{"id":31941,"date":"2024-03-26T09:19:43","date_gmt":"2024-03-26T08:19:43","guid":{"rendered":"https:\/\/www.dbi-services.com\/blog\/?p=31941"},"modified":"2024-04-03T08:55:49","modified_gmt":"2024-04-03T06:55:49","slug":"containers-security-protect-against-ssn-exfiltration-with-neuvector","status":"publish","type":"post","link":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/","title":{"rendered":"Containers Security &#8211; Protect Against SSN Exfiltration with NeuVector"},"content":{"rendered":"\n<p>You may have heard a few weeks ago, in France, more than 30 millions Security Social Numbers (SSN) have been stolen. These data have been exfiltrated from databases. In these modern days, you are probably running your website in a container and use Kubernetes for its autoscaling capabilities. You then need to take care of containers security.<\/p>\n\n\n\n<p>A common method to exfiltrate data is to use a Command and Control (C&amp;C&nbsp;also known as&nbsp;C2) attack. It existed before containerization but its principle is still the same. It is about infecting a machine with a malware. An external attacker can then leverage this malware to send command to and receive data from this compromised machine. As a Kubernetes Administrator you have to be able to thwart such attacks and tackle containers security. Let&#8217;s find out how in this blog post!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-neuvector-observability-for-containers-security\">NeuVector observability for containers security<\/h2>\n\n\n\n<p>Often C2 tools are used by what we call script kiddies. They have no deep knowledge in security and are just messing around with tools when an opportunity arises. They could use a basic C2 tool to exfiltrate data without being encrypted. This is plain HTTP and with a L7-aware tool you would be able to see these data flowing out. However, by default Kubernetes doesn&#8217;t have such observability capacity and what you would see in your network is shown below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"506\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1-1024x506.png\" alt=\"Data exfiltration in a Kubernetes cluster.\" class=\"wp-image-31945\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1-1024x506.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1-300x148.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1-768x380.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1-1536x759.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-1.png 1898w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Exactly, you would see nothing! Our orange container in our blue pod myapp (in the green namespace myapp) doesn&#8217;t trigger any specific alarm in our Kubernetes cluster. All seems normal whereas this container has been compromised. It exfiltrates data to an external website that is under the control of an attacker.<\/p>\n\n\n\n<p>To be able to detect such exfiltration we will install the application <a href=\"https:\/\/www.suse.com\/neuvector\/\" target=\"_blank\" rel=\"noreferrer noopener\">NeuVector from SUSE<\/a>. It is very easy to install through an operator or with <a href=\"https:\/\/helm.sh\" target=\"_blank\" rel=\"noreferrer noopener\">Helm<\/a>. In a previous <a href=\"https:\/\/www.dbi-services.com\/blog\/install-neuvector-5-on-openshift-local-4-14\/\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>, I&#8217;ve described how to install it in OpenShift. NeuVector is a Swiss Army knife for security in Kubernetes. It provides numerous features to protect your Kubernetes cluster and improve your overall containers security. Here we will use NeuVector capability to observe data in L7 (here HTTP) of a packet.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-data-loss-prevention-dlp-in-neuvector\">Data Loss Prevention (DLP) in NeuVector<\/h2>\n\n\n\n<p>For this L7 observability to operate, we need to configure it in NeuVector. Let&#8217;s see how to do that. In NeuVector you can configure DLP sensors. A sensor is just a regex filter to will detect a patters in the L7 of each packet. By default there is a sensor for the American Social Security Number (SSN) and the Credit Card in various formats (visa, master, american express,&#8230;). A DLP sensor for the french SSN doesn&#8217;t exist so we first need to create it as shown below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"310\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-1024x310.png\" alt=\"DLP sensors configuration in NeuVector.\" class=\"wp-image-31946\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-1024x310.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-300x91.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-768x233.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-1536x465.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-2-2048x620.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"440\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-1024x440.png\" alt=\"DLP sensors configuration in NeuVector.\" class=\"wp-image-31947\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-1024x440.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-300x129.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-768x330.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-1536x661.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-3-2048x881.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We give a name to our sensor and define the regex pattern that will find a french SSN in any packet. This SSN format is detailed <a href=\"https:\/\/www.ameli.fr\/assure\/droits-demarches\/principes\/numero-securite-sociale\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a> in French. The regex pattern used is the one below:<\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: bash; title: ; notranslate\" title=\"\">\n\\b&#x5B;12]\\d{2}(0&#x5B;1-9]|1&#x5B;0-2]|20|21|22|23|24|25|26|27|28|29|30|31|32)\\d{2}\\d{3}\\d{3}\\d{2}\\b\n<\/pre><\/div>\n\n\n<p>With this sensor created, we can now apply it to our pod as shown below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"331\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-1024x331.png\" alt=\"DLP sensors applied to a container in NeuVector.\" class=\"wp-image-31949\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-1024x331.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-300x97.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-768x248.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-1536x497.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1-2048x663.