VMware and Deep Packet Apocalypse
Earlier this week I spoke at a database security event about the inevitable virtsec architectural shift from (layer 4) core deep packet inspection to application protocol context (layer 7). A few hours after my preso a netsec vendor presented a virtsec vision of agents/sensors deployed at numerous key checkpoints across a virtualized infrastructure. It was indeed a beautiful slide. One of the attendees asked if the architecture was layer 7 and he replied “yes, deep packet inspection, layers 1-7, we do everything.”
Rather than single out a particular vendor, let me describe what I see taking place in coming months/years for the network IPS space. Those first generation IPS deep packet architectures charged with inspecting ALL traffic passing through them (and warning of suspicions and terminating sessions based on qualified suspicions) will have to really scramble to keep up with the demands of server and VM security. Doing everything, as the vendor claimed, is enigmatic when your core deep packet architecture is based on pattern matching. There are at least two fundamental problems, from which many others spring.
The first problem is driven by a fundamental requirement for any core pattern recognition system: accuracy and reliability depend upon stability. A suspicious attack needs to stay suspicious. And past suspicious attacks need to represent most of the future suspicious attacks. Mutation/change when it comes to attacks means an increasing likelihood of obfuscation and evasion for pattern matching architectures.
Yet exploits are now mutating at a fast pace; some can even mutate in the midst of an attack. Mutation accelerates the obsolescence of static pattern recognition. I talked about this in Attack of the Mutant Bots months ago at Always On.
The second problem with exploit pattern recognition is that it can become resource-intensive. All traffic (“everything” as the vendor commented) passing through an appliance (or checkpoint) is inspected. As more patterns (and permutations) are added more processing is required to keep up. Now imagine that deep packet inspection IPS deployed via scattered agents at an array of key checkpoints between VLANS, hypervisors and servers in a partially virtualized data center. Larger and larger libraries are pattern matched in multiple checkpoints against all traffic pulsing back and forth through meshes of VMs and servers.
Rhetorical Questions Worth Asking
Exactly how many processor cycles will be needed to operate these scattered full traffic inspection points? How much latency will be produced at how many concomitant places? How many false alarms will ripple through these multiple points and create more noise and confusion? How many sensors will be required between each zone (or fuzzy perimeter) to keep each isolated to its own level of security?
This “chokepoint architecture” is a substantial barrier to both the accrual of the benefits of virtualization (movement, flexibility, mutation, utilization, etc) and the effective protection of the data center. It will force Draconian tradeoffs of a massive scale relative to the single point tuning at the outer perimeter, where firewalls function well to limit access to particular ports and segments.
>>Deep packet inspection within the server or VM mesh means mushrooming processing and security management requirements in a scenario now having to inspect and track mutation inside AND outside multiple new fuzzy perimeters. <<
Deep packet-centric inspection intrusion prevention, for this reason, is the enemy of VMware and every vendor betting on the fast adoption of virtualization in the data center. The Draconian tradeoff of the pattern match requirement in a fluid environment is, however, the best friend of an appliance-centric old guard that has monetized specialized hardware and security as a service (complexity equals revenue) models that understands the impact of virtsec on their business models. I see a similar “when do you virtualize” struggle about to take place between the vendors of commodity and specialized processors.
Everyone agrees that virtualization of the data center is inevitable. The question is when. And the answer to that question will have a substantial impact on market caps across many appliance categories in levels that we perhaps haven’t seen for awhile.
That is why VMsafe at Cannes drew such a reaction. It is a declaration of war on a tired status quo that has produced minimal innovation in recent years (especially relative to the black hats/malicious hackers). It is security’s next big hope or failure, on multiple fronts; and as VMware plans next steps the enemies of virtualization will naturally assemble armies of experts, pundits and partners in defense of a past that is already dying. They will do their best to distract the market with rumors of hypervisor attacks and ongoing risk debates, until they are ready to take the plunge.
That is why one blog’s recent description of virtsec as a defibrillator for the security industry resonated soon after VMworld.
I also think that it is inevitable that the network intrusion prevention space will bifurcate into packet inspection at the perimeter (integration into exploit-centric next generation firewalls) and advanced layer 7 server IPS systems (in front of servers, databases and VMs) that are more accurate, use less processor cycles and can protect systems without heightened availability risks, latency and detection obfuscation headaches.
