Sitemap

Redefining Security for the AI Era: Blueprint for a Distributed Future

Moving Beyond SIEMs and Firewalls to Secure AI, Cloud, and the Edge

8 min readJul 6, 2025

--

Press enter or click to view image in full size
https://www.youtube.com/watch?v=9OTKkOrPoR0

The goal of the attackers is to get in and stay in so they can turn the lights out when the time comes. So the stakes are pretty high. Security has always mattered, but it matters more now than ever. The second big trend is the onset of artificial intelligence. And we talked about this with G2’s keynote on day one. AI is changing all the fundamental things about an application. It’s changing all the things around us at a breakneck speed.

Press enter or click to view image in full size
https://www.youtube.com/watch?v=9OTKkOrPoR0

And so an attacker could trick a model into revealing those secrets that it knows. So this creates a whole new challenge for security.

Press enter or click to view image in full size

It’s more than likely that we can see the lateral movement of an attacker, but the vast majority of this data is untapped because it’s just simply too large to see. We haven’t been able to bring that into that centralized architecture that Mike was talking about.

Press enter or click to view image in full size

Distributed Security Architecture. Three key things. And so, the first is to be able to distribute your data storage across multiple different data stores. We’ll talk about that. Next piece is being able to distribute your data analytics that runs across those data stores. And then the final pillar is really around how do you do distributed enforcement.

Press enter or click to view image in full size

Because in this world that you talked about earlier, Mike, of stolen credentials and compromised machines, attackers, they’ve got a password. So, they’re just logging in. So, in order to identify friend from foe, you really need to look at the process level. I want to see every single machine, and I want to see what process on that machine, even if it has a legitimate credential, what process initiates the flow and what process terminates that flow on the server side. And so, the good news is we can see that data. That’s the good news. The bad news is that is three orders of magnitude more data than we’re adjusting today with firewall logs, 1000X.

Press enter or click to view image in full size

Federation is all about how do I look across multiple different things but provide that insight from a single location.

Press enter or click to view image in full size

So moving the data analytics close to the source of the data, this is the architecture for the future.

Press enter or click to view image in full size

The security processor, in this case it’s a DPU, is going to be looking at those packets and saying, let’s identify friend from foe. Let’s look at that east-west traffic pattern in very fine-grained detail and figure out good from bad. But this architecture is not limited to a DPU.

In the next generation of these devices, you are going to see not just a DPU, but a GPU. And this is going to allow us to put logic or reasoning into this distributed system. And this is going to be super important in a world of AI-based applications like we talked about in Gigi’s keynote on day one. So in a traditional application, you could think of the security model as looking at every question answer pair in isolation. So can I have Tom’s social security number? In this case, the application says yes. I would rather it said no, but you can look at each transaction individually. When we move to this AI-based world, remember I talked about the model? It knows all your secrets. When you were a kid, do you remember playing the game 20 questions?

Press enter or click to view image in full size

Having the ability to apply compensating controls to both traditional applications as well as these new AI based applications, we think this is going to be a really, really transformative capability, and it wasn’t possible without the distributed architecture and the AI to manage all this stuff. So AI is changing how we do security in our own world in our own applications. But as we move into this world of AI based applications, where’s it all going?

Press enter or click to view image in full size

I think they are related to the same incident and being able to bring that logic together, and then there’s a lot of talk about fully autonomous SOC, and there’s different views and different opinions about when we’ll get there, if that’s the right goal, but I think everybody shares the common goal of saying there’s a lot of manual toil and labor that’s involved in SOCs still today. We are 10 plus years into this automation journey, but there’s still a lot of work that gets done manually, and I think AI really has the ability to transform how we do things there.

Press enter or click to view image in full size

So when you think about how, you know, the trends that we were just talking about, how AI is really driving the need for this new architecture and the pace that things are happening, I can’t believe it wasn’t that long ago that ChatGPT first came on the scene, and you look at what’s happened in the last couple of years, and it’s just like things are crazy in terms of the pace.

Press enter or click to view image in full size

we are talking about here is going from that centralized view where you’re trying to bring things to one place whether that’s your data storage, whether that’s your analytics, whether that’s your enforcement technologies, and rethinking that into a distributed architecture where you are using federation to pull all the pieces together. So that’s a key differentiator. And this wasn’t possible before. We’re talking about things like eBPF. We’re talking about this federation capability. We are talking about how DPUs are enabling smart switches. There’s a lot of new things that are happening in this space, super exciting time.

Press enter or click to view image in full size

Cisco and Splunk’s Vision for a New Security Architecture

Tom Gillis (Cisco) and Mike Horn (Splunk) discuss the need for a new security architecture due to evolving threats and the impact of AI.

Key Trends Driving Change

  1. Evolving Threat Landscape
  • Attacks now target infrastructure (switches, routers, firewalls) rather than just data theft.
  • Attackers aim to maintain persistent access for future disruptions.

2.AI’s Impact on Security

  • AI introduces a new “model” layer in applications, which retains sensitive data and behaves unpredictably.
  • AI-driven applications generate massive data volumes, overwhelming traditional security tools.

Limitations of Traditional Security Architecture

  • Centralized models (e.g., firewalls, SIEMs) struggle with scale and visibility, especially for lateral movement in networks.
  • Zero Trust challenges: Attackers use stolen credentials, making it hard to distinguish legitimate from malicious activity.

Proposed Distributed Security Architecture

  1. Distributed Data Storage
  • Move from a single “data lake” to multiple “data ponds/puddles” (e.g., cloud logs, device-level data).
  • Federation enables querying across decentralized data without centralizing it.

2. Distributed Analytics

  • Analytics must run close to data sources (e.g., edge devices, cloud providers) for real-time insights.

3. Distributed Enforcement

  • Hybrid mesh firewalls: Policies enforced at multiple points (hardware, software, host-level via eBPF).
  • Smart switches: Combine networking and security (using DPUs/GPUs) to inspect traffic at scale.

AI’s Role in Security Operations

  • SOC efficiency: AI assists analysts by automating tasks (threat correlation, reporting) and reducing manual work.
  • Vulnerability management: AI helps deploy compensating controls faster than patching (e.g., mitigating Log4j exploits years later).

Future: AI in the Physical World

  • AI will expand beyond software into physical systems (e.g., medical devices, manufacturing).
  • Security must adapt to protect AI-driven robotics and IoT.

Call to Action

  • The shift to a federated, distributed architecture is urgent, not futuristic.
  • Demos available at Cisco & Splunk booths (RSA Conference).

Key Takeaway

Cisco and Splunk advocate for a distributed security model to handle AI-scale threats, leveraging decentralized data, analytics, and enforcement — enabled by advancements in DPUs, federation, and AI-driven SOC tools.

Artificial intelligence (AI) is now central to many operations, yet its security is often overlooked. To address this, we should implement a layered defense strategy — symbolized as a “donut” of security measures — around AI systems. In a previous discussion on securing AI, I highlighted the need to protect data, models, usage, infrastructure, and governance. This video expands on that by exploring how to secure data, models, and usage while visualizing these defenses using a donut diagram.

Security Capabilities

To build an effective defense, four key capabilities are needed: discovery, assessment, control, and reporting. The first step, discovery, involves identifying all AI implementations within an organization, including authorized and unauthorized (or “shadow AI”) uses. Without visibility, securing these systems is impossible. An agentless discovery approach is ideal since it doesn’t require pre-deployed software. Once discovered, observation is crucial — collecting logs from AI systems into a centralized data lake enables threat detection and analysis.

Assessment

The next layer, assessment, focuses on evaluating AI systems for vulnerabilities, misconfigurations, and compliance gaps — referred to as AI security posture management. This ensures systems remain aligned with security policies. Additionally, penetration testing (pen testing) is essential to identify weaknesses before attackers exploit them. Since many organizations import AI models from external sources (e.g., Hugging Face), scanning these for malware or hidden risks is critical to mitigate third-party threats.

Control

Control mechanisms are vital for securing AI interactions. An AI gateway acts as a checkpoint, filtering malicious inputs like prompt injection attacks (a top threat per OWASP). Depending on the deployment stage, organizations may choose to monitor suspicious activity before enforcing blocks. Guardrails can also prevent misuse, such as jailbreak attempts that bypass safety protocols. Additionally, privacy controls are necessary to prevent sensitive data (e.g., PII, trade secrets) from leaking via AI outputs.

Reporting

The final layer, reporting, enables risk management and compliance. A dashboard provides a consolidated view of threats, vulnerabilities, and incidents, helping prioritize responses. Compliance reporting ensures adherence to regulations (e.g., GDPR) and frameworks like MITRE’s AI Risk Management Framework or OWASP’s Top 10 for LLMs. Audit trails prove policy enforcement and help maintain accountability.

Conclusion

By integrating discovery, assessment, control, and reporting, organizations can create a robust “donut” of defenses around their AI systems. This layered approach ensures security while maintaining compliance, making AI both functional and resilient against breaches.

--

--

evoailabs
evoailabs

Written by evoailabs

Tech/biz consulting, analytics, research for founders, startups, corps and govs.