NeuVector

Unified Kubernetes security and compliance platform.

NeuVector

Key Features

NeuVector is the only container security platform to enable Security as Code
First and Only Data Loss Prevention (DLP) Solution for Containers
Only Layer 7 firewall for containers.

Protection against common threats like

Ransomware extortion
Crypto-jacking
Service disruption
Data theft
Man-in-the-middle attack
Kill chain attack
NeuVector architecture diagram

Neuvector

End-to-end solution for container network security NeuVector is the only 100% open source, Zero Trust container security platform. Continuously scan throughout the container lifecycle, remove security roadblocks, & bake in security policies at the start to maximize developer agility. NeuVector is the only Kubernetes-native container security platform that delivers complete container security.

CI/CD Automated Scanning

NeuVector supports two types of build-phase scanning: registry and local.

NeuVector CRD for Policy As Code

NeuVector custom resource definitions (CRDs) can be used by various teams to automatically define security policies in the NeuVector container security platform. Developers, DevOps, DevSecOps, and Security teams can collaborate to automate security policies for new or updated applications deployed to production. CRDs can also be used to enforce global security policies across multiple Kubernetes clusters.

NeuVector Modes

The NeuVector Violation Detection module has three modes: Discover, Monitor, and Protect.

Scanning & Compliance

NeuVector enables full lifecycle scanning & compliance through vulnerability scanning and running of the CIS benchmarks for security, as well as custom compliance checks.

Network Segmentation and Threats

Using the container firewall network rules, egress controls, and threat detection

Enterprise Authentication & SSO

LDAP, Active Directory, SAML, OpenID, Okta integration

Zero Trust

Integrate zero trust security across all your containerized workflows to ensure your applications are protected from evolving threats. NeuVector’s runtime security ensures that only authorized processes and network connections are permitted within the containerized environment, further enhancing the security of your Kubernetes deployments.

Container Segmentation

Essential for PCI compliance and many financial organizations, NeuVector’s container segmentation capability creates a virtual wall to keep personal and private information securely isolated on your network.

Deliver real-time protection with the industry’s only Container Firewall

NeuVector delivers highly integrated, automated security and is the only next generation container firewall with packet-level interrogation and enforcement. NeuVector’s container firewall provides inspection, segmentation, and protection of all traffic into and out of a container. This includes container to container traffic as well as ingress from external sources to containers, and egress from containers to external applications and the internet. Our Layer 7 container firewall protects your applications from internal application level attacks such as DDoS and DNS. detects threats such as SQL injection, DDoS, DNS attacks and other application layer attacks by inspecting the payload even for trusted connections.

Automated network segmentation:

behavioral learning to discover the connections and application protocols used between services and automatically creates whitelist rules to isolate them.

Deep Packet Inspection

NeuVector applies DPI to identify attacks, detect sensitive data, or verify application access to further reduce the attack surface. Only network layer analysis enables security to detect and verify the allowed protocols, helping security teams enforce business policy. DPI examines the contents of data packets using specific rules preprogrammed by the user, an administrator, or an internet service provider (ISP). Then, it decides how to handle the threats it discovers. Not only can DPI identify the existence of threats but, using the contents of the packet and its header, it can also figure out where it came from. In this way, DPI can pinpoint the application or service that launched the threat.

Monitor ‘East-west’ and ‘North-south’ container traffic

icroservices and containers dramatically increase internal East-West traffic in a data center. Without application-aware container network security, an attacker can exploit containers once inside a data center. NeuVector detects and displays real-time connection info for all container traffic, internal, ingress and egress.

Auto Capture Packets for Debugging and Threat Investigation

NeuVector makes it easy to view summary connection data and drill down into actual packet details for each container, even as they scale up and down. When a threat is detected, NeuVector will automatically capture and display the packet info, making it easy to investigate.

FULL SDLC vulnerability Management

Data Loss Prevention (DLP)

WAF Sensors

Built in waf sensors like Cross site request forgery (CSRF),Malicious file upload,Reflected cross-site scripting, Sensitive data exposure amongst many.

Zero Day Attack Prevention

Security as Code

Forensic Analysis

NeuVector's forensic analysis feature provides detailed information about container events, including who accessed the container, what was accessed, and when. This information can be used to investigate security incidents and take corrective action.

Violation Protection

Discovers behavior and creates a whitelist based policy to detect violations of normal behavior.

Endpoint/Host Security

Detects privilege escalations, monitors processes and file activity on hosts and within containers, and monitors container file systems for suspicious activity.

Alerting and Notifications

The platform offers real-time alerting and notifications for security incidents and policy violations, enabling timely responses.

API Security:

NeuVector helps protect container APIs from vulnerabilities and unauthorized access.

Container Forensics

NeuVector provides forensic analysis capabilities to investigate security incidents, identify root causes, and trace container activities.

Microservices Security

Organizations can secure individual microservices within their containerized applications, implementing fine-grained access controls and network policies.

Incident Response

In the event of a security incident, NeuVector provides incident response capabilities, allowing organizations to investigate, contain, and remediate threats.

Anomaly Detection

It detects suspicious activities and anomalies within containerized environments, helping organizations identify potential security threats.

Runtime Security

NeuVector’s runtime security employs behavior-based zero-trust security policies. These policies provide an additional layer of security that remains effective even when vulnerabilities are unidentified or lack patches. Notably, NeuVector holds nine United States Patents for its innovative network-centric network inspection and its ability to enforce network policies in Kubernetes without relying on side-cars, agents, or IPTables manipulation.

NeuVector CRD for Policy As Code

NeuVector custom resource definitions (CRDs) can be used by various teams to automatically define security policies in the NeuVector container security platform. Developers, DevOps, DevSecOps, and Security teams can collaborate to automate security policies for new or updated applications deployed to production. CRDs can also be used to enforce global security policies across multiple Kubernetes clusters.

CRDs can be used to support many use cases and workflows:

  • Define security policy during application development, to push into production.
  • Learn behavior using NeuVector and export the CRD for review before pushing into production.
  • Migrate security policies from staging to production clusters.
  • Replicate rules across multiple replicated clusters in hybrid or multi-clouds.
  • Enforce global security policies (see examples for this at bottom).
CRDs bring many benefits, including:

Define / declare the security policy, as code.

Version and track the security policies the same as application deployment manifests.

Define the allowed behavior of any application including network, file and process behavior.

NeuVector supports two kinds of custom resource definitions.

NvSecurityRule

NvClusterSecurityRule is scoped at the cluster level. Either of the resource types can be configured in a yaml file and can be created during deployment, as shown in the deployment instructions and examples for NeuVector. The significance of the NvSecurityRule resource type with a scope of namespace lies in the enforcement of the configured domain of the target group, which must match the configured namespace in the NeuVector’s CRD security policy. This provides enforcement to prevent unwanted cross-namespace policy creation which affect a Target-Group policy rule.

NvClusterSecurityRule

For the NvClusterSecurityRule custom resource definition, this has a cluster level scope, and therefore, does not enforce any namespace boundary on a defined target. However, the user-context that is used for importing the CRD-yaml file must have the necessary permissions to access or reside in the same namespace as the one configured in the CRD-yaml file, or the import will be rejected.

