<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Segmentation on microsegment.io</title>
    <link>https://microsegment.io/categories/segmentation/</link>
    <description>Recent content in Segmentation on microsegment.io</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 14 Apr 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://microsegment.io/categories/segmentation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Thoughts on the Attack matrix for Kubernetes</title>
      <link>https://microsegment.io/2020/04/14/thoughts-on-the-attack-matrix-for-kubernetes/</link>
      <pubDate>Tue, 14 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2020/04/14/thoughts-on-the-attack-matrix-for-kubernetes/</guid>
      <description>&lt;h1 id=&#34;introduction&#34;&gt;Introduction&lt;/h1&gt;&#xA;&lt;p&gt;In a recent blog post Yossi Weizman talks about the &lt;a href=&#34;https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/&#34;&gt;Attack matrix for&#xA;Kubernetes&lt;/a&gt;&#xA;and i had a couple of thoughts about it. As Yossi rightly says, Kubernetes is&#xA;becoming a vital part in the compute stack of many companies. What i hear in my&#xA;network and during sessions with IT security teams is that they face new&#xA;challenges with Kubernetes-based orchestration platforms. The container&#xA;platforms are also perceived like a black box for traditional networking and IT&#xA;security folks, so it makes sense to understand the security risks that are&#xA;inherent to those platforms first.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mitre ATT&amp;CK and Segmentation</title>
      <link>https://microsegment.io/post/2019-11-08-mitre-attack-and-segmentation/</link>
      <pubDate>Fri, 08 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-11-08-mitre-attack-and-segmentation/</guid>
      <description>&lt;p&gt;When people think about their strategic IT security projects, they often&#xA;think of the last incident they were affected of and try to mitigate that,&#xA;often by using technology only.&lt;/p&gt;&#xA;&lt;p&gt;This is a valid approach and probably is not so wrong, because we often&#xA;see waves of incidents rolling in, the wannacry wave, other ransomware&#xA;waves, certain exploit kits or malware waves. So it makes some sense&#xA;to concentrate on those threats when they happen. Of course you should&#xA;have done something long before it hit you or other people, but the&#xA;nature of IT security is that this hardly ever happens.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The importance of outbound policy</title>
      <link>https://microsegment.io/post/2019-11-05-the-importance-of-being-ehm-outbound-policy/</link>
      <pubDate>Tue, 05 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-11-05-the-importance-of-being-ehm-outbound-policy/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/William_Cheswick&#34;&gt;Bill Cheswick&lt;/a&gt;, a pioneer&#xA;in internet firewalls got, besides establishing what we today know as the&#xA;perimeter firewall, famous for the below quote to describe his ideas on&#xA;perimeter firewalls:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;A sort of crunchy shell around a soft, chewy center.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;The quote and metaphor is still used a lot by security professionals around&#xA;the world, to describe the state of the internal network &lt;strong&gt;behind&lt;/strong&gt; the perimeter&#xA;firewall.&lt;/p&gt;&#xA;&lt;p&gt;A crunchy shell in the 1990s was exactly the thing you needed to be more secure&#xA;from the threats found at that time. A lot of it was attacks against servers,&#xA;buffer and heap overflows on services directly exposed to the internet when not&#xA;consumed directly from the internet.&#xA;People could easily DoS or even better, hack, those services. Exposed sendmail&#xA;servers been a huge target at that time. Everything was exposed and routed, it is&#xA;hard to imagine today. The perimeter firewall did a great job and shielded the&#xA;vulnerable services from the evil internet and helped to secure them from the&#xA;outside world. The internet grew exponentially and threats changed quite&#xA;significantly and we all know that most threats today focus on endpoints rather&#xA;than datacenter services as a entry vector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ideas on Segmentation metrics (part three)</title>
      <link>https://microsegment.io/2019/10/02/metrics-for-security-segmentation-part-three/</link>
      <pubDate>Wed, 02 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2019/10/02/metrics-for-security-segmentation-part-three/</guid>
