Cybersecurity Governance Infrastructure & Operations

Rethinking Segmentation for Better Security

Implementing effective segmentation for security with relatively flat enterprise networks is a hard and tedious task involving multiple teams and application downtime. The result: business critical applications are at higher risk and the compliance costs is very high. How can CISOs and Security Architects rethink segmentation to make security more robust and simpler to manage?

Contributor

Transcript

Sanjog Aul [00:00:00]:
Welcome listeners. This is Sanjog Aul, your host and the topic for our conversation is Rethinking Segmentation for Better Security. So segmentation is not new for security leaders and architects, but the flat enterprise networks make it very hard and tedious to implement, leaving business critical applications at greater risk. With the compliance cost staying very high, can we do better? Are there new and promising approaches for implementing segmentation? Are the related technology tools keeping pace with the dynamic shifts in the security management needs? How can we operationalize segmentation technologies for the best outcome? To discuss it, joining me isAriel Zeitlin. Ariel is the CTO and Co-Founder at Guardicore, a company specializing in security solutions for cloud and software defined data center environments. Hello Ariel, thank you for joining us.

Ariel Zeitlin [00:00:54]:
Thanks for having me.

Sanjog Aul [00:00:56]:
So let’s talk with. The first question I’ll have for you is how well is segmentation, the subject of segmentation, understood and implemented by the security community? And also I was curious, why is segmentation becoming so important now?

Ariel Zeitlin [00:01:12]:
Yeah, so segmentation is, I think, one of the oldest concepts in security. The logic is simple. You break down your network into segments and enforce some sort of access control between the segment or a firewall. That’s what firewalls will build to do. The benefits are clear and simple to understand. You have the higher level of segmentation you have, meaning the smaller segments, the attack surface is reduced and the impact of a potential breach is limited to the size of the segment, but while it’s not a new topic, a few things have changed significantly in the recent years. I think the first being is that enterprise infrastructure has become more diverse.

Ariel Zeitlin [00:01:48]:
There are cloud fast brain virtualization and each of those means there’s introduction of new attack surface and this happens fast. The second thing that changed is that regulation becomes more specific and it’s asked for segmentation, and there are compliance standards that require segments to be very smaller, sometimes as small as a single application. Look at PCI, DSS or SWIFT CSP regulation and then similar and the third thing that changed in my opinion is that the presence of that directory inside the data center is acknowledged now and the risk on the business continuity due to that of the fact that the networks are relatively flat and unsegmented is on everybody’s mind. So those three create sort of a sense of urgency now and push organizations to segment more. Internal auditors like compliance are requiring to segment more and to emphasize that.

Ariel Zeitlin [00:02:44]:
There was a recent Citigroup survey that asked a couple of hundreds of CISOs what was their priorities for this year and number one was cloud, but inside the cloud, firewall and segmentation were two out of five priorities and another example, the House of Representatives shared a report on the Equifax Bridge, which I think everybody in the security community knows and the report pointed out the lack of internal segmentation as one of the key gaps that allowed the impact of the bridge to be so big. So while it’s not a new concept, it’s becoming more and more important now because of all of those things that I mentioned.

Sanjog Aul [00:03:21]:
Now let’s talk about the tools. So how have the tools evolved to keep pace with this morphing security management needs? What do you see still missing?

Ariel Zeitlin [00:03:31]:
Yes. Okay. Segmentation is basically a problem we would expect a firewall to solve. That’s what again, they were built to do, put the relevant machines from one segment to a dedicated VLAN routed through a firewall. I think that was fine when the infrastructure was relatively uniform. You had some bare metals and then some virtualized environment and the segments would be somewhat big and static, which something you can manage with firewalls on VLAN, but today it doesn’t look like that anymore and it doesn’t work anymore.

Ariel Zeitlin [00:04:03]:
And the reason is that the infrastructures today include not just bare metal virtual environment, but also includes cloud and containers. Sometimes more than one cloud provider, sometimes more than one virtualization provider inside an organization. So the infrastructure is more complex. Applications span in many cases all the infrastructure. So creating a VLAN across this complex infrastructure becomes very complex and the second thing that makes the VLAN approach more challenging is that the cadence of a change in the application is very high and it impacts dependencies and thus it impacts the policies. Those are the two things that I think that making the traditional approach not very fit to the to the needs. I’ll give you a specific example of one of our customers.

