Cloud Native
Security Talks
RSS

CloudNativeSecurityCon North America 2022

The Eye of Falco: You Can Escape but Not Hide

Stefano Chierici & Lorenzo Susini, Sysdig

Abstract

Container technologies rely on features like namespaces, cgroups, SecComp filters, and capabilities to isolate different services running on the same host. However, SPOILER ALERT: container isolation isn’t bulletproof. Similar to other security environments, isolation is followed by red-teamer questions such as, “How can I de-isolate from this?” Designed with the principle of least privilege in mind, capabilities provide a way to isolate containers, splitting the power of the root user into multiple units. However, having lots of capabilities introduces complexity and a consequent increase of excessively misconfigured permissions and container escape exploits, as we have seen in recently discovered CVEs. Fortunately using Falco, a CNCF container runtime security tool, it’s possible to monitor Linux capabilities, detect misconfigured containers, and proactively respond to secure environments. In this talk, we explain how you can use Falco to detect and monitor container escaping techniques based on capabilities. We walk through show real-world scenarios based on recent CVEs to show where Falco can help in detection and automatically respond to those behaviors

More from CloudNativeSecurityCon North America 2022

Open in the index →
  1. Why Machines Deserve Rights: Rethinking Automated Infrastructure Access with OSS Teleport Machine IDKenneth DuMez, Teleport 2022-10-24
  2. Verifiable eBPF Traces for Supply Chain Artifacts with Witness and TetragonCole Kennedy, TestifySec 2022-10-24
  3. Uncovering the History of Your Software ArtifactsMikhail Swift, TestifySec 2022-10-24
  4. Securing Access to Kubernetes Infrastructure with Kubernetes Zero Trust PrinciplesMohan Atreya, Rafay Systems 2022-10-24
  5. Panel Discussion: Securing the Golden Path: Adding Guardrails for Developers Without Getting in Their Way!Aradhna Chetal, TIAA; Elizabeth Vasquez Alban, Barclays; Kapil Bareja, Saviyant; Jim Bugwadia, Nirmata & Anil Karmel, RegScale 2022-10-24
  6. How’s Your Supply Chain with Your Insecure OSS Ingestion?James Holland, Citi 2022-10-24
  7. Day in the Life of a Base Image: The Evolution of Vulnerabilities in the Most Popular ContainersAyse Kaya, Slim.AI 2022-10-24
  8. Conan.Io – Lessons Learned from Securing 40,000 C++ PackagesDiego Rodriguez-Losada Gonzalez, JFrog 2022-10-24
  9. Cloud Native Security for the Rest of UsTiffany Jernigan, VMware 2022-10-24
  10. Building Images for the Secure Supply ChainAdrian Mouat, Chainguard 2022-10-24
  11. Source Attestations with GitsignBilly Lynch, Chainguard 2022-10-25
  12. See It to Believe It: Bringing Observability to Otherwise Opaque Container BuildsParth Patel, Kusari & Shripad Nadgowda, Intel 2022-10-25
  13. Secure CI/CD Using JSON Web Token (JWT)Dov Hershkovitch, GitLab 2022-10-25
  14. Pwning the CI (with GitHub Action Workflows)Stephen Giguere, Bridgecrew 2022-10-25
  15. Policy-Based Governance for End-to-End Integrity Control of PoliciesYuji Watanabe, IBM Research & Jayashree Ramanathan, Red Hat 2022-10-25
  16. Panel Discussion: Say Hi to the New Couple in the Town – DockerSlim and Kyverno – Making Your Kubernetes Workloads More Secure!Mritunjay Sharma, Slim.AI; Shuting Zhao , Nirmata; Ruhika Bulani, D.Y. Patil College of Engineering, Aku 2022-10-25
  17. Know Your Dependencies: A Guide to Automating Dependency AssuranceSteve Judd, Jetstack 2022-10-25
  18. Introducing the OWASP Top Ten for KubernetesJimmy Mesta, KSOC Labs, Inc. 2022-10-25
  19. Getting More Confident with Your Security Helper Libraries Thanks to Go FuzzingJeremy Matos, Grafana Labs 2022-10-25
  20. Fileless Attack - Detecting the UndetectableCarolina Valencia, Aqua Security 2022-10-25
  21. Beyond Proof of Concept: Keys to a Successful SPIRE Rollout in ProductionEli Nesterov, N/A 2022-10-25