Load Balancing and NetSecOps - What’s the Deal?

November 12, 2020 Flowmon, Infrastructure Management

Kemp, known for its well-tuned and easy-to-use load balancer LoadMaster, has acquired Flowmon, extending its product portfolio and growing through acquisition. So you may ask, how does the technology fit?

User experience matters above all else

A load balancer plays a critical role in the application delivery chain - it knows everything about the application itself.

Meanwhile, NPMD technology ensures the applications are delivered through a well-functioning network by providing:

  • understanding of network traffic,
  • insight into bandwidth utilization,
  • key network performance metrics,
  • complex troubleshooting that goes beyond the visibility provided by the application delivery alone.

In addition, NDR technology contributes by leveraging the same network telemetry to detect threats, indicators of compromise, and adversary activities in the company digital environment.

A joint NetOps, SecOps and AppOps effort

This is not an attempt to coin a new buzzword, but I envision this unified technology as NetSecAppOps that ensures network performance and health, lending transparency to the digital environment and making it a true enabler of business goals.

LoadMaster is, in fact, much more than just another load balancer (or application delivery controller).

Defined in software, delivered in the kernel, and based on proven lmOS with over 20 years of Linux kernel optimization and integration, it ensures the best performance for applications regardless of whether they're delivered using containers, virtual machines, cloud, or bare metal. Kemps’s 360 Central and 360 Vision simplify application delivery through:

  • central management of applications,
  • SSL certificates,
  • security profiles (WAF). 

On top of that, it provides insight into application health going from availability of application servers through their load and up to the application response time and prediction of issues in application delivery.

Combined with Flowmon, we’re talking about true end-to-end visibility, monitoring, and root cause analysis.

When users have trouble reaching applications properly,  network visibility is essential to analyzing the root cause of the issue, which can vary from network or firewall configuration, bandwidth utilization, poor network performance, or the effect of middleboxes on the network traffic.

Flowmon’s network-layer root-cause analysis complements LoadMaster’s ability to fully understand the application itself, reports on user experience and performance degradation with root cause analysis in real time. Also, not all the applications are delivered through a load balancer and in such cases, Flowmon is the only source of truth when it comes to application performance or troubleshooting of application-related issues.

And don’t forget about security.

While LoadMaster is able to protect the application from threat actors with a built-in web application firewall, Flowmon extends this protection to the whole digital environment (even if composed of multiple hybrid environments) covering not only the application delivery chain but also both north-south and east-west traffic. Therefore, it can detect adversary techniques such as discovery, lateral movement, data collection, command & control, or exfiltration, effectively turning the network into another layer of protection against cyber threats and ensuring applications are delivered in a secure environment.

What about the future?

We stand at the birth of a new approach to business enablement via technology. The challenge now is to bring all the information under one user interface where the application delivery workflow is seamlessly fused with out-of-the-box detection and prediction of performance and security incidents, built-in root cause analysis, and response automation.

We are witnessing something unique, and I can only hope you share our excitement about what’s coming.

Pavel Minarik

With over 20 years of experience in enterprise IT and security, Pavel’s career at Progress started in 2021 after the acquisition of Kemp Technologies and Flowmon Networks. As Acting CISO at Progress, Pavel is responsible for overseeing enterprise-wide information security strategy, risk management and regulatory compliance. His role is focused on aligning security initiatives with business objectives, strengthening security posture, building resilient security programs and leading cross-functional teams in complex, fast-paced environments.

As Vice President of Product Security at Progress, he is responsible for the secure software development life cycle across all Progress products, defining and implementing product security standards and ensuring that security is inherent to the product development practice. During M&A initiatives, Pavel leads product security reviews and assessments as part of technical due diligence.

In his previous role as Vice President of Technology, he was responsible for the overarching technology strategy of Progress’ Flowmon, Loadmaster and WhatsUp Gold Infrastructure Management products—as well as experimental development in this area. With his experience as the former CTO of Flowmon Networks, Pavel led product management for Progress’ flagship Flowmon NPMD & NDR solution.

As a former senior researcher at the Institute of Computer Science of Masaryk University, Pavel has participated in several R&D projects across network traffic monitoring, analysis and cybersecurity domains. He is also the author of more than ten publications on behavior analysis and algorithms for traffic processing and anomaly detection, summarized in his Ph.D. thesis, “Building a System for Network Security Monitoring.”

Areas of Expertise:

  • Cybersecurity
  • Network Detection & Response
  • Network Performance Monitoring & Diagnostics
  • Software Development

Credentials & Publications

  • 10+ years membership in AFCEA Czech Chapter
  • MINAŘÍK, Pavel. Building a System for Network Security Monitoring. Ph.D. thesis. Brno, 2012.
  • VYKOPAL, Jan; Tomáš PLESNÍK and Pavel MINAŘÍK. Network-based Dictionary Attack Detection. In Proceedings of International Conference on Future Networks (ICFN 2009). Los Alamitos, CA, USA: IEEE Computer Society, 2009, pp. 23-27. ISBN 978-0-7695-3567-8.
  • MINAŘÍK, Pavel; Vojtěch KRMÍČEK and Jan VYKOPAL. Improving Host Profiling With Bidirectional Flows. In 2009 International Conference on Computational Science and Engineering. Vancouver, Canada: IEEE Computer Society, 2009, p. 231-237. ISBN 978-0-7695-3823-5.
  • DYMÁČEK, Tomáš and Pavel MINAŘÍK. NetFlow Data Visualization Based on Graphs. In Visualization for Computer Security, 5th International Workshop, VizSEC 2008 Proceedings. Berlin, Heidelberg, Germany: Springer-Verlag, 2008, pp. 144-151. ISBN 978-3-540-85931-4.