Ariel Zeitlin [00:04:47]:
It’s a global investment bank that needed to comply with a new regulation by SWIFT. SWIFT is a provider of software that helps banks exchange money. This is how banks transfer money between them and this regulation requires to put all SWIFT servers into a separate segment and whitelist all the connections in and out of it. It’s very common to like specific financial services applications. The footprint of an application across the bank is not big. In this specific case, it’s around 100 servers, a bit less, but it still took them around 10 months to accomplish and here’s why, here’s how they described why it took so much time.

Ariel Zeitlin [00:05:27]:
The first, they needed to create a new VLAN across all of their data centers, across all of their switches and across all of their infrastructure and this task was very tedious for the networking team. The different types of switching equipment to configure Cisco here and Arista there and in something different in the cloud and they do architect to implement this change and it just took a lot of networking people effort and also they needed some locations, they needed to actually buy new networking equipment and cabling. So it made it even more, even harder. So once they were done with the VLAN, the next thing they needed to do is to move the application to the new VLAN.

Ariel Zeitlin [00:06:08]:
And this required additional few things to accomplish. First, they needed to shut the application down, which means it’s one of the most important applications in the bank. Or from the business perspective, they needed to choose a specific time in where the impact would be smaller and another thing that was complex is that when they moved the application, some of the IP is actually changed when they moved it to new VLAN. So they needed to find all those places where the IPs are maybe hard coded. So from the application team, this was a very scary and very tedious task to identify all this.

Ariel Zeitlin [00:06:45]:
So this is why it took a lot of time, a lot of effort, a lot of preparations to do this and again, I’m going back, it’s just hundreds of servers. So what happens if the demand can actually have hundreds and thousands of those applications? So this process is not even converging and I think this kind of explains why. Also, it’s a no technique and it’s something that people are used to, but the way regulation works and the way environments are built today, this is a very difficult task to do with traditional tool.

Sanjog Aul [00:07:18]:
So let’s talk about some of the new or promising approaches that may be available for implementing segmentation, which you feel somebody should consider. What would those be?

Ariel Zeitlin [00:07:31]:
Yeah, so on a very high level, I think the logical approach to solve all of these challenges is to distribute the file. Instead of creating VLANs and routing the traffic through firewall choke points that are challenged by the complexity of networking inside the hybrid environments and so on. All the challenges that we described before, the idea is to virtually distribute the file and instead of bringing the workload to the firewall, bringing the firewall to the workload and the local firewall will enforce the policy relevant to the specific workload and if the implementation is good, it will also follow the workload across the infrastructure. So you can migrate across different racks or it moves to the cloud. As long as the implementation is good, the policy can actually travel with the machine. So this is on a logical level. In practice, there are two types of actual implementations.

Ariel Zeitlin [00:08:22]:
First type is the kind of infrastructure based segmentation and it’s usually provided by the infrastructure vendors. In this implementation, the infrastructure vendor will implement the distributed firewall as part of its product, part of the infrastructure and it also provides some nice user interface to manage the policy across this distributed firewall. The advantages of this approach, it’s part of the infrastructure and it means that while you deploy the infrastructure, you deploy new switches or you deploy say VMware solution, you also deploy this micro segmentation technology in the same manner. The second advantage is that it’s sometimes bundled into other infrastructure packages so it can be cheaper for you to buy. There are a few disadvantages but and mostly I think if you have enough interesting workloads outside the control of this specific infrastructure, the solution doesn’t cover that. So if you all of your interesting infrastructure, let’s say on 90-95% of your interesting workloads are inside this infrastructure control that you should definitely consider at least this approach, but if you have more than that, a lot of risk will be left on the table and will not be addressed by this approach. The second approach is what sometimes is called an overlay approach and it’s usually provided by independent vendors.

Ariel Zeitlin [00:09:47]:
It usually means there is some sort of an agent that runs on the workload and implements the local firewall feed. The main advantages are is that as expected, it’s truly infrastructure agnostic. It will at least theoretically solve the coverage issue in a very elegant way. All your workloads on prem in the cloud infos are covered by the same technology in the same manner. The second is that in many cases it’s cheaper to start with. Let’s say you have very big infrastructure but the most important applications for the next couple of years that you actually want to segment maybe like just 20% of your infrastructure. So using an overlay approach you can deploy technology only there and focus only on them, and this will be cheaper, significantly cheaper to implement.

Ariel Zeitlin [00:10:32]:
And those are the main advantages, but I think from the disadvantages, I think one of the major is that it relies on agent being installed on the workloads and this may require a longer vetting process in the organization to make sure they don’t harm the application, but if you look at all the vendors in this space, they fall into those two categories.

