Cloud Native
Security Talks
RSS

CloudNativeSecurityCon North America 2023

Unpacking Open Source Security in Public Repos & Registries

Ben Hirschberg, ARMO

Abstract

The container ecosystem has exploded in the decade since it’s been introduced, with containers becoming the backbone for the way be package, deploy, orchestrate, schedule & operate our production applications. It’s no surprise then, that so many public facing resources have popped up over the years, both complementary open source projects & public registries that aggregate commonly used container images. In this talk we will unveil data from first of its kind research conducted by scanning the most popular and widely adopted open source projects––from Grafana to Prometheus, Lens, Helm, ArgoCD and others to the public registries from which we pull our base images––from DockerHub, Quay, to GCR, & ECR. We will share how these public-facing resources leveraged by practically all developers stack up against common compliance frameworks - CIS, MITRE ATT&CK®, NIST, NSA-CISA, the most common misconfigs, prevalence of well-known CVEs (through a Log4J example) with a look at the stats & hard numbers, and any other red flags you need to be aware of when leveraging public resources. We will wrap up with a risk analysis and scoring of the resources, highlight the risks to pay attention to, & provide some best practices to keep your systems & ops safe in this evolving security landscape.

More from CloudNativeSecurityCon North America 2023

Open in the index →
  1. Zero Trust Workload Identity in KubernetesMichael Peters, Red Hat 2023-02-01
  2. Yes, Application Security Leads to Better Business Value. Learn How from Experts.Larry Carvalho, RobustCloud; Hillary Benson, Gitlab; Kirsten Newcomer, Red Hat; David Zendzian, VMware 2023-02-01
  3. Who Are You? I Really Want to Know… the Magic Behind OIDCEddie Zaneski, Chainguard 2023-02-01
  4. What's a Zero-Trust Tunnel? Exploring Security and Simpler Operations with Istio Ambient MeshJim Barton & Marino Wijay, Solo.io 2023-02-01
  5. Verifiable GitHub Actions with eBPFJose Donizetti & Itay Shakury, Aqua Security 2023-02-01
  6. Standardization and Security - A Perfect MatchRavi Devineni & Vinny Carpenter, Northwestern Mutual 2023-02-01
  7. So You Want to Run Your Own Sigstore: Recommendations for a Secure SetupHayden Blauzvern, Google 2023-02-01
  8. Security as Code: A DevSecOps ApproachXavier René-Corail, GitHub 2023-02-01
  9. Security Does Not Need to Be Fun: Ignoring OWASP to Have a Terrible TimeDwayne McDaniel, GitGuardian 2023-02-01
  10. Securing User to Service Access in KubernetesMaya Kaczorowski & Maisem Ali, Tailscale 2023-02-01
  11. Securing Self-Hosted GitHub Actions with Kubernetes and Actions-Runner-ControllerNatalie Somersall, GitHub 2023-02-01
  12. Securing Diverse Supply Chains Across Interconnected SystemsWayne Starr, Defense Unicorns & Aaron Creel, SpaceX 2023-02-01
  13. Package Transparency for WebAssembly RegistriesKyle Brown, SingleStore 2023-02-01
  14. On Establish a Production Zero Trust ArchitectureFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  15. OmniBOR: Bringing the Receipts for Supply Chain SecurityFrederick Kautz, SPIFFE/SPIRE 2023-02-01
  16. Network Security at Scale: L3 Through L7 at SplunkMitch Connors, Aviatrix & Bernard Van De Walle, Splunk 2023-02-01
  17. More Than Just a Pretty Penny! Why You Need Cybersecurity in Your CultureCallan Andreacchi & Michaela Flatau, Defense Unicorns 2023-02-01
  18. Improving Secure Pod-to-Pod Communication Within Kubernetes Using Trust BundlesThomas Edward Hahn, TCB Technologies, Inc & Mark Hahn, Qualys 2023-02-01
  19. Identity Based Segmentation for a ZTAZack Butcher, Tetrate & Ramaswamy Chandramouli, National Institute of Standards and Technology 2023-02-01
  20. How to Secure Your Supply Chain at ScaleHemil Kadakia & Yonghe Zhao, Yahoo 2023-02-01
  21. How Do You Trust Your Open Source Software?Naveen Srinivasan, Endor Labs & Brian Russell, Google 2023-02-01
  22. Get Your Security Priorities Straight! How to Identify Workloads Under Real Threat with ContextBen Hirschberg, ARMO & Arie Haenel, Intel 2023-02-01
  23. From the Cluster to the Cloud: Lateral Movements in KubernetesYossi Weizman & Ram Pliskin, Microsoft 2023-02-01
  24. From Illuminating to Eliminating Crypto Jacking Techniques in Cloud NativeMor Weinberger, Aqua Security 2023-02-01
  25. Finding the Needles in a Haystack: Identifying Suspicious Behaviors with eBPFJeremy Cowan & Wasiq Muhammad, Amazon Web Services 2023-02-01
