Video summary
The interview highlights a critical shift in enterprise security as organizations enter the agentic AI era, where traditional perimeter defenses are no longer sufficient. With the rise of autonomous agents, Large Language Models (LLMs), and data stores like MCP services, the attack surface has expanded significantly, creating new vulnerabilities such as autonomous infiltration and potential agent-to-agent hacking. Experts emphasize that relying solely on parameter firewalls is inadequate because they can be bypassed; instead, companies must adopt lateral security strategies that encompass zero trust architectures and zero-day threat protection. The speed and autonomy of modern attacks mean that organizations cannot afford to delay deployment, as waiting for manual patching cycles leaves systems exposed to rapid exploitation by sophisticated threats.
To address these challenges, the discussion focuses on the necessity of an integrated security stack rather than a fragmented collection of tools often described as "Swiss cheese" with too many holes. Broadcom's approach involves deploying security at the hypervisor level to ensure high throughput and low latency, which is essential for AI workloads that are sensitive to delays. A key innovation presented is the use of agentic AI within the signature pipeline for intrusion detection systems, allowing for intelligent virtual patching where only relevant signatures are pushed to specific hosts based on real-time needs. This method not only accelerates response times but also prevents administrators from being overwhelmed by managing thousands of individual configurations, effectively turning security operations into a scalable, automated process that keeps pace with the velocity of emerging threats.
Furthermore, the conversation addresses the unique risks posed by dynamic environments like Kubernetes and microservices, where agents function similarly to autonomous microservices capable of multi-step reasoning and code generation. To secure these complex ecosystems, the solution includes an AI gateway that sits at the ingress level to provide comprehensive visibility, logging, and protection against data exfiltration of sensitive information such as PII and credentials. This gateway enhances existing web application firewall capabilities by adding specific API protection, ensuring that agents do not go rogue or leak critical data. The strategy involves real-time discovery of all active agents and tools to identify shadow IT, allowing administrators to quickly quarantine unauthorized entities and enforce strict guardrails while humans focus on high-level policy decisions rather than mundane operational tasks.
Ultimately, the interview concludes that security must be embedded directly into the core infrastructure from day one, moving closer to the resource layer to handle the heavy traffic density generated by AI systems. As hardware costs rise and network traffic increases, the industry is shifting toward solutions that offer both horizontal scale and vertical integration, ensuring that security does not become a bottleneck for performance. Senior leaders like CISOs and CIOs are realizing that picking the right architecture now is vital to avoid compromise before it happens, driving a rapid adoption of comprehensive security offerings that combine networking, virtualization, and advanced threat protection. This holistic approach ensures that enterprises can leverage the intelligence and efficiency of AI while maintaining robust defenses against an evolving landscape of autonomous cyber threats.
Read the full video transcript
[music]
Hello, I'm John Furry, your host of the
Cube. This is the Cub's VMware Explore
coverage. Of course, we got two days of
live cube coverage from the show floor.
I'm here with the broadcast executives
to unpack the innovation at news and
news at the show. Now, here up here in
the cube now is Zumesh. John is VP and
general manager of the application
networking and security division. And
we're going to talk about the agentic AI
era and its impact on the attack surface
areas in the enterprise. We're seeing
new threats from autonomous infiltration
of LLMs, agents, data stores, MCP
services as the new infrastructure is
being deployed. These are huge
opportunities to to nail down. You got
to nail these challenges or agents
cannot scale. Great to see you again.
Thanks for coming on the cube.
>> Thank you, John.
>> So, you know, we've had this
conversation every kind of cycle. The
perimeter is gone. What's the surface
area? LLMs bring in a lot of opportunity
and intelligence in the enterprise.
Obviously, the domain expertise and the
data is unlocking.
>> What is the attack surface area look
like now with AI being injected into the
equation?
>> So, it's very interesting time, right?
Uh news gets old very quickly in these
days. Like last year, it was autonomous
attacks. Oh my god, anybody can become a
genius and start attacking rapidly. Then
mythos showed up and we saw okay, it's
very good at finding vulnerabilities.
has got everybody worried. How are we
going to protect against that? And
lately the agent AI stuff gets out of
your environment, starts hacking other
customers and goes all over the place.
