Containers and serverless are the two main areas of focus by Aqua Security for its latest cloud native security platform update. That update also comes at a time of competitive upheaval across the space.
The 4.2 update includes Aqua’s Vulerability Shield (vShield) that uses automated vulnerability and component analysis combined with security research to generate runtime policies that can detect and block access to vulnerable components in containers. This can be activated for vulnerabilities found in scan results and will automatically enable the relevant targeted runtime controls.
The company described this “virtual patching” as acting as a shield against exploitation of the vulnerabilities. This sort of vulnerability was at the heart of a security flaw that was discovered earlier this year impacting the runC container runtime that underpins Docker, cri-o, containerd, and Kubernetes.
Fernando Montenegro, senior analyst for information security at 451 Research, explained that this virtual patching also hits at the heart of an ongoing battle within the container security space.
“This notion of just patching something is fundamental, but it’s also hard to do at scale,” Montenegro said in an interview with SDxCentral. “It’s almost one of those religious debates in the industry, with one side saying you should just patch, but the other side noting that it’s hard to do at scale. It’s interesting to see this applied to containers.”
The latest update also includes runtime protection for serverless functions. Aqua said its NanoEnforce technology allows security teams to detect and prevent attacks against cloud-based serverless functions with “negligible impact on function invocation time or memory footprint.”
Montenegro said that the vulnerability shield and serverless function support were important aspects of the update. He explained that the former addressed a gap in larger organizations between how quickly they find a security issue and how quickly they can close it, while the latter continues to bolster security concerns around the serverless space.
Outside of those two main features, the latest update also includes container image scanning by layer that allows developers to more easily isolate the root sources of security issues; a new infrastructure view to allow for quicker identification of unprotected clusters and hosts; and native integration with the Prometheus open source monitoring tool and the Harbor open source image registry.
The update also follows a $62 million Series C funding round Aqua closed in April. The cash infusion raised the company’s total VC haul to more than $100 million. As part of the latest platform update, Aqua said it has since accelerated growth, invested in research and development, and has increased its employee headcount by 30%.
Container SecurityThe focus on container security is becoming increasingly important as more organizations adopt the platform as a way to glean more efficiencies from their cloud deployments. A recent survey conducted by Diamanti found that more than 35% of IT operations teams were driving container adoption, which was more than double the 17% that were doing so last year. That same survey also found that security remained the top challenge to container adoption.
Dror Davidoff, CEO and co-founder of Aqua Security, noted that this growing adoption along with recent container security flaws have raised awareness about risks associated with not having a dedicated cloud native focused security platform in place.
"The reality is that the traditional control points for application security simply can’t identify, let alone block, attacks in these new infrastructures," Davidoff explained to SDxCentral. "So, we are certainly seeing a higher level of interest from security teams, from compliance teams, and the architects putting in place digital transformation platforms. They want to know that they are as secure – or even more secure – than yesterdays’ applications."
That challenge is also impacting how vendors are approaching the space. For instance, Palo Alto Networks recently acquired Aqua rival Twistlock, which is also focused on the cloud native space, and serverless security-focused startup PureSec.
“Today [customers] are talking about containers,” Palo Alto Chairman and CEO Nikesh Arora told investors on a conference call. “If you look at the market there are only two companies [securing containers] and Twistlock was by far the leader.” It’s safe to assume the second container security company Arora is referencing is Aqua.
Davidoff said that the deal has not impacted Aqua's plans, and that it "would be investing in this market whether we had competitors or we didn’t."
Montenegro noted that the security market was indeed going through some changes as it adopts to the new cloud native world. He explained that more established vendors like Palo Alto need to react to what their customers are asking for, and today that is a greater focus on container environments.
However, he also explained that while the larger cloud providers are increasing their security focus, there is still room for security-specific player in the areas of multi-cloud environments and more specialized deployments. “It’s definitely getting to be more competitive, but these more focused vendors can act more agile in adapting to more specific use cases that the larger players either can’t adapt to quickly or just don’t want to,” Montenegro added.
CORRECTION: Story updated to note that Aqua Security has already increased its headcount by 30%.
Comments