READ ME
This deck has been successfully presented at conferences and webinars. Make a copy of this material prior to making any changes. Thank you.
Threat Detection for Containers, Kubernetes and Cloud
Name
Title, Sysdig
Once, there was a perimeter
You had a perimeter guarded by a firewall
Detecting intrusions was your breach indicator
Now, there is no perimeter in the cloud
Cloud providers own external connections
Cloud is exposed to the outside world
You need to control access to services your team uses
You need to detect �unusual activity
4
Without a perimeter, a security camera is more important than a good lock
5
Watch for changes that create security gaps
Identify intruders and suspicious insider behavior
Send an alert and take immediate action
The Security Camera for Modern Apps
CNCF INCUBATED PROJECT
created by Sysdig
What is Falco?
CNCF INCUBATED PROJECT
About Falco
The Falco sensor
High level architecture
Sensor
Sensor
Sensor
Sensor
System Calls
System Calls
Audit Logs
CloudTrail
Alerts
Collector
High level architecture
Beyond system calls and containers
Plugins are dynamic shared libraries
which allow Falco to collect and extract fields
from streams of events
Open source drives effective cloud security
Users and builders
CNCF INCUBATED PROJECT
Resources
Get started at Falco.org
Check out the Falco project in Github
Get involved in the Falco community
Meet the maintainers on the Falco Slack
Follow @falco_org on
Join a Falco workshop
Questions
Thank you!