      <description>&lt;p&gt;&lt;span class=&#34;inline-svg-icon&#34; &gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; viewBox=&#34;0 0 576 512&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M542.22 32.05c-54.8 3.11-163.72 14.43-230.96 55.59-4.64 2.84-7.27 7.89-7.27 13.17v363.87c0 11.55 12.63 18.85 23.28 13.49 69.18-34.82 169.23-44.32 218.7-46.92 16.89-.89 30.02-14.43 30.02-30.66V62.75c.01-17.71-15.35-31.74-33.77-30.7zM264.73 87.64C197.5 46.48 88.58 35.17 33.78 32.05 15.36 31.01 0 45.04 0 62.75V400.6c0 16.24 13.13 29.78 30.02 30.66 49.49 2.6 149.59 12.11 218.77 46.95 10.62 5.35 23.21-1.94 23.21-13.46V100.63c0-5.29-2.62-10.14-7.27-12.99z&#34;/&gt;&lt;/svg&gt;&#xA;&lt;/span&gt;&#xA;Please check out &lt;a href=&#34;https://microsegment.io/2019/08/22/metrics-for-security-segmentation-part-one/&#34;&gt;Part&#xA;one&lt;/a&gt; and &lt;a href=&#34;https://microsegment.io/2019/09/02/metrics-for-security-segmentation-part-two/&#34;&gt;part two of&#xA;this series&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Continuing our series about metrics for segmentation, there are a couple more&#xA;angles how you can measure the effectiveness of your segmentation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The incomplete ITSA 2019 guide to segmentation</title>
      <link>https://microsegment.io/post/2019-10-01-the-incomplete-itsa-guide-to-segmentation/</link>
      <pubDate>Mon, 30 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-10-01-the-incomplete-itsa-guide-to-segmentation/</guid>
      <description>&lt;p&gt;Next week it is the &lt;a href=&#34;https://www.it-sa.de/&#34;&gt;ITSA 2019&lt;/a&gt; in Nuremberg and i thought&#xA;it will be good to give you high priests of segmentation a overview of the&#xA;companies exhibiting their solutions for &lt;strong&gt;segmentation&lt;/strong&gt; and&#xA;&lt;strong&gt;microsegmentation&lt;/strong&gt; there.&lt;/p&gt;&#xA;&lt;h2 id=&#34;illumio&#34;&gt;Illumio&lt;/h2&gt;&#xA;&lt;p&gt;This one is special, because you will have the chance to meet me personally&#xA;presenting the power of host-based microsegmentation to you for the three days&#xA;of ITSA 2019. Feel free to come by and ask me anything about Illumio, this site&#xA;or really anything that comes up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scaling up vs scaling out your security segmentation</title>
      <link>https://microsegment.io/post/2019-09-15-scale-up-vs-scale-out/</link>
      <pubDate>Mon, 09 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-09-15-scale-up-vs-scale-out/</guid>
      <description>&lt;p&gt;&#xA;  &lt;img src=&#34;https://microsegment.io/img/scale-up-vs-scale-out.png&#34; alt=&#34;Scale-up-vs-scale-out&#34;&gt;&#xA;&#xA;&lt;/p&gt;&#xA;&lt;p&gt;If you follow discussion on running cloud native, monolithic or more&#xA;traditional applications you may have stumbled over the terms &amp;ldquo;scale up“ and&#xA;&amp;ldquo;scale out“. Don’t feel bad if you don’t know these, because they were formerly&#xA;just &amp;ldquo;vertical scaling“ (scale up) and &amp;ldquo;horizontal scaling“ (scale out).&lt;/p&gt;&#xA;&lt;h1 id=&#34;what-is-scale-up&#34;&gt;What is scale up?&lt;/h1&gt;&#xA;&lt;p&gt;Scale up means, if you have e.g. a server in your datacenter running your&#xA;database, to make the database faster or have more concurrent client getting&#xA;served, you would add more hardware to that server and just make it the biggest&#xA;machine available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ideas on Segmentation metrics (part two)</title>
      <link>https://microsegment.io/2019/09/02/metrics-for-security-segmentation-part-two/</link>
      <pubDate>Mon, 02 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2019/09/02/metrics-for-security-segmentation-part-two/</guid>
      <description>&lt;p&gt;&lt;span class=&#34;inline-svg-icon&#34; &gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; viewBox=&#34;0 0 576 512&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M542.22 32.05c-54.8 3.11-163.72 14.43-230.96 55.59-4.64 2.84-7.27 7.89-7.27 13.17v363.87c0 11.55 12.63 18.85 23.28 13.49 69.18-34.82 169.23-44.32 218.7-46.92 16.89-.89 30.02-14.43 30.02-30.66V62.75c.01-17.71-15.35-31.74-33.77-30.7zM264.73 87.64C197.5 46.48 88.58 35.17 33.78 32.05 15.36 31.01 0 45.04 0 62.75V400.6c0 16.24 13.13 29.78 30.02 30.66 49.49 2.6 149.59 12.11 218.77 46.95 10.62 5.35 23.21-1.94 23.21-13.46V100.63c0-5.29-2.62-10.14-7.27-12.99z&#34;/&gt;&lt;/svg&gt;&#xA;&lt;/span&gt;&#xA;Please check out &lt;a href=&#34;https://microsegment.io/2019/08/22/metrics-for-security-segmentation-part-one/&#34;&gt;Part one of this series of&#xA;articles&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h1 id=&#34;metric-one-do-you-have-more-than-one-segment&#34;&gt;Metric One: Do you have more than one segment?