This post is also available in: 日本語 (Japanese)
In December of 2019 Palo Alto Networks acquired Aporeto, a startup with an innovative approach to reducing the threat of lateral attacks using identity-based microsegmentation. Since that acquisition, our teams have been hard at work integrating the technology into Prisma Cloud. With the latest release, the technology will be available as a new module called Identity-Based Microsegmentation.
The Aporeto integration into Prisma Cloud gives our customers a Cloud Native Security Platform that offers the most comprehensive security for any application across any public cloud.
Enterprises have shifted their cybersecurity methodology to ask when will a breach happen instead of if one will occur. When there is a breach, the best option is to contain the blast radius to prevent lateral spread, and preventing the attacker from getting access to a high-value asset. With the rise in cloud adoption and the move to dynamic, cloud native infrastructure, containing these lateral attacks is more challenging than ever.
As an example, here are two attack scenarios:
Microsegmenting your application infrastructure at scale, across any cloud, with a Zero Trust methodology – that is, assuming the network is always compromised – is the best approach to preventing lateral attacks. And it is the approach we are moving toward as an industry. Thanks to the Aporeto integration, we offer a novel approach to microsegmentation that is decoupled from the underlying network infrastructure: Identity-Based Microsegmentation.
Network segmentation technologies have traditionally relied on IP as the identifier. This approach worked when infrastructure was static and managed by a networking team. Reliance on public cloud and the shift towards elastic and immutable cloud native infrastructure breaks IP-based policies – and status quo network security operations workflows.
Identity-Based Microsegmentation in Prisma Cloud is based on four principles:
With Prisma Cloud Identity-Based Microsegmentation, network and cloud security teams can address the needs of dynamic cloud native applications:
Over the coming weeks, Identity-Based Microsegmentation will be available in Prisma Cloud Enterprise Edition as a live preview. You can get more details about this module through our product page or download our latest eBook.
In addition to the Aporeto integration, you can learn about all of the enhancements in this latest release during our upcoming digital fireside chat on October 20. Palo Alto Networks product leadership and other industry experts will discuss trends in cloud native security as well as our overall product vision – register here .
By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement. Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder.