VNX-Secure

A defensive control plane, with stated limits.

VNX-Secure authenticates, authorizes, detects, contains, audits and recovers for VNX-DNA. It never acts against another system.

ExperimentalIncluded in release v9.0.0

What is implemented

“Verified in software” means covered by committed unit, property or integration tests. It does not mean tested against real attackers.

  • Identity and authentication

    scrypt-hashed secrets, HMAC tokens and revocation

    Verified in software
  • Replay protection

    nonce plus timestamp window

    Verified in software
  • Authorization

    deny-by-default policy where an explicit deny wins; fuzzed

    Verified in software
  • Detection

    16 deterministic rules with an explainable risk score

    Verified in software
  • Containment

    idempotent playbook: session isolation, credential revocation, rate limiting

    Verified in software
  • Audit

    HMAC-chained log with evidence preservation

    Verified in software
  • Sandboxed parsing

    forked child with memory, CPU and time limits; resource isolation, not a code-execution boundary

    Verified in software
  • Attack scenarios

    10 synthetic scenarios detected and contained; 0 false positives over 270 benign requests

    Simulated
  • Network isolation

    an interface with a recording stub only

    Architectural only

What it does not protect

VNX-Secure is not claimed to be unhackable. It is a first defensive layer, tested against synthetic attacks on one host, without external review or real traffic.

  • Bypass

    It enforces policy only for access through its gate. Confidentiality rests on AES-256-GCM and key custody.

  • Host compromise

    An attacker with the same user or root privileges can read the key and rewrite logs. An off-host anchor is future work.

  • Supply chain

    Dependencies are not hash-pinned and releases are not yet signed.

  • Slow attacks

    Fixed thresholds were chosen for clarity, not tuned on real data; activity below them is not detected.

  • Future work

    Post-quantum cryptography is planned, not implemented. VNX-RAM is architectural only.

Full limitations document

VNX-Secure protects VNX-DNA archives. It is not used to protect this website.