When seconds count: Extending EDR to ADCs to erase the AI exploit window

Patch Tuesday used to buy defenders a short head start. Now the exploit often lands before the patch does since automated scanners can weaponize a newly disclosed vulnerability within hours. That inversion is pushing security teams toward virtual patching: shielding an application from a known flaw at the network layer while the real fix is tested and rolled out.

John Maddison (pictured), chief marketing officer and head of technology alliances at F5 Inc., has spent two years at the application delivery and security vendor, which turns 30 this year. F5’s customers are increasingly demanding that kind of protection as the gap between vulnerability disclosure and exploitation collapses, Maddison noted.

“What you need now is AI-powered security that can look at the traffic, where it’s going, what it’s trying to get to and produce protection in real time to stop things like zero days,” he said. “All the protections that sit in what we call CDNs or WAFs are going to be AI-powered. They have to be going forward.”

Maddison spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how virtual patching can help close shrinking remediation windows and how F5’s partnership with CrowdStrike treats network appliances as endpoints. (* Disclosure below.)