Showing posts with label container. Show all posts
Showing posts with label container. Show all posts

Tuesday, December 31, 2019

Looking ahead to 2020, Rackspace CTO Joel Friedman offers his predictions

As the New Year 2020 begins, hybrid and multi-cloud will continue to gain traction, as will software as a service (SaaS). Security remains a tough nut to crack, and edge computing will gain ground, but Joel Friedman, Rackspace CTO, predicts more modestly than the current hype may suggest.


PREDICTION 1: HYBRID/MULTI-CLOUD REMAINS ASCENDANT
Smart organizations have locked onto the benefits of running apps and data in the places that make the most sense, whether that’s public or private cloud, colocation or, most commonly, a bespoke combination of these that can evolve as business needs and resources dictate. However, the complexity of managing multiple clouds across the dimensions of cost, security, governance, identity and DevOps patterns will continue to grow in 2020.


This complexity is related to the forced reliance upon a multitude of platforms, the rate of technological change, disruptions to traditional service delivery models and a real shortage of skill sets required to bring it all together. Due to these factors, it is likely that multi-cloud solutions will prevail, while the search for qualified external help will intensify.

Finding external help may prove difficult, as not only will managed service providers need to maintain a multi- or hybrid cloud instance, but internal and external vendors will need to work together to manage a multitude of issues around cost governance, security and tagging, to name a few. Fortunately, 451 Research has found these growing pains can be alleviated with clear communication and flexibility on each partner’s part.

PREDICTION 2: SAAS = PROBLEM SOLVED
On top of infrastructure, one of the cloud strategies I hear on repeat when working with customers is that “cloud first” starts with SaaS. They don’t want to reinvent the (inferior) wheel by developing applications for ‘solved’ problems. Mature SaaS offerings are a culmination of many iterations of customer mandated features, user experience analysis, and just as important, industry best practices around process workflows.

In many cases, organizations choosing to fit their internal process to best match their SaaS vendor’s implementation – as opposed to always opting for customizing the platform to suit legacy workflows. Furthermore, SaaS has a compounding effect with data; once data is in the system, other ecosystem players can offer turn-key integration and add-on services, further enhancing the value proposition of SaaS. 

While this isn’t necessarily a new trend, Friedman predicts this will be the norm in 2020 and expects to see more and more niche, and vertically-focused applications developing a SaaS model.


PREDICTION 3: SECURITY REMAINS A STRUGGLE
When it comes to security, many organizations remain burdened with legacy systems riddled with technical debt and corresponding security vulnerabilities. They understand the need to harness cloud-compatible security frameworks, operating models and tools to operate securely in cloud-native environments, but it can be slow and rough going.

Most industries simply have not reached the place where mature cloud security practices are being implemented, and this creates fertile ground for breaches. Too many are still attempting to apply traditional security controls and methodologies to cloud-native environments and deployments. 

This generally does not work well; not only is the security implementation likely to be ill fit, it also creates drag on the organization’s desired benefits of agility. This sometimes leads to fragmentation, where business units go around central security and implement on their own shadow security. The risks of this should be obvious.

In 2020, Friedman thinks that the cloud continues to present some growing pains to even the most digital-native and forward-thinking organizations. These organizations understand how the cloud can aid their business in moving fast, but they don’t yet have the maturity to implement real-time or just-in-time posture management and ‘least privilege’ protocols in the ephemeral, complex and constantly changing world of multi-cloud. 

While security teams straddle the old world of insecure legacy applications and platforms (those which cannot or should not be modernized), and the relative newness of cloud operating models, I unfortunately expect to see the breach headlines continue in 2020 along with all of the free credit monitoring can handle.

Even when the security teams agree in concept that it’s possible to be more secure in the cloud, many do not have cloud compatible security frameworks, operating models and tools to aid the business in operating in cloud-native environments securely.


PREDICTION 4: CLOUD CONTROL PLANE WILL BECOME THE NORM
There has been a trend over the past few years in which the management plane has been reversing from the datacenter to the cloud. For early cloud adopters, the datacenter was still the central control point. Organizations burst into the cloud or had back-end projects with no internet accessibility. As cloud grew in popularity, more and more greenfield projects became cloud-native.

Granted, many still integrate with on-premises or hosted private clouds for identity, business intelligence or other data enrichment requirements, but the hyperscalers have now moved past denying that hybrid cloud is real (in attempts to capture all workloads), and pivoted their strategy to capture those datacenter workloads where they stand and bring them into their ecosystem. 

This includes Snowball Edge, AWS RDS of VMware, Azure Stack/Azure Arc and Google Anthos. Expect to see more such services in 2020. And why shouldn’t we? Cloud providers have proven their effectiveness of securely operating at scale, and API-enabling everything.


PREDICTION 5: EDGE WILL GAIN MODERATE GROUND
Edge computing is a new frontier — no player is currently dominating this space, as it is a naturally fragmented market. When choosing locations over platforms to address local markets, data sovereignty, and other use case specific needs, I believe organizations may want to align in a technology-neutral and consistent manner. And based on the trends over the past year, containers and serverless seem like a natural beneficiary for edge.

As Kubernetes dominates in the container orchestration arena, serverless is another story in which, as of yet, there are no victors. AWS, Azure and Google Cloud Platform all have their own flavors of Function-as-a-Service (FaaS), which are embedded within their respective cloud ecosystems. Will OpenFaaS with kNative gain some ground based on open standards, addressing the often spoken lock-in avoidance and mobility potential? We shall see. 

Either way, Friedman predicts that 2020 will see lots of innovation and exploration in the edge space, but he suspects this is the year of gaining momentum and the floodgates won’t open until 2021.

Thursday, December 19, 2019

Ericsson and Telstra achieve container-based commercial Evolved Packet Core milestone

Ericsson and Australian communications service provider Telstra have deployed the industry’s first live cloud-native container-based Evolved Packet Core for 4G and 5G services. The achievement is a significant milestone in network orchestration and automation.
The cloud-native container-based Evolved Packet Core has been deployed in Telstra’s production Network Functions Virtualization Infrastructure (NFVi), provided by Ericsson. It is fully integrated into Telstra’s mobile core network and is carrying live 4G and 5G Non-Standalone (NSA) traffic.

Telstra’s cloud-native Evolved Packet Core includes Ericsson Packet Core Controller and Ericsson Packet Core Gateway products. They support 4G and 5G Non-standalone (NSA) control and user plane functions in both a centralized configuration and edge-breakout configurations.
As part of this deployment, Ericsson’s Packet Core Controller is deployed as a cloud-native container-based Mobility Management Entity (MME) in an existing MME pool.
Both the Ericsson Packet Core Controller and Packet Core gateway are designed from the ground up to be fully cloud-native container-based solutions. They run on Ericsson’s Cloud Container Distribution (CCD) that is part of Ericsson’s NFVI solution or on other Cloud Native Computing Foundation (CNCF) aligned distributions.
Ericsson CCD provides container management and orchestration for the latest Ericsson cloud native applications. CCD can be run on bare metal or within a Virtual Machine in an OpenStack deployment.
Ericsson and Telstra have a long history of partnering in industry innovation. In May 2019 Telstra launched 5G commercial services using Ericsson solutions.  
This achievement is a key step in Telstra’s goal to build a web-scale core network and deliver the full power of 5G to consumers and enterprise customers. The containerization of core network functions will move communication service providers such as Telstra towards greater orchestration and automation of their networks. This in turn will help them to create and deliver new services such as enhanced mobile broadband, network slicing, mobile edge computing, mission critical vertical industry support and advanced enterprise services.
Containerized technologies are also designed to improve network resilience and software upgrade techniques to increase overall network availability for Telstra’s customers and services.
“Telstra and Ericsson are leading the mobile industry with this first container-based cloud-native Evolved Packet Core in Telstra’s production environment and carrying live traffic. This is an important step towards fundamentally changing the way both companies deploy and operate mobile core networks,” said Emilio Romeo, head of Ericsson Australia and New Zealand. “Core networks will become much more flexible and agile, allowing operators such as Telstra to quickly create and deploy compelling new services for their customers. This in turn helps operators build new revenues.”
“Through the T22 initiative, Telstra’s business is being transformed to improve service delivery and provide customers with enhanced experiences. To achieve this transformation, Telstra’s network needs to become more flexible and efficient, and cloud-native container-based applications such as Ericsson’s containerized Evolved Packet Core are a key element of this,” said Shailin Sehgal, product enablement technology executive, Telstra. “This is key to cost effectively scaling and automating our network and speeding up the delivery of innovative new services that are essential in a 5G world. We are pleased to be working with Ericsson to deliver innovation into our network that will assist Telstra maintain its industry leadership.”

Tuesday, December 17, 2019

McAfee joins with Google Cloud to integrate McAfee Security offerings with GCP for Linux and Windows workloads, containers

McAfee and Google Cloud entered into an alliance to integrate key McAfee solutions for endpoint and container security within Google Cloud. Under this new partnership, McAfee will tightly integrate its endpoint security solutions for Linux and Windows workloads, as well as its MVISION Cloud solution for container security, on Google Cloud infrastructure.

Several enterprise customers leverage virtual machines (VMs) running in the cloud to handle key Linux and Windows workloads. Ensuring security of these workloads is critical. With this new integration, customers will be able to deploy McAfee’s advanced endpoint security solutions across these key workloads and VMs via Google Cloud Marketplace.


McAfee’s workload security technology uses advanced machine learning and cloud analytics to help protect against file-based, fileless, and script-based threats at scale for workloads deployed on Google Cloud.

Google Cloud provides organizations with critical infrastructure, platform capabilities and solutions, along with expertise, to reinvent their business with data-powered innovation on modern computing infrastructure. The Mountain View, California-based company delivers enterprise-grade cloud solutions that leverage Google technology to help companies operate more efficiently, modernize for growth and innovate for the future. Customers in more than 150 countries turn to Google Cloud as their trusted partner to solve critical business problems.  

McAfee is the device-to-cloud cybersecurity company. Inspired by the power of working together, McAfee creates business and consumer solutions that make the world a safer place. 


McAfee MVISION Cloud for Containers service extends data security, threat prevention, governance, and compliance capabilities of the MVISION Cloud platform to provide additional security for container-based workloads on Google Cloud. Organizations can also leverage MVISION to integrate security into DevOps processes and toolsets to discover and address security issues before applications are deployed.

“Increasingly, customers are choosing to move critical workloads and applications to the cloud because of the strong security protections it can provide,” said Anand Ramanathan, vice president of product and marketing at McAfee. “As more of these enterprises choose to leverage Google Cloud’s hyperscale capabilities, we’re excited to integrate our core capabilities in VM and container security to ensure Google Cloud customers can benefit from the highest levels of data protection and threat prevention.”

“We’re excited to partner with McAfee to bring their proven, trusted security capabilities to enterprise customers,” said Kevin Ichhpurani, corporate vice president, Global Ecosystem at Google Cloud. “Integrating McAfee’s solutions into Google Cloud means customers will have even more tools to ensure the highest levels of data security and protections as they migrate mission-critical workloads to the cloud.”

Friday, December 13, 2019

A10 Networks Orion 5G security lineup delivers business transformation for service providers

A10 Networks announced its Orion 5G Security Suite that enables mobile carriers and service providers to be ready for the business transformation 5G and NFV brings. The suite allows customers to meet the requirements needed today and helps them future proof their networks for tomorrow by delivering security, scalability, agility and analytics, while integrating with a partner ecosystem. A10 brings unique expertise from working with many of the production 5G networks that are now operational around the world.

A10 Networks has been at the forefront of initial 5G rollouts with tier-one carriers worldwide and is working with many others to plan for their future 5G initiatives. 

With the announcement of the 5G Orion Security Suite, service providers have a proven comprehensive suite of secure applications services that have been engineered for cloud-native architecture to aid in making their 5G and NFV strategies successful. 


The Orion 5G Security Suite enables advanced security and reliability functions as individual services by modularizing and offering them as a service layer with a set of connected technologies that employ automated intelligence, machine learning and centralized visibility and control.

Partnering with tier-one operators, A10 has honed its solutions to meet the critical 5G requirements for improved security, reliability and performance learned from 5G network rollouts over the last year. A10 provides an interconnected suite – virtual or physical – resulting in lower latency, larger scale, higher reliability and lower TCO—all of which have been required for the emerging 5G use cases customers are enabling.


In the last year to 18 months, first movers have deployed the first wave of 5G networks and demonstrated improved customer satisfaction and increased average revenue per user (ARPU), despite an increase in network demands, including higher data usage and download rates.

The Orion 5G Security Suite addresses existing and emerging mobile network architecture requirements for agility, consolidated services, greater scale, and lower latency communications across the Gi-LAN, virtualized evolved packet core (vEPC), and multi-access edge computing (MEC) environments. 

The Orion 5G Security Suite’s disaggregated, cloud-native security services provide agility while maintaining scale and performance by leveraging cutting-edge technologies. It also goes beyond just protecting the data plane through a GiFW by adding protection for the control plane and signaling plane with full visibility.

The Orion 5G Security Suite represents a major evolution of the company’s 5G strategy outlined in late 2018 by providing a comprehensive solution for mobile operators and other service providers to successfully deploy 5G non-standalone (NSA) and standalone (SA) solutions at hyperscale for 5G devices and new NFVi requirements.

A10 supports existing 4G and 3G network architectures and use cases for the Gi-LAN and EPC, while catering to demanding requirements for 5G architectures, including the cloud-native agility needed for MEC. These solutions can be deployed in infrastructure but are future proofed for 5G deployments. This includes functional consolidation for application visibility and control, subscriber-aware intelligent traffic steering, Gi/SGi firewall with carrier-grade NAT (CGNAT), GTP/SCTP firewall, integrated DDoS for frequently attacked services, intelligent traffic steering and more.

5G demands are inherently different than 4G, with smaller packet sizes, more throughput, and higher concurrent session counts. A10 solutions can scale concurrent sessions to multi-billion levels and throughput to multi-terabit levels in a scale-out cluster. 5G deployments can benefit from compact and efficient options, for example, 385 Gbps in compact physical network functions (PNFs), or high-performance 180 Gbps virtual network functions (VNFs) and cloud-native network functions (CNFs). 


Support for Kubernetes and Docker containers are available now. The compact PNF form factors and very high-performance software offerings (including containerized) are especially beneficial in emerging MEC use cases where space and power are at a premium.

With new user-plane and control-plane security requirements coupled with the increased attack surface and scale brought by 5G and IoT device proliferation, more advanced, scalable and automated approaches are needed. To guarantee uptime and ensure control- and user-plane security, components include edge firewall, GTP firewall, Gi/SGi firewall, control- and user-plane policy enforcement, DNS protection, RAN security gateways (SeGW), and more. 

Additionally, A10’s advanced DDoS protection solution includes artificial intelligence (AI) and machine learning (ML) capabilities with its Zero-day Attack Protection (ZAP), continuous base lining, and One-DDoS for distributed intelligence. This provides full visibility into all packets versus traditional sample-based-only solutions. Network-wide ML-powered DDoS detection and mitigation for in-house protection can also be offered as a customer scrubbing service.

A10’s solutions can be delivered in a variety of form factors to meet the demands of the emerging NFVi architecture including, VNFs, CNFs, bare metal and PNFs. These solutions are integrated with leading NFVi architectures and interoperate with multiple MANO environments for faster network roll-out and optimized performance and agility. A10 also provides flexible software licensing and consumption with FlexPool subscription-based capacity pooling licensing.

A10 Harmony Controller provides actionable intelligence to manage subscriber services, meet law enforcement agency mandates and compliance, and deliver per-subscriber analytics. Harmony Controller provides visibility, management, orchestration and automation. Coordination of distributed One-DDoS data from all the Orion 5G Security Suite solutions is seamlessly orchestrated from the integrated aGalaxy TPS system.

A10’s products integrate with multiple third-party solutions and vendors, ranging from DevOps tools, such as Ansible, to providers of 5G solutions such as Ericsson, Red Hat, NEC, Tech Mahindra and Lenovo.

Thursday, December 12, 2019

A10 Networks extends carrier-class firewall product lineup with a container offering, new 5G network ready features

A10 Networks announced Wednesday that it is extending the capabilities of the Thunder Convergent Firewall (CFW), part of the A10 Orion 5G Security Suite, to support the coming cloud-native 5G requirements. The container-based carrier-class firewall delivers up to 180 Gbps throughput, one of the fastest in the industry. 


A10 is also releasing a new version of its Advanced Core Operating System (ACOS) 5.1, which includes multiple 5G-ready updates. Thunder CFW running ACOS 5.1 brings functionality, performance and scale of the existing physical and virtual appliances to the container firewall, helping to prepare service provider customers in their transition to cloud-native 5G infrastructures.


The Thunder containerized firewall was recently demonstrated as part of the Linux Foundation’s end-to-end cloud-native 5G network proof of concept at KubeCon + CloudNativeCon. This first of its kind proof-of-concept (PoC) was a fully containerized, end-to-end 5G non-stand-alone (NSA) distributed cloud network, which paves the way for commercial deployments in mobile operator networks globally.


The Thunder CFW includes functionality that helps ensure the security, reliability and availability of 5G networks as they transition from physical network functions to be completely cloud native. It can be broadly deployed in mobile networks at the SGi, roaming and radio access network (RAN) interfaces. 



The A10 vThunder virtual network function (VNF) package has been integrated and validated with leading NFV-MANO solutions, including Ericsson Cloud Manager, NEC Netcracker HOM, Red Hat OpenStack, and tested in recent ETSI NFV Plugtests for end-to-end VNF lifecycle operation capabilities.



“The Thunder CFW release is an integral foundational element to our comprehensive A10 Orion 5G Security Suite. With the ACOS 5.1 release, A10 has integrated comprehensive feedback from multiple proven deployments in tier-one mobile operators over the last year. These production networks have required hyperscale, lower latency, automation, and advanced security,” said Yasir Liaqatullah, vice president, product management at A10 Networks. “As 5G adoption increasingly requires multi-terabit performance on the Gi-LAN, we continue to provide industry-leading scale in virtual network functions (VNFs), cloud-native network functions (CNFs) and physical network functions (PNFs), including scale-out agile deployments with containerized solutions for virtual mobile edge compute requirements.”



In addition to the release of the high-performance containerized firewall CNF, A10 Networks also released new PNFs with its 7600 series models, delivering up to 385 Gbps throughput in a compact RU physical appliance.


The A10 Orion 5G Security Suite is available now. Thunder CFW with ACOS 5.1 and the new CNF and PNF form factors will be available later this month.

Wednesday, December 11, 2019

McAfee releases CASB-integrated cloud security platform for container-based applications

McAfee announced McAfee MVISION Cloud for Containers that integrates container security with its Cloud Access Security Broker (CASB) and Cloud Security Posture Management (CSPM) security solution. 

Leveraging NanoSec’s zero trust application visibility and control capabilities for container-based deployments in cloud environments, the solution provides customers with the ability to speed up application delivery, while enhancing the governance, compliance and security of their container workloads.




The acquisition of NanoSec will strengthen the container security capabilities of McAfee MVISION Cloud and MVISION Server Protection products, giving its customers the ability to speed up application delivery while enhancing governance, compliance and security of their hybrid, multi-cloud deployments. 

NanoSec’s security capabilities will be applied to applications and workloads deployed in containers and Kubernetes and will be integrated into McAfee MVISION Cloud and MVISION Server Protection offerings. These capabilities include continuous configuration compliance and vulnerability assessment as well as runtime application-level segmentation for detecting and preventing lateral movement of threats.


Container security has long been treated as separate from other Infrastructure as a Service (IaaS) security solutions, requiring evaluation, investment and management of multiple, niche products thus increasing total cost of ownership and complexity and reducing security. 

McAfee MVISION Cloud for Containers integrates Cloud Security Posture Management (CSPM) and Vulnerability Scanning for container workloads into the existing McAfee MVISION Cloud platform to give customers a unified cloud security solution where consistent security policies can be implemented across all forms of cloud IaaS workloads.

McAfee MVISION Cloud integrates with DevOps tools, helps users “shift-left” to pre-emptively improve compliance and secure container workloads by running security audits in the DevOps pipeline and providing security incident data directly back to the development teams. 

Additionally, McAfee MVISION Cloud also continuously monitors the production deployments of these container workloads to ensure configuration drift does not compromise the security of the applications.


Currently available, McAfee MVISION Cloud for Containers provides CSPM that integrates Configuration Audit checks for containerized workloads to ensure the container platforms run in accordance with CIS and other best practice compliance standards. This is designed to ensure security checks for the complete container stack including the configuration of the virtual machine the container runs on, as well as the storage, network and other Platform as a Service (PaaS) services the container may be accessing.

The offering also adds vulnerability scanning of container images that helps to identify and prevent the use of weak or exploitable components of the container images. This reduces the overall risk profile of the application by minimizing the attack vectors. With Shift Left DevOps integration, users can perform CSPM and Vulnerability Scanning checks earlier in the application development lifecycle. This helps identify risk and provide meaningful feedback to developers within the build process. Additionally, continuously monitor and prevent configuration drift on production deployments of the container workloads.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...