So it's really a scary time for our
customers. Anything everything can go
and anybody can become an expert and
unknowingly also things can happen with
these agents. So I think this is the
time where you have you can't put off
security any longer. Oh, I got a
parameter firewall. I'm good. No, no,
no. not good. It can be bypassed. So now
the security gurus or experts are saying
you know you can't take two years, three
years. You have to deploy lateral
security. You have to think all the
stages of security and properly tackle
them because you have to put all the
prevention in place because these
attacks are going to come it's going to
be too late. So you better put
segmentation in place. You better start
thinking of more than even the lateral
firewalling. You start thinking about uh
advanced threat protection, zero day
tax. What are you going to do? And
you'll have to patch your environment.
Both things are customers. The
infrastructure you buy from vendors like
Broadcom, but their own applications and
these days is big harming.
They just could be patching their entire
lives, right? Because there so many
vulnerabilities are being found. So we
also suggesting to our customers we can
help you with virtual patching we can
give you signatures while you're waiting
to do your own application patching we
can patch for you. So lot of exciting
stuff but lot of the same security tools
you can enhance properly you can provide
the visibility and you can guide them to
deploy much faster and that's the
environment which is is the security is
moving to and so our customers have to
select the vendors properly. Yeah, I
mean your point about um the the attacks
that are happening, it's not
hypothetical, they're real. We're seeing
play out and the velocity uh is is a
huge deal. Speed of attacks um but now
you have autonomy as a factor. Um you
mentioned lateral security. Explain the
strategy of how people are thinking
about this because it's happening.
People are taking a more cautious
agentic approach. You're seeing more
deterministic workloads end to end and
they're well scoped. So it's not you
know truly autonomous but that's that's
the where the entry point is in the
enterprise how what needs to be in place
for agent to agent as as these
proliferate in the infrastructure
>> you almost you almost need to think of
uh zero trust and zero day properly and
not just peace meal so there in lies the
challenge right uh everybody knows you
have to do zero trust and zero day today
it's a must you can't I'll just put a
little
>> it's not optional you not an option is
it has to
>> it's not an option but our customers
have bought multiple security products
they can't put it together it's like
buying Swiss cheese yeah you have pieces
of security because you have plenty of
holes which people can drive through so
you kind of need somehow an integrated
stack and more a software stack where
all the elements are talking to each
other and that's exactly what we have
with red defend and not only that you
need to give them the full visibility
and you need to walk them through
prescriptive kind of thing that's what
we did with DFW1234 last year we have
released ATP1234
so it's in a very rigorous stepwise
fashion made it very simple they can
deploy they can look at things and then
they can go about you know securing the
environment and then with our IDS IPs we
have lot of signatures available we're
coming up we have a signature pipeline
which we are enhancing with agentic AI
of course you use AI to further advance
Yeah, mythos could be a double-edged
sword. One hand is good and other hand's
bad. You
>> But we we have to use it. We have to use
it to make our security better, right?
Otherwise, we won't be able to fight.
>> All right. So, take us through just
detail out. I want to get nail you down
on this because I think people want to
know what what's in the box as they say.
What's on by default? Sounds like you
guys have zero trust as an always on
>> configuration. Yes.
