Zscaler Appoints Steve McMahon as New Chief Customer Success Officer Jay Chaudhry
In the past year, Zscaler achieved a significant milestone by [...]
In the past year, Zscaler achieved a significant milestone by [...]
The goal of any technology or engineering team is to build products that make life easier for their end-users. That’s especially true in the world of IT. Against the backdrop of rising cloud costs, p… Read more on Cisco Blogs
[[{"value":"
The goal of any technology or engineering team is to build products that make life easier for their end-users. That’s especially true in the world of IT. Against the backdrop of rising cloud costs, performance demands, and new security and sovereignty requirements, hybrid cloud offers more options – and more complexity – than ever. Whether it’s a “build your own” approach or full-scale managed services, organizations want the ability to choose the path that will create the simplest, best experience for their employees and customers, and the most value for their business.
With that in mind, it is no surprise that Cisco’s converged infrastructure solutions offered through our world-class ecosystem partners are popular with customers. Simply put, converged infrastructure exists to simplify and accelerate application delivery. These solutions are designed, validated, and optimized for a wide variety of application workloads and use cases so that IT teams can reduce their complexity and risk.
The converged infrastructure offering from Cisco and Hitachi Adaptive Solutions is built on decades of industry expertise and technology innovation together. And now, Cisco is thrilled to support Hitachi Vantara’s announcement of the next and logical evolution of this solution: A new suite of managed as-a-service offerings with a flexible consumption option for hybrid cloud use cases. This is also an important deliverable from the strategic partnership agreement that the two companies signed June 2023, specifically to help customers simplify their hybrid cloud management.
This new offering, Hitachi EverFlex with Cisco Powered Hybrid Cloud embodies the benefits of both simplicity and choice. It means that Hitachi Vantara, with solutions powered by compute, networking, and software from Cisco and storage technologies from Hitachi, assumes the responsibility for maintaining a range of IT infrastructure functions, backed by contractually agreed-to service levels, metrics, and consumption-based pricing.
Organizations are finding that consumption-based IT infrastructure delivered as-a-Service (aaS) can help overcome challenges often present in hybrid cloud deployments, such as operational complexity, rising costs, increasing security risk, and demands for faster time to value.
According to the Cisco Global Hybrid Cloud Trends Report, hundreds of IT organizations globally cited three top concerns:
37% said security concerns are a significant challenge to deploying to multiple clouds.
35% reported operational complexity as a key challenge when using multiple clouds.
33% said the cost containment was an issue, especially as companies adopted more public cloud resources.
Together, Hitachi and Cisco address these challenges by accelerating the transition to hybrid cloud and providing organizations with the flexibility to meet their specific business requirements.
Hitachi Vantara Hybrid Cloud Managed Services offers a variety of capabilities including:
Monitoring and alerting, capacity management, provisioning, and IT change management.
Continuous improvements and innovation by applying automation, AI/ML technologies, and leveraging leading practices.
Use of predictive analytics of operational data to drive innovation and streamline delivery.
The goal is for Hitachi Vantara to empower a cloud-like experience for IT organizations on-premises and in the cloud. Customers benefit from improved data availability, hybrid cloud observability, better operational and infrastructure efficiency, including the enablement of hybrid cloud automation.
And because we know that one-size-fits-all is rarely the best option, customers have flexibility to choose from more self-service offerings all the way to fully managed service, pay-as-you-go options all backed by professional services, support, and training.
Managed services also help our channel partners diversify and differentiate their businesses, within key areas of demand including hybrid cloud. With this managed service offering, Cisco and Hitachi channel partners can access proven, reliable solutions powered by two trusted brands that meet dynamic business requirements through consumption-based, cloud-like experience services.
“Our joint efforts with Hitachi Vantara around hybrid cloud managed services support a holistic approach to achieving customers’ business outcomes,” said Alexandra Zagury, vice president of partner managed and as-as-service sales, Cisco. “Our combined portfolio, including Hitachi Infrastructure Orchestration as-a-Service (HIOaaS), deliver the reliability, flexibility and insights that allow the customer to be more agile in today’s dynamic business environment. And the Partner-to-Partner model taps into one of the biggest growth drivers in the industry right now by providing customers with more choice and partners with the opportunity to build offers around their competencies.”
Being ready and adaptive to whatever the future brings is a powerful tool. This is at the heart of what makes Cisco UCS X-Series powered by Cisco Intersight, an award-winning solution and our most popular computing system. Future readiness means that the technology investments that our customers make today will help them better meet the evolving demands of tomorrow—driven by AI and the increasing importance of data.
One way for customers to ensure future readiness is to work with partners that can be there for them every step of the way. That’s at the essence of the new hybrid cloud managed service offering from Hitachi Vantara – it’s choice and simplicity delivered as a service customized for the specific needs of our customers.
Hitachi Press Release
Hitachi Landing Page
Hitachi White Paper
"}]] Announcement of a new hybrid cloud managed service offering powered with Cisco UCS and Hitachi storage technologies. Read More Cisco Blogs
There’s no questioning the importance of sustainability, and IT leaders at organizations of all sizes are working to understand the impact.
We sat down with IT leaders to get answers on what they are … Read more on Cisco Blogs
[[{"value":"
There’s no questioning the importance of sustainability, and IT leaders at organizations of all sizes are working to understand the impact.
We sat down with IT leaders to get answers on what they are doing right now to help build a more sustainable future. From large organizations like Amazon to mid-sized London clinics and beyond, sustainability is everyone’s responsibility, at every level. A more sustainable future can be realized by coming to grips with your own emissions, making sustainability part of new partnerships, and educating everyone from the top down. Organizations that don’t keep up will be left behind.
A more sustainable future starts with understanding the current landscape of your organization’s emissions today. That means data, tracking, and metrics must be available to create clear, achievable goals.
Alex Bazin, CTO at Lewis Silkin, began a project to measure their emissions impact and found that the majority came from their supply chain. Alex said they also discovered that some of their supply chain partners had a deep understanding of their individual emissions output. Taken altogether, they were able to create a complete picture of their Scope 3 emissions. Bazin now says he asks suppliers about their environmental, social, and governance (ESG) capabilities before engaging with them.
Carolyn Brown, CIO at the British Medical Association, said ESG initiatives are no longer a “take it or leave it proposition,” they’ve become a required expectation. In fact, Laura Kendrick, CIO of IPG Mediabrands, said that with “big clients,” tech leaders who would’ve otherwise received a pass would now be dropped at the first phase of the pitch process without clearly outlined ESG values. She also noted, “18 months ago, that probably wouldn’t have been that critical.”
