No video

Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec

  Рет қаралды 41,405

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

Күн бұрын

Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec
While Kubernetes offers new and exciting ways to deploy and scale container-based workloads in production, many organizations may not be aware of the security risks inherent in the out-of-the-box state of most Kubernetes installations and the common practices for deploying workloads that could lead to unintentional compromise. Join Brad Geesaman, the Cyber Skills Development team lead at Symantec, on an eye-opening journey examining real compromises and sensitive data leaks that can occur inside a Kubernetes cluster, highlighting the configurations that allowed them to succeed, applying practical applications of the latest built-in security features and policies to prevent those attacks, and providing actionable steps for future detection.
The hardening measures taken in response to the attacks demonstrated will include guidelines for improving configurations installed by common deployment tools, securing the sources of containers, implementing firewall and networking plugin policies, isolating workloads with namespaces and labels, controlling container security contexts, better handling of secrets and environment variables, limiting API server access, examining audit logs for malicious attack patterns, and more.
About Brad Geesaman
Brad was recently the Cyber Skills Development Engineering Lead at Symantec Corporation where he supported the operations and delivery of ethical hacking learning simulations on top of Kubernetes in AWS. Although he spent several years as a penetration-tester, his real passion is educating others on the real-world security risks inherent in complex infrastructure systems through demonstration followed by practical, usable advice on detection and prevention.
Join us for KubeCon + CloudNativeCon in Barcelona May 20 - 23, Shanghai June 24 - 26, and San Diego November 18 - 21! Learn more at kubecon.io. The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy and all of the other CNCF-hosted projects.

Пікірлер: 9
@nunofernandes8857
@nunofernandes8857 3 жыл бұрын
Excellent talk! As an admin working on AWS workloads, this blew my mind. I honestly had no idea of more than half the issues you approached. GJ!!
@DF-bd4hl
@DF-bd4hl Жыл бұрын
Very nice talk !! Thanks for all this information.
@bmejia220
@bmejia220 Жыл бұрын
Terrific talk I learned so much thank you
@SanketPatelJ
@SanketPatelJ 6 жыл бұрын
36:12 interesting choice of colors for the credits! First is red :)
@serverlessnomad
@serverlessnomad 6 жыл бұрын
Excellent work, very informative.
@robertdeheer1307
@robertdeheer1307 5 жыл бұрын
Thanks, brilliant talk
@isacm4029
@isacm4029 6 жыл бұрын
Indeed! very informative
@littlebighumancom
@littlebighumancom 3 жыл бұрын
Great stuff. Im also curious what software he used to create the 3D diagrams
@RobertObuchUk
@RobertObuchUk 3 жыл бұрын
it may be www.cloudcraft.co
Effective RBAC - Jordan Liggitt, Red Hat
39:38
CNCF [Cloud Native Computing Foundation]
Рет қаралды 31 М.
Securing Cluster Networking with Network Policies - Ahmet Balkan, Google
30:55
CNCF [Cloud Native Computing Foundation]
Рет қаралды 29 М.
黑天使遇到什么了?#short #angel #clown
00:34
Super Beauty team
Рет қаралды 36 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 36 МЛН
Они так быстро убрались!
01:00
Аришнев
Рет қаралды 2,8 МЛН
I'm Excited To see If Kelly Can Meet This Challenge!
00:16
Mini Katana
Рет қаралды 33 МЛН
Attacking and Detecting Attacks on Kubernetes Clusters
49:29
RSA Conference
Рет қаралды 1,1 М.
Life of a Packet [I] - Michael Rubin, Google
34:19
CNCF [Cloud Native Computing Foundation]
Рет қаралды 83 М.
Tutorial: Hands-on Hacking Kubernetes and Ways to Prevent It - Eric Smalling, Snyk
1:13:23
CNCF [Cloud Native Computing Foundation]
Рет қаралды 3,6 М.
Helm Chart Patterns [I] - Vic Iglesias, Google
28:32
CNCF [Cloud Native Computing Foundation]
Рет қаралды 37 М.
CrashLoopBackoff, Pending, FailedMount and Friends: Debugging Common Kubernetes Cluster
34:54
CNCF [Cloud Native Computing Foundation]
Рет қаралды 23 М.
Kubernetes Security Best Practices - Ian Lewis, Google
28:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 50 М.
Tutorial: Communication Is Key - Understanding Kubernetes Networking - Jeff Poole, Vivint Smart Home
1:17:48
CNCF [Cloud Native Computing Foundation]
Рет қаралды 30 М.
Kubernetes Design Principles: Understand the Why - Saad Ali, Google
37:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 125 М.
Kubernetes Security: Attacking and Defending K8s Clusters
34:50
SANS Cloud Security
Рет қаралды 5 М.
Certifik8s: All You Need to Know About Certificates in Kubernetes [I] - Alexander Brand, Apprenda
35:57
CNCF [Cloud Native Computing Foundation]
Рет қаралды 44 М.
黑天使遇到什么了?#short #angel #clown
00:34
Super Beauty team
Рет қаралды 36 МЛН