Cloud

Container Security

Container security protects containers throughout their entire lifecycle, from the image through to deployment and operation.

Container security involves protecting containers throughout their entire lifecycle. This starts with creating the image and extends to monitoring during live operation.

How it works

A container is based on an image containing operating system parts, libraries and the application. Vulnerabilities in the image pass directly into production. Images are therefore scanned before use and sourced only from trusted registries. In operation, containers should run with the fewest possible privileges. Runtime protection detects unusual processes, file changes and network connections.

For example, a team uses a public base image that has not been updated for two years. A scan in the build pipeline finds several critical vulnerabilities. The build is stopped, and the team switches to a maintained, slim base image. The number of findings drops significantly.

What to look out for

  • Scan images in the build pipeline and in the registry.
  • Use slim base images with few components.
  • Do not run containers with root privileges.
  • Sign images and check the signature before deployment.
  • Do not store secrets within the image.
  • Monitor containers during operation, as scans cannot detect attacks.

How it differs from virtual machines

Containers share the host system's kernel. A breakout from a container could compromise the host and other containers. The separation is weaker than with virtual machines. This makes restricted privileges and up-to-date hosts very important.

Switzerland and regulation

There are no specific Swiss regulations for containers. Anyone who is ISO 27001 certified or subject to FINMA supervision must also meet the requirements for secure development and operation in container environments.

Typical mistakes

Often, scans are introduced, but the findings do not block anything. The list of issues grows without any changes being made. Another mistake is not monitoring containers at runtime because teams rely on the build-time scan.

Relevance for the SOC

Runtime signals from containers are an important source for detection. Because containers are short-lived, the data must be stored centrally to investigate incidents retrospectively.

How we implement it

We integrate runtime signals from your container platform into our SOC. Containment is performed within the mandate that you define.

How ANOMAL implements this