newsfilter.io
Interview, Fireside Chat

a16z Podcast | When Large Scale Gets Really Massive -- Managing Today’s Enterprise Networks

  • Customers face increasingly sophisticated attacks from professional organizations and nation-states that actively QA solutions against tailored campaigns, shifting the threat landscape from untargeted script-kid activities to attacks that start and end within minutes.
  • The number of connected devices is predicted to scale to billions driven by IoT, breaking the existing hub-and-spoke model which is expected to fail at hundreds of thousands of nodes.
  • The organization plans to deploy a linear peer-to-peer and ring communication architecture across a vast range of devices, including lightweight wearables and heavy servers, to serve as a commercially viable first of its kind in the enterprise.
  • This new topology enables constant time operations regardless of network size, allowing a billion or more devices to cluster near each other and aggregate data on the LAN before communicating across the WAN.
  • Future operations require a shift from days-old or even minutes-old data to real-time telemetry to prevent organizations from "playing whack-a-mole," as delays render data useless for detecting complex scenarios like the specific state of machines affected by Heartbleed.
  • The platform aims to function as one giant API allowing users to ask questions in English to instantly monitor networks, build custom models, and create dashboards without relying on historical database query cycles.
  • Detection capabilities are expected to evolve from systems management teams taking two weeks or security tools taking three weeks to identify issues, enabling the detection of vulnerabilities within seconds.
  • Immediate remediation actions, such as quarantining machines or stopping services, will follow detection instantly, replacing triage cycles that currently span weeks or months.
  • The lightweight runtime, described as a two-meg installer using 7-meg of RAM, is anticipated to be deployed on process controllers, ATMs, and point-of-sale devices to monitor existential threats.
  • Existing tools are characterized as fundamentally outdated compared to the threat environment, with the current state of network management having not changed since BigFix was built 20 years ago.
  • Customers currently receive hundreds of indicators of compromise daily but cannot act on them because legacy systems may identify patterns from three weeks ago by the time the attack has concluded.
  • The business outlook relies on scaling to billions of devices without performance degradation, requiring a fundamentally new architecture to assess telemetry and state where the answer to a query remains constant regardless of network size.
  • A unique value proposition is established by the ability to ask any question of hundreds of thousands of nodes and receive an instant answer, allowing customers to stop relying on broken, delayed systems.
  • The company intends to allow users to see exactly where they are affected by vulnerabilities without needing to create scripts or wait for days, refining the ability to aggregate information in real-time.