  26. Demystifying Zero-Trust for Cloud Native TechnologiesKishore Nadendla, TIAA; Mariusz SABATH, IBM Research; Asad Faizi, Eskala.io; Aradhna Chetal, CNCF Security TAG; Philip Griffiths, NetFoundry 2023-02-01
  27. Cryptographic Agility: Preparing Modern Apps for Quantum Safety and BeyondNatalie Fisher, VMware 2023-02-01
  28. Cloud Native Security Landscape: Myths, Dragons, and Real TalkEdd Wilder-James & Loris Degioanni, Sysdig; Kim Lewandowski, Chainguard; Isaac Hepworth, Google; Randall Degges, Snyk 2023-02-01
  29. Cloud Native Security 101: Building Blocks, Patterns and Best PracticesRafik Harabi, Sysdig 2023-02-01
  30. Beyond Cluster-Admin: Getting Started with Kubernetes Users and PermissionsTiffany Jernigan, VMware 2023-02-01
  31. Avoiding IAC Potholes with Policy + Cloud ControllersAndrew Martin, ControlPlane 2023-02-01
  32. No video 🦝 Let’s Talk Software Supply Chains with TAG SecurityMichael Lieberman, Kusari 2023-02-01
  33. Zero Trust in the Cloud with WebAssembly and WasmCloudKevin Hoffman, Cosmonic 2023-02-02
  34. When SysAdmins Quit: Protecting Kubernetes Clusters When the Owner of Multiple Admin KUBECONFIGs QuitsArun Krishnakumar, VMware 2023-02-02
  35. The Four Golden Signals of Security ObservabilityDuffie Cooley, Isovalent 2023-02-02
  36. Taming Attestation for the Cloud Native World with ParsecPaul Howard, Arm 2023-02-02
  37. Spicing up Container Image Security with SLSA & GUACIan Lewis, Google 2023-02-02
  38. Solving Multi-Service Without a Service MeshEvan Anderson, VMware 2023-02-02
  39. Sharing Security Secrets: How to Encourage Security AdvocatesCailyn Edwards, Shopify 2023-02-02
  40. Self Healing GitOps: Continuous, Secure GitOps Using Argo CD, Helm and OPAUpkar Lidder , Tenable 2023-02-02
  41. Security That Enables: Breaking Down Security Silos in the DevOps EcosystemSaurabh Wadhwa, Uptycs 2023-02-02
  42. Security++: Hide Your Secrets via a Distributed Hardware Security ModuleIris Ding & Malini Bhandaru, Intel 2023-02-02
  43. Securing the Superpowers: Who Loaded That EBPF Program?John Fastabend & Natalia Reka Ivanko, Isovalent 2023-02-02
  44. SBOMs, VEX, and KubernetesKiran Kamity, Deepfactor; Jonathan Meadows , Citi; Dr. Allan Friedman, Cybersecurity and Infrastructure Security Agency; Andrew Martin, Control Plane; Rose Judge, VMware 2023-02-02
  45. Not All That’s Signed Is Secure: Verify the Right Way with TUF and SigstoreZachary Newman, Chainguard, Inc. & Marina Moore, New York University 2023-02-02
  46. Modifying the Immutable: Attaching Artifacts to OCI ImagesBrandon Mitchell, BoxBoat, an IBM Company 2023-02-02
  47. Mapping Motives Tells a Story: Analysis of 2,000 Enterprise Cloud DetectionsDavid Wolf & Joshua Smith, Devo 2023-02-02
  48. Leveraging SBOMS to Automate Packaging, Transfer, and Reporting of Dependencies Between Secure EnvironmentsIan Dunbar-Hall & Jerod Heck, Lockheed Martin 2023-02-02
  49. Learning from Supply Chain Failures and Best Practices in Other IndustriesDemian Ginther, Superorbital, LLC 2023-02-02
  50. Keyless Code Signing Without FulcioNathan Smith, Chainguard 2023-02-02
  51. Journey to Cloud-Native, K8s and Trying to Secure It.Graham E. Chukwumaobi, Independent 2023-02-02
  52. Handling JWTs: Understanding Common PitfallsBruce MacDonald, InfraHQ 2023-02-02
  53. Good Fences Make Good Neighbors: Making Cross-Namespace References More Secure with ReferenceGrantNick Young, Isovalent 2023-02-02
  54. Do This, Not That – Lessons from 7 Headline Grabbing Security BreachesMaya Levine, Sysdig 2023-02-02
  55. Delivering Secure Healthcare Applications with OSSRobert Wood, Centers for Medicare and Medicaid Services (CMS) & Gedd Johnson, Defense Unicorns 2023-02-02
  56. Container Patching: Making It Less Gross Than the Seattle Gum WallGreg Castle & Weston Panther, Google 2023-02-02
  57. Container Factory for Aerospace & Defense EnterprisesSarah Miller & Melissa Robertson, Collins Aerospace 2023-02-02
  58. CSI Container: Can You DFIR It?Alberto Pellitteri & Stefano Chierici, Sysdig 2023-02-02
  59. CNI or Service Mesh? Comparing Security Policies Across ProvidersRob Salmond, SuperOrbital & Christine Kim, Google 2023-02-02
  60. 12 Essential Requirements for Policy Enforcement and Governance with OSCALRobert Ficcaglia, SunStone Secure, LLC 2023-02-02
  61. No video 🦝 TAG Security Cloud Native Security Whitepapers OverviewShlomo Zalman Heigh, CyberArk 2023-02-02
  62. No video 🦝 Security Threat Modeling Live from Scratch SessionAndrew Martin, Control Plane 2023-02-02
  63. No video 🦝 A Sneak Peak Into Security Reviews with the CommunityRagashree MC, Carnegie Mellon University 2023-02-02