Session

Unleashing the Storm: Security Exposure Testing for CNCF Projects with the Kubernetes Storm Center

Integrating new apps into diverse K8s ecosystems introduces a complex web of potential attack surfaces. Assessing the security impact of these deployments requires significant time and resources. To shift-left the security exposure impact analysis, we envision the K8s Storm Center to standardize continuous security exposure testing inside a specific cluster configuration for a given project. We discuss the usefulness for a CNCF project maintainer and demo on Harbor how to leverage existing K8s security tools like e.g. icekube, kdigger, tracee and tetragon to:

-Automate attack path validation: by translating Kubehound's theoretical paths into concrete chains of attack steps to evaluate which paths are realistically vulnerable in a specific configuration.
-Visualize attack paths: by translating eBPF logs into STIX we have a sharable data standard to see how vulnerabilities interconnect within a specific environment, revealing weaknesses arising from seemingly harmless configurations.

Vadim Bauer

Cloud Native builder in the Clouds with Kubernetes. CNCF Project Harbor maintainer.

Zürich, Switzerland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top