Author: Glen Kosaka
How NeuVector Can Protect Against the XZ Backdoor Attack CVE-2024-3094 in Kubernetes Environments
Security researcher Andres Freund reported to Debian that the xz/liblzma library had been backdoored. As a result, CVE-2024-3094 was published with a critical CVSS score of 10. This vulnerability stems from a supply chain compromise on versions 5.6.0 and 5.6.1 of XZ Utils. XZ Utils is data compression software included in major Linux distributions. The […]
Read More
Kubernetes環境におけるXZバックドア攻撃CVE-2024-3094に対するNeuVectorの防御方法
セキュリティ研究者の Andres Freund 氏が、xz/liblzma ライブラリがバックドアされている […]
Read More
How NeuVector Leverages eBPF to Improve Observability and Security
Extended Berkeley Packet Filter There’s been a lot of recent interest in eBPF (extended Berkeley Packet Filter) and its application for container security solutions. Let’s examine eBPF’s features and benefits and how NeuVector utilizes them to enhance its full-lifecycle container security solution. eBPF enables products to run sandboxed programs in a privileged context, such as […]
Read More
NeuVector UI Extension for Rancher Enhances Secure Cloud Native Stack
We have officially released the first version of the NeuVector UI Extension for Rancher! This release is an exciting first step for integrating NeuVector security monitoring and enforcement into the Rancher Manager UI. The security vision for SUSE and its enterprise container management (ECM) products has always been to enable easy deployment, monitoring and management […]
Read More
NeuVector UI拡張機能 for Rancherがセキュアなクラウドネイティブスタックを強化
NeuVector UI拡張機能 for Rancherの最初のバージョンを正式にリリースしました!このリリー […]
Read More
NeuVector Releases v 5.3.0: Enhancing Network Security and Automation
We are pleased to announce the release and general availability of NeuVector version 5.3.0! This release adds significant functionality to our market-leading container network security protections, as well as support for GitOps security as code automation. It also expands the breadth of platform compatibility with Arm64 and public cloud marketplace support. Enhanced Zero Trust […]
Read More
NeuVector、v 5.3.0をリリース: ネットワークセキュリティと自動化を強化
NeuVectorバージョン5.3.0のリリースと一般提供を発表いたします!本リリースは、市場をリードするコン […]
Read More
Security Controls for the OWASP Kubernetes Top 10
Using NeuVector to Reduce Risk in Kubernetes Kubernetes has become the de-facto standard for container orchestration platforms and is widely used in business-critical infrastructure in enterprises of all sizes. With this popularity comes an increase in focus for hackers to exploit vulnerabilities and misconfigurations in Kubernetes clusters. The orchestration layer system resources, as well as […]
Read More
OWASP Kubernetesのセキュリティ管理、トップ10
NeuVectorを使用してKubernetesでのリスクを低減 Kubernetesは、コンテナのオーケスト […]
Read More
NeuVector by SUSE release 5.2 is now available!
I am pleased to announce the availability of version 5.2 of the NeuVector container security platform. This release packs a significant number of valuable enhancements and bug fixes for users requiring full-lifecycle security for their Kubernetes container pipeline and deployments. Vulnerability scanning and admission controls are critical NeuVector features for ensuring supply chain security. In […]
Read More
Microservices
Integrated, Automated Security for Containers Deployed with Kubernetes, Red Hat Openshift, IBM Cloud, Google Cloud, AWS and More End-to-End Kubernetes Protection Transition to microservices securely. NeuVector offers end-to-end vulnerability management to establish your risk profile and the only patented container firewall for immediate protection from zero days, known, and unknown threats. Get integrated, automated […]
Read More
Container Security: Zero Trust Runtime Security
Protect data in production Traditional security practices focus on exceptions, blocklists, signatures, malware, and vulnerability scanning. These legacy approaches, while important to a layered security approach, focus efforts on being reactive which is becoming harder to scale. Zero-Trust is critical in moving to a proactive approach to security, where we can declare acceptable behavior and […]
Read More
Kubernetes Security: Vulnerability Management
Profile Risk with Vulnerability Management Throughout the Build, Ship, and Run Pipeline NeuVector scans for vulnerabilities during the entire continuous integration/continuous delivery (CI/CD) pipeline, from Build to Ship to Run. Use the Jenkins plug-in to scan during build, monitor images in registries and run automated tests for security compliance. Prevent deployment of vulnerable images with admission […]
Read More
Container Security: Network Visibility
Network Inspection + Container Firewall for unmatched visibility You can’t secure what you can’t see. Deep network visibility is the most critical part of runtime container runtime security. In traditional perimeter-based security, administrators deploy firewalls to quarantine or block attacks before they reach the workload. Inspecting container network traffic reveals how an application communicates with other […]
Read More
Container Security: Supply Chain Security
For organizations shifting left, security practices that keep pace with accelerated software development and deployment are critical. NeuVector is the only container security platform to enable Security as Code, the easiest way to streamline the incorporation of security policies into the development process. Eliminate tension between development and security. Speed the CI/CD pipeline. Bake security […]
Read More
Container Security: Compliance with NeuVector by SUSE
Compliance is top-of-mind for most organizations. Maintaining compliance in container environments is a new challenge that requires special consideration. NeuVector can help you navigate the maze of compliance regulations and ensure that you meet or exceed expectations for common standards like PCI-DSS, HIPAA, and GDPR. The NeuVector Solution The NeuVector Container Security Platform provides supply […]
Read More
Kubernetes Security: Container Segmentation
Essential for PCI compliance and many financial organizations, NeuVector’s container segmentation capability creates a virtual wall to keep personal and private information securely isolated on your network. Container segmentation, also called micro-segmentation or nano-segmentation, is often required because containers contain personal or private information about customers or employees or other critical business data. Without segmentation, […]
Read More
Cloud Migration
Deploy containers in the cloud with confidence. NeuVector protects your data and IP in public and private cloud environments. Advanced Security for Public Cloud Deployments Public cloud containers have increased exposure to threats and attacks and require added visibility and security for defense in depth. Traditional cloud firewalls and security features such as Security Groups […]
Read More
DevOps Transformation
Speed your journey to DevOps. NeuVector covers the entire CI/CD pipeline with complete vulnerability management and attack blocking in production with our patented container firewall. Integrate security automation into all stages of the pipeline. DevOps Agility. Total Security. NeuVector is a cloud-native security container which deploys with standard devops tools as part of your […]
Read More
Enterprise and Edge Scale Security with NeuVector Container Security 5.1
I’m excited to announce the general availability of the SUSE NeuVector container security platform version 5.1. With the 5.1 release, customers will benefit from more efficient and powerful vulnerability scanning and admission controls across multiple clusters through centralized enterprise scanning, auto-scaling scanners and support for the new Kubernetes (1.25+) pod security admission (PSA) standard. The […]
Read More
Zero Trust – das neue Sicherheitsmodell für Cloud-native Anwendungen und Infrastruktur
Zero Trust gewinnt als Sicherheitsansatz immer mehr an Aufmerksamkeit, denn dieses Konzept kann die Sicherheitslage von Unternehmen im Kampf gegen Hacker erheblich verbessern. Im Moment scheint jeder Anbieter von Softwaresicherheitslösungen auf den Zug aufspringen zu wollen. Zero Trust ist jedoch kein Produkt oder Service. Zero-Trust-Sicherheit kann nicht von einzelnen Produkten oder Anbietern abgedeckt werden. Aber […]
Read More
SUSE NeuVector 5.0 Delivers a Powerful Open Source Security Platform
I’m excited to announce the general availability of the SUSE NeuVector container security platform. This release makes a full lifecycle container security platform available to all enterprises and users worldwide through an Apache v2 licensed open source software model. As container security continues to be a critical need for organizations building and running Kubernetes applications, […]
Read More
Critical Vulnerability in Apache Log4j 2 (CVE-2021-44228)
A critical, high severity vulnerability (CVSS v3.0 10/10 rating) in the Apache Log4j open source Java logging library was disclosed Thursday, December 9 on the foundation’s github page. On Wednesday, Dec 15 a new vulnerability CVE-2021-45046 was published and patched, according to this article. This was the result of an incomplete initial patch of CVE-2021-44228 which […]
Read More
How to Use NeuVector with the Mitre Att&ck Framework
There are many attack vectors for cloud-native Kubernetes and container deployments, some new and some traditional. To help organizations learn about these and protect against them, MITRE has published a knowledge base of techniques and tactics in a new matrix focused on containers. The newly published ATT&CK® for Containers provides container-specific attack vectors across the […]
Read More
How to Use Terraform to Deploy Secure Infrastructure as Code
How to Ensure that the Infrastructure Remains Secure and Applications Are Secured Before Deployment
Read More
An Introduction to Secure Infrastructure as Code (IaC) Using Terraform
A hot topic these days is Infrastructure as Code, or IaC, and how to use tools like Terraform to deploy IaC. There are tremendous benefits for following Infrastructure as Code principles, one of which is security, or Security as Code. What is Infrastructure as Code (IaC)? Infrastructure as Code enables modern infrastructures such as cloud […]
Read More
Protect Kubernetes Containers on AWS Using the Shared Responsibility Model
Editor’s note: This post was updated on August 17, 2022 Deploying an AWS container security solution is a critical requirement to protect your data and assets running on AWS, including EC2, EKS, ECS, Kubernetes, or RedHat OpenShift. In its ‘ d Responsibility Model,’ AWS states that the security responsibility is shared between AWS and the customer, you. […]
Read More
How to Protect Web Applications in Containers Using DPI and DLP
Protect Kubernetes Applications with Your Existing Threat Rules By Fei Huang The software security industry has grown very quickly in the past decades, and companies large and small are all using some type of network and endpoint security solution. These include solutions for anti-virus, anti-malware, web application firewall (WAF), layer 7 next generation firewall, penetration […]
Read More
How to Optimize I/O Intensive Containers on Kubernetes
Understanding the Real-time Characteristics of Linux Containers By Jay Huang Highly threaded, I/O intensive Linux containers running on Kubernetes should be able to use the full extent of their CPU requests. But is this really possible? Understanding how the Linux operating system schedules tasks and allocates CPU time to tasks can help application developers optimize […]
Read More
How to Create ‘Security Policy as Code’ to Automate Application Security Policies in the CI/CD Pipeline
DevOps and DevSecOps teams can now automatically deploy and update new applications securely using Kubernetes Custom Resource Definition (CRDs) As DevOps teams integrate their toolchain to enable automated deployment of container-based applications, one aspect has always slowed down a modern cloud-native pipeline: security. And while automated vulnerability scanning is now standard practice, creating the security policies […]
Read More
Container Security Monitoring with Prometheus and Grafana
Today, millions of applications are running in containers, with many millions more going into production. It is not easy to manage and monitor a massive number of containers in any deployment at the same time. In order to better visualize and track container status, the combination of Prometheus and Grafana provides a simple, easy-to-deploy solution. By integrating these […]
Read More
Using Admission Control to Prevent Unauthorized or Vulnerable Image Deployments in Kubernetes
Kubernetes Admission Control is a Critical Link in a Container CI/CD Pipeline An important security enforcement point to build into the container CI/CD pipeline is to prevent unauthorized or vulnerable images from being deployed into production Kubernetes clusters. While basic Kubernetes admission control provides some capabilities, preventing vulnerable images from being deployed requires extensions to […]
Read More
Container Segmentation Strategies and Patterns
At a recent container security conference the topic of ‘container segmentation patterns’ came up, and it became clear that many security architects are wrestling with how to best segment workload communication in the dynamic environment of containers. The question was also raised “Is the DMZ dead?” The concept of network segmentation has been around for […]
Read More
How to Protect Sensitive Data in Containers with Container DLP
We recently announced the industry’s first Container DLP capability to help enterprises protect sensitive data. Let’s take a deeper look into data loss prevention (aka data leak protection) and how it applies to containers. What is Data Loss Prevention (DLP)? DLP solutions help detect potential sensitive data violations and prevent accidental or malicious data breaches. Sensitive data […]
Read More
How to Secure Containers in a Service Mesh such as Istio and Linkerd2
Visualize and Protect Service Mesh System and Application Containers with NeuVector By Chip Hwang We recently announced NeuVector integration with service meshes which enables powerful Layer 7 network inspection and protection of container traffic, even with pod to pod encryption on. This is an exciting technology leading capability from NeuVector which allows enterprises to protect Kubernetes in production by extending […]
Read More
NIST SP 800-190ガイドを使用してコンテナを保護する方法
NIST SP 800-190 は、コンテナの潜在的なセキュリティ上の懸念に焦点を当て、これらの懸念に対処する […]
Read More
How Kubernetes Networking Works – Under the Hood
By Tobias Gurtzick Kubernetes networking is a complex topic, if not even the most complicated topic. This post will give you insight on how kubernetes actually creates networks and also how to setup a network for a kubernetes cluster yourself. This article doesn’t cover how to setup a kubernetes cluster itself, you could use […]
Read More
Achieving PCI Compliance for Containers
Although microservices and containers are not explicitly mentioned in PCI-DSS for PCI compliance, organizations implementing these technologies must focus carefully on monitoring, securing, and governance. Microservices and containers offer some unique characteristics that support pci compliance. For example, microservices emphasize an architecture with one function per service/container. This aligns well with PCI-DSS 2.2.1, implementing only […]
Read More
How Kubernetes Networking Works – The Basics
Kubernetes 101 Before I get into Kubernetes networking, here are the basic concepts to know about in Kubernetes. For those not familiar with Kubernetes, these are the objects and terms used in a Kubernetes deployment. Kubernetes is a container orchestration and management tool for automating the deployment and monitoring of containers. Kubernetes is supported by […]
Read More
Kubernetes System Security – Protecting Against Kubelet Exploits
By Andson Tung As critical as it is to protect application containers deployed by Kubernetes, it is just as critical to protect the Kubernetes system containers from attacks or from being used in an attack. In this post I’ll focus on one important Kubernetes security area – protecting the Kubelet, which manages the pods on […]
Read More