The enterprise technology landscape is undergoing a radical transformation, and at its core is the modern data center. Virtual machines (VMs) and agile Kubernetes-based environments have long served as the foundation of this infrastructure. However, as companies deploy artificial intelligence in daily business operations, they must aggressively expand their AI ecosystems to handle highly resource-intensive AI workloads. Ultimately, this shift is redefining what is possible in IT infrastructure and driving unprecedented growth across the enterprise.
This rapid expansion comes with a dark side: the same frontier AI that is accelerating business operations is being weaponized by adversaries. Attackers are increasingly deploying these models to intelligently find vulnerabilities, generate exploit code, correlate across targets, and execute chained attack paths at machine speed. The impact is staggering. As documented in recent M-Trends reporting, AI-discovered vulnerabilities have collapsed the median time to exploit (TTE) from 771 days in 2018 to sub-hourly windows today.
This explosive growth creates a sprawling attack surface that is notoriously difficult to secure consistently and efficiently. Furthermore, when facing threats that move at sub-hourly speeds, defenders can no longer rely on traditional playbooks. They must operate continuously, cost-effectively, and at that exact same machine speed. To effectively defend this modern ecosystem, organizations need robust lateral security that scales with the immense demands of high-performance workloads while enforcing consistent protection across highly distributed VM and Kubernetes clusters.
Purpose-built to address these challenges for the VMware Cloud Foundation (VCF) private cloud, VMware vDefend offers a multi-layered defense approach to protect east-west traffic against ransomware and advanced threats. vDefend includes an Intrusion Detection and Prevention System (IDPS), which inspects all traffic entering or leaving the network, detecting and preventing known threats from gaining access to the network, critical systems, and data.
Let’s look at how vDefend IDPS addresses these critical needs.
The vDefend IDPS Advantage
To protect modern, distributed workloads without sacrificing speed, security must be built-in, not bolted on. By leveraging a hypervisor-native architecture, vDefend distributed IDPS provides seamless, plug-and-play zero-trust lateral protection. Furthermore, because policies are distributed and automated, protection scales effortlessly, applying instantly as workloads are created or migrated across your environment.
High-Performance Lateral Threat Prevention with Turbo IDPS
vDefend introduces High-Performance Lateral Threat Prevention via an optimized Turbo IDPS architecture. By boosting throughput from 9 Gbps to 17 Gbps per host (17 Tbps per VCF instance), an 88% increase, Turbo IDPS ensures that every internal flow is inspected for malicious activity at line-rate speeds. Now you can seamlessly protect your East-West traffic while meeting the immense demands of high-performance AI workloads.
Optimizing Inspection with Maximum Performance
In a Zero Trust architecture, deep packet inspection is vital, but applying it blindly to all traffic is computationally inefficient. While vDefend distributed IDPS offers a robust 17 Gbps of throughput per host, securing high-capacity workloads optimally requires intelligent bypassing.
The “EXEMPT” rule action enables this strategy by allowing security operators to easily identify specific trusted flows (data backups, database replications, etc.) and exclude them from the IDPS scanning engine.
Key benefits for vDefend customers:
- Optimize resources: Exempting high-volume trusted flows preserves valuable compute resources. It frees up CPU cycles to apply IDPS rules exactly where needed—such as virtual patching—while explicitly bypassing them where unnecessary.
- Reduce Alert Fatigue: Frees up time for SOC operators to focus on actual threats by eliminating the false positives typically caused by generic signature alerts.
Simplifying Zero Trust and IDPS Deployment with vDefend ATP Journey
vDefend ATP Journey (ATP 1-2-3) streamlines comprehensive IDPS deployment by transforming the complex path to Zero Trust into an intuitive, data-driven Security Journey. This methodology assesses an organization’s current security posture. It provides a structured workflow that smoothly guides users through sequential segmentation stages—from securing critical infrastructure services to fully locking down inter-environment traffic.
Key User Benefits:
- Easy Enablement: Accelerates configuration deployment through automated workflows and applies prescriptive IDPS policies in accordance with security best practices.
- Operational Efficiency: Provides real-time updates on security gaps through the Security Segmentation Report and recommends specific rules to address and improve overall posture.
Advanced Threat Prevention with vDefend IDPS
Defending against AI-Driven Threats: Distributed Virtual Patching
Frontier AI models have armed attackers with the ability to find previously unknown zero-day vulnerabilities across software and at machine speed. Attacks can now propagate in hours. Given the speed of AI-driven threats, it’s imperative to have a solution that can proactively address them and effectively maintain a defensive posture.
vDefend IDPS acts as a shield, proactively blocking potential exploits for newly detected vulnerabilities until official patches can be applied. It uses frequently updated signatures to protect against the latest global threats and supports custom signatures—imported or developed in-house—allowing customers to quickly and virtually patch their applications.
This video, vDefend Virtual Patching, demonstrates how distributed IDPS can be applied to protect against these threats.
Learn more about vDefend Virtual Patching here.
Threat Visibility
Deploying vDefend IDPS in a detect-only mode transforms network monitoring into a high-visibility threat intelligence tool. By generating high-fidelity alerts mapped directly to the MITRE ATT&CK framework, the system illuminates exactly how an attacker breaches the network and moves laterally. This detailed mapping of the attack kill chain provides SOC teams with the essential, deep context required to quickly investigate, understand, and respond to complex security events before they escalate.
vDefend IDPS provides:
- Early Detection: Empowers incident response teams to take early action and minimize damage.
- NDR Context: Integrates seamlessly with Network Detection and Response (NDR), a threat correlation engine, to create a comprehensive, multi-layered security posture.
Learn more about the vDefend ATP solution here.
Streamlined Regulatory Compliance
Achieving compliance with stringent frameworks doesn’t have to be a resource-intensive challenge. vDefend IDPS transforms complex regulatory mandates into a streamlined, automated process.
Core Benefits
- Embedded, Frictionless Compliance: Simplifies alignment with PCI-DSS, HIPAA, and NIST Zero Trust by building security directly into the infrastructure layer rather than bolting it on.
- Virtual Patching: Protects unpatched workloads against known and zero-day vulnerabilities.
- Audit Control and Reporting: Automatically logs and captures network packet data to easily generate comprehensive audit trails and enforcement reports.
Inspection for All Workloads – VMs, Kubernetes and Bare-metal
In addition to protecting VM workloads, vDefend IDPS extends deep packet inspection directly to container nodes and bare-metal servers. Analyzing this highly dynamic container traffic provides granular visibility into lateral East-West traffic. This allows organizations to scale cloud-native architectures without compromising their underlying security posture.
Key benefits for vDefend customers:
- Consistent Policy: Enforce consistent label-based policies that span across VMs and Kubernetes clusters.
- Unified Management Console: Manage all workloads from a single console.
- Lateral Movement Prevention: Prevent lateral movement by applying policies directly at the source—at the Container Network Interface (CNI) for pods and vNICs for VMs.
vDefend distributed IDPS protects a diverse range of modern workloads—from VMs and containers. By leveraging Advanced Threat prevention on the gateway firewall, these detection capabilities extend directly to bare-metal servers. Additionally, full support for air-gapped environments ensures your infrastructure meets all regulatory compliance requirements.
Conclusion
The rapid expansion of AI workloads is radically reshaping the modern enterprise data center. Simultaneously, adversaries are weaponizing frontier AI models to launch high-speed, sophisticated cyberattacks. To navigate this, organizations must make vDefend IDPS an integral, foundational part of their security journey. By embedding security into the hypervisor, vDefend seamlessly delivers true zero-trust protection. The platform addresses a vast breadth of critical use cases, from virtual patching to securing modern containers. Furthermore, with recent high-performance architectural enhancements such as Turbo IDPS, vDefend powers advanced threat prevention without introducing network bottlenecks. Ultimately, vDefend IDPS ensures your infrastructure remains agile, scalable, and decisively protected against AI-driven threats.
Learn more:
- Multi-Layer Defense in the AI Era | Video
- VMware Advanced Threat Prevention Datasheet
- VMware vDefend Datasheet



