Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

Container Deployments Bring Security Woes at DevOps Speed

Nearly half of all companies know that they're deploying containers with security flaws, according to a new survey.

Companies are rushing to deploy containers in their application infrastructure — and in that rush, they're deploying containers that they know are insecure. That's one of the conclusions reached in a new report that looks at the state of container security.

The Tripwire State of Container Security Report was conducted in partnership with Dimensional Research. The study finds that companies are unsure about container security, and they're paying a price for that insecurity.

That price is paid in security incidents: 60% of those surveyed say that their organization suffered a container security breach in the last year. Tim Erlin, vice president of product management and strategy at Tripwire, says that he was surprised by that number because there are relatively few reports of container breaches in the news media.

And the security issues don't mean that companies aren't concerned with security. Ninety-four percent of respondents to the survey say that security is one of their significant container concerns. "The first thing they want is how to detect bad things happening; the second is how to prevent those bad things," says Erlin.

Not surprisingly, the level of concern tends to rise with the number of deployed containers. Thirty-four percent of those with fewer than 10 containers describe themselves as "very concerned" about security, while 54% of those with more than 100 containers deployed describe themselves with the same language.

The solution for the container security problem lies in the development cycle, Erlin says. "The way to address container security is to build security controls into the DevOps process. If you're looking for vulnerabilities or mis-compliance, you want to find them in the build ahead of deployment, and you want to make sure the process will allow them to be fixed before deploying," he explains.

Too many companies are using traditional security scanning processes, in which they scan for vulnerabilities when the application is deployed, and then try to fix issues in a DevOps process — and they're finding that it doesn't work, Erlin says. The problem isn't primarily with the tools they're using.

"I don't think this is a technology challenge as much as an adoption challenge. There are tools available today in a variety of quality from a variety of companies, but we haven't seen DevOps organizations adopting them as part of the build process," Erlin says. Looking ahead, though, he sees promise in the form of new employees being hired to work with containers.

"I was talking to an analyst this morning, and he said that companies are seeing new hires bring the container technology with them from their time in colleges and universities," he says. Still, the new hires are no quick fix: 71% of those in the survey say that they expect to see more container security incidents in the coming year.

Related Content:

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PaulChau
50%
50%
PaulChau,
User Rank: Apprentice
1/28/2019 | 9:22:56 PM
Bigger things are coming
I would not be surprised if those figures continue to increase in the coming years. People are starting to realise that there is value in targeting information held in storage containers in companies and more importantly in cloud storage spaces. Such easy access for people who are looking for a payout...
EdwardThirlwall
50%
50%
EdwardThirlwall,
User Rank: Moderator
1/27/2019 | 11:16:32 PM
Put a stop now
It is good that they are aware of their current situation now as opposed to being exposed to the truth only at a much later date when too much damage might have already been done. On their next phase of deploying storage containers, they need to already have an alternative put in motion should they wish to put a stop to this underlying issue.
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Active Directory Needs an Update: Here's Why
Raz Rafaeli, CEO and Co-Founder at Secret Double Octopus,  1/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...