18 karma · joined April 14, 2015
We must do X - any insight into how to do X, or what features X needs to have?
Yes, outright prevention is important. Yet proper centralized log collection and intelligence helps with all three missions, including prevention.
Proper logging allows you to identify known-good behavior patterns and outlying anomalies. With profiles in place, one can automate blocking of reconnaissance and probes, not just blocking known vulnerabilities.
Other people were attempting to solve this problem too - https://registry.hub.docker.com/u/kiyoto/docker-fluentd/
Docker has a bad security reputation; this is one more step in the right direction.
Might just be limited to my use case for Docker, but so far it's security agnostic.
So far I've perceived Docker to be like virtualenv for python - useful but orthogonal to any security practices.