security.” The agency is looking to tap into the flexibility of cloud to break-down the IT architecture and re-build it every day, so hackers will experience a new operating environment every day. NGA believes that such a move can confuse hackers and the familiarity with the system, and in the process, will reduce the chances of an attack as well.

Though this idea is unique, its practical application is always questionable. Is it possible to build such a dynamic IT architecture that changes every day? Will there be a specific pattern that would be followed in choosing the architectural style? These are important questions that have to be answered if the NGA wants to use this strategy to prevent outside attacks on its system. If an architectural style is going to be repeated after every few days, then it becomes predictable for hackers. Also, if there is no randomization, then architectural styles can be guessed by sophisticated hackers.

Given these questions, we can say that the NGA’s approach to cyber security is not for everyone. Currently many federal departments have vast amounts of data and legacy systems that can make it almost impossible for them to tear down the IT architecture and build one from scratch each day. At the same time, simply installing cyber security measures at the edges of a network system is not going to work anymore.

So, federal departments have to strike a balance between the aggressive security approach of the NGA and its own problems of legacy systems and siloed data,

Overall, it’ll be interesting to see if NGA’s plan can be implemented across the board.

The post NGA wants to speed cloud deployment appeared first on Cloud News Daily.