>> What else does the customer need to do
to maintain that control or manage the
security? Um uh
>> so I I think you know they they need to
make sure that they turn on the options
right some options we will obviously
take them through but as they get to as
they get more comfortable with it you
know we have very high scale right so we
have very high scale because in AI
environments two things matter of course
what is your security stack but uh the
throughput matters so we have very very
high throughput we are doing like 75
terab per uh v center cluster uh for
firewalling we are doing 17 terabit for
IDS IPS and the other aspect is also
latency because in AI workloads latency
matters so our security is done at the
hypervisor level much like AS6 so we
make sure the packet doesn't go left
right you're not copying it 15 times so
we are delivering all that at the same
time but the customers need to be able
to you know say okay I'm okay you're
gonna turn this on by default at least
they need to agree to that. If they
agree to that, I think we can secure
their environments in a very nice
fashion and as they get hit with new
vulnerabilities
>> or CVEes, we can help them with IDS IPS
signature pipeline so that they can do
virtual patching quickly because we can
intelligently push that from a central
location in a distributed fashion and we
won't push all the signatures everywhere
a little bit more intelligent. That's
where AI comes in again. we'll use the
IIO what is running in the host we'll
only push the
>> those signatures into that host and if
they upgrade the software we'll get rid
of the old signatures so all that kind
of thing is inbuilt into infrastructure
so it scales
>> and at the same time intelligent they
are not bewildered oh my god I have to
learn 50,000 things how will I ever do
it
>> well this is where I think AI is
interesting because you mentioned
segmentation at the top of this
interview and you know when you look at
things like oh we got a vulnerability
how do we quarantine it the the process
of doing security now can be applied
with agents. So a lot of these
configurations and management you can
actually you know segment something
pretty quickly. Yes.
>> So talk about that impact because I
think this is a new reality in the
security world is that
>> there's a lot of that blocking and
tackling you're doing on a whether
you're a red team or whatever you're
doing you can actually move faster. What
what specifically is AI doing better now
than that humans had to do before and
what's the role of the human? So I so I
think the human is still there to do
some audits and checks and bounds. What
if uh you know I'm using agents in my
solution like security services platform
to provide the visibility and quickly do
the operational stuff like you just
click a button and boom the rules will
go in because I'll calculate them
rapidly or those changes. So so I think
there at some point there should be
checks and bounds a little bit because
you want to make sure like the stuff
didn't go crazy. Other than that I think
the humans just need to decide the top
level policies right what are the guard
rails what's going to happen and leave
the busy work if I can call it to AI and
the machinery over there and that's
exactly what we are doing with agents in
our security services platform we want
we want to take all the busy nittygritty
work out where humans a can and make
mistakes and then they take too long
take too long
>> we're seeing here at explore a lot of
ecosystem partners are engaging a lot of
activity people have good visibility on
what the AI infrastructure is going to
look like at least from a a mechanic
standpoint AI factories etc coming out
but the number one question I get and
I'd love to ask this question so if I'm
your friend and I say tell me the impact
of agentic AI we're seeing LLMs we're
seeing MCP servers all these new tools
it's a great environment for AI
development um agents are here what's
different what what should I be aware of
with Agentic infrastructure and agentic
applications. What's the number top
three things I need to look at and pay
attention to?
>> So, first of all, I need to be able to
discover them, right? MCP, who's talking
to who? What are the tools? I need to be
able to figure that out that picture
because in traditional IT everything was
written down someplace that doesn't work
in this environment. These will come and
go very fast. So, you need to be able to
discover them in real time. And then the
same things which are used for
traditional work uh machines you know
virtual machines and Kubernetes clusters
you want the same kind of policies to be
enhanced to work with MCP and all these
other uh tools and agents which are
talking to each other. So and you as you
discover you'll be able to tell these
are real this is shadow IT what the hell
is going on and then then your
administrators can say I never authorize
all this what the hell is all this
running so I can
>> quarantine this and not let it talk to
the rest of the infrastructure. So that
stuff is very easy for do for us to do
with a few tweaks to our existing
enhancement we can figure all this out
and show it to the end customer. This is
this is what you allowed. This is what
this shadow somebody without your
knowledge is cranking out all these
things and doing something.
>> Yeah. Yeah. A is running wild. It's kind
of like a TV show. Um these days uh
modern apps are running on Kubernetes.
We've seen that in all the reference
architectures on the big AI AI scaled
systems because you got to run control
planes. You got to run the resources.
>> Um APIs are very dynamic. Um that in
cloud native is all API based and
microservices. How do you guys protect
the API side of it? Okay. So we we have
this other product called the AI load
balancer. Now the and it's it's a
wonderful load balancer but it's
specifically very strong in the
Kubernetes in the ingress side right uh
because in the ingress side you have to
load balance and to manage it and it's
an integrated load balancer layer 4
layer 7 gslb waf so customers love it.
