nimbus
nimbus copied to clipboard
Network Segmentation: Addresses Multiple intents
Generate zero-trust policies generated by the discovery engine based on application behaviour
The attacks that can be mitigated are:
- Exploit public-facing applications
- Registration of malicious network functions
- Software Deployment Tools
- Malicious VNF installation
Techniques:
- Radio control manipulation via rogue xApps
- Trusted Relationship
- Registration of malicious network functions
- Software Deployment Tools
- gNodeB Component Manipulation
- Network Sniffing [Tactic: Credential Access]
- Adversary-in-the-Middle [Tactic: Credential Access]
- Network Sniffing [Tactic: Resource Development]
- Adversary-in-the-Middle [Tactic: Resource Development]
Parameters need to be provided such which container is to be isolated
The adapters that are involved are:
KubeArmor, Network Policy, Service Mesh
Document WIP
Detailed Design for API cataloging
Look into API clarity/Traceble setup nginx ingress controller and visibility into north-south traffic.
PR in review