Aqua Security today added container threat analysis to its Cloud Native Security Platform and Cloud Security Posture Management products.

The new product, Dynamic Threat Analysis (DTA), protects containerized applications from image-based malware by automatically running images in a secure sandboxed environment. It then analyzes image runtime behavior and checks for anomalies and can perform forensics after a suspected incident. And if the image does contain malware, the sandbox prevents it from infecting workloads and resources on the host or network.

Aqua’s threat hunting team started seeing an uptick in sophisticated malware attacks targeting containers a little over a year ago, said Rani Osnat, VP of strategy at Aqua Security. “Their aim is to attack commercial applications, commercial infrastructure, for monetary gain,” he said. “And the way they do that, they try to run cryptocurrency miners, which is relatively easier to do with containers because the stakes are quite low.”

Cryptocurrency mining is a relatively cheap and easy way for cybercriminals to make money. It only requires a couple of lines of code to operate in addition to stolen processing power and cloud CPU usage. So hackers embed their cryptomining malware in container images, and once deployed they run it as long as possible — usually until someone notices the computing performance drop or growing cloud costs.

How Hackers Avoid Container Image Scanners

Osnat likens it to pickpocketing. A cyberattack against a bank, on the other hand, in which hackers want to steal account numbers and other sensitive data takes a long time and it may not be successful. “With crypto-currency mining, instead of robbing a bank it’s more like pickpocketing,” he said. “You’re not going to get a lot of loot from every transaction, but if you do enough of them it adds up.”

Hackers also use this image-based malware for credential theft, data exfiltration, or using containers for DDoS attacks, Osnat added.

What’s changed over the past year, however, is that hackers use obfuscation and evasion techniques to avoid detection by static scanners. These attacks use innocuous-looking images to embed their own code, which is often encrypted or deployed as polymorphic malware to avoid detection. The malicious behavior of the image can only be observed during runtime, and by then the malware has most likely already infected the system.

“With Aqua DTA, we developed a sandbox, a way to securely run a container in a secure environment that’s separated and isolated from the network,” Osnat said. “But the container doesn’t know that, so it behaves as if it were running in a live environment and we simply trace everything it does and give a very detailed analysis. This integrates into the workflow so that it becomes part of your DevSecOps process.”

Customers can configure DTA to automatically scan only images within a specific scope, for example according to a label or within a named registry. The new product is available in preview, and Aqua expects it to be generally available later this quarter.

Aqua Updates CSPM

Aqua also today announced updates to its cloud security posture management software-as-a-service (SaaS). This product is based on its CloudSpolit acquisition that closed last year. Aqua changed the name to Aqua CSPM, and it includes preview versions of Aqua DTA and integrated container image vulnerability scanning using Aqua’s Trivy open source scanner. The vulnerability scanner included in the preview currently supports Amazon Web Services (AWS) environments, with additional registry support planned throughout the year.

CloudSploit, a cloud security posture management (CSPM) company, developed a SaaS-based platform that provides visibility across customers’ cloud resource estates. It automatically manages cloud security risk and benchmarks against industry standards.

CSPM addresses the management of cloud security — processes and tools to avoid cloud misconfigurations that can lead to data leakage. Gartner recommends all cloud security vendors invest in CSPM, and forecasts “through 2024, organizations implementing a CSPM offering and extending this into development will reduce cloud-related security incidents due to misconfiguration by 80%.”

It has also become a hot mergers and acquisitions market with Zscaler’s Cloudneeti purchase as the most recent example of larger cloud security companies scooping up CSPM startups.

Last year Trend Micro bought Cloud Conformity and Sophos acquired Avid Secure. And in 2018, CheckPoint acquired Dome9 and Palo Alto Networks bought a couple of CSPM vendors: Evident.io and RedLock. Also that year VMware bought CloudCoreo and CloudHealth to round out its CSPM.