Cloud Native
Security Talks
RSS

KubeCon Europe 2024

Playing Defense: The Reactive Cloud Native Security Battle

Ayse Kaya, Slim.AI

Abstract

Recent joint research from ESG and Slim.AI, polled from SREs, DevOps & Platform Engineers explores the state of cloud native security, shedding light on an increasingly worrying attack surface that is only growing. Analyzing the data we learn that a mere 12% are managing to achieve security SLOs. This is compounded by regulatory pressures, the complexity of the supply chain with its own set of exploits & challenges, all this with a fragmented tooling ecosystem that is making it difficult to understand how to prioritize & remediate rapidly in a single consolidated place. This session will dive into these new findings, on how container & OSS security continues to add difficulty with triaging security––as well as the cascading impact of the continuous rise in cloud native sec, vulns, and the supply chain as a whole. Join this session to learn how to take cloud native security from reactive to proactive along with real practical tips for minimizing the noise & achieving security SLOs.

More from KubeCon Europe 2024

Open in the index →
  1. Securing the Supply Chain with Sigstore Artifacts Signatures at ScaleDmitry Savintsev & Yonghe Zhao, Yahoo 2024-03-20
  2. Safety or Usability: Why Not Both? Towards Referential Auth in K8sRob Scott, Google & Mo Khan, Microsoft 2024-03-20
  3. SLSA and FRSCA: Beyond Snacks and Soda!Christopher Hanson, RX-M, llc. 2024-03-20
  4. OAuth2 Token Exchange for Microservice API SecurityAhmet Soormally & Letz Yaara, Tyk 2024-03-20
  5. I'll Let Myself In: Kubernetes Privilege Escalation TacticsAndrew Martin & Iain Smart, ControlPlane 2024-03-20
  6. Why Barricade the Door if the Window Is Open? Making Sense of Kubernetes Initial Access VectorsShay Berkovich, Wiz 2024-03-21
  7. VEXinating Your Container Images: The European WayDina Truxius, Federal Office for Information Security (BSI) & Jose Antonio Carmona Fombella, VMware 2024-03-21
  8. Stop Leaking Kubernetes Service Information via DNS!John Belamaric, Google & Yong Tang, Ivanti 2024-03-21
  9. Navigating the Software Supply Chain Defense LandscapeMarina Moore & Aditya Sirish A Yelgundhalli, New York University 2024-03-21
  10. Misconfigurations in Helm Charts: How Far Are We from Automated Detection and Mitigation?Francesco Minna, Vrije Universiteit Amsterdam & Agathe Blaise, Thales SIX 2024-03-21
  11. Memory Armor for SPIRE: Fortifying SPIRE with Confidential Containers (CoCo)Matthew Bates, Stealth Security Startup & Suraj Deshmukh, Microsoft 2024-03-21
  12. Keep Hackers Out of Your Cluster with These 5 Simple TricksChristophe Tafani-Dereeper & Frederic Baguelin, Datadog 2024-03-21
  13. Federated IAM for Kubernetes with OpenFGAJonathan Whitaker, Okta 2024-03-21
  14. Confidential Containers for GPU Compute: Incorporating LLMs in a Lift-and-Shift Strategy for AIZvonko Kaiser, NVIDIA 2024-03-21
  15. Cloud Native Security: Cell-Based Architecture & K8sRostyslav Myronenko & Shweta Vohra, Booking.com 2024-03-21
  16. Bringing SPIFFE to Linkerd for Mesh ExpansionZahari Dichev, Buoyant 2024-03-21
  17. Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native EcosystemConstanze Roedig, Technische Universität Wien & James Callaghan, ControlPlane 2024-03-21
  18. You Shall Not Pass! Unless You Are GUAC Verified….Parth Patel, Kusari & Dejan Bosanac, Red Hat 2024-03-22
  19. Living off the Land Techniques in Managed Kubernetes ClustersRonen Shustin & Shay Berkovich, Wiz 2024-03-22
  20. Leveraging OCI 1.1 for Enhanced SBOM Integration and Vulnerability Scanning in HarborAnais Urlichs, Aqua Security & Shengwen Yu, VMware 2024-03-22
  21. Lessons Learned from Generating 100M SBOMs: Google’s Approach to SBOM ComplianceBrandon Lum & Isaac Hepworth, Google 2024-03-22
  22. Kubernetes Security Blind Spot: Misconfigured System PodsShaul Ben Hai, Palo Alto Networks 2024-03-22
  23. Kubernetes MLSec: Securing AI in SpaceFrancesco Beltramini & James Callaghan, ControlPlane 2024-03-22
  24. Keeping Kubernetes Safe: The Lowdown on Locked NamespacesMarco De Benedictis, ControlPlane 2024-03-22
  25. It's Not Just About SBOMs: Perspectives on Cloud Native Supply Chain SecurityMichael Lieberman, Kusari; Dana Wang, OpenSSF - The Linux Foundation; Marina Moore, New York University; John Kjell, TestifySec; Arnaud Le Hors, IBM 2024-03-22
  26. IAM Confused: Analyzing 8 Identity Breach IncidentsMaya Levine, Sysdig 2024-03-22