惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
Engineering at Meta
Engineering at Meta
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 司徒正美
I
InfoQ
S
SegmentFault 最新的问题
博客园 - 叶小钗
N
Netflix TechBlog - Medium
Y
Y Combinator Blog
IT之家
IT之家
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
月光博客
月光博客
The Cloudflare Blog
U
Unit 42
GbyAI
GbyAI
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog

VMware Security Blog

VMware vDefend Advances Multi-Layer Lateral Security, Deployment Automation and Performance for the Frontier AI Era VMware vDefend Sessions at VMware Explore 2026 Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS Introducing VMware vDefend Lateral Security Design Blueprints for VCF 9.1 AMD Ionic Driver Vulnerabilities Affecting VMware ESX VMware at Pwn2Own Berlin 2026 VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era Breaking the Ransomware Kill Chain: Why Distributed Lateral Security Is No Longer Optional Virtual Patching: Guarding Against a Tsunami of AI-discovered Exploits with vDefend and Avi VMware vDefend: Zero Trust Lateral Security for Kubernetes Workloads on VCF Why Perimeter Firewall is Not Enough: Lessons from the GoAnywhere MFT Zero-Day Advancing Zero Trust Private Cloud with vDefend Lateral Security Game changer: How AI simplifies implementation of Zero Trust security objectives vDefend DFW 1-2-3-4: Deploy Zero Trust Microsegmentation in a Few Weeks to Rapidly Secure VCF Workloads Stacking Your Defenses: Integrating Advanced Threat Prevention and SIEM Unleash Zero Trust: Secure Private Cloud and Agentic AI Workloads with VMware vDefend Innovations VMware vDefend Sessions at Explore 2025 Dubai Airports Secures Critical Infrastructure with VMware vDefend
VMware vDefend IDPS: Securing Private Cloud Workloads in ...
Sunil Wadwani · 2026-08-25 · via VMware Security Blog

The enterprise technology landscape is undergoing a radical transformation, and at its core is the modern data center. Virtual machines (VMs) and agile Kubernetes-based environments have long served as the foundation of this infrastructure. However, as companies deploy artificial intelligence in daily business operations, they must aggressively expand their AI ecosystems to handle highly resource-intensive AI workloads. Ultimately, this shift is redefining what is possible in IT infrastructure and driving unprecedented growth across the enterprise.

This rapid expansion comes with a dark side: the same frontier AI that is accelerating business operations is being weaponized by adversaries. Attackers are increasingly deploying these models to intelligently find vulnerabilities, generate exploit code, correlate across targets, and execute chained attack paths at machine speed. The impact is staggering. As documented in recent M-Trends reporting, AI-discovered vulnerabilities have collapsed the median time to exploit (TTE) from 771 days in 2018 to sub-hourly windows today.

This explosive growth creates a sprawling attack surface that is notoriously difficult to secure consistently and efficiently. Furthermore, when facing threats that move at sub-hourly speeds, defenders can no longer rely on traditional playbooks. They must operate continuously, cost-effectively, and at that exact same machine speed. To effectively defend this modern ecosystem, organizations need robust lateral security that scales with the immense demands of high-performance workloads while enforcing consistent protection across highly distributed VM and Kubernetes clusters.

Purpose-built to address these challenges for the VMware Cloud Foundation (VCF) private cloud, VMware vDefend offers a multi-layered defense approach to protect east-west traffic against ransomware and advanced threats. vDefend includes an Intrusion Detection and Prevention System (IDPS), which inspects all traffic entering or leaving the network, detecting and preventing known threats from gaining access to the network, critical systems, and data

Let’s look at how vDefend IDPS addresses these critical needs.

The vDefend IDPS Advantage

To protect modern, distributed workloads without sacrificing speed, security must be built-in, not bolted on. By leveraging a hypervisor-native architecture, vDefend distributed IDPS provides seamless, plug-and-play zero-trust lateral protection.  Furthermore, because policies are distributed and automated, protection scales effortlessly, applying instantly as workloads are created or migrated across your environment.

High-Performance Lateral Threat Prevention with Turbo IDPS

vDefend introduces High-Performance Lateral Threat Prevention via an optimized Turbo IDPS architecture. By boosting throughput from 9 Gbps to 17 Gbps per host (17 Tbps per VCF instance), an 88% increase, Turbo IDPS ensures that every internal flow is inspected for malicious activity at line-rate speeds. Now you can seamlessly protect your East-West traffic while meeting the immense demands of high-performance AI workloads.

Optimizing Inspection with Maximum Performance

In a Zero Trust architecture, deep packet inspection is vital, but applying it blindly to all traffic is computationally inefficient. While vDefend distributed IDPS offers a robust 17 Gbps of throughput per host, securing high-capacity workloads optimally requires intelligent bypassing.

The “EXEMPT” rule action enables this strategy by allowing security operators to easily identify specific trusted flows (data backups, database replications, etc.) and exclude them from the IDPS scanning engine.

