Company News

INNOVATE Completes AWS Strategic Initiative on EKS Protection with Amazon GuardDuty

Through our AWS practice within the Cloud Security Center of Excellence, INNOVATE has successfully completed the AWS strategic initiative on EKS protection with Amazon GuardDuty.

Amazon GuardDuty is AWS’s threat detection service, using machine learning, anomaly detection and integrated threat intelligence to identify and prioritize potential threats. It continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts, EC2 workloads, containerized applications, and databases (Aurora and S3). Using AWS and leading third-party sources, GuardDuty combines machine learning, anomaly detection, network monitoring and malware detection to help protect workloads and data on AWS, analyzing tens of billions of events from multiple AWS data sources, including AWS CloudTrail event logs, VPC flow logs, EKS system and audit-level logs, and DNS query logs.

Cloud and container adoption keeps growing every year. Gartner estimated that 90% of global organizations would be running containerized applications in production by 2026. Alongside real benefits in cost, performance and scalability, accelerated container adoption brings security risks, such as running containers with high or critical vulnerabilities, or malicious container images from public repositories. That’s why companies need new security measures in their cloud environments to detect and mitigate potential vulnerabilities and threats in their containers, including in Amazon Elastic Kubernetes Service (Amazon EKS), the managed Kubernetes service for running Kubernetes on AWS and on-premises.

As part of this initiative, our team of AWS-certified cloud security architects took part in a series of workshops with AWS to deepen and test Amazon GuardDuty’s specific capabilities for EKS protection on AWS.

Through this initiative, our Cloud Security Center of Excellence has built the knowledge and experience to help our clients secure their containerized AWS environments, adding EKS protection on AWS to the INNOVATE portfolio, including:

  • Threat detection at every layer of Kubernetes deployment on Amazon EKS
  • Threat detection coverage to protect Amazon EKS clusters
  • Analysis of Kubernetes data sources from EKS clusters, monitoring for malicious and suspicious activity
  • Visibility into individual Kubernetes container runtime activity (file access, process execution, network connections)
  • Continuous monitoring of all Amazon EKS clusters across the organization
  • Over two dozen new threat detections leveraging high-fidelity, system-level events designed for known container attack techniques, with container-level context

If you’re already working with Kubernetes, or considering EKS on AWS for your solutions and services, don’t hesitate to contact us. Our experts can help you secure them using Amazon GuardDuty’s detection and protection capabilities for EKS.