Cloud Native
Security Talks
RSS

CloudNativeSecurityCon Europe 2022

Real Time Security - eBPF for Preventing attacks

Liz Rice, Isovalent

Abstract

eBPF is used in several cloud native security tools. In some respects it is already being used for preventative security: - Cilium uses eBPF to enforce NetworkPolicy - Default seccomp profiles - more properly called seccomp-bpf - limit the system calls that applications can use When it comes to runtime security, Falco today uses eBPF to detect suspicious application behavior, but this isn’t preventative - it generates alerts that are used asynchronously to react to malicious events. Is this really the best we can do with eBPF? The answer is a resounding “no”. In this talk we’ll dive into demos and code to explore how eBPF can be used for the next generation of security enforcement tooling. This talk will cover: - Why enforcing NetworkPolicy with eBPF has been in place for years, but preventative security for applications has taken longer - How Phantom attacks can compromise the use of basic system call hooks - How other eBPF attachment points, such as BPF LSM, can be used for preventative security You don’t need to know about eBPF to get the most out of this talk, but you will need a basic understanding of kernel and user space, and a willingness to see some C code.Click here to view captioning/translation in the MeetingPlay platform!

More from CloudNativeSecurityCon Europe 2022

Open in the index →
  1. VEX! or... How to Reduce CVE Noise With One Simple Trick!Frederick Kautz 2022-05-16
  2. Using CNCF Best Practices for Software Supply Chain to Guide and Enhance Your Security PostureRyan Gibbons, 3m & Conor Rogers, Stelligent 2022-05-16
  3. The Unexpected Demise of Open Source LibrariesLiran Tal, Synk 2022-05-16
  4. TUF Maintainer Panel DiscussionAndrew Krug, Datadog; Asra Ali, Google; Marina Moore, NYU; Trishank Karthik Kuppusamy, Datadog; & Jussi Kukkonen, VMware 2022-05-16
  5. Security Champions: The What, Why, and HowAnn Marie Fred, Red Hat 2022-05-16
  6. Protect the Pipe! A Policy-based Approach for Securing CI/CD PipelinesShripad Nadgowda, IBM Research & Jim Bugwadia, Nirmata 2022-05-16
  7. Fuzzing the CNCF LandscapeAdam Korczynski & David Korczynski, Ada Logics 2022-05-16
  8. Dissecting the Discovery of the 0-Day Supply Chain Vulnerability in Argo CDMoshe Zioni, Apiiro 2022-05-16
  9. CTF Overview and ExperienceLewis Denham-Parry, Control Plane 2022-05-16
  10. Vanquishing Vulnerabilities in ValenciaAlba Ferri Fitó, Sysdig & Eric Smalling, Synk 2022-05-17
  11. Towards the Hardened Cloud-Native Cornerstone: Container Runtime Protection from Security to PrivacyKailun Qin, Intel 2022-05-17
  12. Top 5 Reasons (and 5 Myths Debunked) to Invest in Securing the Software Supply ChainHector Linares, Microsoft 2022-05-17
  13. Shrinking Software Attack Surface with WebAssembly & CNCF WasmcloudLiam Randall, Cosmonic 2022-05-17
  14. Securing the Supply Chain with WitnessCole Kennedy, TestifySec 2022-05-17
  15. Putting the Supply Chain Pieces together: A Deep Dive into the Secure software FactoryMichael Lieberman, Citi 2022-05-17
  16. Purple Teaming Like Sky’s the Limit – Adversary Emulation in the Cloud with Stratus Red TeamChristophe Tafani-Dereeper, Datadog 2022-05-17
  17. Deep Dive: Serverless Security (STAG Presentation)Andrew J Krug, Datadog; Ragashree M C, Nokia; Ashish Rajan, CISO & Ariel Shuper, Cisco 2022-05-17