Towards the Hardened Cloud-Native Cornerstone: Container Runtime Protection
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Intro
Container Security Risks (Users' View)
(Extended) Container Threat Modeling
Container Attack Vectors (Attackers' View)
Container Attack Scenarios (AS)
Any Best Practice?
What Do We Have So Far?
What Else Can We Apply?
Not Enough Security Deployment!
Weaknesses (Still) Across Every Layer!
Unprivileged Sandboxing
Sandboxing Containers with Landlock
Defend Against Cross-HT Attacks
Containers with Core Scheduling
Can Hardware Assist?
An Augmented Threat Model
Secure - Confidential Containers
Gaps From A Bird's Eye View
A Further Augmented Threat Model?
Taught by
CNCF [Cloud Native Computing Foundation]