Reinventing Seccomp with eBPF and KRSI for Enhanced Kernel Security
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Explore a 26-minute conference talk that delves into reinventing Seccomp using modern technologies like eBPF and KRSI for enhanced Linux kernel security. Learn about Seccomp's critical role in access control and its implementation in Kubernetes environments, while discovering how emerging technologies are reshaping kernel security landscapes. Gain practical insights into extending security policies through eBPF capabilities and understand how KRSI and LSM can strengthen container security. Watch a demonstration of a proof-of-concept that showcases a modern alternative to Seccomp, combining eBPF and KRSI technologies for improved runtime syscall inspection and filtering. Master the practical knowledge needed to implement advanced security measures for containerized workloads in cloud-native environments.
Syllabus
Reinventing Seccomp for Fun and Profiles - Ben Hirschberg, ARMO & Dor Serero, Microsoft
Taught by
CNCF [Cloud Native Computing Foundation]