Merged into VNX-DNA at V9

VNX-Secure

A defensive control plane around VNX-DNA archives and operations. It decides who may do what, detects misuse deterministically, contains it, records every decision in a tamper-evident log, and restores a known-good state.

Status

VNX-Secure

Defensive control plane for VNX-DNA: deny-by-default policy, deterministic detectors, HMAC-chained audit, integrity snapshots, recovery and a safe attack simulator.

Active
Securityversion 9.0.0sourcedocumentation

What is implemented

  • Identity and deny-by-default policy

    Principals with secrets; every operation is denied unless a policy rule allows it; a known-good policy is kept for recovery.

    implemented
  • Deterministic detection

    16 detectors over request events (for example invalid tokens, rate abuse, path probing) with explainable risk scores.

    implemented
  • Idempotent containment

    Rate limits, locks, session containment, input quarantine and credential revocation.

    implemented
  • HMAC-chained audit log

    Every decision is appended to a hash-chained log with an anchor; vnx security audit verify detects edits.

    implemented
  • Integrity snapshot

    Authenticated baseline of policy and state: VERIFIED, MODIFIED, UNKNOWN or FAILED.

    implemented
  • Recovery state machine

    Verify the audit chain, restore the known-good policy, rotate credentials, re-verify integrity and archives.

    implemented
  • Secure archive gate

    Gated list / verify / locate / extract on VNX archives under the policy.

    implemented
  • Safe attack simulator

    Ten synthetic scenarios run locally with no network access; used for regression testing.

    simulated
  • CLI

    vnx security init | status | integrity | sessions | policy | simulate | recover | crypto | audit.

    implemented

Evidence

BenchmarkClassResultVersion
VNX-Secure simulated attack scenariosSimulated10 / 10 included scenarios detected and contained; 0 findings over 270 benign requests; median detection 4.2 ms, recovery 12.1 msV9

Limits we state plainly

  • Validated against the included simulated attack scenarios only, on one host. Not tested against real attackers or real traffic.
  • No independent audit, penetration test or certification.
  • The CLI trusts the local operating-system user who owns the security home directory.
  • Post-quantum cryptography is planned, not implemented. The cryptographic registry (vnx security crypto) marks each algorithm IMPLEMENTED, PLANNED or EXPERIMENTAL.