Cloud Native
Security Talks
RSS

KubeCon North America 2021

Keeping Up with the CVEs: How to Find a Needle in a Haystack?

Pushkar Joglekar, VMware

Abstract

An end user team bought a new product that ships as a set of container images. Their CISO requests a scan of the images before going live. The internal scan, to everyone’s surprise results in 314159 vulnerabilities. The CISO is furious & rejects any claims that the scanner is faulty, since it worked fine for VM images. After multiple back and forth exchanges with the product’s vendor, the vast majority of the detected vulnerabilities are false positives / do not have a fix / are not in the code execution path. Everyone breathes a sigh of relief until a few weeks later, the same thing happens for another product & the story repeats itself. It does not have to be this way! In this talk using the Kubernetes images as an example we will unravel how vulnerability scanners work, their blind spots and discuss how to implement a practical approach that allows end users to assess product’s security not by the raw vulnerability numbers & severity but by the risk it poses to their environment.

More from KubeCon North America 2021

Open in the index →
  1. sigstore: How We Started, Where We Are, Where We are HeadedBob Callaway, Red Hat & Dan Lorenc, Google 2021-10-13
  2. My Container Image has 500 Vulnerabilities, Now What?Matt Jarvis, Snyk 2021-10-13
  3. Kubernetes Supply Chain Security: The Software FactoryAndrew Martin, Control Plane 2021-10-13
  4. Kubernetes Exposed! Seven of Nine Hidden Secrets That Will Give You PauseIan Coldwater, Twilio & Brad Geesaman, Aqua Security 2021-10-13
  5. Exploiting a Slightly Peculiar Volume Configuration with SIG-HonkIan Coldwater, Twilio; Brad Geesaman & Rory McCune, Aqua Security; Duffie Cooley, Isovalent 2021-10-13
  6. Untangling the Multi-Cloud Identity and Access Problem With SPIFFE TornjakBrandon Lum & Mariusz Sabath, IBM 2021-10-14
  7. Know Your Enemy: Mapping Security Risks Using Threat Matrix for KubernetesYossi Weizman & Ram Pliskin, Microsoft 2021-10-14
  8. Insights into Unsecured Kubernetes in the WildJay Chen & Aviv Sasson, Palo Alto Networks 2021-10-14
  9. Fine-Grained User Authorization for Kubernetes with OPA and LDAPCagri Cetin & Quentin Long, Yelp Inc. 2021-10-14
  10. We Built the Kubernetes SBOM and Now You Can Write Your Own!Adolfo García Veytia, uServers 2021-10-15
  11. The Hitchhiker's Guide to Kubernetes VulnerabilitiesRobert Clark & Micah Hausler, Amazon 2021-10-15
  12. Everything Wrong with K8s Authentication and How We Worked Around ItMo Khan & Margo Crawford, VMware 2021-10-15
  13. Bridging the Great Divide: SPIFFE/SPIRE for Cross-Cluster AuthenticationAndrew Harding, VMware 2021-10-15