UPDATED 01:25 EST / AUGUST 25 2016

NEWS

Industry analysts highlight Docker’s superior security credentials

Security considerations are a significant barrier to adoption for just about every new technology that bursts onto the scene, and Docker containers are no exception. However, two organizations are now claiming that security should in fact be a driver of container adoption.

Cybersecurity firm NCC Group and technology analyst Gartner Inc. recently published research that shows containerized apps are more secure than traditional, non-containerized apps.

Nathan McCauley, director of security at Docker Inc., told eWeek that Gartner is now communicating this advice to its enterprise users.

“It is significant in combination with the NCC Group report, which recognizes Docker’s leadership in the area of container security,” he said.

Gartner claims in its research that an application deployed in a container is more secure than the same app would be when running on a bare-metal operating system. The thrust of Gartner’s argument is that applications and users are “isolated on a per-container basis,” which means they cannot compromise the host operating system or other containers.

NCC Group added in its own report that containers, “from a security perspective, create a method to reduce attack surfaces and isolate applications to only the required components, interfaces, libraries and network connections.”

Docker’s McCauley also penned a blog post supporting the claims, pointing out some of the key security features that Docker containers enable, and how these compare with other container formats. One of the most important of these features is Docker’s “seccomp filtering” technology, which was added to Docker version 1.10 in February. Seccomp is integrated with the Linux kernel and provides granular security controls, McCauley said.

McCauley also pointed to features made available in Docker 1.12 (released in July), such as built-in certificate authority, mutual Transport Layer Security (TLS) authentication, authorization between nodes, and most important, cryptographic node identities.

“In particular, cryptographic node identities are one of the fundamental building blocks that will enable future security features,” McCauley told eWeek.

However, this array of security features doesn’t mean Docker containers are automatically secure. In order to properly secure an environment, users need to follow the established best practices for configuration, which is precisely why Docker released its Docker Bench tool last year.

“We are updating Docker Bench to take advantage of the new orchestration features that shipped in 1.12 and continue to update our sysbench release for every benchmark that comes out,” McCauley said.

Image credit: PixelCreatures via pixabay.com

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.