The impact of creating clear sustainability goals and actions isn’t just about material concerns for our ecosystem anymore. When it comes to decision making on sustainability, it’s about defining and balancing both the hard and soft goals.
Similarly, the type of initiatives that James Maunder, CIO at the London Clinic, calls “quick wins”—such as turning off PCs and switching lights to LEDs—can help accelerate short-term goals. In the long-term view, the clinic is pushing to digitalize hospital paperwork to reduce waste.
Maunder suggested that the London Clinic needs thought leadership from organizations like Cisco to not only challenge their sustainability goals, but to inspire them toward meeting those goals. This is how technology leaders can affect real change across organizations.
Action and thought leadership need to be in place from the top down. As Clare Ward, Amazon’s Worldwide Technology Leader, Travel & Hospitality Solutions, explained, “leaders create more than they consume.” This mindset is precisely the kind that can go on to support more concrete goals and realize action plans.
Benjamin Jones, CTO at GFK, suggested that while it might not be the case that everyone is well-versed in all things sustainability, big impacts can be made by “individuals who will champion elements of it and promote those for colleagues.”
Promoting sustainability from the inside means understanding the wider sustainability ecosystem—who’s talking about it and how. Jon Townsend, Director of Technology and Information Security at National Trust, said he feels that everyone has a role to play in promoting sustainability. That means shifting the conversation to focus on the reality that no one person is responsible for achieving sustainability. Rather, it’s a holistic principle that everyone must consider at every turn.
Not all roles influence sustainability equally. If a CIO isn’t thinking about sustainability as part of their function, they’re “doing something wrong,” Townsend argued. C-suite leaders, unsurprisingly, are in the best position to influence sustainability initiatives.
More than that, they can make sure that the entire IT department is acting with sustainability in mind. Going even further, they can help customers understand the path to net-zero emissions.
The responsibility to monitor, plan, and educate both team members and customers starts at the top. This should be shared by senior leaders, who can then ensure the team at large is aware and aligned at every turn.
With more and more organizations requiring ESG initiative visibility as part of their partnership pitch process, ongoing education on sustainability has become another crucial piece of the puzzle. Education programs, like the one being rolled out by IPG Mediabrands, promote sustainability goals internally and demonstrate to clients and the industry at large that an organization has something relevant and impactful to add to global sustainability efforts.
In practice, internal education is the scaffolding that makes achieving sustainability goals possible. As Paul Coby, CIO of Persimmon Homes, pointed out, energy consumption by global data centers needs to be considered as organizations shift to cloud-based management models.
“It’s not an infinite resource you’re consuming,” Coby warned. Storing data unnecessarily creates waste. “In the same way that you wouldn’t waste food, don’t waste data,” Townsend said—a brilliant example of the kind of critical piece of education that technology leaders must embrace.
Just as technologies are ever changing, ESG initiatives will be forever ongoing. This means that understanding our role now as action-takers and educators has ripple effects that will continue into the next quarter, year, and decade.
Having visible and realistic ESG goals, robust internal education, accessible emissions metrics, and leadership with a passion for sustainability are ways we can make progress now. It’s not just about protecting the planet for the next generation of IT leaders—it’s about doing business better.
CIO/IT Leader Guide: Getting Started on Sustainability White Paper
"}]] Technology leaders discuss the evolving role of the CIO and the importance of finding innovative and sustainable solutions in today's technology-driven world. Read More Cisco Blogs
For today’s IT teams, managing distributed users, devices, applications, and workloads is not an easy task—especially when these disparate elements often connect across multiple infrastructures, as we… Read more on Cisco Blogs
[[{"value":"
For today’s IT teams, managing distributed users, devices, applications, and workloads is not an easy task—especially when these disparate elements often connect across multiple infrastructures, as well as across the IT stack. To overcome such complexity, organizations need to simplify their network operations, which can be achieved by taking a network platform approach, according to the IDC Analyst Connection, sponsored by Cisco, “How a Network Platform Approach Is Becoming an Imperative for IT and Business Agility.”
Many may think of a network platform as just the interface, portal, or dashboard used to manage a network, but it is so much more. According to the IDC Analyst Connection: “A network platform is an integrated system that combines hardware, software, policy, and open APIs with an intuitive user interface, advanced telemetry, and automation.”
A network platform’s foundation is based on integrated hardware and software that is designed to work together seamlessly. On top of that is a common policy structure that ensures consistent operations across the platform. Open APIs not only open the platform to third-party technical capabilities, but also enable quicker connection to adjacent platforms and increased automation.
An intuitive user interface is essential because it makes it easier to manage the network and gain end-to-end visibility, detailed analytics, and seamless control of the entire distributed network. Similar to end-to-end visibility, advanced telemetry gathers critical data and insight into performance and behavior of the network, which can then be augmented with artificial intelligence (AI) and machine learning (ML) to identify correlations where operational efficiencies can be increased. This also helps IT professionals set policies to reduce user-introduced errors and drive further automation.
Automation and AI are intrinsically intertwined with all the other elements of a network platform. According to the IDC Analyst Connection: “Visibility telemetry should be fed into an analytics engine that can quickly identify network performance or security problems and help with guided or automatic remediation. This advanced visibility and automation also creates rich data pools that can use open APIs to integrate with third-party IT and network management systems.”
According to our own research, AI is 60% faster at identifying misconfigurations and 50% faster at remediating them. Similarly, we found that AI can provide a 50% reduction in the time it takes to configure and deploy network resources. This all adds up to more efficient operations, cost savings, and improved security.
AI-driven automation can also help organizations address the IT skills gap by taking over some tasks that would otherwise require a level of IT specialization, while also freeing up IT staff to focus on more strategic responsibilities.
“A unified network platform allows AI for IT operations (AIOps) automation tasks to be applied to multiple parts of the network,” according to IDC. “This approach enhances network and IT staff efficiency by applying AI-enhanced closed-loop automation across a wider part of the network and reduces the manual burden of managing complex, distributed networks.”
Cisco platforms for networking align to the principles outlined by the IDC Analyst Connection. These solutions combine the elements of a physical and virtual infrastructure via unified management, policy, data, and APIs to build a more complete and consistent platform. They simplify complex tasks through AI-driven automation, streamline provisioning and budgeting, offload day-to-day tasks, and enable teams to deliver greater business impact by shifting IT from manual execution to strategic development. The consolidation of capabilities makes it easier to provide a more unified experience to end users.
Because the capabilities reside on a platform, it is easier to update those capabilities and ensure consistency and configuration compliance as future needs evolve. And with APIs, a platform can continue to expand, providing a conduit for more complete and creative solutions that can transform an enterprise. As customer needs evolve, investing in a platform will extend use cases, integrate new technologies, and solve emerging customer needs.
