1 of 17

READ ME

This deck has been successfully presented at conferences and webinars. Make a copy of this material prior to making any changes. Thank you.

2 of 17

Threat Detection for Containers, Kubernetes and Cloud

Name

Title, Sysdig

3 of 17

Once, there was a perimeter

You had a perimeter guarded by a firewall

Detecting intrusions was your breach indicator

4 of 17

Now, there is no perimeter in the cloud

Cloud providers own external connections

Cloud is exposed to the outside world

You need to control access to services your team uses

You need to detect �unusual activity

4

5 of 17

Without a perimeter, a security camera is more important than a good lock

5

Watch for changes that create security gaps

Identify intruders and suspicious insider behavior

Send an alert and take immediate action

6 of 17

The Security Camera for Modern Apps

CNCF INCUBATED PROJECT

created by Sysdig

7 of 17

What is Falco?

    • Runtime security engine
    • Observability for endpoints and cloud infrastructure
    • Built on eBPF
    • Integrated with Kubernetes

CNCF INCUBATED PROJECT

8 of 17

About Falco

9 of 17

The Falco sensor

10 of 17

High level architecture

Sensor

Sensor

Sensor

Sensor

System Calls

System Calls

Audit Logs

CloudTrail

Alerts

Collector

11 of 17

High level architecture

12 of 17

Beyond system calls and containers

Plugins are dynamic shared libraries

which allow Falco to collect and extract fields

from streams of events

13 of 17

Open source drives effective cloud security

  • Closes talent gap
  • Provides rule transparency
  • Innovation is faster

14 of 17

Users and builders

CNCF INCUBATED PROJECT

15 of 17

Resources

Get started at Falco.org

Check out the Falco project in Github

Get involved in the Falco community

Meet the maintainers on the Falco Slack

Follow @falco_org on

Join a Falco workshop

16 of 17

Questions

17 of 17

Thank you!