https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
    • Diversity, Equity & Inclusion
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • MSP 501 Information Center
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Analytics


Shutterstock

Threat Detection Malware

VMware Takes On Lateral Security with Contexa Threat Detection

  • Written by Jeffrey Schwartz
  • June 2, 2022
VMware will offer broad threat detection with telemetry from its various solutions.

VMware has added threat detection capability called VMware Contexa that discovers lateral network traffic. The new technology, released on Thursday, is a cloud-based service that VMware is adding across its various offerings.

The launch of Contexa comes in advance of next week’s RSA Conference in San Francisco, where VMware will demonstrate it. It also comes a week after Broadcom agreed to acquire VMware for $61 billion. VMware had planned the Contexa launch before the announcement of the deal.

Detecting lateral network movement is important because it has become a prevalent threat. Lateral movement typically indicates an undiscovered attack that often has occurred months or in some cases, years earlier.

VMware claims that Contexa is more likely to discover lateral network traffic than current security information and event management (SIEM) and extended detection and response (XDR) solutions. That’s because SIEM and XDR offerings rely on sampled telemetry, said Tom Gillis, senior VP and general manager of VMware’s Advanced Security Business Group.

VMware's Tom Gillis

VMware’s Tom Gillis

“It’s a hint or an indicator of what’s happening, but it doesn’t give you the visibility,” Gillis said of SIEM and XDR offerings. “It’s not because the analytics of SIEM [or XDR] are bad; it’s because [they] doesn’t have access to the raw data to be able to understand what’s happening.”

VMware Contexa is not a product; rather, it is analytics technology that monitors traditional virtual environments through VMware NSX and endpoints via VMware Workspace One and Carbon Black. For modern, cloud-native app environments, Contexa detects threats via VMware Tanzu. VMware is offering it at no additional cost.

Advances in silicon from AMD and Intel have resulted in 128 core servers, making it possible to run more than 100 VMs on physical host, Gillis emphasized. Little of that traffic is actually analyzed, Gillis noted.

“By instrumenting the virtualization layer, we see every packet and every process,” he said. “And we understand them in context.”

Billions of Threats Detected

Contexa currently processes more than 1.5 trillion endpoint events and 20 billion network flows daily, according to a VMware internal analysis performed last month. Contexa detects roughly 2.2 billion suspicious activities each day, according to the analysis. VMware combines the machine learning data with information from 500 human researchers across the VMware Threat Analysis Unit and among different incident response partners. Among those events, VMware said it provides automated responses to more than 80% of them.

Omdia's Eric Parizo

Omdia’s Eric Parizo

“By combining threat insights from NSX, Carbon Black and Workspace One, and supplementing those capabilities with machine learning and human expertise, VMware has an opportunity to excel as a provider of threat intelligence and threat detection, investigation and response across the entire modern enterprise,” said Eric Parizo, lead analyst for Omdia’s Cybersecurity Operations (SecOps) Intelligence Service. (Informa is the parent company of both Omdia and Channel Futures.)

Workspace One and MACS

VMware Contexa is available now for VMware’s Workspace One client virtualization offering and its Modern Apps Connectivity Services (MACS).  MACS is an offering consisting of the VMware NSX Advanced Load Balancer and VMware Tanzu Service Mesh. VMware’s NSX Advanced Load Balancer provides consolidated, multicloud, north-south application services.

Tanzu Service Mesh automates the execution of distribution of apps with secure east-west connectivity across Kubernetes clusters and connects to traditional virtual machine environments. It provides traffic management, policy control, encryption and authorization services to distributed apps. VMware plans to add Contexa to other offerings over time, including its Carbon Black endpoint protection offering.

“With Contexa, VMware is doing what’s rare in enterprise cybersecurity, namely offering a solution that’s truly innovative, by way of the depth and integration of its security telemetry across endpoints, applications, within virtual and hybrid data centers, at access points, and across distributed cloud edge environments,” Parizo said.

