VNX-Secure
A defensive control plane, with stated limits.
VNX-Secure authenticates, authorizes, detects, contains, audits and recovers for VNX-DNA. It never acts against another system.
What is implemented
“Verified in software” means covered by committed unit, property or integration tests. It does not mean tested against real attackers.
- Identity and authentication
scrypt-hashed secrets, HMAC tokens and revocation
Verified in software - Replay protection
nonce plus timestamp window
Verified in software - Authorization
deny-by-default policy where an explicit deny wins; fuzzed
Verified in software - Detection
16 deterministic rules with an explainable risk score
Verified in software - Containment
idempotent playbook: session isolation, credential revocation, rate limiting
Verified in software - Audit
HMAC-chained log with evidence preservation
Verified in software - Sandboxed parsing
forked child with memory, CPU and time limits; resource isolation, not a code-execution boundary
Verified in software - Attack scenarios
10 synthetic scenarios detected and contained; 0 false positives over 270 benign requests
Simulated - Network isolation
an interface with a recording stub only
Architectural only
What it does not protect
VNX-Secure is not claimed to be unhackable. It is a first defensive layer, tested against synthetic attacks on one host, without external review or real traffic.
- Bypass
It enforces policy only for access through its gate. Confidentiality rests on AES-256-GCM and key custody.
- Host compromise
An attacker with the same user or root privileges can read the key and rewrite logs. An off-host anchor is future work.
- Supply chain
Dependencies are not hash-pinned and releases are not yet signed.
- Slow attacks
Fixed thresholds were chosen for clarity, not tuned on real data; activity below them is not detected.
- Future work
Post-quantum cryptography is planned, not implemented. VNX-RAM is architectural only.
VNX-Secure protects VNX-DNA archives. It is not used to protect this website.