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We select our container in our pod and add a DLP Policy to use the sensor we have just created:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-1024x447.png\" alt=\"DLP sensors applied to a container in NeuVector.\" class=\"wp-image-31950\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-1024x447.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-300x131.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-768x335.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-1536x671.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-5-2048x894.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We apply our sensor to detect any french SSN and set the action to Alert to just log any match found.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-data-exfiltration-detection\">Data exfiltration detection<\/h2>\n\n\n\n<p>With NeuVector and this DLP in place, we have added L7 observability in our Kubernetes cluster and can now see the following regarding our pod myapp:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"505\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6-1024x505.png\" alt=\"Data exfiltration in a Kubernetes cluster detected by NeuVector.\" class=\"wp-image-31951\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6-1024x505.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6-300x148.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6-768x379.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6-1536x758.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png 1914w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Yes! We can now detect a french SSN being exfiltrated from our Kubernetes cluster.<\/p>\n\n\n\n<p>In NeuVector, we can use the graphical &#8220;Network Activity&#8221; view to observe the traffic in our cluster and we would see the following: <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"334\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1024x334.png\" alt=\"DLP sensor alert in NeuVector Network Activity.\" class=\"wp-image-31948\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1024x334.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-300x98.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-768x251.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-1536x501.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-4-2048x668.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>There is a traffic from myapp to the external world and this link is orange. If we click on it, we can see our DLP sensor has detected some traffic that matches our regex filter. We can also see that alert in the security events as shown below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"307\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-1024x307.png\" alt=\"DLP sensor alert in Security Events.\" class=\"wp-image-31952\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-1024x307.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-300x90.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-768x230.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-1536x460.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-8-2048x614.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We can see the action is Alert as this is what we have configured. At this stage the traffic is not blocked so our data are still being exfiltrated but at least it is logged.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-remediation\">Remediation<\/h2>\n\n\n\n<p>Let&#8217;s now see how we could stop these data from being exfiltrated. We will switch the DLP sensor action to &#8220;Deny&#8221; and switch the pod in &#8220;Protect&#8221; mode to block that traffic:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"44\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-1024x44.png\" alt=\"DLP sensors applied to a container.\" class=\"wp-image-31954\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-1024x44.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-300x13.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-768x33.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-1536x66.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-9-2048x88.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"53\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-1024x53.png\" alt=\"DLP sensors applied to a container.\" class=\"wp-image-31955\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-1024x53.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-300x16.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-768x40.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-1536x79.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-10-2048x106.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We can now see the deny action below in our security event:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"266\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-1024x266.png\" alt=\"DLP sensor alert in Security Events.\" class=\"wp-image-31956\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-1024x266.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-300x78.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-768x200.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-1536x399.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-11-2048x533.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-wrap-up\">Wrap up<\/h2>\n\n\n\n<p>We have seen how NeuVector can provide L7 visibility in your Kubernetes cluster. It can detect a pattern in HTTP packets such as a french SSN, log it and block it. We could also use this method to detect legit applications that would send data unencrypted. This would be a good way to improve your containers security by forcing the use of encryption with HTTPS. In case the data are exfiltrating by using HTTPS we could not use this DLP sensor method but would need to apply a different security strategy. Find out more in this <a href=\"https:\/\/www.dbi-services.com\/blog\/enhance-containers-security-prevent-encrypted-data-exfiltration-with-neuvector\/\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Containers security by preventing data exfiltration with NeuVector. French SSN exfiltration can be detected with NeuVector.<\/p>\n","protected":false},"author":109,"featured_media":31951,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1320,1522,149],"tags":[762,2667,2634,3212,2564],"type_dbi":[3018,3017,2943,3213,3289],"class_list":["post-31941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops","category-kubernetes","category-security","tag-containers","tag-devops-2","tag-kubernetes-2","tag-neuvector","tag-security-3","type-containers","type-devops","type-kubernetes","type-neuvector","type-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Containers Security with NeuVector to prevent data exfiltration.