“Where I think VMware has a particularly compelling opportunity to excel is in its ability to use its unique position within the application infrastructure to observe and understand application-layer traffic, in both traditional virtual applications and cloud-native containerized and microservices-based applications, and pinpoint anomalous activity,” he added. “Even today this remains a remarkably challenging endeavor that few vendors can do consistently and effectively.”

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Jeffrey Schwartz or connect with him on LinkedIn.

 

Tags: VARs/SIs Analytics Channel Chatter New Products & Services Security Technologies

Most Recent


  • HPE Bolsters Compute Portfolio for Partners Embracing Cloud-Native Development
    HPE becomes first tier-one server provider to offer compute with optimized cloud-native silicon for MSPs.
  • Cloud Roundup
    Heads Up, Partners: Google Cloud, New Relic Make Big Moves
    We’ve also got updates from Backblaze, Veritas, AWS, PwC and Pax8.
  • 5G revenue opportunity
    How to Differentiate to Leverage 5G's Revenue Opportunity
    Conversational intelligence can help differentiate services that leverage 5G.
  • HPE Greenlake depiction
    HPE Fulfills 2019 Promise with Platform Enhancements, Private Cloud Revamp for GreenLake
    The platform deepens security, extends developer tools to provide, scalable and unified experience, from edge to cloud.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Rohit Ghai RSA CEO at RSA 2022
    RSA Day 1: SolarWinds, IBM, Perimeter 81, Dell, Mandiant, More
  • focus a camera
    Knowledge 2022: ServiceNow Focused on Partner Experience to Drive Growth
  • Chinese Cloaked Hackers
    The Gately Report: Cybereason Helps MSSPs Provide Unified Security, Details Massive Espionage Ring
  • Must See
    IBM, F5, Appgate, Axonius, CyberGRX Among 'Must-See' Vendors at RSA

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Heads Up, Partners: Google Cloud, New Relic Make Big Moves

June 28, 2022

Google Cloud Sustainability Summit: New Programs, Tools for Partners

June 28, 2022

VMware Continues Shift to Subscription Model with vSphere+ and vSAN+

June 28, 2022

Industry Perspectives

View all

How to Differentiate to Leverage 5G’s Revenue Opportunity

June 28, 2022

Why MSPs are Attractive Cyberattack Targets

June 24, 2022

IT Partner Programs Must Evolve to Meet Market Demands

June 21, 2022

Webinars

View all

VEP Platform for Delivery of uCPE, SD-WAN and SASE

June 29, 2022

The Digital Worker: How to Empower Customers with a Flexible, Scalable VDI Solution to Enable Remote Work

June 30, 2022

Growing Partner Revenue and Customer Satisfaction with Power Management Services

June 23, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

May 6, 2022

Twitter

ChannelFutures

.@HPE has bolstered its compute portfolio for partners embracing cloud-native development. @HPE_Partner… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

.@Oracle's @NetSuite has launched a new program, SuiteReferral, to offer benefits to organizations that invite peer… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

It’s early in the week but already #cloud companies are making waves: @GoogleCloud, @NewRelic, @Pax8. Also, news fr… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

5G is here and providing great revenue opportunities. Find out how from @dubberapp #5G #networks #communication… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

.@Vonage, @GoTo are key players in unified communication market worth nearly $190 billion by 2031.… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

.@IronNet lays off 17% of workforce due to market conditions. dlvr.it/ST0v61 https://t.co/0uOaMU662Y

June 28, 2022
ChannelFutures

.@HPE announced platform enhancements and new cloud services for HPE GreenLake, the company’s flagship offering.… twitter.com/i/web/status/1…

June 28, 2022
ChannelFutures

.@cybereason issues alert on #BlackBasta ransomware group with 50 victims in two months. dlvr.it/ST0Vz2 https://t.co/Xf8wpeKl14

June 28, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X