&lt;/h1&gt;&#xA;&lt;p&gt;&lt;span class=&#34;inline-svg-icon&#34; &gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; viewBox=&#34;0 0 640 512&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M640 264v-16c0-8.84-7.16-16-16-16H344v-40h72c17.67 0 32-14.33 32-32V32c0-17.67-14.33-32-32-32H224c-17.67 0-32 14.33-32 32v128c0 17.67 14.33 32 32 32h72v40H16c-8.84 0-16 7.16-16 16v16c0 8.84 7.16 16 16 16h104v40H64c-17.67 0-32 14.33-32 32v128c0 17.67 14.33 32 32 32h160c17.67 0 32-14.33 32-32V352c0-17.67-14.33-32-32-32h-56v-40h304v40h-56c-17.67 0-32 14.33-32 32v128c0 17.67 14.33 32 32 32h160c17.67 0 32-14.33 32-32V352c0-17.67-14.33-32-32-32h-56v-40h104c8.84 0 16-7.16 16-16zM256 128V64h128v64H256zm-64 320H96v-64h96v64zm352 0h-96v-64h96v64z&#34;/&gt;&lt;/svg&gt;&#xA;&lt;/span&gt;&#xA;This question is, of course, more of a&#xA;rhetorical question, but there is a point about this one. Of course almost all&#xA;companies have more than one segment. Most companies use VLANs extensively. We&#xA;break out DMZs and internal data center LANs of course.  Sometimes we use&#xA;firewall interfaces between those VLANs or segments and treat them as zones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ideas on segmentation metrics (part one)</title>
      <link>https://microsegment.io/2019/08/22/metrics-for-security-segmentation-part-one/</link>
      <pubDate>Thu, 22 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2019/08/22/metrics-for-security-segmentation-part-one/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;What you measure is what you get&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;If you are like me and live and breath IT or IT security, the above statement&#xA;probably does not ring a bell and you don&amp;rsquo;t realize the source of this.&#xA;It is from a person called &lt;a href=&#34;https://en.wikipedia.org/wiki/Robert_S._Kaplan&#34;&gt;Robert. S. Kaplan&lt;/a&gt;&#xA;who developed something you may have heard of, the balanced scorecard.&lt;/p&gt;&#xA;&lt;p&gt;I will not dig into economics, because we are not in business school,&#xA;but the essence of the scorecard is that you need metrics on which you&#xA;can measure success or failure to be successful or be able to reach&#xA;your objectives.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A short history of segmentation</title>
      <link>https://microsegment.io/2019/08/19/a-short-history-of-segmentation/</link>
      <pubDate>Mon, 19 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2019/08/19/a-short-history-of-segmentation/</guid>
      <description>&lt;p&gt;&#xA;  &lt;img src=&#34;https://microsegment.io/img/ethernet-timeline.png&#34; alt=&#34;The ethernet timeline&#34;&gt;&#xA;&#xA;&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s start this with quoting wikipedia on what &lt;em&gt;network segmentation&lt;/em&gt; is according&#xA;to a encyclopedia.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Network segmentation in computer networking is the act or practice of&#xA;splitting a computer network into subnetworks, each being a network segment.&#xA;Advantages of such splitting are primarily for boosting performance and&#xA;improving security.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;h1 id=&#34;how-did-this-start&#34;&gt;How did this start?&lt;/h1&gt;&#xA;&lt;p&gt;&#xA;  &lt;img src=&#34;https://microsegment.io/img/ethernet-history.jpg&#34; alt=&#34;First ethernet draft&#34;&gt;&#xA;&#xA;&lt;/p&gt;&#xA;&lt;p&gt;Some of the readers might actually be old enough to remember how &lt;em&gt;local area&#xA;networks&lt;/em&gt; started out in the early 90s.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A collection of zero trust resources</title>
      <link>https://microsegment.io/post/zero-trust-resources/</link>
      <pubDate>Sat, 10 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/zero-trust-resources/</guid>
      <description>&lt;h1 id=&#34;work-in-progress&#34;&gt;Work in progress&lt;/h1&gt;&#xA;&lt;p&gt;This list is work in progress, if you have suggestions on what to add,&#xA;please add a comment below or drop me a mail or note.&lt;/p&gt;&#xA;&lt;h1 id=&#34;the-origins&#34;&gt;The origins&lt;/h1&gt;&#xA;&lt;p&gt;Zero Trust is not exactly a new idea, but a name for a architecture that takes&#xA;least privilege as the first design principle and assumes nothing can be&#xA;trusted.  I am not sure who established the category at this moment, but it&#xA;seems Google and Forrester Research have both been working on this.  &lt;a href=&#34;https://twitter.com/kindervag&#34;&gt;John&#xA;Kindervag (@kindervag)&lt;/a&gt; originally published the&#xA;model in 2010.&#xA;That paper is still valid 9 years after the first publication and it shows&#xA;great foresight and vision. Kudos to that.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
