









As the digital landscape enters the age of Artificial Intelligence, the traditional methods of securing applications are being fundamentally challenged. The emergence of advanced AI models has shifted the advantage towards attackers. With AI, even a novice attacker is now weaponized into a sophisticated hacker while operating semi-autonomously at very low cost, and unprecedented scale. Imagine the massive damage that ransomware gangs and/or nation-state actors could do with these cyber weapons. In recent times, ransomware attacks have led to business operations going offline for weeks and months, resulting in financial losses in hundreds of millions of dollars. To maintain a cyber resilient posture, organizations must move beyond reactive security and embrace a proactive defense-in-depth strategy centered on lateral security and virtual patching.
Frontier AI models have the intelligence to identify unknown (zero day) software vulnerabilities (bugs) and find ways to exploit them faster than ever before. Attackers can leverage these exploits to infiltrate digital enterprises, propagate laterally, hopping and hunting, to find high value assets for ransom or for stealing secrets. They can initiate widespread, volumetric and/or targeted attacks semi-autonomously – leading to an exponential increase in the attack surface. “Security through obscurity” is no longer a viable cyber security strategy.
If enterprises can quickly patch software vulnerabilities, they can certainly reduce the risk of a breach and/or its spread. However, this is an extremely time consuming and resource intensive endeavor. There are thousands of software tools and apps, each with varied software versions, deployed on different types of hardware and operating systems and spread across multiple data centers. In larger organizations, “race to patch” can take weeks to months to roll out patches enterprise wide, leaving the organization exposed to infiltration, ransom and potentially business disruption.
To help quickly protect against this tsunami of exploits unleashed against workloads & apps and to buy down risk, enterprises need to focus on two key defenses for their private cloud workloads:
Virtual patching is a vulnerability-shielding tactic that protects assets by implementing a minimal layer of security policies at the network or application delivery level, front ending that asset. These measures intercept and block exploit attempts before they can reach the vulnerable software, effectively “patching” the flaw in the communication path rather than the software itself.
VMware vDefend provides a revolutionary approach to virtual patching of workloads by integrating security directly into the VMware Cloud Foundation (VCF) hypervisor fabric. The vDefend IDPS (Intrusion Detection and Prevention System) is applied directly to the vNIC of every workload, enabling deep, granular inspection of application traffic (every packet) moving across the VCF private cloud, specifically targeting network-layer exploits and lateral movements.
The vDefend Advantage: What makes vDefend IDPS powerful for this use case is its architectural advantage, signature strategy, and operational simplicity.
vDefend Distributed Firewall: Restrict Unauthorized Lateral Propagation
To further restrict lateral propagation of threats, vDefend also provides a high-performance hypervisor-embedded Layer-7 Distributed Firewall (DFW). It allows comprehensive lateral segmentation of VCF workloads through highly streamlined context (or tag) based security policies. Lateral segmentation includes both macro and micro-segmentation, applied to ensure trusted (least-privileged) access to infrastructure services, environments (or zones), and applications. DFW is fully scale-out, eliminates traffic tromboning and the need for network changes (unlike traditional firewalls), and preserves the segmentation posture during vMotion events. It also includes a built-in prescriptive deployment tool, DFW 1-2-3-4 (blog), enabling rapid self-deployment across all workloads in as little as a few weeks.
While vDefend secures the internal network, the Avi Web Application Firewall (WAF) acts as the first line of defense for web-facing applications, providing virtual patching at the web layer.
How Avi WAF Prevents Exploitation
Examples of Vulnerabilities Protection
Avi WAF for Vulnerability Scanner to further Virtual Patching: Avi WAF provides an inbuilt SDK that can import Dynamic Application Security Testing (DAST) scanner results to construct the customized WAF policy to protect the application from security threats found by the scanner. Avi WAF supports Qualys Web App Scanning and OWASP ZAP Attack Proxy DAST scanner results.
The Avi Advantage: Key differentiators for Avi WAF are its software-defined architecture, scale-out and full access to the Avi customer base.
In the era of AI-accelerated threat landscape, the “race to patch” has reached a breaking point. Organizations can no longer rely solely on eventual roll-out of code updates to stay secure. By leveraging vDefend Distributed IDPS for lateral virtual patching, vDefend DFW for lateral segmentation and Avi WAF for web application security, enterprises can implement a comprehensive private cloud cyber defense strategy. This multi-layered approach provides an immediate and comprehensive defense that blocks hackers from exploiting vulnerabilities, buying the IT team the critical time needed to maintain long-term application integrity.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。