Product Description
Container security protection system (Ultra-SmartLxCShield) is a container security testing and protection management tool for enterprise users. It is capable of scanning the vulnerabilities and configuration information in images and orchestration components to help enterprises solve the problem that traditional security software cannot perceive the container environment; meanwhile, it provides container process whitelisting, file read-only protection, and container escape testing, etc., effectively preventing the occurrence of security risk events when containers are running. Container security capabilities cover three key stages in the container lifecycle, covering image security when building containers, security configuration (baseline checking) when deploying containers, and intrusion testing and defense when running containers, realizing a closed loop of container security prediction, defense, testing, and response, and effectively preventing the occurrence of container security risk events.
One-click testing results visualization
After assignment of the testing task, the Agent collects the corresponding files, parses and analyzes the compliance baseline, and ensures that the container is run with minimum authority, thus improving the security of the system and applications. Compliance baseline test results are presented in a visual list, allowing users to clearly see the description, pass status and test details of each check item. This helps users to quickly understand the reasons for failing the baseline test and make timely changes and updates to the container configuration.
Comprehensive and advanced testing technology
It supports various virus databases such as T-sec, AntiVir, clamAv, etc. to discover Trojan viruses in the image, and through various matching modes such as regular matching, ssdeep, known malicious samples, etc., it can deeply discover web backdoor files in the image, and discover sensitive information/operations in the image, such as the ssh-key, user passwords in the environment variables, and data files in the image.
Container runtime testing
Abnormal mounts, sensitive configurations, Trojan viruses, WebShell, lateral movement, suspicious operations, file monitoring, reverse shell, container escape, container isolation.