Application Experience Insights with Kemp: Recent Episodes

Kemp Technologies

Join Jason Dover, VP of Product Strategy at Kemp in this series to explore the technologies, processes and models that connect people, applications and services. We'll talk with people that have experience building and using technology to deliver application services to customers and tackle topics related to modern application architectures, cloud, DevOps and security. We'll speak to the folks behind the scenes that make Kemp's product offerings possible and get fresh perspectives from folks around the industry.http://www.kemptechnologies.com

View Details

Today's IT landscape is more complex than ever. The traditional secure perimeter of the network has effectively evaporated and trends such as BYOD, IOT and the gig economy means that unmanaged devices have to be given a measure of limited trust in terms of accessing critical application resources and services. 

But with the cacophony of security offerings, how do you actually approach the security of your application ecosystem in 2021 and beyond. Enter Zero Trust, a model that involves assuming every entity attempting to connect to your environment is a potential threat actor, instrumenting granular access control, application-level micro-segmentation, and a least privileged access model.... Sounds complicated - where do you start, how do you begin adopting these principles, and what are the options... 

Barry Gleeson I Jason Dover I Kurt Yung

View Details

In today’s IT ecosystem where many technologies have started to become commoditized, user experience is the new battleground of differentiation, it a key component to creating unique competitive value propositions and a primary ingredient in business success. But what exactly is user experience, specifically in the context of non-consumer products that are leveraged by IT administrators, DBAs, and engineers to run their organization’s applications and networks. Why is it so important, how does it differ from UI alone and what role does it play in the overall customer experience?

Today, we’ll dive into these topics, what it means to take a user-centric approach to product development, and some of the tactics involved in creating meaningful user experiences for customers.

Jason | Keith Kennedy | Mark Delaney

View Details

In traditional IT organizations, engineering and architecture groups have the luxury of defining and describing what should be... Infrastructure and Operations teams, on the other hand, assume the unenviable responsibility of dealing with the world as it really is, experiencing the highs and the lows of day 2 operations, traversing the challenges of services being leveraged in ways they were never intended, predicting how things might go wrong and having a corresponding toolbox for each possible eventuality. This combined with recent trends that emphasize greater degrees of change and agility within a company’s IT landscape means that things will break. As a result, there’s been significant transformation around the methods and tools applied to operate IT infrastructures along with the needed skills. For example, analytics no longer is limited financial data modeling but is now being applied to day to day incident management – ML is no longer just for cracking enemy nation communications – and AI isn’t just a Hollywood concept but is now weaved into the tooling leveraged for monitoring networks and apps.

Today, we’ll dive into these changes, how they’re impacting enterprise IT and cover how their power can be harnessed for increased efficiency. 

I’m joined today by two of my colleagues and friends, Benjamin Hodge and Barry Gleeson…

Jason | Ben Hodge | Barry Gleeson

View Details

Overview...

In recent years, interest has skyrocketed in all thing’s agility. In the IT world, phrases like minimizing blast radius, managing cattle versus pets and just in time service delivery have become part of our everyday language. The main point is that businesses both inside and outside of the technology industry are enamored with finding ways to do things faster through creation of loosely coupled autonomous teams and infrastructure unencumbered by the processes, red tape and fragile monolithic tooling of yesteryear. One specific trend that has emerged is that of “Infrastructure as Code” or IAC for short. The basic principles behind this model is to codify everything, use version control, continuously test, integrate and deploy and make the code that drives this as modular as possible. For those just looking to move in this direction, it can be challenging and confusing. In our discussion today, we’re going to work to demystify this space by talking to experts that have already been on the journey and work in this world on the day-to-day basis… I’m joined by a panel made up of 3 members of Kemp’s Platform Operations team, Roy Dunican, Michal Jeco and Dariusz Banach.

Jason | Roy Dunican | Michal Jeco | Dariusz Banach

View Details

More than ever, organizations of all sizes are investing in cloud architecture for improved time to market of services, ability to provide just in time delivery for lines of business, scalability and security benefits. This involves changing practices, processes and mindset. In reality, cloud is less of a destination and more of an operating model. That said, the hyper-scalers such as Microsoft, Amazon and Google have provided the infrastructure and tooling that enables organizations to expedite the transition to this operating model. 

Today, we’ll talk in particular about AWS, some of the challenges of publishing packaged Enterprise applications – that is that were not built as cloud native and potentially were previously deployed on premises – and how intelligent Layer 7 load balancers can help these types of projects succeed. We’ll deep dive into the following key areas

  • Networking and Blast Radius
  • Scalability and Automation
  • Security

Hosts: Jason Dover| Frankie Cotto | Andy Redman
http://www.kemptechnologies.com

View Details

Episode 1: Your Load Balancer – The Hidden Key for Improved Security Posture

Overview

Security is critical to a positive application experience for organizations of all sizes and has increasingly become a major consideration in recent years. Nearly 3 quarters of all businesses experience phishing and social engineering exploits and 2019 saw the most ransomware attacks ever. This makes cybersecurity top of mind for IT leaders and has resulted in a cybersecurity spend forecast of $133.7B USD by 2022. To improve their security posture, technology teams are augmenting their approach to application deployment and optimizing their environments by leveraging existing infrastructure in new ways. In this episode, we’ll discuss how application load balancers, which are already deployed in 99% of environments, can leveraged to play a key role across 3 areas of overall security architecture

  • Authentication & access
  • Application layer security
  • Micro-segmentation / per app deployment model

Jason | Iain Kenney | Derek Kiely

Questions covered…

  • Why is the load balancer a relevant place for consolidating security functions?

Privileged position, touches data that infers security aspects related to AX and proximity to apps, by definition every reverse proxy is a rudimentary FW

  • Why have we seen a trend of authentication & access consolidated into the load balancer
    • Last line of defense before the app
  • From an authentication & access perspective, what are the elements that a load balancer would typically have to interact with
    • LDAP and RADIUS systems
    • Certificate infrastructure for X.509/PIV/CAC in FED
    • Talk about importance of SAML as we move deeper into cloud age
    • LANL use case
  • Beyond simply validating that a user should be allowed access, what about making actual decisions based on context of identity (e.g. location, group membership, etc.)
    • Rite AID use case
  • What’s the difference between network layer security and web application layer security and why does it matter?
  • Is IPS sufficient?
  • What are some of the web application security use cases where a load balancer would play a role?
    • Consolidation of L7 WAF services based on doing decryption
    • Addressing application vulnerabilities (GhostCat)
    • PCI DSS requirements
    • Data exfiltration
    • PaaS eCommerce platform use case
  • Over the past few years, we’ve been hearing the term micro-segmentation come up as it relates to security, specifically since VMware started down the software-defined route and later with NSX – what is it all about?
  • To what extent can load balancers help if an organization wants to start applying a zone micro-segmentation approach to their infrastructure?
  • Small zones @ app, service, sub-service level
  • Requires viable costing model, strong centralized mgmt., automation

http://www.kemptechnologies.com