At Cisco, our goal is to simplify operations through platforms that are aligned to domains and will over time converge into our Cisco Networking Cloud vision. The Cisco Networking Cloud is the “north star” of Cisco platforms, with a goal of evolving from disparate systems to a solution that is consumed and managed as a unified entity.
We’ve made great strides in delivering network platform capabilities that can help organizations achieve operational simplicity, but there is more work still to be done. Stay tuned as we continue to evolve our network platform approach. In the meantime, watch our Simplify Network Operations with a Platform Approach webinar for a deeper dive into the topic, and be sure to check out our Transform Infrastructure page for more on the benefits of Cisco’s Networking Cloud vision.
"}]] Cisco’s goal is to enable simplified operations with a platform aligned to domains that over time will converge into a unified solution delivered via our Cisco Networking Cloud vision. Read More Cisco Blogs
Augmented reality (AR) has the potential to unlock a new level of interaction with the world around us. The Cisco Store has harnessed this technology by creating the Cisco Store Xplorer AR app.
When… Read more on Cisco Blogs
[[{"value":"
Augmented reality (AR) has the potential to unlock a new level of interaction with the world around us. The Cisco Store has harnessed this technology by creating the Cisco Store Xplorer AR app.
When the app is first opened, it detects whichever store is nearby: the SJC store, the RTP store, or the relevant travel store. The experience has the capability to be customized as well: upon entering the store, visitors can click a Welcome button to be shown a personalized message on the entry signage, powered by Wipro VisionEDGE.
Augmented reality app detects the presence of a nearby store
As visitors explore the store, they can point their phones at hotspots located throughout the store to learn more about Cisco’s retail solutions and partner technology (for instance, a Meraki camera on the ceiling). They are given the option to read the product specifications or see what the camera dashboard is capturing in real-time.
Scanning a hotspot through the app
The Cisco Store Xplorer can increase the operational and data-collecting efficiency of the store. The app is integrated with Meraki API to allow staff to see data from Meraki sensors without needing to access a dashboard; for instance, it gives quick visibility into air quality metrics picked up by the MT15. Furthermore, the app is integrated with VusionGroup’s electronic shelf labels: a staff member only needs to enter a product’s ID into the app and the corresponding shelf label will blink, allowing staff members to easily locate the item. Applying this technology to retail environments will allow for a much smoother shopping experience.
The possibilities for improved efficiency are limitless with the Cisco Store Xplorer app. Moving forward, visitors can even see and interact with the technology hotspots using the upcoming Apple Vision Pro.
The Cisco Store Xplorer is now available on both the App Store and Google Play. Come visit the Cisco Store Tech Lab to see it in action!
"}]] Experiencing the Cisco Store on a more interactive level with the Cisco Store Xplorer augmented reality app. Read More Cisco Blogs
Most days of the week, you can expect to see AI- and/or sustainability-related headlines in every major technology outlet. But finding a solution that is future ready with capacity, scale and… Read more on Cisco Blogs
[[{"value":"
Most days of the week, you can expect to see AI- and/or sustainability-related headlines in every major technology outlet. But finding a solution that is future ready with capacity, scale and flexibility needed for generative AI requirements and with sustainability in mind, well that’s scarce.
Cisco is evaluating the intersection of just that – sustainability and technology – to create a more sustainable AI infrastructure that addresses the implications of what generative AI will do to the amount of compute needed in our future world. Expanding on the challenges and opportunities in today’s AI/ML data center infrastructure, advancements in this area can be at odds with goals related to energy consumption and greenhouse gas (GHG) emissions.
Addressing this challenge entails an examination of multiple factors, including performance, power, cooling, space, and the impact on network infrastructure. There’s a lot to consider. The following list lays out some important issues and opportunities related to AI data center environments designed with sustainability in mind:
Performance Challenges: The use of Graphics Processing Units (GPUs) is essential for AI/ML training and inference, but it can pose challenges for data center IT infrastructure from power and cooling perspectives. As AI workloads require increasingly powerful GPUs, data centers often struggle to keep up with the demand for high-performance computing resources. Data center managers and developers, therefore, benefit from strategic deployment of GPUs to optimize their use and energy efficiency.
Power Constraints: AI/ML infrastructure is constrained primarily by compute and memory limits. The network plays a crucial role in connecting multiple processing elements, often sharding compute functions across various nodes. This places significant demands on power capacity and efficiency. Meeting stringent latency and throughput requirements while minimizing energy consumption is a complex task requiring innovative solutions.
Cooling Dilemma: Cooling is another critical aspect of managing energy consumption in AI/ML implementations. Traditional air-cooling methods can be inadequate in AI/ML data center deployments, and they can also be environmentally burdensome. Liquid cooling solutions offer a more efficient alternative, but they require careful integration into data center infrastructure. Liquid cooling reduces energy consumption as compared to the amount of energy required using forced air cooling of data centers.
Space Efficiency: As the demand for AI/ML compute resources continues to grow, there is a need for data center infrastructure that is both high-density and compact in its form factor. Designing with these considerations in mind can improve efficient space utilization and high throughput. Deploying infrastructure that maximizes cross-sectional link utilization across both compute and networking components is a particularly important consideration.
Investment Trends: Looking at broader industry trends, research from IDC predicts substantial growth in spending on AI software, hardware, and services. The projection indicates that this spending will reach $300 billion in 2026, a considerable increase from a projected $154 billion for the current year. This surge in AI investments has direct implications for data center operations, particularly in terms of accommodating the increased computational demands and aligning with ESG goals.
Network Implications: Ethernet is currently the dominant underpinning for AI for the majority of use cases that require cost economics, scale and ease of support. According to the Dell’Oro Group, by 2027, as much as 20% of all data center switch ports will be allocated to AI servers. This highlights the growing significance of AI workloads in data center networking. Furthermore, the challenge of integrating small form factor GPUs into data center infrastructure is a noteworthy concern from both a power and cooling perspective. It may require substantial modifications, such as the adoption of liquid cooling solutions and adjustments to power capacity.
Adopter Strategies: Early adopters of next-gen AI technologies have recognized that accommodating high-density AI workloads often necessitates the use of multisite or micro data centers. These smaller-scale data centers are designed to handle the intensive computational demands of AI applications. However, this approach places additional pressure on the network infrastructure, which must be high-performing and resilient to support the distributed nature of these data center deployments.
As a leader in designing and supplying the infrastructure for internet connectivity that carries the world’s internet traffic, Cisco is focused on accelerating the growth of AI and ML in data centers with efficient energy consumption, cooling, performance, and space efficiency in mind.
