Tigera is applying zero-trust principles to container security to reduce cloud-native application’s attack surface.
The move is “about reducing the broad attack surface with zero-trust and actively mitigating risks with the combination of preventive measures, combining behavioral baselining and known threats knowledge to detect anomalous activity at runtime, and the ability to remediate risks in real time,” Tigera CEO Ratan Tipirneni, said in a statement.
Tigera claims its cloud-native application protection platform (CNAPP) Calico Cloud integrates zero-trust workload access controls, identity-aware microsegmentation, firewalls, and security information and event management (SIEM).
As the name suggests, CNAPP products secure cloud-native, microservices-based architectures including containers, Kubernetes, and serverless workloads. They also combine cloud security posture management, cloud workload protection platforms, and cloud infrastructure entitlements management, which manage identity and access privileges across multi-cloud environments. And finally, they help organizations adopt a DevSecOps approach to security by identifying vulnerabilities and misconfigurations early in the development process.
By applying zero-trust principles to CNAPP, Tigera claims it can reduce the attack surface.
“You have to assume that an advanced persistent threat is going to go inside your network,” Tipirneni said. Enterprises need an architectural approach and “active build and runtime security” to solve it, starting with a foundation of zero-trust strategy, he said.
When giving equal access to microservices sitting inside Kubernetes for external communication, the attack surface increases dramatically, he added. To address this issue, Tigera offers zero-trust workload access that “can enable a very fine-grained egress access only for that microservice.”
In addition, even if organizations do everything right, they may still end up with a threat inside their infrastructure, he warned. Ransomware groups could take advantage of that to make an entry and spread inside of the infrastructure. “The way to stop them from spreading is if you have very powerful microsegmentation for workloads,” he said.
Because of that, Tigera’s zero trust model “enables only specific application function calls", Tipirneni added.
“Zero trust in simple language is … you're not trusting anything, only things that need to talk to something else are enabled and everything else you don't trust,” he said.
Comments