Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Twistlock Aims to Shore Up Container Security With New Offering

    Written by

    Sean Michael Kerner
    Published November 11, 2015
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Proper Docker container configuration is a good first step for security, but according to Twistlock CEO Ben Bernstein, it’s not enough.

      Twistlock today announced the general availability of its Container Security Suite, which aims to go beyond best practices configuration for security to provide improved runtime security.

      “You should think of us as a traditional security technology for an environment where you run containers,” Bernstein told eWEEK. “We’re not saying that containers are insecure by nature; we’re just adding more layers of security on top of what you already have.”

      There are multiple security controls and best practices for Docker container security, many of which are inherited from the Linux operating system on which Docker is deployed, including cgroups and namespaces, which provide isolation and control.

      Twistlock is focusing on different areas of container protection, particularly the DevOps development lifecycle for continuous integration. “We do image hygiene and runtime protection,” Bernstein said.

      For the application image, Twistlock looks at multiple levels, including the file layer as well as the whole image in order to find potential risks. An application image is at some point deployed inside the Docker runtime environment, which presents an additional potential set of risks.

      With containers, there is the ability to look into a service to make sure only authorized services are running, Bernstein said. Twistlock performs heuristics and dynamic profiling at runtime to identify potential risks. The runtime protection component of Twistlock’s technology is linked to six pending patents that the company has developed.

      “At runtime, we provide an active protection for containers,” Bernstein said.

      Twistlock looks at the resources being consumed by a container application, which include API processes that are spawned, as well as ports being opened. Twistlock, which is not an invasive technology, is not sitting in system memory and doesn’t actually have a footprint in the actual container application that is being protected and scanned, Bernstein said.

      “We’re running as a dedicated privileged container on each host, and we’re using the operating system to do profiling because, at the end of the day, containers are just processes,” Bernstein said.

      From an image hygiene perspective, in the open-source Docker community, there is the Notary project and the Content Trust initiative, which aim to provide validated and authenticated images for Docker. Content Trust debuted alongside the Docker 1.8.0 release in August.

      “Notary is an awesome way to make sure there isn’t a man-in-the-middle attack on an image,” Bernstein said. “What might not be awesome is maybe the person that initially wrote the code made a mistake or there was some hygiene image with the original issue.”

      Twistlock is able to scan the image to determine the quality and if there is a potential vulnerability.

      Twistlock is available for users of Google Cloud Platform as a service to protect the Google Container Engine. The technology can also can work with Amazon’s container service, though Twistlock does not yet have a formal partnership with Amazon, Bernstein said. Twistlock also is currently available as a free trial for Docker container users to evaluate.

      “The commercial model will be a yearly subscription,” Bernstein said. “If you want to get it for free, we offer support for up to two hosts for free.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×