Uh we have lot of penetration with
kubernetes and the VMware kubernetes
vks. So already WFT is there as a
security element and it's becoming
popular. W VA waf seven eight years ago
was not that hot but in the last two
three years with all these attacks
coming in
>> and all these attacks which come in at
the web server level it's it's getting
really hot. So we have that product over
there. So we thought when you're talking
Kubernetes and agent take a agent agent
AI workloads are all Kubernetes they're
all talking API. we have this wonderful
platform which customers are deploying
in large number why don't we take the w
and add the API protection on top again
principle crack open the packet looking
inside the packet why not look at the
APIs too so we are looking at the API
and providing the AP we have releasing
we have released that code and where
that is your w becomes w so we have bot
management API production and web
application firewall all in one tool
And it is going to be able to provide
API visibility, API vulnerability
detection and how do you you know stop
what is not allowed at an API level
because a lot of people come in the
through an API they can make you you
know execute some code at the end of an
API which can cause a lot of trouble. So
it'll stop all that and it's sitting
right there with the Kubernetes
workloads. So it is the right place
>> and obvious sits in Kubernetes. Where is
that? What is that? So it basically it's
it sits at the ingress level.
>> English. Okay. Okay. Okay. How does that
evolve? Because I was talking with a
friend from the cloudnative compute
foundation CNCF coupon. We've been every
been to every show since its inception
in North America and Europe. And we were
riffing on the idea that you know
Kubernetes and microervices
um were a big thing. And of course we
that's cloud native. He said agents are
a lot like microservices. You got to
look at it. Mhm.
>> Take us through the evolution of Avi and
this this piece because
>> it's almost the same movie you're seeing
because they're out running around and
they're standing up turn terminating
their relationships but they're doing
reasoning and work. They could be
coding. I mean agents not just like a
search paradigm. They're they're
multi-step process. They could discover
something write some code on the fly.
>> Yes,
>> that's a cool thing but also it could be
dangerous.
>> It could be very dangerous. So, so you
know again the thing the good thing is
we don't have to start from zero in any
place right we talked about kubernetes
and uh workloads running over there but
all these agent AI workloads are also
kubernetes workloads so same environment
we have the auv load balancer ingress
load balancer doing vap now we thought
about it hey this this whole notion of
AI gateway right AI gateway kind of does
three things it discovers all these
agents uh and who are they talking to
etc and it also provides visibility and
logging and so that you can you know
track what happened over time and it
does the usual every AI gateway does
like route to the cheapest model or open
source model okay that's the easy part
but the third part is the tougher one
how do you provide security to these
agents we've been in customer
conversations without naming them at our
EBC's
>> and when the CISO shows up they keep
asking
not explain to me how exactly my agents
are talking, how you going to protect me
and all that. Yeah, identity is one
thing but beyond identity, how are you
going to do the blocking and tackling so
that they don't go rogue and they
>> what is the blocking and tackling? What
does that entail?
>> So, so I think some of it is the same
principle, right? First you have to be
able to see what's happening then you
have to pro you know lateral
segmentation etc that you you wouldn't
have reached hugging face if you had
lateral segmentation in place. Right. So
you're saying hugging face wouldn't have
happened, the open AI thing wouldn't
have happened.
>> Yeah. If you if you had if you had done
the lateral segmentation at least would
have protected the propagation from
happening. But going to our AI gateway
with which again we are taking the AI
tool and we enhancing it's already a
pseudo gateway with the API protection
and all that. What we want to add to
there is also the Xfiltration right your
PII information your credentials your
credit card numbers they don't go out.
