• United States



Vice President, Intel Security Group

The Early Adopter’s Guide to Securing the Software-Defined Data Center

Aug 09, 20164 mins

With Gartner estimating that more than 85% of data center workloads are now virtualized, it’s clear that the age of the software defined data center (SDDC) is upon us. The next steps in the evolution toward SDDC will be moving other traditionally hardware-bound functions like networking and storage into a full “as-a-service” model, so that applications and workloads can be flexibly provisioned and resourced in both private and public cloud environments.

There are many IT and business advantages to infrastructure virtualization, including:

  • More flexible and fluid allocation of existing resources
  • Faster deployment of new resources
  • Lower failure rates
  • Higher availability
  • Hardware and processing workloads can be managed independently

Given these benefits, it’s not surprising that one study predicts the SDDC market will grow at a compound annual rate of 28.8% over the next four years to surpass $77 billion in 2020.

However, SDDC also introduces some new complexities, particularly in the area of security. One of the few advantages of the old hardware-constrained model was that breaches could be more easily confined to physical servers. That isn’t the case with virtual infrastructure. Intruders may be more difficult to detect and may also be able to do more damage by traversing virtual machines (VMs) once inside the firewall.

That isn’t a reason to ignore the many benefits of a fully virtualized architecture, however. By designing security into the migration process, IT organizations can actually improve their defenses.

One of the reasons companies struggle with security today is that they’ve applied tools and technologies in a patchwork fashion over time as computers have become more connected and new threats have emerged. SDDC is an opportunity to rethink your approach to the data center. By baking security into the process, you can make your entire infrastructure more resilient.

Take Advantage of Automation

The SDDC is characterized by a high degree of automation because many tasks that were once performed manually in hardware have moved to software. Automation is useful for security as well. New security technologies are designed specifically for the unique characteristics of highly virtualized environments, such as large amounts of cross-VM traffic. Security pros can use automation to provision these tools according to the unique characteristics of each situation, rather than throwing them like a blanket over every asset in the data center.

For example, policy-driven automation can be used to provision specific security profiles for each application or virtual machine, with those protections traveling with the VM as it moves between on-premise and public cloud infrastructure.

The SDDC also permits more fine-grained tracking of activity across the network. A new breed of security analytics technology can gather system and network activity logs and analyze them to spot anomalies and suspicious patterns. Advanced threat intelligence shared between connected systems can provide all parties with better information about emerging threats. These capabilities not only give IT better visibility into the environment but also the capacity to more easily spot vulnerabilities that originate inside the organization, such as zombie servers and unauthorized use of cloud services.

As you proceed down the path toward SDDC, keep these best practices in mind:

  • Adopt new security technologies designed specifically for virtualized environments, such as policy-based orchestration and intrusion detection systems designed to monitor “east-west” traffic between VMs.
  • Choose low-risk pilots and sandboxed applications at first to become familiar with the tools and environment.
  • Apply micro-segmentation, which subdivides the data center into logical elements that can each be managed with their own security policies. This helps to limit intruders from moving laterally within the infrastructure.
  • Double down on existing practices such as policy implementation and control, monitoring, and patch management. Virtualized infrastructure makes patching easier because machines can be taken off-line temporarily without disrupting operations.
  • Adopt tools that provide visibility into all tiers of the local network as well as any cloud infrastructure you may use.
  • Most experts agree that breaches are inevitable, so have a strategy for quickly detecting, isolating and containing intruders.
  • Use two-stage authentication and encryption with highly sensitive data.
  • Subscribe to sources like the Open Networking Foundation to stay abreast of new developments in security for software-defined networks.

The software-defined data center opens new horizons in flexibility and scalability. Think security from the outset and your entire operation will be better off for it.

For more on this topic, download our new white paper, Three Key Considerations in Securing the Software-Defined Data Center.

Vice President, Intel Security Group

Candace Worley is a senior technology executive and recognized thought leader in the endpoint security industry. For the past 20+ years, she has developed and delivered successful enterprise software solutions resulting in notable market growth and new revenue streams for global companies. As Sr. Vice President and General Manager for McAfee Enterprise Endpoint Security (recently branded Intel Security) Candace built her reputation as a respected business leader; known for her predictive insights, strategic vision and ability to execute. Initially joining McAfee as a product manager in 2000, she advanced rapidly within the company, and by 2010, was appointed Sr. Vice President and General Manager. She is currently Vice President of Enterprise Solutions Marketing responsible for go-to-market strategy and alternate routes to market, global enterprise messaging, solutions pricing and packaging, technical marketing, pricing and licensing strategy, and competitive intelligence across the ISecG corporate products portfolio. As a member of the senior leadership team at Intel Security, Candace plays a key role as a solution and corporate spokesperson with customers, analysts and press. Candace holds a Masters of Business Administration from Marylhurst College in Oregon and a Bachelor of Science in Management from Oregon State University. Candace currently resides in Oregon. She spends her free time gardening, cooking and traveling.

More from this author