Session
Make the most of a single Indicator of Compromise: real-time multi-pod correlation
Ever been alerted by a single security event and then spent ages querying logs to confirm what it was?
Usually, we pay vendors to do this and ship our data to some SaaS or data-storage-situation.
This talk is about pre-correlating IoCs in real time, locally on each node. With an adaptive streaming operator, that exports only the enriched data, which can include several pods in one "span".
This is ongoing research for the Austrian Armed Forces to create a sovereign kubernetes SOC that reduces data volume. 100% open-source.
You'll see a 3-step attack chain, where entire steps are undetectable but the in-place correlation still extracts the entire attack path.
This solution is for data-center operators or anyone who has a few k8s clusters and no nerve to check each alert.
Constanze Roedig
Independent OpenSource Maintainer and Cybersecurity Researcher
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top