Archived Content

The following content is from an older version of this website, and may not display correctly.

They have come from Google, Juniper and Level 3 and worked with the US Department of Defence on its own security polices, but this week it was time for the founders of new cloud security player NetCitadel to break free from their roots and launch their own attack on the industry.

Founders Mike Horn (CEO), Theron Tock (CTO) and Vadim Kurland say they have devised a new way to approach security in cloud environments, providing a solution that is based heavily on automation and the tracking of cloud infrastructure that can work independent of a vendor’s stack.

The OneControl Security Orchestration Platform also comes with one of today’s most talked about catch phrases attached to it - software defined - (in this case, software-defined security).

Mike Horn, who has been in the network security industry for 15 years for the likes of Level 3, some of this spent carrying out penetration testing for the US Department of Defence for its Defence Research Engineering Platform, says the company is taking a similar approach to some of the moves being made by the likes of the founders and tech team’s previous employers, like Juniper and Cisco.

“But the big difference is they (Juniper and Cisco) are doing this for their own technology stack. With a Cisco solution you need Cisco routers and firewalls and UCS (Cisco’s Unified Computing System). We do ours from the ground up so it can work in any customer environment, which means it is much more heterogeneous,” Horn says.

Kurland was one of Google’s first network engineers and Theron Tock was a founding CTO of Neoteris, a pioneer in the SSL VPN appliance space which was eventually acquired by Netscreen and then Juniper.  The company has also pulled in key staff from VMware, Bluecoat and Fortinet, among others.

What have they created?
The OneControl Security Orchestration Platform has been designed to work across cloud, virtual and physical environments using security intelligence designed to reduce the time it takes to respond to changes in the compute environment. Horn says the platform means users can implement new policies in minutes rather than weeks.

“As networks have evolved and new technologies like the Cloud, virtualization and BYOD (Bring Your Own Device) have come into the enterprise it’s made the network very dynamic. Constantly servers are coming and going, and users are too but the security infrastructure that needs to protect these enterprise networks was developed prior to all this. What we have been hearing from customers is that they are struggling with how to keep their security infrastructure up to date with the things happening inside the virtual environment,” Horn says.

“NetCitadel developed, similar to the software-defined network approach, a centralized intelligence layer- the security orchestration platform. This can link to your virtual environment, get information about your virtual machines and their current configurations, what resource pools they belong too, and it maps this into the security information protecting those servers.”

Horn says apart from ensuring changes take place close to real time, as the solution tracks user, application, workloads and infrastructure movements, it also removes some of the pain points seen with manual changes, which can be susceptible to human error.

“This is all about keeping track of new servers being added or moved between different data centers, tracking and synchronizing changes happening in networking and the compute layer.”

The solution is based on the premise that there are four steps to understanding security policy changes – understanding when security policy needs to change, analysing the impact of the change, creating the new security policy and deploying the change.

“We can automate all four phases of that lifecycle. We have connectors into Amazon, VMware vCenter [and so on] to detect changes in real time, to know servers have moved,” Horn says. “We use business logic to define relationships so we know which devices need to change, then we translate that into the appropriate configuration for different types of devices, then go out and update from hundreds to maybe thousands of pieces of infrastructure in real time.”

There are a number of technologies that makes this work, including an event framework – the overlaying architecture “like a platform bus” which admins can place into an Amazon API. “The event framework will listen to the API from Amazon based on the credentials the user will use to link to it, then it listens out for any changes. This means it is constantly monitoring these APIs,” Horn says.

Surrounding this sits a policy language – “a business logic layer”. This technology, similar to technology released by Cisco and Juniper, can abstract this admin information to look at the business policy of proprietary servers but translates these into a lot of IP addresses. “We built a language that abstracts that and allows them to dive even deeper into the business language,” Horn says.

This ‘Rosetta Stone’, as Horn likes to call it, can also listen in to how Cisco likes to talk to Juniper, for example.

“Underpinning all this is the deployment engine – we can push hundreds of devices, even from multiple vendors, to ensure we are deploying where a lot of the technology takes hold.”

But is the industry ready?
The question is, will companies really feel comfortable placing responsibility for their security in software? The roadmap for OneControl shows NetCitadel believes the industry will be cautious at first.

The OneControl Security Orchestration Platform is a virtual appliance can sit on most types of virtual infrastructure between the data center and firewall devices – as long as there is IP connectivity. “As soon as we establish that connection we can start adjusting content to policy on what the admin wants,” Horn says.

The starting price for the solution is US$25,000 which covers up to 25 security devices. A Virtual Security Module can be added for the tracking of virtual environments and a Cloud Security Module separately for tracking cloud environments. This approach, according to Horn, allows companies to dip their toes into the security automation space - an areas he said many companies are still hesitant to dive head first into.

Horn says the company plans on releasing more modules throughout the year, allowing for different levels of automation and customization depending on customer needs. He says he believes many of these needs will come from the financial services industry, which has recently been plagued by cloud security issues, and governmental departments, but as more companies move to the Cloud, the user group NetCitadel will target will become much wider.