First and Only Data Loss Prevention (DLP) Solution for Containers

Container DLP capabilities protect sensitive PII and PCI data in container networks across multi-cloud and hybrid cloud environments

NeuVector 3.0 now offers the first true data loss/leak prevention solution that can detect personally identifiable information (PII) and other sensitive data within container network flows and prevent potential data breaches. Increasingly stringent industry regulations are forcing businesses to delineate and adhere to more comprehensive procedures for how sensitive data is handled and stored. From enterprises that process and retain payment card data (subject to PCI-DSS compliance) to those doing business with EU citizens (subject to GDPR) and beyond, the stakes – and potential fines – for protecting sensitive data have grown considerably. Container adoption has also swelled, but the highly dynamic nature of container environments has thus far made it challenging for businesses to verify precisely how sensitive data is transmitted from containers.
NeuVector’s new container DLP capability leverages deep packet inspection (DPI) and Layer-7 visibility to examine the network payloads for all connections within container and Kubernetes-orchestrated environments. It also detects the flow of sensitive and private data – such as PII and payment card information – within container traffic. The detection works even with service mesh encryption of pod to pod connections by Istio and linkerd2 through an integration announced last month. With this critical addition, NeuVector is the only container network security solution that features packet-level interrogation and enforcement for today’s deployments as well as future service mesh deployments. This container DLP capability is also extensible, offering enterprises the ability to detect any type of network payload for their own applications by using custom application signatures.

Supply Chain Security

Supply chain security illustration

For organizations adopting a shift-left model, supply chain security has become a critical part of modern software delivery. NeuVector enables Security as Code so teams can embed policy decisions earlier in the pipeline rather than relying only on manual controls later in production.

This approach helps teams validate vulnerabilities across multiple databases, align workloads with standards such as PCI, GDPR, HIPAA, and NIST, and control which container images are admitted into the cluster.

By declaring both deployment and security intent through Kubernetes-native resources, development and platform teams can review, test, and refine protection policies as part of normal CI/CD workflows.

Compliance with NeuVector by SUSE

Compliance is top-of-mind for most organizations. Maintaining compliance in container environments is a new challenge that requires special consideration. NeuVector can help you navigate the maze of compliance regulations and ensure that you meet or exceed expectations for common standards like PCI-DSS, HIPAA, and GDPR.

NeuVector is uniquely positioned to help organizations enforce major compliance standards.

Pre-configured compliance templates to identify issues and generate audit reports
Unique network segmentation and container firewall technology to detect threats, block attacks, and capture forensic network data.
CIS Benchmarks and custom checks to prevent misconfigurations of container infrastructures.
Configuration auditing and compliance with standards based
A vulnerability and compliance management tool to identify and remediate the most critical risks.
End-to-end vulnerability scanning in the CI/CD pipeline and into production.

Payment Card Industry Data Security Standard (PCI DSS)

Enterprises seeking to leverage containers and microservices in compliance with the Payment Card Industry Data Security Standard (PCI DSS) will find some advantageous synergies between the regulations and the technologies – but also some aspects that require particularly careful attention.

Container environments raise PCI DSS compliance challenges in the areas of monitoring, establishing security controls, and limiting the scope of the Cardholder Data Environment (CDE) with network segmentation. Because of containers’ ephemeral nature – spinning up and down quickly and dynamically, and often only existing for a number of minutes – monitoring and security solutions must be active in real-time and able to automatically respond to rapidly transforming attacks.

Because most container traffic is internal “east-west” communication between containers, traditional firewalls and security systems designed to vet north-south traffic are blind to nefarious threats that may escalate within the container environment. And, the use of containers can actually increase the CDE, requiring critical protections for the entire microservices environment unless limited by a container firewall, like that in NeuVector, able to fully visualize and tightly control its scope.

NeuVector workflow

NeuVector integration across the CI/CD lifecycle

NeuVector can be integrated across development, testing, and deployment workflows to extend security visibility throughout the software delivery lifecycle.

Development and continuous integration

During development and CI, NeuVector supports automated vulnerability scanning through registry scanning and pipeline integrations such as Jenkins.

It can also be used during automated testing to observe network connections and workload behavior, helping teams identify issues before code reaches staging or production.

NeuVector CI workflow

Continuous delivery and runtime enforcement

NeuVector can perform pre-deployment compliance validation and security auditing before release, and continue enforcing controls in production.

The platform combines network security, container inspection, and host protection to help secure workloads at runtime.

NeuVector CD workflow