Using SmartNICs to Provide Better Data Center Security
44CON Information Security Conference via YouTube
Overview
Explore a comprehensive conference talk on enhancing data center security using SmartNICs, delivered by Jack Matheson at 44CON 2018. Dive into the challenges faced by traditional security models and discover how SmartNIC-based solutions address performance and security issues in edge-centric policy enforcement. Learn about a novel SmartNIC-based reference architecture for network layout and examine examples of SmartNIC security controls with their corresponding threat models. Uncover an innovative technique for tamper-proof host introspection, leveraging SmartNICs' unique position to analyze and inspect host memory. Gain insights into how this approach complements network controls, enhancing workload integrity measurement and improving overall data center security compared to traditional software-only controls.
Syllabus
Introduction
Agenda
The Problem
The Attack Surface
Traditional Host Security
Time and Persistence
SmartNICs
MustHaves
Typical SmartNIC
Isolation
Checklist
OVS Model
Connection Tracking Rules
Embedding
OVS
OBS
Memory Access
Putting it all together
Demonstration
Taught by
44CON Information Security Conference