---
title: "New Tigera Secure Enterprise 2.3 Anomaly Detection Deepens Visibility into Suspicious Kubernetes Activities"
source: "https://www.tigera.io/blog/new-tigera-secure-enterprise-2-3-anomaly-detection-deepens-visibility-into-suspicious-kubernetes-activities/"
---

[Company Blog](https://www.tigera.io/category/company-blog/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# New Tigera Secure Enterprise 2.3 Anomaly Detection Deepens Visibility into Suspicious Kubernetes Activities

By [Vince Lau](https://www.tigera.io/blog/author/vincetigera-io/) on Feb 20, 2019 • 3 min read

## Advancements in machine learning, unified policy, cloud integration, flow log, and user interface bolster Kubernetes security efficacy and operations efficiency.

Tigera is excited to announce several new capabilities with [Tigera Secure Enterprise Edition](https://www.tigera.io/tigera-products/compare-products/) 2.3, extending the ability to uncover sophisticated Kubernetes attacks. Tigera Anomaly Detection capabilities provide insight into unusual behaviors that compromise the security and performance of Kubernetes environments. The solution offers the best of breed anomaly detection by offering both machine learning and rule-based capabilities to handle large and complex Kubernetes network datasets. This release empowers businesses to detect and respond to reconnaissance scans, protocol deviation activities, and volumetric deviations activities. Detailed forensics for every detection enable security teams to resolve incidents faster than before. This major product release demonstrates Tigera’s long-term vision to deliver a comprehensive Kubernetes network security solution.

![Tigera Secure Enterprise Edition 2.3 anomaly detection timeline showing top influencers and unusual behaviors in Kubernetes](/app/uploads/2019/02/tigera-AD-UI-FINAL.png)

*Figure 1 – Kubernetes pod anomaly behavior heatmap provided within Tigera Secure Enterprise Edition 2.3.*

In addition to the new Anomaly Detection features, Tigera Secure Enterprise Edition 2.3 also brings the following additional capabilities:

- - Enterprise Calico Policy – Enhanced with web application security support. The solution enables a single location for multi-layer enforcement with network and web application security policies. Multi-layer enforcement increases operations efficiency by reducing the need to write and manage multiple policies for different layers. In addition, Enterprise Calico Policy provides tiering and web application visibility capabilities beyond Open Source Calico Policy. Tiering capabilities enable enterprise teams to collaborate in a concurrent manner. Web application security insight helps meet security and compliance requirements.

 

- - Security Groups and Kubernetes Policy Integration – Enables fine-grained policy control within Amazon Web Services (AWS) Security Groups. This capability allows access control between VPC members and pods, and vice versa. The solution extends a zero-trust security model to non-Kubernetes resources within VPC members by integrating Network Policy and AWS Security Groups.

 

- - Network Flow and Audit Log — Enhanced flow logs with web application workload context containing allowed and denied HTTPS requests. Audit logs provide detail around authorized and unauthorized policy changes. Log retention has been extended to seven days for flow logs and a year for audit logs. Amazon S3 integration easily enables offline storage that helps meet multiple-year compliance retention requirements.

 

- User Interface with RBAC — Improved user interface with role-based access control (RBAC) that enables teams such as DevOps, Platform, and Security to have their own proper level of access. Each team can now resolve security and operational issues quicker with access to their own set of network flow data. Administrators can operate in a more efficient manner by delegating network troubleshooting to individual DevOps teams instead of relying on a centralized function.

 

## Highlights of Tigera Secure Enterprise Edition 2.3

This new release builds upon the proven success of Tigera Secure Enterprise Edition. Large and complex Kubernetes network datasets make it difficult to detect malicious activities with traditional monitoring tools.

Anomaly Detection, powered by machine learning, deepens visibly into sophisticated Kubernetes attacks. It also addresses an essential compliance requirement by monitoring infrastructure and applications for unexpected behavior. Enterprise Calico Policy enables unified defense-in-depth web application security, even when infrastructure is compromised. Security Groups’ integration enhances Kubernetes’ security posture with fine-grain access control between resources in AWS security groups. The enhanced network flow and audit logs help address ever-growing compliance requirements. The new RBAC UI enhancements empower teams to work independently and also collaborate to resolve outage, security, and monitoring issues with Kubernetes.

Please [schedule a demo](https://www.tigera.io/demo/) for more information.

————————————————-

[**Free Online Training**](https://www.tigera.io/events/)

Access Live and On-Demand Kubernetes Tutorials

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Solve Common Kubernetes Roadblocks and Advance Your Enterprise Adoption

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6529 metric#misses=16 metric#hit-ratio=99.8 metric#bytes=2019641 metric#prefetches=416 metric#store-reads=29 metric#store-writes=10 metric#store-hits=424 metric#store-misses=5 metric#sql-queries=28 metric#ms-total=1008.86 metric#ms-cache=18.73 metric#ms-cache-avg=0.4928 metric#ms-cache-ratio=1.9 -->
