Guardians of the Runtime: Leveraging Behavioral Analysis and Policies

English
This talk will be held in English. / Dieser Vortrag wird auf Englisch gehalten.

In this presentation, we will explore an innovative approach to securing Kubernetes clusters using behavior analysis during continuous integration testing and generating native policies based on behavior.

By leveraging continuous behavioural analysis, we can replace tedious manual policy definitions which take long to define and can break easily. We will also discuss the importance of native policies, which allow us to enforce security policies directly within Kubernetes without relying on third-party tools.We will cover hands-on practices for implementing this approach, including how to integrate behavioral analysis into CI testing and how to use native policies to enforce security policies.

By the end of this presentation, attendees will have a deeper understanding of how to leverage innovative approaches to security in Kubernetes clusters, and how to use behavioral analysis and native policies to protect their environments against the latest threats.

  • Kubernetes basics (core concepts, kubectl)
  • Kubernetes security (admission controller, network policies, seccomp/security profiles)
  • Continuous Integration (CI)

  • Understand the limitations of traditional Kubernetes policy definitions.
  • Explain the concept of behavioral analysis for Kubernetes security.
  • Recognize the value of using native Kubernetes policies.
  • Outline steps to integrate behavioral analysis into CI/CD.
  • Apply native policies for enforcing security based on observed behavior.

Matthias Bertchy
Matthias Bertchy
is a Senior Kubernetes Developer at ARMO, maintaining Kubescape, an open-source security platform. His career in security began in 2011 as a Security System Engineer in Switzerland. He quickly distinguished himself, achieving his Ethical Hacker (GPEN) certification in 2012 and the prestigious CISSP in 2015. With over five years of experience as a Senior DevOps Engineer and Platform Architect, Matthias was instrumental in leading digital transformations for major Swiss banks. A dedicated member of the Kubernetes community, Matthias is a regular contributor, an active member of SIG Node, and a trusted reviewer for both kubelet and test-infra.

CLC-Newsletter

Du möchtest über die CLC auf dem Laufenden gehalten werden?

Anmelden