CloudNativeSecurityCon_2023-CloudSecurityEvents.pdf

编号:140568 PDF 10页 827.15KB 下载积分:VIP专享
下载报告请您先登录!

CloudNativeSecurityCon_2023-CloudSecurityEvents.pdf

1、A Lightweight Framework For Security ReactionsCloud(Security)EventsEvan AndersonWhat Is An Event?A notification that something happened in a system.Photo by Jeff Finley on UnsplashWhat Is CloudEvents?CNCF project to standardize event format and metadataDocumented formats:JSONAVROProtobufXMLKey field

2、s(extensible):typesourceidtimestampSecurity EventsBefore an IncidentSoftware buildsDeploymentsVulnerability ScansCVEsTest resultsSDL process stagesIncident ResponseUnexpected System CallsConfiguration ChangesNetwork ConnectionsLogins and AuthenticationsTokens or certs issuedExamples?Falco has a seri

3、es of blog posts using the following projects to achieve the same result:Delete any pod which spawns an interactive terminal shellhttps:/falco.org/blog/falcosidekick-response-engine-part-1-kubeless/Example Eventsce-specversion:1.0ce-type:falco.rule.output.v1ce-source:falco.orgce-id:f7628198-3822-4c9

4、8-ac3f-71770e272a16ce-time:2023-01-11T21:45:31Zce-rule:Terminal shell in containeroutput:21:45:31.,rule:Terminal shell in container,output_fields:container.id:f29b261f8831,container.image.repository:mysql,k8s.ns.name:default,k8s.pod.name:alpine,proc.cmdline:bash-il,proc.name:bash,proc.pname:runc,pro

5、c.tty:34816,user.loginuid:-1,user.name:root“ce-specversion:1.0ce-type:dev.cdevents.service.upgraded.0.1-draftce-source:https:/my-argo-instance.dev/ce-subject:/namespaces/myns/deployments/fooce-time:2023-01-18T22:14:17Zce-id:e699633e-de83-4427-a6dd-9e702ae008d9-8context:.,subject:id:deployments/foo“,

6、environment:id:“namespaces/myns,source:.,name:staging,url:.,artifactId:oci:/.If You Are A Vendor:Generate CloudEvents!Document how to consume them webhook,kafka topic,etcDocument your event types and schemasIf You Are An End-User:Remediatio

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(CloudNativeSecurityCon_2023-CloudSecurityEvents.pdf)为本站 (2200) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