Sanjog Aul [00:10:50]:
Let’s take a quick break listeners. We’ll be right back, and Ariel when we come back would love to understand the different critical parameters or aspects one must keep in mind when you are evaluating these new approaches or technologies and even comparing or when you’re comparing related technology vendors. So listeners, please stay tuned. We’ll write back.

Sanjog Aul [00:12:18]:
This is CTN Brandcast on CIO Talk Network. Welcome back listeners. Ariel, when we are considering these new approaches and the technologies that you mentioned, what would be some of those critical aspects and parameters one must keep in mind? And also how would one go about comparing even related technology vendors?

Ariel Zeitlin [00:12:42]:
That’s a good question. I think one thing to keep in mind when you’re comparing approaches or even vendors that are the same approach is the most important thing is simplicity and time to actually getting the policy in production. This is the most important thing and all the selections should be made based on this factor. From our experience, three kind of properties or three factors. The most important and impact the simplicity and time to policy the most. First is coverage. Will the solution be able to work in all the environments I have now or I will have in the future? So make sure you understand this well. Missed coverage will probably mean that you will need to either leave risk on the table or need to run another tool and manage policies across two different tools, which is really impractical.

Ariel Zeitlin [00:13:35]:
So coverage is number one. Second is how flexible is the policy engine and will the policy engine allow me to easily express what I want to achieve? And I’ll give you an example. So most of the vendors, some vendors support whitelist approach, some vendors support blacklist approach or mix of whitelist and blacklist. So you need to think really well on what type of policy you would like to apply. If you only want to create a few segments right across your data center and completely whitelist all the connections that can get in and out of the segment and say all the rest is not allowed, probably a whitelist approach is good enough for you. If you also like to say things like I don’t want my databases to access the Internet directly or I want to make sure that a server is connected by SSH only if this SSH connection is coming from a John Box or from some audited machine. Those are not whitelist kind of policies. That’s much easier to express in a blacklist approach.

Ariel Zeitlin [00:14:41]:
So think really well on what do you want to implement and make sure that the policy engine of the vendor can actually support it, and by the way, if you do not know, we are not sure we do suggest taking the most flexible policy engine. The third thing that impacts the simplicity and the time to policy is the UX of setting the pause. In our experience. By the way, this is the one thing that impacts the time to project delivery the most. How simple it is to understand your applications and their dependencies. How simple it is to understand what the segment should look like and what the policies between the segments should look like, and how easy is the simple the workflow for setting the policy and tuning it.

Ariel Zeitlin [00:15:26]:
Usually this will require some sort of a visibility tool that will give you an idea of how the graphic looks like and most of the vendors actually provided, but make sure that you get exposed to this part of the product enough to understand how simple it will be with hundreds and thousands of servers that you will have in your environment. Ask the vendor to demo this step by step play with the product. Try to really understand how it will look not in a demo that the vendor gives you on a call, but actually try to understand how it will look in your environment. There are more, but we found those free coverage, the flexibility of the engine and the user experience and the workflow to be the most fundamental for the success of the project.

Sanjog Aul [00:16:09]:
Let’s talk about operationalizing these technologies. What’s the most effective way of doing it? And if you were to build kind of a playbook, what would be the first steps in that playbook?

Ariel Zeitlin [00:16:21]:
I think this is a very important question and actually not a very simple one to answer in a few minutes, but as many aspects are involved into this, I’ll touch on the most important ones that, I feel are responsible for most of the failures or delays that we’ve seen. First you need to identify your goals. Milestone assignment like any project that is well managed, some of the milestones and goals will be driven by some sort of a compliance deadline. Others will be driven, some by some internal priorities and initiatives. This is my most important application with the biggest exposure. I would like to start with it first and I want to finish it like in three months and there are many other approaches like aiming first at some low hanging fruits. I gave you this example of a customer who wanted to make sure that all the SSH connections to a server are only allowed if it goes if they go through a jump box because he considered this to be the most burning risk for him.

Ariel Zeitlin [00:17:16]:
I actually do this low hanging fruit approach first because it gives a great way to show ROI fast and accelerate the internal technology adoption. I really believe in this, so identifying managing this as a project with goals and milestones and timeline. I think this is a very important thing to start with, If you don’t have a good plan, it can be delayed. Drag management will start asking why do we have this technology purchased and deployed for six months and we still have no significant risk reduction implemented? The second thing is you need to figure out the responsibility model, and depending on the organization, the responsibilities of who is going to manage this distributed firewall is actually shift, and the reason is that today in many cases the networking team is the team that is responsible of managing the firewalls.