Now that VMware has crossed the Rubicon and put the data center on notice, every deep packet-centric network IPS architecture (with or without some layer 7 add-ons) will face a choice of where to go (outer or inner perimeter), and it will make all the difference.
Get Seeking Alpha Free Stock Alerts by Email!
Get Free Stock Alerts by Email!
ETFs In Focus
-
Editor's Picks
-
Most Popular
- Opportunity in Emerging Markets Amidst This Panic
- iPhone Sales Drastically Surpass Q4 Consensus; Apple Reaches 10m Goal
- Buy, Sell or Hold: BofA Will Strengthen as the Weak Perish
- How Much Will a Wells-Wachovia Deal Cost Taxpayers?
- Fannie and Freddie Did Not Cause This Crisis
- 36 Opportunities for the Beginning of the Bull
- Full list of Editor's Picks »
- Iceland: When Too Big to Fail Becomes Too Big to Rescue »
- Who Is Now Number One in the Banking Industry? »
- 36 Opportunities for the Beginning of the Bull »
- 25 Cash Cows to Ride Out the Storm- Barron's »
- 3 Stocks That Are Begging To Be Bought »
- Bailout Bill Passes; What Happens Now? »
- Big Tech Prepares for Big Layoffs »
- iPhone Sales Drastically Surpass Q4 Consensus; Apple Reaches 10m Goal »
- Fannie and Freddie Did Not Cause This Crisis »
- Why Is Everybody Selling as Buffett Is Loading Up? »
- Now's the Time to Buy Bank Stocks »
-
Long Ideas
-
Short Ideas
-
Cramer's Picks
- Four Energy Bargains
- A-Power Energy Announces Huge Contract, Stock Down 11%
- Dun & Bradstreet: Weeding Out Disinformation in the Information Age
- Cramer: Dow Could Drop Another 14%, Oil's Going to $50
- Irrational Despair Is Creating Great Buying Opportunities in Two Chinese Companies
- Many Companies Are Still Raising Dividends
- Transportation Sector May Be Overly 'Clobbered'
- Gilat Take Two: Anteing Up Again
- Opportunity in Emerging Markets Amidst This Panic
- A Stock the Average Joe Can Understand: The St. Joe Co.
- Full list of Long Ideas »
- Gaming Stocks Still a Poor Bet - Barron's
- After Coming Rate Cuts, Some Appealing Short ETFs
- M/I Homes: Common Share Price Perplexing
- Trading ERO This Week
- Talk Me Down From the Wells Fargo Ledge
- SKF Regaining Its Old Form?
- Continuing Haircut in DST's Investment Portfolio
- Fortis and Bradford and Bingley Banks Thrown Lifelines
- The Short Case on KBH Homes
- International Game Technology: Good Short Opportunity
- Full list of Short Ideas »
- The Cramer Crash?
- Cramer: Dow Could Drop Another 14%, Oil's Going to $50
- Musical Chairs - Cramer's Mad Money (10/3/08)
- Not Much to Recommend - Cramer's Lightning Round (10/3/08)
- Imminent Rate Cut? - Cramer's Stop Trading! (10/3/08)
- American Express to the Sell Block - Cramer's Mad Money (10/2/08)
- Buy Rarely; Sell Repeatedly - Cramer's Lightning Round (10/2/08)
- Any Kind of Return - Cramer's Stop Trading! (10/2/08)
- Throw Everything At It - Cramer's Mad Money (10/1/08)
- No Buy Recommendations - Cramer's Lightning Round (10/1/08)
- Full list of Cramers Picks »
Trading Center
Hedge Fund Jobs
Job Seekers: Search jobs by category, get job alerts by email or live feed, apply online See full list of jobs »
Employers: See all recruitment options, get applications online or by email Post a job »



This article has 3 comments:
Then there are the other issues that are problemmatic from the standpoint of pattern match defense: SQL injection; cross-site scripting;and layer 2 evasions (like IP fragmentation).
The data center that has both servers and VMs in a mesh will require more flow visibility, more vulnerability intelligence and more app knowledge than the traditional systems are capable of delivering. I think these devices will stay at the perimeter (because they're exploit-focused) while a new data center (or server/VM) IPS category will take shape as meshes replace pipes.
Thanks for your comment./
Greg