Cloud Native
Security Talks
RSS

CloudNativeSecurityCon North America 2023

Spicing up Container Image Security with SLSA & GUAC

Ian Lewis, Google

Abstract

Understanding and verifying the content of images that you deploy in production environments is difficult and error prone. Images could be built in an insecure environment, by a malicious actor, or include dependencies that are insecure. Users often don’t have enough information to determine if images are trustworthy. Two new tools can help; Supply chain Levels for Software Artifacts (SLSA), and Graph for Understanding Artifact Composition (GUAC). In this talk attendees will learn how to add SLSA provenance metadata to their container images and strongly link images back to their source code on multiple build systems including GitHub Actions and Google Cloud Build. We will also cover how to verify images and their metadata before use; both when running locally and when running images in Kubernetes. Using policy engines like Kyverno and Sigstore policy-controller we can verify an image’s source code repository, builder identity, build entry points, and more to protect production environments from malicious images. Finally we’ll discuss how to understand your image’s supply chain using GUAC. We’ll discuss how we can combine SLSA with GUAC to better understand the contents and build provenance of your images from the base layers on down.

More from CloudNativeSecurityCon North America 2023

Open in the index →
  1. Zero Trust Workload Identity in KubernetesMichael Peters, Red Hat 2023-02-01
  2. Yes, Application Security Leads to Better Business Value. Learn How from Experts.Larry Carvalho, RobustCloud; Hillary Benson, Gitlab; Kirsten Newcomer, Red Hat; David Zendzian, VMware 2023-02-01
  3. Who Are You? I Really Want to Know… the Magic Behind OIDCEddie Zaneski, Chainguard 2023-02-01
  4. What's a Zero-Trust Tunnel? Exploring Security and Simpler Operations with Istio Ambient MeshJim Barton & Marino Wijay, Solo.io 2023-02-01
  5. Verifiable GitHub Actions with eBPFJose Donizetti & Itay Shakury, Aqua Security 2023-02-01
  6. Unpacking Open Source Security in Public Repos & RegistriesBen Hirschberg, ARMO 2023-02-01
  7. Standardization and Security - A Perfect MatchRavi Devineni & Vinny Carpenter, Northwestern Mutual 2023-02-01
  8. So You Want to Run Your Own Sigstore: Recommendations for a Secure SetupHayden Blauzvern, Google 2023-02-01
  9. Security as Code: A DevSecOps ApproachXavier René-Corail, GitHub 2023-02-01
  10. Security Does Not Need to Be Fun: Ignoring OWASP to Have a Terrible TimeDwayne McDaniel, GitGuardian 2023-02-01
  11. Securing User to Service Access in KubernetesMaya Kaczorowski & Maisem Ali, Tailscale 2023-02-01
  12. Securing Self-Hosted GitHub Actions with Kubernetes and Actions-Runner-ControllerNatalie Somersall, GitHub 2023-02-01
  13. Securing Diverse Supply Chains Across Interconnected SystemsWayne Starr, Defense Unicorns & Aaron Creel, SpaceX 2023-02-01
  14. Package Transparency for WebAssembly RegistriesKyle Brown, SingleStore 2023-02-01
  15. On Establish a Production Zero Trust ArchitectureFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  16. OmniBOR: Bringing the Receipts for Supply Chain SecurityFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  17. Network Security at Scale: L3 Through L7 at SplunkMitch Connors, Aviatrix & Bernard Van De Walle, Splunk 2023-02-01
  18. More Than Just a Pretty Penny! Why You Need Cybersecurity in Your CultureCallan Andreacchi & Michaela Flatau, Defense Unicorns 2023-02-01
  19. Improving Secure Pod-to-Pod Communication Within Kubernetes Using Trust BundlesThomas Edward Hahn, TCB Technologies, Inc & Mark Hahn, Qualys 2023-02-01
  20. Identity Based Segmentation for a ZTAZack Butcher, Tetrate & Ramaswamy Chandramouli, National Institute of Standards and Technology 2023-02-01
  21. How to Secure Your Supply Chain at ScaleHemil Kadakia & Yonghe Zhao, Yahoo 2023-02-01
  22. How Do You Trust Your Open Source Software?Naveen Srinivasan, Endor Labs & Brian Russell, Google 2023-02-01
  23. Get Your Security Priorities Straight! How to Identify Workloads Under Real Threat with ContextBen Hirschberg, ARMO & Arie Haenel, Intel 2023-02-01
  24. From the Cluster to the Cloud: Lateral Movements in KubernetesYossi Weizman & Ram Pliskin, Microsoft 2023-02-01
  25. From Illuminating to Eliminating Crypto Jacking Techniques in Cloud NativeMor Weinberger, Aqua Security 2023-02-01
  26. Finding the Needles in a Haystack: Identifying Suspicious Behaviors with eBPFJeremy Cowan & Wasiq Muhammad, Amazon Web Services 2023-02-01
