Network Namespaces for Advanced Threat Protection

Paradox simplifies the use of namespaces for fine-grained network control and process isolation

What are Network Namespaces? 

Namespaces are a feature of Linux that partition and control kernel resources such that one set of applications sees one set of resources, while another set sees a different set of resources. Network namespaces can be used to force applications to use a specific network interface, or to provide isolation of network traffic between processes. As an example, network namespaces are one of the technologies used to create Linux Container isolation. 

Network Namespaces

So what’s the news? 

As with many of the powerful features of Linux, network namespaces can be tricky to configure to meet specific needs within  enterprise environments, or protect against advanced network threats, so tend in practice to be rarely used (except for their use under the hood e.g. for Linux Containers).

Advanced threats – really? 

A relevant attack was recently highlighted by the Leviathan Security Group (TunnelVision CVE-2024-3661) that allows VPN tunneling to be completely bypassed. The Leviathan Group positioned network namespaces as the only complete mitigation. 

So what’s the Paradox offer? 

Becrypt’s security focused operating system Paradox now enables and simplifies the configuration of Network Namespaces. Policies can be easily defined and deployed via a centralised management platform, allowing isolation of high-risk activities, such as system administration, from general network access. 

Please get in touch if you’d like to find out more.

 

 

Share the Post:

Related Posts

Strengthening Security in Critical National Infrastructure: The Power of Becrypt’s High Assurance Cross Domain Solution

Critical National Infrastructure (CNI) organisations are continuously exposed to a variety of threats including advanced cyberattacks and operational risks. Traditional security measures often fall short in effectively mitigating these challenges, highlighting the need for a more robust approach. Becrypt APP-XD, the first ever API-centric Cross Domain Solution, meets this demand by offering a solution that not only enhances security but also ensures reliable communication across different trust domains.

Read More

Looking for more information?

Please Contact us

And one of our team will get right back to you.

We're here to help

Please Contact us

general enquiries

+44 (0) 845 8382050

Support

+44 (0) 345 8382070

Join Our Newsletter

Receive our latest blog posts directly in your inbox!