Constructing community and workload safety architectures could be a daunting job. It entails not solely choosing the proper resolution with the suitable set of capabilities, but in addition guaranteeing that the options supply the fitting stage of resilience.
Resilience is commonly thought of a community operate, the place the community have to be sturdy sufficient to deal with failures and supply alternate paths for transmitting and receiving information. Nevertheless, resilience on the endpoint or workload stage is regularly neglected. As a part of constructing a resilient structure, it’s important to incorporate and plan for eventualities during which the endpoint or workload resolution may fail.
Once we study the present panorama of options, it often boils down to 2 totally different approaches:
Agent-Based mostly Approaches
When selecting a safety resolution to guard software workloads, the dialogue typically revolves round mapping enterprise necessities to technical capabilities. These capabilities sometimes embody security measures similar to microsegmentation and runtime visibility. Nevertheless, one facet that’s typically neglected is the agent structure.
Typically, there are two predominant approaches to agent-based architectures:
- Userspace putting in Kernel-Based mostly Modules/Drivers (in-datapath)
- Userspace clear to the Kernel (off-datapath)
Safe Workload’s agent structure was designed from the bottom as much as defend software workloads, even within the occasion of an agent malfunction, thus stopping crashes within the software workloads.
This robustness is because of our agent structure, which operates utterly in userspace with out affecting the community datapath or the applying libraries. Due to this fact, if the agent have been to fail, the applying would proceed to operate as regular, avoiding disruption to the enterprise.
One other facet of the agent structure is that it was designed to present directors management over how, when, and which brokers they need to improve by leveraging configuration profiles. This strategy supplies the pliability to roll out upgrades in a staged style, permitting for essential testing earlier than going into manufacturing.
Agentless-Based mostly Approaches
One of the best ways to guard your software workloads is undoubtedlythrough an agent-based strategy, because it yields one of the best outcomes. Nevertheless, there are cases the place putting in an agent just isn’t potential.
The primary drivers for selecting agentless options typically relate to organizational dependencies (e.g., cross-departmental collaboration), or in sure circumstances, the applying workload’s working system is unsupported (e.g., legacy OS, customized OS).
When choosing agentless options, it’s essential to grasp the restrictions of those approaches. As an illustration, with out an agent, it’s not potential to attain runtime visibility of software workloads.
However, the chosen resolution should nonetheless present the mandatory security measures, similar to complete community visibility of site visitors flows and community segmentation to safeguard the applying workloads.
Safe Workload presents a holistic strategy to getting visibility from a number of sources similar to:
- IPFIX
- NetFlow
- Safe Firewall NSEL
- Safe Shopper Telemetry
- Cloud Movement Logs
- Cisco ISE
- F5 and Citrix
- ERSPAN
- DPUs (Knowledge Processing Models)
… and it presents a number of methods to implement this coverage:
- Safe Firewall
- Cloud Safety Teams
- DPUs (Knowledge Processing Models)
Key Takeaways
When choosing the proper community and workload microsegmentation resolution, at all times be mindful the dangers, together with the menace panorama and the resilience of the answer itself. With Safe Workload, you get:
- Resilient Agent Structure
- Utility runtime visibility and enforcement with microsegmentation
- Various function set of agentless enforcement
Study extra about Cisco Safe Workload
We’d love to listen to what you assume. Ask a Query, Remark Beneath, and Keep Related with Cisco Safety on social!
Cisco Safety Social Channels
Share: