Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sysdig Falco presentation #58

Open
castrojo opened this issue Jun 20, 2019 · 5 comments
Open

Sysdig Falco presentation #58

castrojo opened this issue Jun 20, 2019 · 5 comments

Comments

@castrojo
Copy link

It'd be cool to see if we can get @mfdii up here to show us all the sysdig goodies. August 28 and September 25th are open.

@markjacksonfishing
Copy link

Count me in for this @castrojo

@castrojo
Copy link
Author

castrojo commented Sep 5, 2019

Sweet, do you have a description we could use? We'd like to add it all to the meetup page, etc.

@markjacksonfishing
Copy link

Host intrusion detection (HID) has been around for some time. What if we rethought the problems HID solves in the context of Cloud Native platforms? What if we can detect abnormal behavior in the application, container runtime, & cluster environment as well? In this talk, we’ll present Falco, a CNCF Sandbox project for runtime security. We will show how Falco taps Linux system calls & the Kubernetes API to provide low level insight into application behavior, & how to write Falco rules to detect abnormal behavior. We’ll show how to collect & aggregate alerts using an EFK stack (Elasticsearch, Fluentd, Kibana). Finally we will show how Falco can trigger functions to stop abnormal behavior, & isolate the compromised Pod or Node for forensics. Attendees will leave with a better understanding of what problems runtime security solves, & how Falco can provide runtime security, auditing & incident response.

@markjacksonfishing
Copy link

@castrojo let me know when the meetup page drops so i can spread the word ❤️

@markjacksonfishing
Copy link

Title: Falco- Container Native Runtime Security

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants