NeuVector Announces New Container Risk Reports
May 09, 2019

NeuVector announced new capabilities to help container security teams better assess the security posture of their deployed services in production.

New dashboard widgets and downloadable reports provide security risk scores for the most critical run-time attack risks: network-based attacks and vulnerability exploits in containers. Specifically, NeuVector now delivers an intelligent assessment of the risk of east-west attacks, ingress and egress connections, and damaging vulnerability exploits.

An overall risk score summarizes all available risk factors and provides advice on how to lower the threat of attack – thus improving the score. The service connection risk score shows how likely it is for attackers to move laterally (east-west) to probe containers that are not segmented by the NeuVector firewall rules. The ingress/egress risk score shows the risk of external attacks or outbound connections commonly used for data stealing or connecting to C&C (command and control) servers. Additionally, the vulnerability exploit risk combines run-time scan results for containers with the protection mode of the container. If the container is protected by NeuVector’s whitelist rules for network segmentation and process profiling, then there is a lower risk of a vulnerability exploit spreading or critically damaging the service.

“The NeuVector container security solution spans the entire pipeline – from build to ship to run,” said Gary Duan, CTO, NeuVector. “Because of this, we are able to present an overall analysis of the risk of attack for containers during run-time. But not only can we help assess and reduce risk, we can actually take automated actions such as blocking network attacks, quarantining suspicious containers, and capturing container and network forensics.”

Furthermore, leveraging tight integration with Red Hat OpenShift, the risk assessments and reports are specific to the OpenShift projects and namespaces for each user. With this integration, individual users can review the risk scores and security posture for the containers within their assigned projects. They are able to see the impact of their improvements to security configurations and protections as they lower risk scores and remove potential vulnerabilities. The one-click RBAC integration requires no additional coding, scripting or configuration, and adds to other OpenShift integration points for admission control, image streams, OVS networking, and service deployments.

“We are seeing many business-critical container deployments using Red Hat OpenShift,” said Fei Huang, CEO, NeuVector. “These customers turn to NeuVector to provide complete run-time protection for in-depth defense – with the combination of container process and file system monitoring, as well as the industry’s only true layer-7 container firewall.”

Other useful new tools announced by NeuVector today include a summary of network application protocol usage and downloadable security reports. Also an industry-first, NeuVector’s protocol usage analysis for containers shows the actual application protocols detected by NeuVector using layer-7 deep packet inspection and includes the network utilization in gigabytes for each protocol. These are useful for detecting unusual network patterns, unauthorized protocols, or for general application debugging.

Share this

Industry News

May 25, 2023

Red Hat announced new capabilities for Red Hat OpenShift AI.

May 25, 2023

Pipedrive announced the launch of Developer Hub, a centralized online app development platform for technology partners and developers.

May 25, 2023

Delinea announced the latest version of Cloud Suite, part of its Server PAM solution, which provides privileged access to and authorization for servers.

May 24, 2023

Red Hat announced Red Hat Service Interconnect, simplifying application connectivity and security across platforms, clusters and clouds.

May 24, 2023

Teleport announced Teleport 13, the latest version of its Teleport Access Platform to enhance security and reduce operational overhead for DevOps teams responsible for securing cloud infrastructure.

May 24, 2023

Kasten by Veeam announced the release of its new Kasten K10 V6.0 Kubernetes data protection platform.

May 23, 2023

Red Hat announced Red Hat Developer Hub, an enterprise-grade, unified and open portal designed to streamline the development process through a supported and opinionated framework.

May 23, 2023

Pegasystems announced Pega GenAI™ – a set of 20 new generative AI-powered boosters to be integrated across Pega Infinity™ ‘23, the latest version of Pega’s product suite built on its low-code platform for AI-powered decisioning and workflow automation.

May 23, 2023

Appdome announced Build-to-Test which enables mobile developers to streamline the testing of cybersecurity features in mobile apps.

May 23, 2023

Garden released major product advancements to make it easier to write and automate portable pipelines for Kubernetes.

May 22, 2023

Check Point Software Technologies announced the general availability of its industry-leading Next-Generation Cloud Firewall natively integrated with Microsoft Azure Virtual WAN to provide customers with top-notch security.

May 22, 2023

The International Business and Quality Management Institute LLC (IBQMI®) introduced the IBQMI CERTIFIED DEVOPS MANAGER® certification program.

May 22, 2023

GitLab announced the launch of GitLab 16, its latest major release.

May 22, 2023

Mendix, a Siemens business, will unveil Mendix 10, the next major release of the low-code development platform, on June 27, 2023.

May 18, 2023

Opsera announced Patty Hatter as President and Chief Operating Officer (COO).