These challenges are intertwined with the growing investments in AI technologies and the implications for data center operations. Addressing sustainability goals while delivering the necessary computational capabilities for AI workloads requires innovative solutions, such as liquid cooling, and a strategic approach to network infrastructure.
The new Cisco AI Readiness Index shows that 97% of companies say the urgency to deploy AI-powered technologies has increased. To address the near-term demands, innovative solutions must address key themes — density, power, cooling, networking, compute, and acceleration/offload challenges. Please visit our website to learn more about Cisco Data Center Networking Solutions.
We want to start a conversation with you about the development of resilient and more sustainable AI-centric data center environments – wherever you are on your sustainability journey. What are your biggest concerns and challenges for readiness to improve sustainability for AI data center solutions?
"}]] Cisco is evaluating the intersection of sustainability and technology to create a more sustainable AI infrastructure that addresses the implications of what generative AI will do to the amount of compute needed in the future. Read More Cisco Blogs
In 2024, measurable commitments to sustainability have become table s… Read more on Cisco Blogs
[[{"value":"
In 2024, measurable commitments to sustainability have become table stakes for every business. According to Net Zero Tracker, although more companies than ever are committing to net zero targets, only a small percentage of these meet the United Nations (UN) criteria for reaching the goal.
The UN Race to Zero campaign, which set out revised ‘Starting Line criteria’ in June 2022, asks members to implement immediate emission-cutting measures, set a specific net zero target, include coverage of all greenhouse gases (all emission scopes for companies), apply clear conditions for the use of offsets, publish a plan, and provide annual progress reporting on both interim and longer-term targets.
At the recent COP28 climate summit, almost 200 countries reached a historic consensus and agreed to reduce global consumption of fossil fuels to avert the worst effects of climate change. Effectively hailed as the end of oil, the agreement tasks countries to triple renewable energy capacity globally by 2030, speeding up efforts to reduce coal use and accelerating technologies such as carbon capture and storage that can clean up hard-to-decarbonize industries.
However, even with these commitments and technological innovations, energy consumption is expected to rise with the explosive adoption of artificial intelligence (AI). Considered more energy-intensive than other forms of computing, large language models (LLMs) require multiple Graphics Processing Units (GPUs). A single GPU can consume between 250 and 300 watts of power per hour when training an LLM, which requires hundreds of GPUs working together for several days and running without interruption.
For instance, the Megatron-LM, Nvidia’s highly optimized and efficient library for training large language models, used 512 GPUs running for nine days to train its final version, equating to roughly 27,648-kilowatt hours. According to the U.S. Energy Information Administration, a typical American household purchased 10,791 kilowatt hours of energy yearly as of 2022. That means the training of Megatron-LM’s final version used nearly the same amount of energy as two-and-a-half homes annually.
The computing power required to classify, analyze, and respond to AI queries is also exceptionally high, resulting in significant system costs, inefficiencies, and greenhouse gas emissions. This is particularly true for LLMs, such as ChatGPT, which alone has been reported to cost millions of dollars daily to run.
Unlike previous computing booms, training and running LLMs involves a structural cost that remains even after the software has been built or initially trained. Given the billions of calculations required to generate a response to a prompt, these models require massive computing power to run which is much higher than serving web-based applications or pages.
There is a growing demand for higher-performing and less expensive inference AI solutions that can reduce AI’s overall carbon footprint. By creating and putting these higher-efficiency, lower-power solutions into use, we can sustainably address the current and future needs of generative AI and other AI-driven solutions, including fraud detection, translation services, chatbots, and many other current use cases, as well as those yet to be created.
While inference AI currently accounts for a small percentage of overall energy use, it is growing in popularity to support energy-hungry generative AI apps. Organizations driving adoption and using AI are under pressure to measure and publish data on energy use and sources. Creating and employing a more energy-efficient infrastructure, optimizing models, and implementing software tools and algorithms that track and reduce computational workload during the inference process are critical.
Enterprises employing AI solutions today with current infrastructure can also be more energy efficient by using smaller, more specific models that are purpose-built for specific use cases.
In her annual predictions on coming technology trends for the year ahead, Liz Centoni, Cisco Chief Strategy Officer and GM of Applications, offered insight. “Smaller AI models with fewer layers and filters that are domain-specific account for less energy consumption and costs than general systems.”
“These dedicated systems are trained on smaller, highly accurate data sets and efficiently accomplish specific tasks. In contrast, deep learning models require processing vast amounts of data to achieve results,” she explained.
Smart energy management is also a crucial component to address climate change. According to the Natural Resources Defense Council’s recent Clean Energy Now for a Safer Climate Future: Pathways to Net Zero in the United States by 2050 report, by combining electrification with energy efficiency upgrades, it is possible to reduce building-related fossil fuel consumption and its associated emissions by over 90 percent when compared to current levels.
Among its many promising applications, we see AI unlocking a new era of energy networking and efficiency models. Using advances in energy networking and improved energy efficiency, we can significantly reduce the world’s energy needs by 2050 – and along the way we will be better able to control global emissions of greenhouse gases.
The fast-emerging category of energy networking, which combines software-defined networking capabilities and an electric power system made up of direct current (DC) micro grids, will also contribute to energy efficiency, delivering increased visibility, insights, and automation.
Power over Ethernet, a method to deliver DC power to devices over copper ethernet cabling, eliminates the need for separate power supplies and outlets. A low-voltage solution, it also reduces energy costs by allowing centralized control over lighting, video cameras and monitors, window shades, and heating and cooling, among many other devices found in buildings and homes.
By applying networking to power and connecting it with data, energy networking and Power over Ethernet can provide comprehensive visibility and benchmarking of existing emissions and an access point to optimize power usage, distribution, transmission, and storage, as well as measurement and reporting.
Centoni said these methods will make measuring energy usage and emissions more accurate, automating many functions across IT, smart buildings, and IoT sensors, and unlock inefficient and unused energy:
Together, these solutions will be a catalyst for vast new AI-powered capabilities without imposing an unsustainable toll on the environment. They can also enable better energy management and storage, allowing companies to meet their increasing energy consumption and sustainability goals.
With AI as both catalyst and canvas for innovation, this is one of a series of blogs exploring Cisco EVP, Chief Strategy Officer, and GM of Applications Liz Centoni’s tech predictions for 2024. Her complete tech trend predictions can be found in The Year of AI Readiness, Adoption and Tech Integration ebook.
