Главная
Study mode:
on
1
Intro
2
Introductions
3
Why this talk
4
What is a vulnerability
5
Security Response Committee
6
Lifetime of a kes vuln
7
Security Supported Versions
8
A brief history of K8s Security
9
Where to get vulnerability data
10
Vulnerability Distribution
11
Issue Lifetime
12
Bug Bounty Finds
13
Common Weaknesses
14
CWE - Kubernetes All Time
15
CWE - 2020-2021
16
CVSSv3 means rescoring!
17
Key Takeaways
Description:
Explore the comprehensive history of Kubernetes vulnerabilities in this 29-minute conference talk by Robert Clark and Micah Hausler from Amazon. Dive into an in-depth analysis of security issues throughout the Kubernetes project's lifetime, examining patterns, trends, and a taxonomy for classifying vulnerabilities. Learn about root causes, contributing factors, and metrics such as time from commit-to-discovery and time-to-resolution. Gain insights into the impact of community efforts, including SIGs, WGs, and audits, on improving Kubernetes security. Discover how to predict future security performance based on historical data and understand the potential evolution of Kubernetes' security posture. This presentation, part of KubeCon + CloudNativeCon Europe 2022, offers valuable information for developers and end-users of Kubernetes and other CNCF-hosted projects.

The Hitchhiker's Guide to Kubernetes Vulnerabilities

CNCF [Cloud Native Computing Foundation]
Add to list