  27. Demystifying Zero-Trust for Cloud Native TechnologiesKishore Nadendla, TIAA; Mariusz SABATH, IBM Research; Asad Faizi, Eskala.io; Aradhna Chetal, CNCF Security TAG; Philip Griffiths, NetFoundry 2023-02-01
  28. Cryptographic Agility: Preparing Modern Apps for Quantum Safety and BeyondNatalie Fisher, VMware 2023-02-01
  29. Cloud Native Security Landscape: Myths, Dragons, and Real TalkEdd Wilder-James & Loris Degioanni, Sysdig; Kim Lewandowski, Chainguard; Isaac Hepworth, Google; Randall Degges, Snyk 2023-02-01
  30. Cloud Native Security 101: Building Blocks, Patterns and Best PracticesRafik Harabi, Sysdig 2023-02-01
  31. Beyond Cluster-Admin: Getting Started with Kubernetes Users and PermissionsTiffany Jernigan, VMware 2023-02-01
  32. Avoiding IAC Potholes with Policy + Cloud ControllersAndrew Martin, ControlPlane 2023-02-01
  33. No video 🦝 Let’s Talk Software Supply Chains with TAG SecurityMichael Lieberman, Kusari 2023-02-01
  34. Zero Trust in the Cloud with WebAssembly and WasmCloudKevin Hoffman, Cosmonic 2023-02-02
  35. When SysAdmins Quit: Protecting Kubernetes Clusters When the Owner of Multiple Admin KUBECONFIGs QuitsArun Krishnakumar, VMware 2023-02-02
  36. The Four Golden Signals of Security ObservabilityDuffie Cooley, Isovalent 2023-02-02
  37. Taming Attestation for the Cloud Native World with ParsecPaul Howard, Arm 2023-02-02
  38. Solving Multi-Service Without a Service MeshEvan Anderson, VMware 2023-02-02
  39. Sharing Security Secrets: How to Encourage Security AdvocatesCailyn Edwards, Shopify 2023-02-02
  40. Self Healing GitOps: Continuous, Secure GitOps Using Argo CD, Helm and OPAUpkar Lidder , Tenable 2023-02-02
  41. Security That Enables: Breaking Down Security Silos in the DevOps EcosystemSaurabh Wadhwa, Uptycs 2023-02-02
  42. Security++: Hide Your Secrets via a Distributed Hardware Security ModuleIris Ding & Malini Bhandaru, Intel 2023-02-02
  43. Securing the Superpowers: Who Loaded That EBPF Program?John Fastabend & Natalia Reka Ivanko, Isovalent 2023-02-02
  44. SBOMs, VEX, and KubernetesKiran Kamity, Deepfactor; Jonathan Meadows , Citi; Dr. Allan Friedman, Cybersecurity and Infrastructure Security Agency; Andrew Martin, Control Plane; Rose Judge, VMware 2023-02-02
  45. Not All That’s Signed Is Secure: Verify the Right Way with TUF and SigstoreZachary Newman, Chainguard, Inc. & Marina Moore, New York University 2023-02-02
  46. Modifying the Immutable: Attaching Artifacts to OCI ImagesBrandon Mitchell, BoxBoat, an IBM Company 2023-02-02
  47. Mapping Motives Tells a Story: Analysis of 2,000 Enterprise Cloud DetectionsDavid Wolf & Joshua Smith, Devo 2023-02-02
  48. Leveraging SBOMS to Automate Packaging, Transfer, and Reporting of Dependencies Between Secure EnvironmentsIan Dunbar-Hall & Jerod Heck, Lockheed Martin 2023-02-02
  49. Learning from Supply Chain Failures and Best Practices in Other IndustriesDemian Ginther, Superorbital, LLC 2023-02-02
  50. Keyless Code Signing Without FulcioNathan Smith, Chainguard 2023-02-02
  51. Journey to Cloud-Native, K8s and Trying to Secure It.Graham E. Chukwumaobi, Independent 2023-02-02
  52. Handling JWTs: Understanding Common PitfallsBruce MacDonald, InfraHQ 2023-02-02
  53. Good Fences Make Good Neighbors: Making Cross-Namespace References More Secure with ReferenceGrantNick Young, Isovalent 2023-02-02
  54. Do This, Not That – Lessons from 7 Headline Grabbing Security BreachesMaya Levine, Sysdig 2023-02-02
  55. Delivering Secure Healthcare Applications with OSSRobert Wood, Centers for Medicare and Medicaid Services (CMS) & Gedd Johnson, Defense Unicorns 2023-02-02
  56. Container Patching: Making It Less Gross Than the Seattle Gum WallGreg Castle & Weston Panther, Google 2023-02-02
  57. Container Factory for Aerospace & Defense EnterprisesSarah Miller & Melissa Robertson, Collins Aerospace 2023-02-02
  58. CSI Container: Can You DFIR It?Alberto Pellitteri & Stefano Chierici, Sysdig 2023-02-02
  59. CNI or Service Mesh? Comparing Security Policies Across ProvidersRob Salmond, SuperOrbital & Christine Kim, Google 2023-02-02
  60. 12 Essential Requirements for Policy Enforcement and Governance with OSCALRobert Ficcaglia, SunStone Secure, LLC 2023-02-02
  61. No video 🦝 TAG Security Cloud Native Security Whitepapers OverviewShlomo Zalman Heigh, CyberArk 2023-02-02
  62. No video 🦝 Security Threat Modeling Live from Scratch SessionAndrew Martin, Control Plane 2023-02-02
  63. No video 🦝 A Sneak Peak Into Security Reviews with the CommunityRagashree MC, Carnegie Mellon University 2023-02-02