"}]] You can’t greenwash AI. In 2024, organizations will have greater clarity and insights into achieving sustainability outcomes. Read More Cisco Blogs
Everyone loves the movies. But whether we go out or stay in, we’re relying on countless, mostly invisible pieces of technology that create and coordinate our every experience. The theater complex w… Read more on Cisco Blogs
[[{"value":"
Everyone loves the movies. But whether we go out or stay in, we’re relying on countless, mostly invisible pieces of technology that create and coordinate our every experience. The theater complex where you saw Oppenheimer and Barbie (maybe in one day) this past year? Lights, temperature control and air circulation, complex systems for optimal screen resolution and surround sound in a dozen or so small theaters—not to mention making sure that the hot dogs, popcorn, and sodas are to our liking.
We consumers put extremely high demands on companies to provide just the right experiences, hour after hour and day after day. Which means that those companies—Cisco’s customers and partners—face increasing pressure to provide complex, delightful, differentiated experiences, all while remaining flexible and increasing profits.
They simply can’t do it alone. The demands are too complex, the costs of doing business too high, the pace of change too fast. But we CAN do it together—we’re greater together! Partnerships are the way to do business because they’re the best way to create the experiences—outcomes—that consumers want so badly.
And we’re already doing it. Last year, 82% of Cisco partners said they are growing their managed services, and 95% of Cisco’s managed services were sold through partners.
In EMEA, where Cisco Live happens next week, we have a $42B managed services opportunity and projected double-digit growth in the complex areas of security, observability, and Datacenter. In one example, a European auto and truck manufacturer established an agile, centralized IT environment, with managed hybrid cloud and security, which enabled staff to prioritize innovation, streamline secure network access, and meet sustainability goals. The result? A 60% reduction in energy consumption.
With partnerships firmly established, let’s talk about what they mean on a granular, practical level. Exactly how does a partner make this shift to the new ecosystem? We need a model, a blueprint, a vocabulary to help them build their services, identify where they can specialize, and determine where they can be profitable. We need to connect the dots.
Let’s go back for a moment to the movie theater. It’s worth-leaving-the-house-for, multi-sensory outcome is the result of multiple technologies, multiple partners, whose services are stitched together in complex configurations. That stitched-together set of services is an “outcome chain.” It’s an evolution of the traditional “value chain” which involved consecutive steps in providing services, and it’s a more detailed, more accurate rendering of a service stack.
The outcome chain gives us a way to talk about who does what—identifying roles and specializations—and allows for the flexibility and composability required to create outcomes.
But it can be hard to conceptualize. These analogies may help.
We can think of the outcome chain as a bit like DNA: structured yet flexible, multi-faceted and built for change. A close look reveals the beautiful double helix complexity: parallel, twisting strands like rails of a spiral staircase, held together by pairs of nucleotides that look like stair steps. The flexible structure is what allows DNA to do the work of life as it does, unwinding, opening, replicating, transcribing, closing again, over and over and over. Form is function.
The game of Dominoes offers another good analogy. This classic game has a few basic rules, so patterns and connections exist between the dominoes—the structure as it spreads across the table is not random. Yet instead of just one straight line of tiles, each game generates a range of different lines feeding into each other, with a range of points of entry depending on specific rules and relationships.
Neither DNA nor Dominoes are 100% handcrafted, bespoke patterns—those just aren’t scalable. Similarly, the outcome chain is a model that sits right in the sweet spot: flexible enough to accommodate the shifting nature of partner relationships in outcome creation, yet structured enough for clarity, efficiency, scalability and repeatability.
It clarifies how all the pieces come together in composing an outcome. In other words, it reveals who can do what. Partners are increasingly moving towards specialization, taking on specific roles or pieces of the outcome. Other partners may become orchestrators who tie all the pieces together and take on some of the delivery. The outcome chain, with its bird’s eye view, helps partners identify which part they want to take on, and how their part connects to others.
Yet these very choices can feel overwhelming. It’s like opening a menu in a new restaurant and seeing long lists of tempting dishes: you may need some guidance. When you divide that menu into parts (appetizers, salads, entrees, and desserts), it’s suddenly much easier to find what you want.
The equivalent of that diner-friendly menu? The EDGE framework—a Deloitte and Cisco whitepaper. It’s a way of simplifying the various structures of outcome chains by identifying four basic functions or stages, so partners can more easily identify which stage of the outcome chain is their best fit. Here are those EDGE stages:
Explore. The customer’s objectives get clarified; discovery, strategy and modeling follow.
Design. The conceptualization stage, where different versions of an offer’s concept and architecture are developed.
Guide. This is about deployment and operation: solution rollout, installation and integration.
Experience. Support and maintenance of the solutions, with adjustments and improvements made as needed.
Each of these stages can naturally be broken down into a range of more detailed service segments and levels of sophistication. Each stage and segment calls for different strengths, strategies and resources, and each yields different profit margins on different timelines. The point is, among all this complexity and flexibility, EDGE offers a structure that helps partners identify their best fit in the outcome chain.
The partnership ecosystem is an exciting but complex world! The outcome chain model and the EDGE framework give partners the tools to navigate this rich ecosystem with clarity, efficiency, and sustainability. Almost as easy as going to the movies…. or to Cisco Live EMEA in Amsterdam. I’m looking forward to seeing all our partners there and talking more about where they fit into the outcome chain.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!
Cisco Partners Facebook | @CiscoPartners X/Twitter | Cisco Partners LinkedIn
"}]] Consumers put extremely high demands on companies to provide just the right experiences. Which means that Cisco’s customers and partners face increasing pressure to provide complex, delightful, differentiated experiences, all while remaining flexible and increasing profits. Read More Cisco Blogs
Most days of the week, you can expect to see AI- and/or sustainability-related headlines in every major technology outlet. But finding a solution that is future ready with capacity, scale and… Read more on Cisco Blogs
[[{"value":"
Most days of the week, you can expect to see AI- and/or sustainability-related headlines in every major technology outlet. But finding a solution that is future ready with capacity, scale and flexibility needed for generative AI requirements and with sustainability in mind, well that’s scarce.
Cisco is evaluating the intersection of just that – sustainability and technology – to create a more sustainable AI infrastructure that addresses the implications of what generative AI will do to the amount of compute needed in our future world. Expanding on the challenges and opportunities in today’s AI/ML data center infrastructure, advancements in this area can be at odds with goals related to energy consumption and greenhouse gas (GHG) emissions.
Addressing this challenge entails an examination of multiple factors, including performance, power, cooling, space, and the impact on network infrastructure. There’s a lot to consider. The following list lays out some important issues and opportunities related to AI data center environments designed with sustainability in mind:
Performance Challenges: The use of Graphics Processing Units (GPUs) is essential for AI/ML training and inference, but it can pose challenges for data center IT infrastructure from power and cooling perspectives. As AI workloads require increasingly powerful GPUs, data centers often struggle to keep up with the demand for high-performance computing resources. Data center managers and developers, therefore, benefit from strategic deployment of GPUs to optimize their use and energy efficiency.