Key benefits for vDefend customers:

  • Optimize resources: Exempting high-volume trusted flows preserves valuable compute resources. It frees up CPU cycles to apply IDPS rules exactly where needed—such as virtual patching—while explicitly bypassing them where unnecessary. 
  • Reduce Alert Fatigue: Frees up time for SOC operators to focus on actual threats by eliminating the false positives typically caused by generic signature alerts.

Simplifying Zero Trust and IDPS Deployment with vDefend ATP Journey

vDefend ATP Journey (ATP 1-2-3) streamlines comprehensive IDPS deployment by transforming the complex path to Zero Trust into an intuitive, data-driven Security Journey. This methodology assesses an organization’s current security posture. It provides a structured workflow that smoothly guides users through sequential segmentation stages—from securing critical infrastructure services to fully locking down inter-environment traffic.

Key User Benefits:

  • Easy Enablement: Accelerates configuration deployment through automated workflows and applies prescriptive IDPS policies in accordance with security best practices.
  • Operational Efficiency: Provides real-time updates on security gaps through the Security Segmentation Report and recommends specific rules to address and improve overall posture.

Advanced Threat Prevention with vDefend IDPS

Defending against AI-Driven Threats: Distributed Virtual Patching

Frontier AI models have armed attackers with the ability to find previously unknown zero-day vulnerabilities across software and at machine speed. Attacks can now propagate in hours. Given the speed of AI-driven threats, it’s imperative to have a solution that can proactively address them and effectively maintain a defensive posture.

vDefend IDPS acts as a shield, proactively blocking potential exploits for newly detected vulnerabilities until official patches can be applied. It uses frequently updated signatures to protect against the latest global threats and supports custom signatures—imported or developed in-house—allowing customers to quickly and virtually patch their applications.

This video, vDefend Virtual Patching, demonstrates how distributed IDPS can be applied to protect against these threats.

Learn more about vDefend Virtual Patching here.

Threat Visibility

Deploying vDefend IDPS in a detect-only mode transforms network monitoring into a high-visibility threat intelligence tool. By generating high-fidelity alerts mapped directly to the MITRE ATT&CK framework, the system illuminates exactly how an attacker breaches the network and moves laterally. This detailed mapping of the attack kill chain provides SOC teams with the essential, deep context required to quickly investigate, understand, and respond to complex security events before they escalate.

vDefend IDPS provides:

  • Early Detection: Empowers incident response teams to take early action and minimize damage.
  • NDR Context: Integrates seamlessly with Network Detection and Response (NDR), a threat correlation engine, to create a comprehensive, multi-layered security posture.

Learn more about the vDefend ATP solution here. 

Streamlined Regulatory Compliance

Achieving compliance with stringent frameworks doesn’t have to be a resource-intensive challenge. vDefend IDPS transforms complex regulatory mandates into a streamlined, automated process.

Core Benefits

  • Embedded, Frictionless Compliance: Simplifies alignment with PCI-DSS, HIPAA, and NIST Zero Trust by building security directly into the infrastructure layer rather than bolting it on.
  • Virtual Patching: Protects unpatched workloads against known and zero-day vulnerabilities.
  • Audit Control and Reporting: Automatically logs and captures network packet data to easily generate comprehensive audit trails and enforcement reports.

Inspection for All Workloads – VMs, Kubernetes and Bare-metal

In addition to protecting VM workloads, vDefend IDPS extends deep packet inspection directly to container nodes and bare-metal servers. Analyzing this highly dynamic container traffic provides granular visibility into lateral East-West traffic. This allows organizations to scale cloud-native architectures without compromising their underlying security posture.

Key benefits for vDefend customers:

  • Consistent Policy: Enforce consistent label-based policies that span across VMs and Kubernetes clusters.  
  • Unified Management Console: Manage all workloads from a single console.
  • Lateral Movement Prevention: Prevent lateral movement by applying policies directly at the source—at the Container Network Interface (CNI) for pods and vNICs for VMs.

vDefend distributed IDPS protects a diverse range of modern workloads—from VMs and containers. By leveraging Advanced Threat prevention on the gateway firewall, these detection capabilities extend directly to bare-metal servers. Additionally, full support for air-gapped environments ensures your infrastructure meets all regulatory compliance requirements.

Conclusion

The rapid expansion of AI workloads is radically reshaping the modern enterprise data center. Simultaneously, adversaries are weaponizing frontier AI models to launch high-speed, sophisticated cyberattacks. To navigate this, organizations must make vDefend IDPS an integral, foundational part of their security journey. By embedding security into the hypervisor, vDefend seamlessly delivers true zero-trust protection. The platform addresses a vast breadth of critical use cases, from virtual patching to securing modern containers. Furthermore, with recent high-performance architectural enhancements such as Turbo IDPS, vDefend powers advanced threat prevention without introducing network bottlenecks. Ultimately, vDefend IDPS ensures your infrastructure remains agile, scalable, and decisively protected against AI-driven threats. 

Learn more: