csv-w02 open security controller - security orchestration ... · user interface api gui 1 nb rest...

17
SESSION ID: SESSION ID: #RSAC Tarun Viswanathan Open Security Controller - Security Orchestration for OpenStack CSV-W02 Platform Solution Architect Intel Manish Dave Platform Architect Intel

Upload: others

Post on 29-May-2020

53 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

SESSIONID:SESSIONID:

#RSAC

TarunViswanathan

OpenSecurityController- SecurityOrchestrationforOpenStack

CSV-W02

PlatformSolutionArchitectIntel

ManishDavePlatformArchitectIntel

Page 2: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

NoticesandDisclaimers

Inteltechnologies’featuresandbenefitsdependonsystemconfigurationandmayrequireenabledhardware,softwareorserviceactivation.Learnmoreatintel.com,orfromtheOEMorretailer.

Nocomputersystemcanbeabsolutelysecure.

Testsdocumentperformanceofcomponentsonaparticulartest, inspecificsystems.Differencesinhardware,software,orconfigurationwillaffectactualperformance.Consultothersourcesofinformationtoevaluateperformanceasyouconsideryourpurchase. Formorecompleteinformationaboutperformanceandbenchmarkresults,visithttp://www.intel.com/performance.

Intel,theIntellogoandothersaretrademarksofIntelCorporationintheU.S.and/orothercountries.*Othernamesandbrandsmaybeclaimedasthepropertyofothers.

©2016IntelCorporation.

Page 3: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

SDI—TheApplicationDefinestheSystem

The evolution to software-defined infrastructure

Page 4: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

EnterpriseMultiCloudSecurityChallenges

HowcanIprovideconsistentsecurityacross amulticlouddatacenterenvironment.

OpenSecurityControlleraddresses thischallenge.

Page 5: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

OpenSecurityControllerKeyDesignGoals

Centralizedsecuritypolicymanagementforamulticloudenvironment.

Page 6: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

ConceptualArchitecture

Page 7: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

OpenStack*Micro-SegmentationUseCase

Page 8: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

OSCAPIInteractionModelPoliciesUserIntentCloudAppsApplications,UserIntent,andPolicies

OpenDaylight* Midokura*, Plumgrid*, Nuage NSP*, Brocade*…NSX*SDN

Controllers

Virtualization Layer

PhysicalInfrastructure

ComputingHardware

Storage Layer

NetworkHardware

VirtualInfraOpenStack*

VirtualCompute

VirtualStorage

VirtualNetworkVirtualizedSecurityFunctions

CPA

DPA

SecurityFunction/ElementManagersIPSManagers

NGFWManagers

ADCManagers

OpenSecurityController

ManagerPlug-ins

VNFAgentPlug-ins

Business Logic

Service Dispatcher

Jobs Engine

SDNPlug-ins

VirtualizationConnectors

SecurityFunctionsCatalog

H2Database

User Interface API

GUINBRestAPI1

RestAPIWebSockets

4 RestAPIIPC5RestAPISFCPolicy

3 RestAPIImages,deployment,notifications,authentication

2

• Policyinterface• Userintent• Applicationintent

• Lifecyclemanagement

• Deploymentspecs,auto-scalingandHA

• Authentication• Imageservices• Notificationfor

events• Rolebased

accesscontrol

• TrafficredirectionAPI• SFCpolicyAPI• Advancedvisibilityfunctionality

(example6tuplevisibility)

• Dynamicpolicyupdatesandmapping

• Domain/subdomainupdatesandmapping

• Controlpathagent:provisioning,de-provisioning,heartbeats,etc.

• Datapathagent:instrumentationandrealtimestatistics

Page 9: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

CustomerPoC:HealthindustryITservicesprovider

• CustomerhastoadheretoHIPAAregulatoryrequirements

• Existing solutionwasbasedonDCedgedevices.• Customerwantedtogettoadynamicpolicy

basedsecuritysolution forEast-West trafficinspection. Commercialx86Server

CommercialSDNcontroller

(ComputeNode)RHEL7.2

(ControlNode)CommercialOpenStackNewtonDistro

OpenSecurityController

VirtualIntrusionPreventionSystem

NextGenFirewall

VirtualAppDeliveryController

Page 10: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

CustomerDeploymentArchitecture

HighLatency

East-westTraffic

Future:DynamicPolicyBasedEast-WestSecurity

X86server

vIPS vADC App

TopofRackSwitch

SecuritybetweenTenantsandTiers

LatencyGoesDown

GranularControlandScalability

SDNControllerPhysicalAppliances

Current:TopologyBasedSecurityFirewall

IntrusionPreventionSystems/IntrusionDetectionSystems

ApplicationDeliveryController

TopofRackSwitch

App App App App

X86Server

East-westTraffic

SecurityFunctionManager

SecurityController

Page 11: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

CustomerPoC:Largefinancialservicesprovider

Commercialx86Server

CommercialSDNcontroller

(ComputeNode)RHEL7.2

(ControlNode)CommercialOpenStackDistro

OpenSecurityController

NextGenFirewallVendor1

NextGenFirewallvendor2

• CustomerhastoadheretoPCIregulatoryrequirements

• CustomerwantedtogettoaRiskBasedautomated securitypolicymanagementcapability fortheirOpenstackenvironment

Page 12: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

CustomerdeploymentWorkflow

OneTimeSetup1. OpenstackConnector

2. CreateSecurityServicesa) PolicymanagerPlugins

forNGFW1,NGFW2

3. ConfigureSecurityServices

a) DistributedApplianceb) Deployment-

Specifications

ProtectionPolicy1. DefineGlobalRiskbased

Sec-Groups

2. AllPolicymanagersdynamicallyupdated

3. Automatedtrafficredirection viaSDNPlugin

AutomatedZero-TrustSecurityNetworkflowsautomaticallyupdatedtoredirect traffictosecurityservice chain

SecurityAdmin

Spinsworkloadupor down

Dev-Ops

Page 13: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

DEMOAutomatedSecurityServicesOrchestrationforOpenstack

Page 14: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

DemoTopology

Page 15: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

Page 16: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

Apply:RiskBasedApproach

1. Identifyworkloadwhichneedsmicrosegmentation

2. Identifysecuritycontrolstomitigaterisks(vIPS,vNGFW,vADC)

3. AutomateSecurityControlsorchestration

Page 17: CSV-W02 Open Security Controller - Security Orchestration ... · User Interface API GUI 1 NB Rest API Rest API Web Sockets 4 5 Rest API IPC Rest API SFC Policy 3 Rest API Images,

#RSAC

CalltoAction

CurrentStatusPOCwithearlyadoptercustomers/SecurityVNF’sOpenSecurityControlleravailable asOpensource~Mid2017compatiblewithfewSecurityVNFand SDNvendors

CalltoActionContactustogetengaged inthecommunity:Email:[email protected] [email protected] Information:www.intel.com/osc