Prisma AIRS Helps Protect Containers and AI Apps Running on Red Hat OpenShift

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Community Blogs
5 min read
L3 Networker

Prisma-AIRS-Helps-Protect_palo-alto-networks.jpg

 

 

Palo Alto Networks is pleased to announce that Prisma AIRS now supports Red Hat OpenShift, the industry leading hybrid cloud applications platform powered by Kubernetes. With this release, customers can bring AI-powered threat prevention for runtime network protection to each container running on Red Hat OpenShift clusters.

 

The shift to containerized applications has brought many advantages for development and operations, but has also brought challenges for security. Fundamentally, a container is just a different form factor where modern apps are running. Regardless of whether applications are running on bare metal, virtual machines, or containers, they all use the same network stack, and face the same foundational network threats. What makes containers different - and potentially difficult - is the scale of the East-West interconnections. However, traditional firewalls including hardware firewall and VM-Series running outside the cluster don’t have visibility into that traffic and can’t enforce application specific policies and hence, can’t stop the lateral movement of threats. This results in a significant increase in the attack surface. 

 

Red Hat OpenShift:

Red Hat OpenShift  is the leading hybrid cloud application powered by Kubernetes, providing a more consistent experience across on-premises, cloud, and edge environments.  It's designed to meet developers, platform engineering, and IT operations teams “'where they are,”' helping deliver a more seamless journey towards application modernization, modern virtualization,  and AI integration. Red Hat OpenShift streamlines the entire lifecycle of application development—from building and deploying, to running and managing applications. It helps simplify the complexities of application modernization efforts, including building and enabling applications to work with AI models across multi-cloud and hybrid environments, driving improved efficiency and productivity for developers and IT operations teams alike.

 

Prisma AIRS:

Palo Alto Networks Prisma AIRS is an adaptive,  purpose-built centralized security solution that allows you to extend Zero Trust to containerized apps, help meet regulatory data security compliance requirements, protect from known and unknown threats at both the perimeter and between segments, and confidently secure OpenShift and cloud clusters in a single form factor. Additionally, Prisma AIRS protects your AI apps/applications by leveraging our state-of-the- art Cloud-Delivered Security Services (CDSS) to help ensure robust defense against malicious URLs to prevent data exfiltration attacks. Prisma AIRS also enables detailed segmentation of all your apps to secure every communication pathway, from port-to-port to namespace-to-namespace traffic, effectively preventing both known and zero-day application-layer attacks.  

 

Fig1_Prisma-AIRS-Helps-Protect_palo-alto-networks.png

Integrated Solution:

With Prisma AIRS support for Red Hat OpenShift Container Platform, customers can use Prisma AIRS to protect containerized and AI apps running on Red Hat OpenShift clusters. Prisma AIRS is designed to protect all applications running on public or private clouds - containerized, virtualized, and AI. It provides visibility and runtime security against unpatched and unknown threats, allowing you to enforce a consistent security posture in every cloud and across hybrid cloud environments.  Additionally, you can enforce micro-segmentation policies to prevent threats from moving laterally between apps deployed on Red Hat OpenShift clusters. Your NetSec and DevOps teams can continue to use the processes and tools they use today and help ensure a frictionless deployment using Helm charts and Terraform templates. Additionally, Prisma AIRS can be managed with the same Panorama® or Strata™ Cloud Manager (SCM) as other Palo Alto Networks network security products, including physical and  virtual firewalls to provide network security teams with familiar interface and capabilities through a single-pane-of-glass console. 

 

While using RedHat OpenShift clusters to run container and AI applications, Prisma AIRS is the right choice for container network security for 3 reasons:

 

  1. Prisma AIRS is a single solution to provide runtime security and network visibility for container networks, virtual networks, and internet perimeter for containerized, virtualized, and AI applications running on public and private clouds, including RedHat OpenShift and Red Hat OpenShift Service on AWS(ROSA)
  2. Prisma AIRS helps secure applications on container networks, and also the emerging AI ecosystem powering tomorrow’s transformative solutions. According to the Gartner 2024 Magic Quadrant for Container Management, over 75% of AI applications will be running on containers by 2027. Prisma AIRS allows customers to deploy bravely and be ready for the future. 
  3. Prisma AIRS gives NetSec visibility and security inside the cluster without changing operations requirements or creating administrative burden for DevOps, with direct native connections to the container network for high security at high speed.

 

With high security, low complexity, and long security lifespan, Prisma AIRS is the perfect choice to secure the Red Hat OpenShift Container Platform to provide the technological solutions to increasingly common business needs.

 

In summary, with support for Prisma AIRS on Red Hat OpenShift Container Platform, you can:

 

  • Scale Network Security while Executing Digital Transformation

  • Protect Containerized and AI Apps Against Known, Unknown, Foundational, and AI-Specific Threats

  • Secure All applications Easily With Centralized Management And Consistent Tooling

 

To learn more about how AIRS can protect apps running on Red Hat OpenShift, use the following assets:

 

  • 1241 Views
  • 0 comments
  • 0 Likes
Register or Sign-in
Labels