<\/title>\n<meta name=\"description\" content=\"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Containers Security - Protect Against SSN Exfiltration with NeuVector\" \/>\n<meta property=\"og:description\" content=\"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\" \/>\n<meta property=\"og:site_name\" content=\"dbi Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-26T08:19:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-03T06:55:49+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1914\" \/>\n\t<meta property=\"og:image:height\" content=\"944\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"DevOps\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"DevOps\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\"},\"author\":{\"name\":\"DevOps\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735\"},\"headline\":\"Containers Security &#8211; Protect Against SSN Exfiltration with NeuVector\",\"datePublished\":\"2024-03-26T08:19:43+00:00\",\"dateModified\":\"2024-04-03T06:55:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\"},\"wordCount\":858,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png\",\"keywords\":[\"Containers\",\"devops\",\"kubernetes\",\"neuvector\",\"Security\"],\"articleSection\":[\"DevOps\",\"Kubernetes\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\",\"name\":\"Containers Security with NeuVector to prevent data exfiltration.\",\"isPartOf\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png\",\"datePublished\":\"2024-03-26T08:19:43+00:00\",\"dateModified\":\"2024-04-03T06:55:49+00:00\",\"author\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735\"},\"description\":\"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png\",\"contentUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png\",\"width\":1914,\"height\":944,\"caption\":\"French SSN exfiltrated.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.dbi-services.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Containers Security &#8211; Protect Against SSN Exfiltration with NeuVector\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#website\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/\",\"name\":\"dbi Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.dbi-services.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735\",\"name\":\"DevOps\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g\",\"caption\":\"DevOps\"},\"url\":\"https:\/\/www.dbi-services.com\/blog\/author\/devops\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Containers Security with NeuVector to prevent data exfiltration.","description":"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/","og_locale":"en_US","og_type":"article","og_title":"Containers Security - Protect Against SSN Exfiltration with NeuVector","og_description":"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.","og_url":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/","og_site_name":"dbi Blog","article_published_time":"2024-03-26T08:19:43+00:00","article_modified_time":"2024-04-03T06:55:49+00:00","og_image":[{"width":1914,"height":944,"url":"http:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png","type":"image\/png"}],"author":"DevOps","twitter_card":"summary_large_image","twitter_misc":{"Written by":"DevOps","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#article","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/"},"author":{"name":"DevOps","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735"},"headline":"Containers Security &#8211; Protect Against SSN Exfiltration with NeuVector","datePublished":"2024-03-26T08:19:43+00:00","dateModified":"2024-04-03T06:55:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/"},"wordCount":858,"commentCount":0,"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png","keywords":["Containers","devops","kubernetes","neuvector","Security"],"articleSection":["DevOps","Kubernetes","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/","url":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/","name":"Containers Security with NeuVector to prevent data exfiltration.","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage"},"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png","datePublished":"2024-03-26T08:19:43+00:00","dateModified":"2024-04-03T06:55:49+00:00","author":{"@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735"},"description":"Containers security by preventing data exfiltration. French SSN exfiltration can be detected with NeuVector.","breadcrumb":{"@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#primaryimage","url":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png","contentUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/03\/NeuVector-SSN-6.png","width":1914,"height":944,"caption":"French SSN exfiltrated."},{"@type":"BreadcrumbList","@id":"https:\/\/www.dbi-services.com\/blog\/containers-security-protect-against-ssn-exfiltration-with-neuvector\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.dbi-services.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Containers Security &#8211; Protect Against SSN Exfiltration with NeuVector"}]},{"@type":"WebSite","@id":"https:\/\/www.dbi-services.com\/blog\/#website","url":"https:\/\/www.dbi-services.com\/blog\/","name":"dbi Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dbi-services.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/4cd1b5f8a3de93f05a16ab8d7d2b7735","name":"DevOps","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cdd2dd7441774355062c0f0f68612296b059cd1e2ff6c7af0b15dba0ed64a85f?s=96&d=mm&r=g","caption":"DevOps"},"url":"https:\/\/www.dbi-services.com\/blog\/author\/devops\/"}]}},"_links":{"self":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/31941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/users\/109"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/comments?post=31941"}],"version-history":[{"count":13,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/31941\/revisions"}],"predecessor-version":[{"id":32274,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/31941\/revisions\/32274"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/media\/31951"}],"wp:attachment":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/media?parent=31941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/categories?post=31941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/tags?post=31941"},{"taxonomy":"type","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/type_dbi?post=31941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}