28
Micro-Segmentation 101 Adam Brady Systems Engineer

Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Micro-Segmentation 101Adam Brady – Systems Engineer

Page 2: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

What We’ll Cover

What is micro-segmentation?

Why micro-segmentation?

The principles of micro-segmentation

How to implement a strategy in 5 steps

Page 3: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

What is Micro-Segmentation?

Page 4: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

What is Micro-Segmentation?

Page 5: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Contain

Stop the spread of unauthorized lateral movement.

What is Micro-Segmentation?

Control

Page 6: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Why Does Micro-Segmentation Matter?

Page 7: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Vendor Portal

POS system

Vendor

Internal Servers

Page 8: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Without Segmentation…

Common breach methodology

Step 1: Breach low value workload

Step 2: Map paths and connections

Step 3: Move to high value assets

days

200+Avg. dwell time:

1,579# of breaches in 2017 alone:

Page 9: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Micro-Segmentation Addresses Key Concerns

Map Application Dependencies Meet Compliance Requirements

Secure Critical Applications Securely Move To Cloud

Page 10: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Why is Micro-Segmentation Growing Now?

Risk reduction, audit, and compliance

LPM

Page 11: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

What’s Stopping Us?

11

~100 workloads

~200k “flows”

Page 12: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Distributed

Hybrid/Multi-CloudHeterogeneous

Hypervisor

Containerized Hosts OS

Environments are Complex

Dynamic

Page 13: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Segmentation the Old Way

13

Up to 4 hours to create a

firewall rule for new app

87% reported multiple

outages due to configuration!

59% have little to no

visibility into traffic flows

Firewalls won’t work in

the cloud

Static policies need to be

updated manually

You have to re-architect

your apps and network

Page 14: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Different Micro-Segmentation Approaches

WORKLOADS

Segment at the

Workload

Leveraging the native

firewall in the OS

Challenge: Managing agents.

Segment in the

Hypervisor

Adding a firewall to

hypervisors

Challenge: Vendor specific, no bare-

metal, limited cloud support.

VM VM VM VM

VM VM VM VM

Hypervisor

Segment on the

Network

Using firewalls or ACLs

Challenge: No application visibility,

doesn’t work in cloud.

Page 15: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

What Are the Principles of Micro-Segmentation?

Page 16: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

16

Support for all environments

and platforms

Application-centric visibility

Centralized policy creation

and management

Adaptive and automated

Customizable granularity

What You Need for Micro-Segmentation

Page 17: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

How to Implement a Micro-Segmentation Strategy in 5 Steps

Page 18: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

The 5 Steps

It’s as much about process as it is about technology.

1Get the

right tools

3Decide what

to segment

first

2Map your

application

environment

4Test and

enforce

policy

5Decide what

to segment

next

Page 19: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 1: Get the right tools

Application dependency mapping

The right tools should:

Work with multiple environments, platforms, and infrastructure.

Allow for easy testing, validation, and updating of policies.

Be designed with automation and scale in mind.

Policy enforcement

Policy management

Page 20: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 2: Map your application environment

The map should be real time and accurate.

Page 21: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 3: Decide what to segment first

You can’t segment everything at once.Start where you get the greatest return.

Key factors for prioritization:

Value of data

Compliance/audit requirements

Harm if there is an outage

Application owner relationship

Value as a pivot point

Related active projects

There’s no other way

Page 22: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 3: Decide what to segment first

Different segmentation granularity might be appropriate in different places.

Environmental

Segmentation

Application

Segmentation

Tier

Segmentation

Process

Segmentation

Page 23: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 4: Test and enforce policy

The right solution should:

Enable policy modeling.

Provide visual feedback.

Adapt policy to changes in the environment.

Segmentation alters the communications of your applications.

Test policy before you enforce it.

Page 24: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Step 5: Decide what to segment next

Identify the next application priority.

Many organizations never micro-segment everything.

Some environments may never go into enforcement everywhere.

The right solution should:

Support phased deployment.

Support a mix of modeling and enforcement.

Page 25: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Real-World ExamplesEnvironmental Segmentation – separate development and production

Maintain flexibility and contain exposure to high-value targets

Application Segmentation – segment an ordering application Control activity into and out of a critical application

Tier Segmentation – separate web, database, and application servers Reduce the ability of attackers to move freely through an application

Process Segmentation – protect Active Directory Control communications down to the process level and automatically

adjust policy

Page 26: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Closing Advice for Success

1. Start with visibility.

2. Test policy before enforcing.

3. Segment in phases.

4. Build partnerships between security, infrastructure, and application teams.

5. Work with an internal champion who can drive the project.

Page 27: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

Q&A

Page 28: Micro-Segmentation 101...Segmentation the Old Way 13 Up to 4 hours to create a firewall rule for new app 87% reported multiple outages due to configuration! 59% have little to no visibility

More questions?

Contact me:

[email protected]