Showing posts with label Network Monitoring. Show all posts
Showing posts with label Network Monitoring. Show all posts

Friday, March 28, 2014

Network Functions Virtualization Meets Network Monitoring and Forensics

By Adwait Gupte, Product Manager

Enterprises and service providers are increasingly flirting with Network Functions Virtualization (NFV) as a means to achieve greater efficiency, scalability and agility in the core and datacenter.

NFV promises a host of benefits in the way networks are created, managed and how they evolve. Compute virtualization has, of course, redefined data centers, transforming servers from computers to virtual processing nodes that can run on one or many physical servers. This separation of processing hardware from the abstract “ability to process” definition of servers allows a lot of flexibility in the way datacenters are managed and how workloads are managed, especially in multi-tenant environments.

Network Functions Virtualization (NFV) is a similar concept, applied to networking. But haven’t switches and appliances always been distributed network “processing” nodes? NFV proposes replacing the integrated, purpose built software/hardware boxes, such as routers and switches, with commodity processing platforms and software that performs the actual network function. Thus, rather than having a box with its own network OS, processing power, memory and network ports which together function as a router, NFV proposes having a general purpose hardware with processing power, memory and ports that run software that transforms it into a router. In some cases, it’s more costly and less efficient to hand a networking job to a general purpose processor. The advantage of this virtualized router is that the software layer can be changed on the fly to turn this router into a switch or a gateway or a load balancer. This flexibility enables polymorphism within network infrastructure and promises to deliver a more nimble design that can be dynamically repurposed according to the changing needs of the network, thus future proofing the investment made in acquiring the infrastructure.

Today switching and routing functions can be virtualized, with some tradeoffs.  More sophisticated functions for security and network/application monitoring still require hardware acceleration. Tools such as NPM and APM and security systems such as IPS, which operate on real time data, have arrived in a virtual form factor for some use cases. Technologically speaking, this seems to be the logical evolution that follows the virtualization of much of data center infrastructure. While there remains debate as to whether the tool vendors embrace or attempt to stymie this evolution, the more critical question is: What elements require optimized processing and hardware acceleration?

From the customer’s viewpoint, virtualization reduces the CAPEX allocated to such tools and systems. As virtualized tools become available, it might become easier for customers to scale their tool deployments to match their growing networks. The hope of scaling out, without needing to buy additional costly hardware based appliances, is an obvious attraction. They can instead just increase the compute power of their existing infrastructure and possibly buy more instances of the virtualized probes, as necessary. In a multi-tenant situation, these probes may even be dynamically shared as the traffic load of individual tenants varies. But what if those tools and probes cannot function without hardware acceleration? What if running them on general purpose compute proves more expensive than running them on optimized systems?

There’s no reason to adopt virtual tools and systems that can’t get the job done or that increase costs.

Further, while routing/switching are very well understood functions that even nascent players can virtualize, there is a significant operational cost to any such changeover. Advanced monitoring features are much more complicated and sophisticated. In contrast to infrastructure elements, tools and security systems require a greater development investment and more often require highly integrated hardware to function efficiently. 

I think the driving force behind this transformation will have to come from the customers, especially large ones, who have the economic wherewithal to force the vendors to toe the line towards virtualization. An example of such a shift is AT&T’s Domain 2.0 project. As John Donovan put it, “No army can hold back an economic principle whose time has come.”

As the large customers build pressure on the vendors to move towards virtualization, I think we will start seeing some movement towards NFV within advanced products of the networking space. One element of this change is already occurring in forensics or “historical” (as opposed to real time) network analysis. Historical analysis functions, such as IDS or Network Forensics, can be virtualized to a great degree, but these systems, today, tend to be monolithic devices. These devices combine capture, storage and analysis. As has been shown repeatedly in the past, there’s certainly value to specialization; especially when line-rate performance is required. Capturing network data, storing it efficiently for retrieval, and building smart analytics are diverse functions that have been coupled in the past.

Today, just as we consider decoupling network functions from underlying hardware, we should also look at the benefits of decoupling network data from analysis software and hardware appliances. After all, these systems are hardware, software, and data. Ultimately, NFV provides an opportunity for the analytics tools and security systems to offload the data capture and storage duties to other elements, enabling hardware optimization (if required) and freeing the data to be used by a variety of systems. A move towards NFV by the analytics vendors would bring with it all the advantages of scalability and cost-effectiveness that NFV promises in other networking domains—but  analytics vendors need to decouple data processing as much they need to virtualize functionality.

Friday, February 7, 2014

VSS Monitoring Optimizes SDN-based Traffic for Enhanced Performance Monitoring and Security Agility

NPBs and SDN VE Deliver Flexible, Cost-Effective Monitoring and Security Solutions

Last week, VSS Monitoring announced its joint solution with IBM (NYSE: IBM) delivering a converged monitoring fabric for virtual environments. Powered by VSS Monitoring Network Packet Brokers (NPBs) and IBM SDN Virtual Environments (SDN VE), organizations can leverage the solution to accelerate SDN-based environments for performance optimization and fail-safe monitoring at wire-speed, essentially creating a converged monitoring fabric for both physical and virtual-host traffic (including OpenFlow switch traffic). Announced at the OpenDaylight Summit on February 4, 2014, IBM SDN VE solution consists of the new unified controller, virtual switch overlays, non-SDN gateways, and open interfaces. SDN VE supports OpenStack as well as VMware and Kernel-based Virtual Machine (KVM). VSS Monitoring NPBs, in combination with the IBM unified controller, enable organizations to leverage OpenDaylight technologies to facilitate SDN deployments with enhanced performance monitoring and security agility. NPB solutions provide fail-safe monitoring and total visibility into virtual traffic, with VSS’s vMesh, vNetConnect and vSpool. Only VSS Monitoring NPB solutions enhance big data visibility for business intelligence analytics or Big Data applications. 

