By John Smith, Founder and CTO, LiveAction
Once seen as the ultimate way to protect sensitive information, beloved mechanisms like encryption have been turned against organizations and are heavily used by threat actors to hide attack payloads. In fact, recent research shows that 85% of cyberattacks came through encrypted channels in 2022. The bottom line? The network landscape is changing quickly and, in its wake, leaving a host of blind spots that make organizations vulnerable.
As cyber threats continue to evolve – and attackers become more sophisticated – there are a variety of elements contributing to these blind spots, including unavailable or inadequate native telemetry sources, the proliferation of cloud and multi-cloud networks, and the increase in east/west traffic caused by the growth of artificial intelligence (AI) and machine learning (ML). To help better understand these blind spots, and how to prevent them, let’s dive into four specific kinds.
1. The Rise of Cloud and Multi-Cloud Networks
Cloud and multi-cloud networks continue to be a blind spot for network engineers, especially as adoption keeps increasing and services get more complex. While there is a lot of telemetry available for application developers and cloud engineers, networking pros (especially when it comes to the data plane) still rely on looking at flow logs, specifically in AWS and Azure. Although flow logs are detailed, they’re quite difficult to decipher, the volume of data can be quite large, and the context of the flows needs to be correlated to be meaningful.
How do you solve this problem? Two ways:
- First is to use a platform that can ingest flow logs and enhance that data with contextual information that presents it in a meaningful way. For example, AWS flow logs enhance the entry and exit of the flow with specifics of VPC endpoint or IGW, rather than dealing with just IP addresses.
- Second is to leverage packet level analytics to provide even more depth, for example, with HTTP transactions, TCP and UDP performance metrics, and payload information. This helps network teams understand how well the application is performing.
2. East/West Traffic
As analytics, artificial intelligence, and machine learning applications continue to grow, they’re creating a lot of east and west traffic, whether it’s in the private cloud or public cloud. In private cloud specifically, instrumenting to get visibility can be challenging due to performance, scale, micro segmentation with VXLAN, and other issues.
How do you solve these problems?
- Network teams can leverage packet broker technologies that allow organizations to instrument large scale data centers and public clouds that can provide metadata and packet level telemetry.
- This telemetry data is then sent to a Network Detection and Response (NDR) solution to perform analytics, provide visibility, and remediate threats.
3. Encrypted Traffic
Encryption blindness continues to grow. In fact, 96% of organizations claim to be challenged with detecting threats within encrypted traffic. The adoption of TLS 1.3 and the sheer volume of HTTPS usage is making it impractical to decrypt traffic to gain visibility, due to the performance and cost implications. This is a critical blind spot that creates challenges for network and security pros.
How do you solve this problem?
- Organizations must adopt encrypted traffic analysis, which doesn’t require decryption (or payload inspection) and uses machine learning models to understand deep packet dynamics over time. This allows the technology to develop an understanding of anomalous patterns in encrypted traffic and alert teams. These unique patterns are learned for things like malware, exfiltration attempts, command and control traffic, or even simple things like DNS over HTTPS.
4. No Telemetry
Many network devices can export SNMP and IPFIX or NetFlow. This allows network engineers to solve problems like understanding utilization and application traffic flow. But when they do export NetFlow, it might be limited to basic information such as source and destination IP, and ports and interfaces. It also causes blind spots in the network like understanding the real application rather than generic HTTP or HTTPS designation.
How do you solve this problem?
- An easy way to gain visibility into those areas of the network – like branch offices, smaller data centers, or even co-locations – is to insert a small footprint packet analytics capability in the form of virtual, cloud-optimized, or physical appliances. These can be inline or in packets sent from a tap or SPAN port. It can offer full packet level analysis to provide performance, troubleshooting, and forensics information. Keep in mind that you may need to accommodate smaller form factor solutions for those places in the network that pose challenges when retrieving telemetry.
As network blind spots continue to create challenges for organizations in today’s rapidly evolving threat landscape, it’s crucial to adopt a comprehensive approach to deal with performance and security issues. This should include tactics like network performance monitoring, regular vulnerability assessments, the use of advanced security tools, and more. It’s also important to consider your organization’s unique challenges and risks. By implementing some of these best practices, you can enhance your network visibility and eliminate blind spots.
##
ABOUT THE AUTHOR
John Smith is CTO, EVP and founder of LiveAction and previously served as VP of Engineering at Spirent where he was responsible for $150M+ revenue per year product line with over 140 engineers. John has been in networking and software development for over 25 years with companies such as Boeing, Phoenix Technologies and Referentia. John holds 6 patents developed under LiveAction in the areas of network management and visualizations. John holds a MS in computer science and research towards his PhD in machine learning using genetic algorithms for autonomous navigation.





