Merged into VNX-DNA at V9
VNX-Secure
A defensive control plane around VNX-DNA archives and operations. It decides who may do what, detects misuse deterministically, contains it, records every decision in a tamper-evident log, and restores a known-good state.
Status
VNX-Secure
Defensive control plane for VNX-DNA: deny-by-default policy, deterministic detectors, HMAC-chained audit, integrity snapshots, recovery and a safe attack simulator.
What is implemented
Identity and deny-by-default policy
Principals with secrets; every operation is denied unless a policy rule allows it; a known-good policy is kept for recovery.
implementedDeterministic detection
16 detectors over request events (for example invalid tokens, rate abuse, path probing) with explainable risk scores.
implementedIdempotent containment
Rate limits, locks, session containment, input quarantine and credential revocation.
implementedHMAC-chained audit log
Every decision is appended to a hash-chained log with an anchor;
implementedvnx security audit verifydetects edits.Integrity snapshot
Authenticated baseline of policy and state: VERIFIED, MODIFIED, UNKNOWN or FAILED.
implementedRecovery state machine
Verify the audit chain, restore the known-good policy, rotate credentials, re-verify integrity and archives.
implementedSecure archive gate
Gated list / verify / locate / extract on VNX archives under the policy.
implementedSafe attack simulator
Ten synthetic scenarios run locally with no network access; used for regression testing.
simulatedCLI
implementedvnx security init | status | integrity | sessions | policy | simulate | recover | crypto | audit.
Evidence
| Benchmark | Class | Result | Version |
|---|---|---|---|
| VNX-Secure simulated attack scenarios | Simulated | 10 / 10 included scenarios detected and contained; 0 findings over 270 benign requests; median detection 4.2 ms, recovery 12.1 ms | V9 |
Limits we state plainly
- Validated against the included simulated attack scenarios only, on one host. Not tested against real attackers or real traffic.
- No independent audit, penetration test or certification.
- The CLI trusts the local operating-system user who owns the security home directory.
- Post-quantum cryptography is planned, not implemented. The cryptographic registry (
vnx security crypto) marks each algorithm IMPLEMENTED, PLANNED or EXPERIMENTAL.