Hacker News new | ask | show | jobs
by valenciarose 2953 days ago
What about translation of rule subsets to other enforcement mechanisms? ACLs and rules for physical infrastructure like switches and routers being one possible target where embedding the agent itself may be impractical. I understand that SDN dominates the core infrastructure, but more traditional infrastructure is frequently in place closer to enterprise users. The point being defense in depth, rather than relying on physical infrastructure as a sole enforcement mechanism.