Power Constraints: AI/ML infrastructure is constrained primarily by compute and memory limits. The network plays a crucial role in connecting multiple processing elements, often sharding compute functions across various nodes. This places significant demands on power capacity and efficiency. Meeting stringent latency and throughput requirements while minimizing energy consumption is a complex task requiring innovative solutions.
Cooling Dilemma: Cooling is another critical aspect of managing energy consumption in AI/ML implementations. Traditional air-cooling methods can be inadequate in AI/ML data center deployments, and they can also be environmentally burdensome. Liquid cooling solutions offer a more efficient alternative, but they require careful integration into data center infrastructure. Liquid cooling reduces energy consumption as compared to the amount of energy required using forced air cooling of data centers.
Space Efficiency: As the demand for AI/ML compute resources continues to grow, there is a need for data center infrastructure that is both high-density and compact in its form factor. Designing with these considerations in mind can improve efficient space utilization and high throughput. Deploying infrastructure that maximizes cross-sectional link utilization across both compute and networking components is a particularly important consideration.
Investment Trends: Looking at broader industry trends, research from IDC predicts substantial growth in spending on AI software, hardware, and services. The projection indicates that this spending will reach $300 billion in 2026, a considerable increase from a projected $154 billion for the current year. This surge in AI investments has direct implications for data center operations, particularly in terms of accommodating the increased computational demands and aligning with ESG goals.
Network Implications: Ethernet is currently the dominant underpinning for AI for the majority of use cases that require cost economics, scale and ease of support. According to the Dell’Oro Group, by 2027, as much as 20% of all data center switch ports will be allocated to AI servers. This highlights the growing significance of AI workloads in data center networking. Furthermore, the challenge of integrating small form factor GPUs into data center infrastructure is a noteworthy concern from both a power and cooling perspective. It may require substantial modifications, such as the adoption of liquid cooling solutions and adjustments to power capacity.
Adopter Strategies: Early adopters of next-gen AI technologies have recognized that accommodating high-density AI workloads often necessitates the use of multisite or micro data centers. These smaller-scale data centers are designed to handle the intensive computational demands of AI applications. However, this approach places additional pressure on the network infrastructure, which must be high-performing and resilient to support the distributed nature of these data center deployments.
As a leader in designing and supplying the infrastructure for internet connectivity that carries the world’s internet traffic, Cisco is focused on accelerating the growth of AI and ML in data centers with efficient energy consumption, cooling, performance, and space efficiency in mind.
These challenges are intertwined with the growing investments in AI technologies and the implications for data center operations. Addressing sustainability goals while delivering the necessary computational capabilities for AI workloads requires innovative solutions, such as liquid cooling, and a strategic approach to network infrastructure.
The new Cisco AI Readiness Index shows that 97% of companies say the urgency to deploy AI-powered technologies has increased. To address the near-term demands, innovative solutions must address key themes — density, power, cooling, networking, compute, and acceleration/offload challenges. Please visit our website to learn more about Cisco Data Center Networking Solutions.
We want to start a conversation with you about the development of resilient and more sustainable AI-centric data center environments – wherever you are on your sustainability journey. What are your biggest concerns and challenges for readiness to improve sustainability for AI data center solutions?
"}]] Cisco is evaluating the intersection of sustainability and technology to create a more sustainable AI infrastructure that addresses the implications of what generative AI will do to the amount of compute needed in the future. Read More Cisco Blogs
Major data breaches are on the rise, and APIs are increasingly being used to gain access to sensitive data. The reasons for this are twofold: APIs are the first line of defense into an application… Read more on Cisco Blogs
[[{"value":"
Major data breaches are on the rise, and APIs are increasingly being used to gain access to sensitive data. The reasons for this are twofold: APIs are the first line of defense into an application (and it’s data), and more and more applications are accessible via the cloud and APIs. Everything from non-critical functionality, like music streaming and social media, to extremely critical data, such as financial accounts and healthcare, is accessible 24×7 through APIs.
Why is it so desirable to breach API security? There are many nefarious reasons, but here are just a few:
Stealing Personally Identifiable Information (PII) and selling it on the dark web or for identity theft
For asset theft, extortion or ransom
Causing application instability or unavailability
Espionage (corporate or political)
Election interference
Political instability
The list goes on. The availability of data and the dangers of breaches make it critical to get API security right.
Each year, the Open Worldwide Application Security Project (OWASP) comes up with a list of the Top 10 API Security Risks. We’ll take a quick look at the current list, with examples of data breaches caused by each type of risk.
After that, we’ll talk about the API pipeline and ways to prevent common API security issues across the pipeline.
Let’s take a look at the OWASP Top 10 API Security Risks, ranked in order of prevalence (from highest to lowest).
In a BOLA attack, object IDs for application data are leaked in API responses and used to gain unauthorized access to sensitive data.
The large Twitter (now X) API breach was a BOLA attack, where an API that could be used to find users ended up leaking PII.
With broken authentication, an attacker compromises weak authentication methods and gains access to an application (and ultimately, data).
Many security breaches are caused by broken authentication.
This is similar to BOLA, where an attacker is able to gain unauthorized access to data.
In this scenario, the attacker is able to get unrestricted access to an application and its resources. This type of attack can cause application instability or even outages. If large amounts of application resources are consumed without restriction, the result could be very costly (e.g. paid-tier cloud resources)
An example of this would be a Denial of Service (or DoS) attack, where an application is so overwhelmed with traffic, it can no longer function.
With BFLA, unauthorized access to application functionality is allowed. This includes authorization issues between microservices.
An insurance company was the victim of a BFLA attack due to customer data being available to the public via a “protected part” of the application.
This threat involves vulnerability to automated abuse of application transactions, for example ticket sales or thread comments. For example, “Bad bots” could be used to overwhelm an application and circumvent security.
This happened with the Taylor Swift concert ticket snafu in November 2022. Scalper bots were used to buy limited release tickets for verified fans, which were then sold at a huge profit.
Also known as “URL spoofing”, this involves a server using an input URL to a remote resource without validating the given URL, which could allow attackers to get around a VPN or firewall and potentially gain access to sensitive data. The attacker uses the server to make the request appear legitimate.
The huge Capital One data breach in 2019 was an SSRF attack, and resulted in PII for 100 million credit card holders to be stolen. More recently, a class action lawsuit was filed.
Any weak or misconfigured security in an application opens attack surfaces.
