TrustRadius: an HG Insights company

SUSE Security

Score8 out of 10

3 Reviews and Ratings

What is SUSE Security?

SUSE® Security (formerly NeuVector) provides an end-to-end container security platform. This includes end-to-end vulnerability scanning and complete run-time protection for containers, pods and hosts.

SUSE NeuVector makes your Kubernetes secure

Use Cases and Deployment Scope

We use SUSE NeuVector:

1) as a Kubernetes firewall to allow containers internal and external network connections which are necessary and block all other connections;

2) to scan our containers for known software vulnerabilities.

In the near future, we also plan to turn on command execution prevention to allow only whitelisted commands in certain containers.

Pros

  • Scans containers software for known vulnerabilities
  • Denies command execution in containers
  • Prevents unwanted network connections from/to containers

Cons

  • I like everything about NeuVector. They are on the right development path.

Most Important Features

  • Ability to control network connections
  • Container software vulnerability scanner
  • Container registry vulnerability scanner

Return on Investment

  • We went from being blind to what happens in the Kubernetes network to seeing everything and being able to control Kubernetes network communications.
  • Now we are able to detect vulnerable containers faster.

Alternatives Considered

Sysdig Secure

Other Software Used

Oracle Linux, SUSE Rancher, Microsoft Visual Studio Code

SUSE NeuVector

Use Cases and Deployment Scope

as SUSE NeuVector is open source so we use it write code and kubernetes-native container security platform

Pros

  • SUSE NeuVector is the only 100% open source
  • it Scans all your running containers for vulnerable packages.
  • Forbids running unsafe Linux commands in containers.

Cons

  • need to spend lot of time to understand how it function. so may be suse come up with some tutorial video.
  • should have some user-friendly information available.

Most Important Features

  • Scans all your running containers for vulnerable packages.
  • Informs you which containers are running under the root user.

Return on Investment

  • overall experience so far is good with product and its features.
  • May be found little expensive compared to other vendor.