Loading…
October 24 - 25, 2022 | Detroit, Michigan
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon North America 2022 - Detroit, MI + Virtual and add this Co-Located event to your registration to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Eastern Daylight Time (EDT), UTC -4. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Lightning Talks [clear filter]
Tuesday, October 25
 

11:30am EDT

⚡ Lightning Talk: Assessing Environments Against Cloud Native Security Best Practices - Pratik Lotia, Reddit & Jon Zeolla, Seiso
Organizations are in need for a standard, sane way to perform an assessment of their cloud native environments. This talk provides insight on how security professionals as well as auditors can identify whether they are following the controls and practices suggested in CNCF published white papers and thereby adhering to NIST 800-53v5 controls.. We will also provide examples on how we plan to develop open source automation (such as OSCAL) to reduce the toil of audits; and cross mapping to various frameworks and standards to enable builders focus on making their environments safer.

Speakers
avatar for Pratik Lotia

Pratik Lotia

Senior Security Engineer, Reddit
Pratik Lotia is a cloud security engineer at Reddit, where he is responsible for building tools and processes for implementing security best practices for cloud native environments; and contributing to open source projects. He actively contributes to open source projects (including... Read More →
avatar for Jon Zeolla

Jon Zeolla

CTO, Seiso, LLC
Jon Zeolla is the co-founder and CTO of Seiso, an information security company, where he is responsible for the research and refinement of cloud native security solutions, including contributing to open source projects and industry standards focused on Zero Trust, DevSecOps, and Cloud... Read More →



Tuesday October 25, 2022 11:30am - 11:40am EDT
Room 321 Huntington Place: 1 Washington Blvd, Detroit, MI 48226
  Lightning Talks, Track 2

11:45am EDT

⚡ Lightning Talk: Securing K8s Pods from Within: A Runtime Approach - Rahul Arvind Jadhav, Accuknox Inc
For Kubernetes, the basic unit of execution is a pod. All the binaries in all the containers have equal access to the volume mount points and thus have direct access to the service account tokens and k8s secrets that the pod mounts. Almost all Kubernetes attacks exploit/leverage this fact. The only thing an attacker has to ensure is to inject a binary into the pod using a known/unknown vulnerability in any of the binaries within any of the containers. Once the attacker injects a malicious binary, it has unrestricted access to the secrets in predefined volume mount points (we are making it so easy for the attacker!). Typically only a few binaries within the pod need access to the tokens/secrets. The access should be restricted to such a list of processes/binaries, and an automated framework should derive this list. This is easier said than done, taking into consideration that the app is updated every few weeks, i.e., the security posture changes with the app updates. The sessions aim to highlight runtime security risks that are inherent to k8s design and possible solutions to alleviate some of these concerns. Rahul is a dev/maintainer of KubeArmor (runtime security engine).



Tuesday October 25, 2022 11:45am - 11:55am EDT
Room 321 Huntington Place: 1 Washington Blvd, Detroit, MI 48226
  Lightning Talks, Track 2

12:55pm EDT

⚡ Lightning Talk: OPAL: The Open Source GitOps Enabled Platform for Building Authorization - Asaf Cohen, Permit.io
Broken Access Control is the top vulnerability in the OWASP Top 10 security risk list. Proper configuration and enforcement of access control are critical to modern organizations, as privacy and compliance awareness are at their peak. Yet, building authorization or permissions management is a painful process for developers, due to complex and ever-evolving requirements and lack of knowledge for avoiding common pitfalls. OPAL (Open Policy Administration Layer) is an open-source administration layer for OPA (Open-Policy Agent). OPAL detects changes to both policy and policy data in real-time and pushes live updates to policy engines, making them real-time and event-driven. OPAL uses Git as the source-of-truth for policy, enabling GitOps workflows for policy delivery and versioning. OPAL is used by thousands of engineers, from Tesla, Zapier, Cisco, Accenture and others. In his talk, Asaf Cohen, co-maintainer and author of OPAL, will explain the challenges of managing modern authorization and access control and how these challenges can be solved by using open source tools like OPAL. In the end, he will provide use cases and tips for implementing simple and scalable authorization.

Speakers
avatar for Asaf Cohen

Asaf Cohen

Co-founder and CTO, Permit.io
Asaf is the CTO and co-founder of Permit.io, and co-author of open source OPAL.ac. Before he started Permit, Asaf worked on internal developer tools at Facebook. He also worked at Claroty, and at Microsoft, where he worked on the Xbox recommendation system. Prior to that Asaf served... Read More →



Tuesday October 25, 2022 12:55pm - 1:05pm EDT
Room 321 Huntington Place: 1 Washington Blvd, Detroit, MI 48226
 
  • Timezone
  • Filter By Date Cloud Native SecurityCon North America 2022 Oct 24 -25, 2022
  • Filter By Venue Detroit, MI USA
  • Filter By Type
  • Badge Pick-Up
  • Breaks
  • Capture the Flag
  • COVID-19 Test Kit Pick-Up
  • Experiences
  • Hands-on Workshops
  • Keynotes
  • Lightning Talks
  • Opening/Closing Remarks
  • Sessions
  • Content Experience Level
  • Talk Type
  • Subject

Filter sessions
Apply filters to sessions.