So we want you know there's something
notion of oh vast 10 in waf so we going
to for agentic stuff there's another
incarnation of that so we're going to
take the most important stuff of that
enhance it because that's what people
are worried about right enterprises like
I wrote some agents to do some payroll
stuff and low all my information social
security numbers are out there no so you
want to be able to protect that you
don't want to allow it you just don't
want to uh you know rely on some other
tool here there somebody forget get to
connect it you don't want to do that so
security for us is a huge part of uh the
AI gateway and we'll be doing that and
then with v defend you have all the
other parts right your lateral
propagation zero trust zero day so that
together I think we can provide a very
comprehensive and complete security
solution
>> well umesh this the AI story here at
explore is strong obviously it's part of
it it brings intelligence into the
enterprise a lot of unlock block. Um,
final question. As as a senior leader,
uh, and in security, you're seeing a lot
of change. It's funny, the networking is
moving up the stack and software is
moving down the stack. So, you're
starting to see security become a real
critical AI infrastructure component.
It's always been there in other
paradigms.
>> Um, and you have the traditional
security, zero trust, but it's coming
down into the core,
>> you know, around the density of the
systems. uh you mentioned you know
virtualization layer is a big part of it
you have the the ingress piece with a
what's the biggest change with AI that
that's changed in the security world is
it the notion that it's coming down
closer to the resource and embedded from
day one does it change the the uh design
and deployment of infrastructure and
software for these AI systems so
>> I think it's sum or all of the above in
some ways right Yes, it has to be at the
infrastructure level. It has to be at
scale. Otherwise, when are you going to
do it? 2 years from now, by the time
you'll be compromised, you know, may not
have your job or if the right stuff gets
stolen, you'll be in big trouble. So, I
think the realization
>> right from the top, the CISO, CIO, head
of infrastructure level is now suddenly
we go into a meeting, all of them are
there in the meeting because they are
worried, right? So they are worried,
they want to listen, they want to learn
and they want to make sure they are
picking the right architecture, the
right solution, will it work at scale?
If they are picking VCF, are they
picking the right security offering and
the right load balancing offering or
not? And as they thinking of AI to run
on Kubernetes, VKS, do they have correct
solution? So I think all those
conversations that they're happening,
they are realizing they have to deploy
it at the same time. Can we provide them
the tools to do that now? Yes, we can.
As soon as they understand that, I think
some of the customers are moving quickly
forward.
>> It's a very interesting time on the
computer industry because you have
horizontal scale and vertical
integration, but it's not like a just
the the workload. It's happening
everywhere. You can have an end to end.
It's got to know everything end to end
is essentially vertically integrated,
but you got to have horizontal scale.
Yes.
>> And vertical or domain specific end to
end
>> at scale. In the old enterprise, it was
great. You just build a stack, put some
hardware there, there's the workload go.
Yes. Yes. And with hardware prices going
up, I think scale and throughput, not
just scale, throughput has become very
important and that's been an area of
focus for us, right? We want to provide
twice and thrice the amount of
throughput.
Server prices have just gone through the
roof. Uh and the traffic is increasing.
The poor customers, they need to buy
more servers. Traffic is increasing. So
if we can provide them a scalable
solution and not just scale out scale
out as you put it on most servers but
also scale up per core I want to give
them more scale
>> then it becomes very interesting for
them and we are really giving them value
with our product
>> large scale open distributed computing
and the edges we even get to the edge
next year I think will be a big edge
conversation that'll that'll play in um
you're busy you know application and
security is a hot area
>> you feel really interesting times I I
think uh I'm excited about this whole
domain. I'm a you know vendor so it's
good for me that there's so much
happening in this area and there's so
much demand
>> uh for our product
>> and the role of networking is elevated
to up again up the stack security's
coming in network is the key
>> network is the key with AI traffic is
very heavy right and and it has to be
secured
>> yeah I mean some of these racks you have
you know north south east west traffic
going all over the place you have you
know this density around these systems
but that's just conventional networking
meets new AI networking. It's a whole
another ball game.
>> Yes,
>> thank you for taking the time to unpack
all these issues and news at Explore.
Appreciate it.
>> Thank you so much, John.
>> All right, I'm John Furry with the Cube.
We're here for our VMware Explore
coverage, of course, two days of live
coverage. Check out the Cube at the
cube.net. Thanks for watching.