Total Visibility for New Lines of Business

As networks evolve, incomplete visibility to decentralized monitoring and security tools and scaling large network deployments become challenging due to the their inelastic nature. This often requires a rip-and-replace approach or successive proof-of-concepts as organization grows. Network packet brokers have emerged as a critical element of the network infrastructure to solve network visibility and monitoring challenges. Well established for physical networks (LAN, WAN, and Distributed), NPBs now address the same challenges for virtual-host traffic (VMs) in addition to SDN-based environments. By having complete visibility into any and all packets traversing the converged network, organizations gain powerful, timely analytics into the network and application performance for faster root-cause resolution, high service level assurance, 99.999% availability, accelerated user experience, and – in light of Big Data – new lines of business from meaningful customer insights. 

An All Encompassing Monitoring Fabric

Today’s network monitoring environments utilize monitoring and security tools from any number of different vendors. The ability to easily manage and deploy all tools in a coordinated manner is critical for both network operations and security operations. VSS Monitoring NPBs are vendor-neutral and are currently deployed with a wide variety tools that could be deployed in conjunction with or in parallel to the IBM SDN Virtual Environments.

For more information, check out the IBM and VSS Monitoring joint solution brief.

Saturday, January 18, 2014

Top Security Breaches of the 21st Century. Are You Next?

Facts: Top Security Breaches of the 21st Century

  1. 2009 - Several US-based enterprises lose valuable intellectual property exploited by the Chinese hackers (CSO Online). 
  2. 2011 - A multi-billion dollar game company loses millions while its website was down for a month after 77 million user network accounts were hacked (CSO Online). 
  3. 2013 - One mass merchandise retailer's cyber-attack impacts 70+ million customers, exposing credit/debit card information, including security pin codes (The Washington Post). And recently, a high-end retailer is the latest victim (CNET). 

It is 2014. Is your organization next?

The ever-changing, complex, network security landscape makes network management and risk management a monumental task for organizations worldwide. No longer is the case of perimeter defense a de facto standard, which put into question whether or not existing design and deployment models are future-proofed. As emerging threats, both known and unknown, plague the network - enterprise as well as carrier networks - the ability to add layers of defense in real-time, accelerate response, and even better, prevent intrusion from happening in the first place is the new norm.

Defense-in-Depth Network Security - the New Norm

Achieving multi-layer defense in depth is now possible with an architecture that 1) simplifies design and deployment to scale across converged and distributed networks and 2) has carrier class performance. At the same time, threats intelligence can be optimized to accelerate incident detection and response protocols to combat a plethora of multi-dimensional challenges, such as #Next-Gen network, #BYOD, #IoT, #Big Data, #cloud and #virtualization, stress testing the security infrastructure on a day-to-day basis. 

The New Model's Must Haves

This February, learn from security experts and hear from analyst Jim Frey, VP of Research Network Management at EMA, the must haves of a defense-in-depth model powered by network visibility controller system (aka network packet broker | What is network packet broker?), which are: 
  • Visibility - 100% end-to-end visibility, any packet, any where, any tool;
  • Agility - accelerated security proof-of-concept with simplified deployment and lower OpEx;
  • Defense-in-Depth - proactively detect and mitigate security threats AND add defense layers with minimal impact (think investment protection and operations simplicity);
  • Scalability - support multiple 1G/4G/10G/100G segments with 1G/10G security tools, maximizing tool's capacity for higher ROI; and
  • Service Assurance - complete protection for all security zones and PCI DSS, SOX, HIPAA and GRC requirements compliance.

Time is of the Essence. Learn More

To gain insights and in depth knowledge of the gaps in existing design and deployment models, learn more about this new model, get answers to common and emerging network pain points, and understand the benefits and successes a major global bank had achieved, join us for a two-part webinar series on BrightTALK: Optimizing Security and Performance Monitoring channel. 
  1. Part 1 - Architecting Defense-in-Depth Network Security for Scalable Forensics, a 45-min webinar with Tony Zirnoon, Sr. Director of Global Security Strategy & Alliances.  February 5, 2014 at 10am PT. [Register Now]
  2. Part 2 - Network Intelligence Optimization for Security Service Assurance, a 45-min panel discussion plus 15-min Q&A session with Jim Frey, VP of Research Network Management at EMA. February 19, 2014 at 7am PT. [Register Now]
US security professionals can join us at #RSA2014 in San Francisco between February 25 and 27 at the Moscone Center, South Hall. Complimentary Explorer Expo Pass is available for those wishing to consult with our experts at Booth 301. [Sign Up

EMEA security professionals can also join us at #MWC in Barcelona during that same week at the Fira Gran Via, Hall 6. Complimentary Exhibit Floor Pass is available for those wishing to consult with our experts at Booth 6L50 as well. [Sign Up]

Don't Get Left Behind

Understanding the cyber security arena and the challenges surrounding network security is a top of mind agenda for most C-level executives and IT professionals of all organizations. Don't miss this golden opportunity to gain valuable insights and use cases on proven deployments for FREE. Chances are, your competitors probably already get involved. So what's it going to be? Get ahead or get left behind!