NeuVector jumped on Amazon Web Services’ (AWS) re:Inforce event this week to extend its container runtime security focus into AWS’ container and Kubernetes services. It also comes on the heels of another Kubernetes security scare that highlights the ongoing challenge of securing this rapidly evolving environment.

The NeuVector update targets runtime container security for applications deployed in AWS Cloud. The integration includes automated deployment on AWS’ Elastic Container Service for Kubernetes (EKS) with Kubernetes ConfigMaps, runtime security for containers running in AWS’ Elastic Container Service (ECS), and integration into AWS’ App Mesh with a Layer 7 container firewall that can inspect and protect service mesh traffic.

The updates support automated container security deployments that NeuVector CTO Gary Duan described as a “policy-as-a-code concept.” He said it does this by leveraging Kubernetes ConfigMaps to secure initial deployments into production environments with predefined configurations. The Kubernetes ConfigMaps allow for the decoupling of configuration artifacts from images to help maintain application portability.

NeuVector is also using a declarative security policy tool that allows developers to predefine runtime security rules for deployment that runs through the application lifecycle. This includes network and process whitelisting in Kubernetes YAML files that can be deployed alongside new applications that are running in production.

“Users can write their policy rules, and when they are deployed we make sure they are applied to our solution,” Duan said, adding that this results in “no downtime for the protection.”

Beyond Runtime

NeuVector has historically focused on the container runtime environment. This is the place where applications are running services in production environments. Late last year it introduced support for containerd and CRI-O runtime environments.

Runtime security is seen as an advanced level of container protection. The initial focus was on image scanning, which was the process of scanning library content that housed the artifacts that make up a running container. This tackled the basic assumption of controlling the quality of content that was used to construct an application: if clean content was going in, the application should run clean.

However, as containers have increasingly been used to support running production applications, there is a growing focus on securing those applications in runtime. The challenge with this has been in not interfering with the performance of that running application. A number of vendors have tackled this by deploying a thin monitoring layer that can sniff out anomalies. Duan noted that runtime security relies heavily on this form of real-time application performance monitoring.

“Typical customers start with scan, but we have seen them gradually put more focus on runtime,” Duan said,

Glen Kosaka, vice president of product management at NeuVector, said that the company’s strength was still in its focus on securing the runtime environment, but added that the company was expanding its reach into areas like image scanning, admission controls, and broader support “for the full dev environment with CI/CD pipelines.”

Kosaka explained that this expansion was necessary as organizations continue to grapple with their container strategies.

“The industry is still all over the map when it comes to security,” Kosaka said. “Some organizations are still trying to learn about what even runtime security is. Some are still developing their pipelines and are more focused on the vulnerability scanning and have not moved into the production environment yet. And others want as fully automated of a pipeline as they can get.”

Duan also said that there is also a growing focus on the network connections.

“The network can be the first defense to protect the workload,” Duan said. “Understanding how the applications connect together is what we want to provide and is also a challenge.”

He did add that regardless of the strategy, the goal has to be to make a security platform that is usable across an organization. “When shifting to the right you want to make sure that the people at the left can still use it,” Duan said.

Recent Kubernetes Flaws

This is also becoming more of an issue as container-related security flaws continue to percolate. Just this past week a new security flaw emerged that was the result of an unsuccessful patch on a previously discovered flaw.

“People are starting to realize that [Kubernetes] and API servers and other components are attack surfaces,” Kosaka said. “They have no idea what to look for if it gets compromised, so they are more receptive for the need to monitor the network.”

Kosaka also sounded a cautionary stance that AWS executives are hoping to temper and that any security firm worth its chops has to make sure to reiterate.

“Any type of vulnerability or exploit will look to expand or move laterally or steal data and move it outside of that organization,” Kosaka said. “We have to assume there are vulnerabilities that have not yet been discovered. We have to assume the thieves are going to find it and exploit it for months before it’s found.”