Ariel Zeitlin [00:18:04]:
As we have seen that there’s a lot of networking indeed involved in this process. You need to create VLANs and so on, but with this new technology, networking people are not really part of the play in a way. So the responsibility can shift to the security operations or even application owners or DevOps. So you’ll need to figure out what will work in your organization. Who will be in charge of deploying the technology and making sure it’s bundled with the deployment of any new server. Who will be in charge of suggesting approving, tuning the policies. In some cases different policies will be set by different teams.

Ariel Zeitlin [00:18:38]:
We have customers where like global policies such as access to organizational resources are managed by the security team and the dependencies of each application are managed by the application owner themselves or the security. Just review them. This is in fact common. Without cleaning and understanding really well how the ownership will be for this technology, the project may even fail to start, and if you are not able to answer your CIO the question who will own it? Who will manage it? He may be right in not approving it. So there are many best practices here. My best advice if you have a peer that the organization is similar to you, go ask Dan how they implemented this. This will be probably the best, shortest path to the truest.

Ariel Zeitlin [00:19:22]:
But there’s also a lot of material online to understand how it might work for you. So this is the second one, the responsibility model. I think the third one is automation. I think automation is the way now 18 applications are delivered and so needs to the security team that change very fast, and if you fail to automate processes that are affected by those changes will be chasing your own tail here, and here’s an example of what I mean. Let’s say we have this SWIFT application from which we discussed earlier and you want to put it in its own segment. Properly set policy will apply to all the servers of the SWIFT application and you will probably need to identify them and set the policy saying all SWIFT servers that all servers that are part of the SWIFT application and this policy is applied to them.

Ariel Zeitlin [00:20:11]:
More often than not you will rely on some sort of CMDB to identify those servers. Now what happens if a new server is deployed? If you not automate the process of making sure that this server is known to the segmentation tools as part of the SWIFT application, usually by some sort of labeling or tagging, you will need to manually update the policy. So you need to automate that, any new server that is introduced or any change that is done the kind of policy and the tool knows about it and it’s reflected in the policy change. There are many examples of what type automations you are really deployed. It really depends on your own scenario. My best advice would be is you should really become allergic to anything manual because it will not scale with the dynamicity of how the applications data centers look today. I think those are the three major ones but overall it’s a really important question.

Ariel Zeitlin [00:21:06]:
I wish I had a bit more time to discuss that. What some of the vendors sometimes do is some sort of workshop like ask your vendor to better understand how they recommend operationalizing that, but because in many of the organizations this is the first time they undergoing such a product with a different approach, and the vendors probably will have the best expertise and experience.

Sanjog Aul [00:21:30]:
So what’s ahead of the curve for security leaders as you see it and how should the discipline of segmentation evolve in your view, among other security areas to keep up?

Ariel Zeitlin [00:21:44]:
I think what’s ahead of us is even faster more dynamic data center with more technologies that are nascent today. Containers, paths, serverless and applications that change really fast. Business needs them in order to innovate and attract customers, and there’s no way of stopping that, of course, but this also brings a potential of unlike new vulnerabilities and new attack surfaces unless they are addressed accordingly, and the only way for the security to catch on this is to become part of this elite teams that are being formed along the organizations which consist of networking and converged groups of networking, system infrastructure, storage people, DevOps and cloud people that are building these new environments that are very dynamic, very automated and security needs to become part of this elite group and fast. Otherwise they will be chasing those changes endlessly. Any security requirement, segmentation not being an exception here, will need to be implemented as part of this group.

Ariel Zeitlin [00:22:48]:
In fact, it may require not only changing the way the security are working on in processes, but it may also require change in the skill that security people need to have in order to be part of this group. You need to know how to code. You need to know how to develop and implement your security intents and integrate this into the process of deploying those applications.

Sanjog Aul [00:23:10]:
Once again, thank you Ariel for sharing your thoughts and insights about how security leaders and architects can rethink segmentation to enable better security.

Ariel Zeitlin [00:23:20]:
Thank you again for having me.

Sanjog Aul [00:23:23]:
Thanks once more Ariel and listeners. I invite you to find related conversations on our website at ciotalknetwork.com.

Download Podcast
Apple PodcastGoogle PodcastSpotify, Pandora, iHeartRadioSoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

Contributors

Ariel Zeitlin

Ariel Zeitlin, CTO & Co-Founder, Guardicore

Ariel co-founded Guardicore after spending eleven years as a cybersecurity engineer and researcher at the Israeli Defense Forces (IDF), where he worked closely with co-founder Pavel Gurvich. In his last position at the IDF, Ariel led a team... More   View all posts
Add Comment
Click here to post a comment

Exclusive Sponsor

Guardicore MPU 300X250
Ariel Zeitlin