Cloud Native
Security Talks
RSS

CloudNativeSecurityCon North America 2023

Security That Enables: Breaking Down Security Silos in the DevOps Ecosystem

Saurabh Wadhwa, Uptycs

Abstract

This talk addresses two core themes: First, the rise in attackers targeting developers and container image repositories to access pre-production resources. Second, good security should enable DevOps teams to better perform their role, secure builds, and remove the stigma that security = roadblocks. First, we break down how traditional CI/CD workflows are siloed from a security tooling perspective. Siloed security tools create gaps when developer ecosystems are targeted, as it’s difficult to trace attackers across environments. Monitoring a developer’s laptop may be completely isolated from the security data from registry scanning, which in turn may be completely isolated from monitoring runtime services. Second, a walkthrough breaking down the step-by-step flow of the recent Dropbox breach where attackers targeted developers and ultimately stole 130 GitHub repositories. This will be a deep dive into how the attackers targeted developers by impersonating CircleCI, with the ultimate goal of stealing GitHub repos and accessing backend infrastructure. And third, we end with a more positive look at how the right security controls (zero-trust access and registry scanning) in the CI/CD process enable developer teams to better perform their roles and more confidently deploy builds.

More from CloudNativeSecurityCon North America 2023

Open in the index →
  1. Zero Trust Workload Identity in KubernetesMichael Peters, Red Hat 2023-02-01
  2. Yes, Application Security Leads to Better Business Value. Learn How from Experts.Larry Carvalho, RobustCloud; Hillary Benson, Gitlab; Kirsten Newcomer, Red Hat; David Zendzian, VMware 2023-02-01
  3. Who Are You? I Really Want to Know… the Magic Behind OIDCEddie Zaneski, Chainguard 2023-02-01
  4. What's a Zero-Trust Tunnel? Exploring Security and Simpler Operations with Istio Ambient MeshJim Barton & Marino Wijay, Solo.io 2023-02-01
  5. Verifiable GitHub Actions with eBPFJose Donizetti & Itay Shakury, Aqua Security 2023-02-01
  6. Unpacking Open Source Security in Public Repos & RegistriesBen Hirschberg, ARMO 2023-02-01
  7. Standardization and Security - A Perfect MatchRavi Devineni & Vinny Carpenter, Northwestern Mutual 2023-02-01
  8. So You Want to Run Your Own Sigstore: Recommendations for a Secure SetupHayden Blauzvern, Google 2023-02-01
  9. Security as Code: A DevSecOps ApproachXavier René-Corail, GitHub 2023-02-01
  10. Security Does Not Need to Be Fun: Ignoring OWASP to Have a Terrible TimeDwayne McDaniel, GitGuardian 2023-02-01
  11. Securing User to Service Access in KubernetesMaya Kaczorowski & Maisem Ali, Tailscale 2023-02-01
  12. Securing Self-Hosted GitHub Actions with Kubernetes and Actions-Runner-ControllerNatalie Somersall, GitHub 2023-02-01
  13. Securing Diverse Supply Chains Across Interconnected SystemsWayne Starr, Defense Unicorns & Aaron Creel, SpaceX 2023-02-01
  14. Package Transparency for WebAssembly RegistriesKyle Brown, SingleStore 2023-02-01
  15. On Establish a Production Zero Trust ArchitectureFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  16. OmniBOR: Bringing the Receipts for Supply Chain SecurityFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  17. Network Security at Scale: L3 Through L7 at SplunkMitch Connors, Aviatrix & Bernard Van De Walle, Splunk 2023-02-01
  18. More Than Just a Pretty Penny! Why You Need Cybersecurity in Your CultureCallan Andreacchi & Michaela Flatau, Defense Unicorns 2023-02-01
  19. Improving Secure Pod-to-Pod Communication Within Kubernetes Using Trust BundlesThomas Edward Hahn, TCB Technologies, Inc & Mark Hahn, Qualys 2023-02-01
  20. Identity Based Segmentation for a ZTAZack Butcher, Tetrate & Ramaswamy Chandramouli, National Institute of Standards and Technology 2023-02-01
  21. How to Secure Your Supply Chain at ScaleHemil Kadakia & Yonghe Zhao, Yahoo 2023-02-01
  22. How Do You Trust Your Open Source Software?Naveen Srinivasan, Endor Labs & Brian Russell, Google 2023-02-01
  23. Get Your Security Priorities Straight! How to Identify Workloads Under Real Threat with ContextBen Hirschberg, ARMO & Arie Haenel, Intel 2023-02-01
  24. From the Cluster to the Cloud: Lateral Movements in KubernetesYossi Weizman & Ram Pliskin, Microsoft 2023-02-01
  25. From Illuminating to Eliminating Crypto Jacking Techniques in Cloud NativeMor Weinberger, Aqua Security 2023-02-01
  26. Finding the Needles in a Haystack: Identifying Suspicious Behaviors with eBPFJeremy Cowan & Wasiq Muhammad, Amazon Web Services 2023-02-01
  27. Demystifying Zero-Trust for Cloud Native TechnologiesKishore Nadendla, TIAA; Mariusz SABATH, IBM Research; Asad Faizi, Eskala.io; Aradhna Chetal, CNCF Security TAG; Philip Griffiths, NetFoundry 2023-02-01
  28. Cryptographic Agility: Preparing Modern Apps for Quantum Safety and BeyondNatalie Fisher, VMware 2023-02-01
  29. Cloud Native Security Landscape: Myths, Dragons, and Real TalkEdd Wilder-James & Loris Degioanni, Sysdig; Kim Lewandowski, Chainguard; Isaac Hepworth, Google; Randall Degges, Snyk 2023-02-01
  30. Cloud Native Security 101: Building Blocks, Patterns and Best PracticesRafik Harabi, Sysdig 2023-02-01
  31. Beyond Cluster-Admin: Getting Started with Kubernetes Users and PermissionsTiffany Jernigan, VMware 2023-02-01
  32. Avoiding IAC Potholes with Policy + Cloud ControllersAndrew Martin, ControlPlane 2023-02-01
  33. No video 🦝 Let’s Talk Software Supply Chains with TAG SecurityMichael Lieberman, Kusari 2023-02-01
  34. Zero Trust in the Cloud with WebAssembly and WasmCloudKevin Hoffman, Cosmonic 2023-02-02
  35. When SysAdmins Quit: Protecting Kubernetes Clusters When the Owner of Multiple Admin KUBECONFIGs QuitsArun Krishnakumar, VMware 2023-02-02
  36. The Four Golden Signals of Security ObservabilityDuffie Cooley, Isovalent 2023-02-02
  37. Taming Attestation for the Cloud Native World with ParsecPaul Howard, Arm 2023-02-02
  38. Spicing up Container Image Security with SLSA & GUACIan Lewis, Google 2023-02-02
  39. Solving Multi-Service Without a Service MeshEvan Anderson, VMware 2023-02-02
  40. Sharing Security Secrets: How to Encourage Security AdvocatesCailyn Edwards, Shopify 2023-02-02
  41. Self Healing GitOps: Continuous, Secure GitOps Using Argo CD, Helm and OPAUpkar Lidder , Tenable 2023-02-02
  42. Security++: Hide Your Secrets via a Distributed Hardware Security ModuleIris Ding & Malini Bhandaru, Intel 2023-02-02
  43. Securing the Superpowers: Who Loaded That EBPF Program?John Fastabend & Natalia Reka Ivanko, Isovalent 2023-02-02
  44. SBOMs, VEX, and KubernetesKiran Kamity, Deepfactor; Jonathan Meadows , Citi; Dr. Allan Friedman, Cybersecurity and Infrastructure Security Agency; Andrew Martin, Control Plane; Rose Judge, VMware 2023-02-02
  45. Not All That’s Signed Is Secure: Verify the Right Way with TUF and SigstoreZachary Newman, Chainguard, Inc. & Marina Moore, New York University 2023-02-02
  46. Modifying the Immutable: Attaching Artifacts to OCI ImagesBrandon Mitchell, BoxBoat, an IBM Company 2023-02-02
  47. Mapping Motives Tells a Story: Analysis of 2,000 Enterprise Cloud DetectionsDavid Wolf & Joshua Smith, Devo 2023-02-02
  48. Leveraging SBOMS to Automate Packaging, Transfer, and Reporting of Dependencies Between Secure EnvironmentsIan Dunbar-Hall & Jerod Heck, Lockheed Martin 2023-02-02
  49. Learning from Supply Chain Failures and Best Practices in Other IndustriesDemian Ginther, Superorbital, LLC 2023-02-02
  50. Keyless Code Signing Without FulcioNathan Smith, Chainguard 2023-02-02
  51. Journey to Cloud-Native, K8s and Trying to Secure It.Graham E. Chukwumaobi, Independent 2023-02-02
  52. Handling JWTs: Understanding Common PitfallsBruce MacDonald, InfraHQ 2023-02-02
  53. Good Fences Make Good Neighbors: Making Cross-Namespace References More Secure with ReferenceGrantNick Young, Isovalent 2023-02-02
  54. Do This, Not That – Lessons from 7 Headline Grabbing Security BreachesMaya Levine, Sysdig 2023-02-02
  55. Delivering Secure Healthcare Applications with OSSRobert Wood, Centers for Medicare and Medicaid Services (CMS) & Gedd Johnson, Defense Unicorns 2023-02-02
  56. Container Patching: Making It Less Gross Than the Seattle Gum WallGreg Castle & Weston Panther, Google 2023-02-02
  57. Container Factory for Aerospace & Defense EnterprisesSarah Miller & Melissa Robertson, Collins Aerospace 2023-02-02
  58. CSI Container: Can You DFIR It?Alberto Pellitteri & Stefano Chierici, Sysdig 2023-02-02
  59. CNI or Service Mesh? Comparing Security Policies Across ProvidersRob Salmond, SuperOrbital & Christine Kim, Google 2023-02-02
  60. 12 Essential Requirements for Policy Enforcement and Governance with OSCALRobert Ficcaglia, SunStone Secure, LLC 2023-02-02
  61. No video 🦝 TAG Security Cloud Native Security Whitepapers OverviewShlomo Zalman Heigh, CyberArk 2023-02-02
  62. No video 🦝 Security Threat Modeling Live from Scratch SessionAndrew Martin, Control Plane 2023-02-02
  63. No video 🦝 A Sneak Peak Into Security Reviews with the CommunityRagashree MC, Carnegie Mellon University 2023-02-02