Cloud Native
Security Talks
RSS

KubeCon North America 2022

The Insider Threat: Third-Party Applications In Your Cluster

Dagan Henderson, Raft, LLC & Will Kline, Dark Wolf Solutions

Abstract

As powerful as Kubernetes is out-of-the-box, it’s a reasonable bet that your organization’s baseline cluster includes more than just the core Kubernetes components. Service meshes, CSI drivers, admission controllers, and database engines are nearly ubiquitous additions to production-ready clusters. Crucially, these applications allow your organization’s development teams to focus on solving the organization’s unique challenges by building on top of robust third-party solutions that solve common industry problems, but vulnerabilities in third-party code can put the security of your clusters at risk. In this talk, the speakers will briefly review a few examples of real-world vulnerabilities in third-party applications commonly found in large Kubernetes clusters and describe just how they were discovered; demonstrate how critical some vulnerabilities can be; and then review clear, actionable steps your organization can take to help prevent third-party vulnerabilities from being the weak link in your clusters’ security.

More from KubeCon North America 2022

Open in the index →
  1. Using the EBPF Superpowers To Generate Kubernetes Security PoliciesMauricio Vásquez Bernal & Alban Crequy, Microsoft 2022-10-26
  2. Untrusted Execution: Attacking the Cloud Native Supply ChainAndrew Martin, ControlPlane 2022-10-26
  3. Securing the IaC Supply ChainJesse Sanford, Autodesk & Jason Hall, Chainguard 2022-10-26
  4. SLSA FRSCA Recipe For Secure Supply ChainParth Patel & Michael Lieberman, Kusari 2022-10-26
  5. SBOM X-Ray Superpowers: Making Better SBOMs, Using SBOMsBrandon Lum, Google & Chris Phillips, Anchore 2022-10-26
  6. Kubernetes to Cloud Attack Vectors: Demos InsideDanny Hershko Shemesh & Alon Schindel, Wiz 2022-10-26
  7. Armoring Cloud Native Workloads With LSM SuperpowersBarun Acharya, Accuknox 2022-10-26
  8. Securing Edge Workloads With Cert-Manager And SPIFFESitaram IYER & Riaz Mohamed, Jetstack Ltd 2022-10-27
  9. Run As “Root”, Not Root: User Namespaces In K8sMarga Manterola, Isovalent & Rodrigo Campos Catelin, Microsoft 2022-10-27
  10. Path To Production: Sustainable Compliance In Strict EnvironmentsChip Zoller, Nirmata & Brandt Keller, Defense Unicorns 2022-10-27
  11. Migrating From PodSecurityPolicyTim Allclair & Sam Stoelinga, Google 2022-10-27
  12. It's Dangerous To SLSA Alone Out There! Take This Artifact Knowledge Graph!Mihai Maruseac, Google & Michael Lieberman, Independent 2022-10-27
  13. How the Argo Project Transitioned From Security Aware To Security FirstHenrik Blixt & Michael Crenshaw, Intuit 2022-10-27
  14. Hack Back; Let’s Learn Security With CTFs!Lewis Denham-Parry, Chainguard & Natalia Reka Ivanko, Isovalent 2022-10-27
  15. You Like It Or Not; You Need It! - PKI And Certificate ManagementShweta Vohra, IBM 2022-10-28
  16. What Data Tells Us About Software Supply Chain Security & What To Do About ItJosh Bressers, Anchore; Tracy Miranda, Chainguard; John Yeoh, Cloud Security Alliance; Eric Tice, Wipro 2022-10-28
  17. Tutorial: Reducing the Sticker Price Of Kubernetes SecurityPushkar Joglekar, VMware 2022-10-28
  18. So, SBOMs Matter…Now What?Sophie Wigmore & Frankie Gallina-Jones, VMware 2022-10-28
  19. Putting Hackers Breaching Your Cluster In Automatic QuarantineZiv Nevo, IBM 2022-10-28
  20. Fuzzing Session: Finding Bugs and Vulnerabilities AutomaticallyDavid Korczynski & Adam Korczynski, Ada Logics 2022-10-28
  21. B’Envoy-age to Pre-Quantum EncryptionDaniel Rouhana, Independent; Emma Dickenson, Washington State University; Doron Podoleanu, F5 2022-10-28