Cloud Native
Security Talks
RSS

KubeCon Europe 2019

DIY Pen-Testing for Your Kubernetes Cluster

Liz Rice, Aqua Security

Abstract

See how to use kube-hunter to run penetration tests on your Kubernetes clusters, and reveal misconfigurations that might leave you open to attack! Kube-hunter is an open source tool that simulates what a hacker might do when trying to attack a deployment. We’ll discuss the motivations behind the project, and some interesting aspects of how it is implemented. There will be plenty of demos, including: - Testing for the basics, like an unsecured Kubelet API - Simulating an attack from within a compromised container - Re-using credentials from a compromised container You’ll need a basic understanding of Kubernetes components, and with using curl to issue API requests. You’ll leave this talk ready to test your own cluster, and with new insights into the possible routes that an attacker might attempt. Perhaps you’ll even be inspired to submit a new Hunter to the project!

More from KubeCon Europe 2019

Open in the index →
  1. Using eBPF to Bring Kubernetes-Aware Security to the Linux KernelDan Wendlandt, Isovalent 2019-05-21
  2. Portable, Universal Single Sign-On for Your ClustersMiguel Martinez, Bitnami 2019-05-21
  3. Kubernetes + Encrypted Memory = Security * PrivacyHarshal Patil & Pradipta Banerjee, IBM 2019-05-21
  4. Fine-Grained Permissions in Kubernetes: What’s Missing, and How to Fix ThatVallery Lancey, Lyft & Seth McCombs, Triller 2019-05-21
  5. Envoy SDS: Fortifying Istio SecurityYonggang Liu & Quanjie Lin, Google 2019-05-21
  6. Zero Trust Service Mesh with Calico, SPIRE, and EnvoyShaun Crampton, Tigera & Evan Gilman, Scytale 2019-05-22
  7. Smarter Kubernetes Access Control: A Simpler Approach to AuthRob Scott, ReactiveOps 2019-05-22
  8. Inside the CNCF Project Security ReviewsJustin Cormack, Docker 2019-05-22
  9. Crafty Requests: Deep Dive Into Kubernetes CVE-2018-1002105Ian Coldwater, Heroku 2019-05-22
  10. Container Forensics: What to Do When Your Cluster is a ClusterMaya Kaczorowski & Ann Wallace, Google 2019-05-22
  11. Caller ID in KubernetesMichael Danese, Google 2019-05-22
  12. Uber x Security: Why and How We Built Our Workload Identity PlatformTyler Julian, Uber & Daniel Feldman, Scytale 2019-05-23
  13. Securing Multi-Cloud Cross-Cluster Communication with SPIFFE and SPIREEvan Gilman, Scytale, Inc. 2019-05-23
  14. Securing Kubernetes with Trusted Platform Module (TPM)Alex Tcherniakhovski & Andrew Lytvynov, Google 2019-05-23
  15. Secrets Store CSI Driver-Bring Your Own Enterprise Secrets Store to K8sRita Zhang, Microsoft & Anubhav Mishra, HashiCorp 2019-05-23
  16. Protecting the Data LakeAsh Narkar, Styra, Inc 2019-05-23