In May 2023, Toyota revealed a big data breach due to insufficient cloud configurations.
Improper API inventory management includes undocumented (shadow) APIs, deprecated (zombie) APIs and unauthorized (rogue) APIs.
Shadow and zombie APIs are risks because they may not have sufficient security scrutiny. A rogue API can mean the same thing as a shadow API, but it can also be the result of malicious code injection opening up a backdoor into an application.
Weak security in 3rd party APIs used by an application can allow access to data.
An example of this threat is an insecure AWS S3 bucket with access to data, which seems to be responsible for many recent data leaks. Even if the application which hosts the data is very secure, the data could still be accessible through S3 APIs.
We hear about “pipelines” and “moving towards the left” all the time in software development. But what do these concepts mean in the context of APIs?
The API pipeline spans the entire API lifecycle, from initial development (“on the left”) to deployment into production (“on the right”). This is illustrated below.
Let’s discuss the various stages of the API pipeline.
APIs are born in development, ideally by first crafting an OpenAPI specification (OAS spec) to formalize the API, specify parameters, identify possible return parameters and codes, etc.
Many developers use Integrated Development Environments (IDEs) to organize the environment, such as VSCode (open source), PyCharm (community and paid-tier) or GoLand (paid-tier).
Depending on the IDE, there may be extensions to help as you write your OAS specs. For example, VSCode has several OAS spec linter extensions that can statically flag issues with the spec, such as Spectral (open source), and Postman (free and paid-tier). The Spectral extension even has an OWASP Top 10 API Security Risks ruleset. Panoptica (free trial and paid-tier) can run different OAS spec linters from the command line.
AI copilots are all the rage now, and can be used to develop the API client/server code. Popular AI copilots include GitHub Copilot (paid-tier) and others.
Note that not all API security issues can be detected statically. Many issues can only be detected in a dynamic environment, where API calls are actually being acted upon.
After the API code is finished, it is ready for unit testing.
Once development is complete, the API code undergoes unit testing, where “mock” API calls are made to verify that the APIs are behaving correctly. A unit test environment is still static because, although calls can be made to client and server functions, the application isn’t running as a whole.
There are many tools to auto-generate mock API code and run mock API servers, including WireMock (open source), Mockoon (open source), Microcks (open source), Postman (free and paid-tier), RestAssured (open source) and SoapUI (open source).
Once unit tests are written and passing, the API code is ready for CI/CD.
In CI/CD, the code is submitted for code review, the image is built and some gating tests are run automagically. The gating tests include static tests, such as unit tests and OAS spec linters, and dynamic tests like end-to-end functional tests, where the code is actually installed and basic functionality can be tested in an automated way.
If the CI/CD tests all pass, the code is ready to be merged into the code repository and tested in staging.
A staging environment is similar to an actual production environment, but is isolated for internal testing. In staging, the application is installed and a quality assurance team can verify the functionality.
High availability and performance tests can also be run in staging. High availability testing involves verifying that no single points of failure exist in your application. Performance testing verifies that your application performs at scale, which includes a high volume of API traffic.
Tools for API performance and load testing include Locust (open source), SoapUI and Postman.
Another type of tool that is helpful during staging is a fuzzer. A fuzzer passes bad data into API endpoints in your application and tries to negatively affect the application (e.g. make it stop responding, make it crash, leak data, etc.). Examples of fuzz testing tools are RESTler (open source) and Panoptica.
The first time an application is deployed to production, it’s called a “greenfield deployment.” In greenfield, since there are no existing artifacts, there aren’t any versioning or upgrade concerns.
In a production environment, you can dynamically scan real-time API traffic for security risks to protect your application. The Panoptica CNAPP platform has a full suite of API security functionality, which we’ll discuss below.
Brownfield deployment is when the application is upgraded in an existing production environment.
With brownfield, things like API backwards compatibility and versioning come into play. For example, API clients could continue to use a prior OAS spec version after the application has been upgraded with a new one. Multiple API versions must be supported.
A canary deployment is a brownfield deployment where different versions of the application are running simultaneously in order to reduce risk with a new version. The canary deployment manages only a subset of the total API traffic. Here again, API backwards compatibility and versioning are important considerations.
Now that we’ve talked about the OWASP Top 10 API Security risks and the full API pipeline, let’s take a look at some common API security issues and how to prevent them across the pipeline.
BOLAs were the most prevalent kind of API security issue in 2023, according to OWASP. They are included in issues API1:2023 (Broken Object Level Authorization) and API3:2023 (Broken Object Property Level Authorization).
As previously mentioned, in a BOLA attack, an end user is able to access data that they don’t have the authorization to access, usually because metadata is leaked in API responses from the application.
Since data, especially PII, is a major target of breaches, any unauthorized access is a huge security problem.
How can BOLAs be prevented across the API pipeline?
During development, make sure you have a strong authorization model in your application that doesn’t allow access to data without authorization, and make sure no data is leaked in API responses.
In development and CI/CD, use OAS spec linters (discussed earlier) to flag potential authorization issues.
During unit testing and CI/CD, run mock API traffic that tries to access data without authorization.
In CI/CD and staging, run a fuzzer against your API endpoints that will send bad input into the APIs and flag any unexpected access to data.
In staging and production, run dynamic API security tools to inspect API traffic and flag potential BOLA issues. Panoptica has BOLA detection capabilities.
BFLAs occur when application functionality is accessed without the proper authorization, either by an end user calling into the application or between application microservices. BOLA (above) is about accessing data, BFLA is about accessing functionality. Gaining unauthorized access to functionality can ultimately lead to data breaches. BFLAs are OWASP issue API5:2023 (Broken Function Level Authorization).
How can BFLAs be prevented across the API pipeline?
During development, make sure you have a strong authorization model for accessing application functionality from end users and between microservices.
In unit testing and CI/CD, run mock API traffic that tries to access application functionality without authorization.
In staging and production, run dynamic API security tools to inspect API traffic and flag potential BFLA issues. Panoptica has the ability to learn the BFLA authorization model and then detect any potential violations in real-time traffic.
Weak authentication into an application is easier for an attacker to compromise. It could give threat actors access to user accounts and data. Weak (or broken) authentication is included in OWASP issues API2:2023 (Broken Authentication) and API8:2023 (Security Misconfiguration).
One form of this is basic authentication, which requires a username and password, where the password itself is “weak.” This includes short passwords, passwords that are too common (e.g. can be found in a dictionary search), or passwords that are reused across accounts.
Weak authentication can also be due to weak endpoint security, for example using HTTP instead of HTTPs.
