The shift of business applications and on-premises infrastructure to the cloud has resulted in cloud security teams needing to manage the cyber security risks across the workloads, cloud services, resources, users, and applications. Today, security teams must deal with a set of siloed acronym-driven point solutions, providing a fragmented view of the risk with no context and no remediation, leaving cloud applications vulnerable to attacks and increasing security costs & complexities. Enterprise customers are increasingly telling us that they need a unified and cloud-native approach to security across the cloud application lifecycle, helping them continuously assess, prioritize, and reduce risk across a multi-cloud environment.Today we are excited to announce – Qualys TotalCloud solution with FlexScan that helps our customers extend the trusted power and accuracy of Qualys VMDR, augmented with flexible agent-based and agent-less cloud-native assessment to simplify the management of cloud-native security. Qualys TotalCloud brings both Cloud Posture Management and Cloud Workload Security into a unified view for prioritizing and reducing your cloud security risk.There is no single best method for scanning workloads. With each option, you will have to tradeoff cost, coverage, and ease of deployment. With Qualys FlexScan, you can choose the scanning method or a combination of methods that is best suited for your environment. FlexScan will consolidate vulnerability results from all the methods for a workload. For example, for your internet-facing workloads, you can run both network-based scans and agent-based scans to get a more comprehensive assessment of vulnerabilities – outside in and inside out. To learn more about FlexScan, refer to this blog.
What Is TotalCloud?
Qualys TotalCloud is a cloud-native security solution that provides the following benefits:- Offers maximum security coverage of your infrastructure through agent and multiple agentless assessment options
- Provides highly accurate and trustworthy detection of vulnerabilities and misconfigurations
- Consolidates workload and cloud posture into a single risk-based metric and provides specific insights to reduce the risk
- Reduces risk by automating the remediation of your highest-risk assets
- Provides proactive security by checking for security issues before deployment
Scan and Rapidly Assess Your Posture Using Qualys FlexScan Powered by VMDR
Qualys has been scanning workloads for vulnerabilities for 20+ years for both on-prem and cloud assets. Qualys is currently performing 30+ million assessments for workloads in public clouds. Qualys FlexScan is the new zero-touch, cloud-native way of performing agent and agentless security assessments. Zero-touch means there is no need for complex configurations like IP ranges, regions, connectors, etc., or a need to set a schedule to enable scanning. FlexScan automatically uses the cloud APIs and the meta-data to determine the appropriate configuration parameters and starts scanning as soon it discovers a new workload. All you need to do as a user is check a box indicating which FlexScan method you want to use. Many scanning tools in the market lack detection accuracy, resulting in many false positives. By leveraging Qualys’ 6-sigma (Show 99.99966%) accuracy scanning capabilities in VMDR, FlexScan dramatically reduces false positives so that you can focus on the vulnerabilities that matter.FlexScan offers four cloud-native scanning options:- API-based Scan – FlexScan uses Cloud Service Provider (CSP)-provided APIs to collect operating system (OS) package inventory from the workloads for vulnerability analysis. API-based scanning is not suited for all scenarios because it cannot detect a certain class of vulnerabilities, like in Open Source Software (OSS), because of the limited data it can gather.
API-based assessment is quick and best suited for short-lived workloads and the initial assessment of new workloads.
- Snapshot-based Scan – FlexScan captures images of workloads, i.e., snapshots, from a cloud services provider’s (CSP) runtime block storage and then scans them. Snapshot scanning is essentially an indirect method of scanning cloud workloads by looking at this block storage instead of directly looking at them with agents. The snapshot method is expensive because of storage and scanner costs and is recommended when other assessment methods are not possible.
Snapshot-based should primarily be used to assess suspended workloads and for third-party images deployed in the cloud where an agent cannot be installed.
- Agent-based Scan – FlexScan uses the agent embedded in the workload to collect operating system, installed software, and other workload-specific metadata information for vulnerability analysis. If FlexScan does not detect the Qualys Cloud Agent on a newly created workload, it automatically installs the agent. Since agents can collect much more meta-data and workload environment data than other scan methods, this method provides the most comprehensive vulnerability coverage. The costs of agent-based are negligible because the agent is embedded in the workload and uses minimal resources.
Agents are the most flexible scanning method because they excel at detection tasks and can also do it continuously. Another significant benefit of the agent-based approach is that it can perform double duty, like immediate remediation actions such as patching vulnerabilities and fixing workload misconfigurations to protect against exploits.
- Network-based Scan – FlexScan can use network scanner appliances to assess workloads over the network. When a new workload is created, FlexScan will automatically instantiate the network scanner in the appropriate network to conduct the scan of the workload. Network scanners provide similar assessment capabilities as an agent. However, unlike agents, they cannot do any remediation actions.
Networks should be used to assess workloads facing the internet and for workloads on which agents cannot be installed. Only network scanners can detect vulnerabilities related to network protocols. They can give you an outside-in view that the other scanners can’t.