Finally, encryption issues fall into this category. Having endpoints with no encryption or weak encryption can open attack surfaces into your application. If there isn’t any encryption, all API traffic is “in the clear” meaning it can be tapped and easily read. Weak encryption could involve shorter encryption keys that can be easily compromised.
How can weak authentication be prevented across the API pipeline?
Develop secure endpoints (e.g. HTTPs) with strong encryption enabled.
For basic auth, require strong passwords and multi-factor authentication (MFA).
In development and CI/CD, use OAS spec linters (particularly with the OWASP Top 10 ruleset) to flag insecure endpoint issues.
In unit testing and CI/CD, run mock API traffic that uses weak authentication and tries to gain access.
In staging and production, run dynamic API security tools to flag weak authentication in real-time API traffic. Panoptica can detect many forms of weak authentication.
OWASP issue API9:2023 (Improper Inventory Management) includes shadow APIs. Shadow APIs are not documented in an OAS spec. They are a security risk you may not even know you have.
As your application evolves, it’s unlikely that the security of shadow APIs will also evolve. They may even be forgotten entirely, exposing an ongoing security loophole or backdoor into your application.
How can shadow APIs be prevented across the API pipeline?
During development, make sure to take an inventory of all APIs and document each of them in an OAS spec.
In staging and production, run dynamic API security tools that can detect shadow APIs in real-time traffic and reconstruct an OAS spec for them to document them properly. Panoptica has these capabilities.
OWASP issue API9:2023 (Improper Inventory Management) also includes zombie APIs. Zombies APIs are APIs that are deprecated in the OAS spec but are still active within the application. They occur in brownfield and canary production environments, where multiple API versions may be in use. Like shadow APIs, zombie APIs are unlikely to evolve with your application and could receive less scrutiny from a security standpoint, thus leaving a backdoor into your application.
How can zombie APIs be prevented across the API pipeline?
Remove support for zombie (deprecated) APIs as soon as possible.
In staging and production, run dynamic API security tools that can detect zombie APIs in real-time traffic, such as Panoptica.
Even if your application data access is really secure, weak 3rd party authentication could still expose your data to threats. 3rd party access to your data includes databases, S3 buckets, etc. Weak 3rd party authentication is included in OWASP issues API8:2023 (Security Misconfiguration) and API10:2023 (Unsafe Consumption of APIs).
How can weak 3rd party authentication be prevented across the API pipeline?
During development, keep an inventory of all 3rd party APIs and services that are being used by your application.
Verify that 3rd party access is secure.
In CI/CD and staging, use a tool to assess the security of 3rd party API calls. The Panoptica CLI has this functionality.
In staging and production, use cloud security scanners to detect weak 3rd party authentication. Examples of cloud security scanning tools are AWS Config (paid service), Azure Automation and Control (free and paid-tier), GCP Cloud Asset Inventory (free) and CloudQuery (open source and paid-tier).
Unrestricted resource consumption is OWASP issue API4:2023. If an application is inundated with many API calls within a short period of time, it can have negative consequences. For example, application resources such as CPU, RAM and storage can be rapidly consumed or exhausted, leading to potentially higher operational costs, slower response time or even application failure and outages.
How can unrestricted resource consumption be prevented across the API pipeline?
During development, add rate-limiting to the API processing in your application, including a maximum rate of API requests and a reasonable timeout.
In staging, use performance testing that exceeds the allowed rate of API requests and verifies that the application is still functioning as expected.
In staging and production, use an API gateway in front of your application to throttle and rate-limit API requests. Some popular API gateways are AWS API Gateway (free and paid-tier), GCP API Gateway (free and paid-tier), Kong (open source and paid-tier), Tyk (open source) and Azure API Management (free and paid-tier). Note that the application still needs it’s own rate-limiting functionality when using an API gateway.
OWASP issue API6:2023 (Unrestricted Access to Sensitive Business Flows) is related to unrestricted resource consumption, but it implies that automation, bad bots or AI are involved in the API abuse, compounding the resource consumption.
With a URL spoofing attack, an invalid or malicious URL is passed into an API request, and the server proxies the URL without validating it. The suspicious URL could be a fake site or a webhook. This could allow access to sensitive data and PII. This type of vulnerability is covered in OWASP issue API7:2023 (Server Side Request Forgery).
How can URL spoofing be prevented across the API pipeline? Defending against this type of attack can be complex. This is a good resource to get started. The high-level gist of prevention measures is:
During development, perform validation on the given URL, including the IP address and domain name (see above resource link).
Create a list of allowed URLs, if possible, and validate the given URL against the list (see above resource link).
In unit testing and CI/CD, run mock API traffic that attempts to pass an invalid URL into the API.
Data injection can allow threat actors to pass malicious data, configurations or programs into an application via APIs. This could allow access to data (e.g. BOLA) or make an application unstable.
How can data injection be prevented across the API pipeline?
During development, include strict type checking (i.e. check for correct type of data in a request, don’t allow unexpected data types) and input validation in API processing.
Establish an upper limit on size and quantity of data that can be input in a request. For example, have a maximum size for a string input.
In development and CI/CD, use OAS spec linters to detect issues with data input.
In unit testing and CI/CD, run mock API traffic that tries to inject invalid data.
In CI/CD and staging, run a fuzzer against your API endpoints that sends invalid or malformed data into your API. The Panoptica CLI includes fuzzing capabilities.
In staging and production, run dynamic API security tools that can compare API traffic against the OAS spec and flag data discrepancies (including spec drift). The Panoptica CNAPP platform has this functionality.
Code injection is where undesirable code is added to an application. As IDE plugins and AI copilots are increasingly used to generate API client and server code, there’s a risk that “bad” code could be injected into your application. This could have unintended or even malicious side effects. For example, a rogue (malicious) API could be injected into your application creating backdoor access. Rogue APIs fall under OWASP issue API9:2023 (Improper Inventory Management).
How can code injection be prevented across the API pipeline?
During development, it’s important to verify any generated code with thorough code reviews.
In CI/CD, staging and production, image scans can search for any Common Vulnerabilities and Exposures (CVEs) in the application. Panoptica can scan both Kubernetes container images and virtual machine images for issues.
In staging and production, run dynamic API security tools to scan for any rogue APIs. Panoptica has this capability.
From the OWASP Top 10 API Security Risks, through the API pipeline and on to common API security issues and how to prevent them, we’ve covered a lot of ground, with lots of tool suggestions along the way.
Wishing you and your applications the very best in API security!
"}]] Everything is accessible 24x7 through APIs - from non-critical functionality (music streaming and social media) to extremely critical data (financial accounts and healthcare profiles). Here are some ideas to make APIs your first line of defense for an application (and it's data). Read More Cisco Blogs