Abstract

In today's contemporary world, Containers are one of the most trending and hottest topics in IT, wherever you go, you will find people talking about some shiny and new technologies and most of the time they're either talking about Docker, Kubernetes or are deploying it. The pace with which these modern technologies are evolving, attackers are also catching up with the same speed and are finding flaws inside them. So, in today's session we will be talking about how we can secure the life of an application inside the container and the container itself. You will learn about Isolation process, Control groups, Managing Container Privileges and how to secure them. After this session, you'll be able to secure your own Docker container workloads.

Expectation from Audience

 * Level : Intermediate
 * Familiar with the Basics and working of Docker

Contents

Introduction

 * What is Docker
 * Kernel Internals
 * Docker Engine

Securing Platform

 * Testing a Docker Platform
 * Audting Docker artifacts

Securing Kernel

 * Isolation using Linux Namespaces
 * Control Access using Control Groups
 * Playing with container Privileges
 * Access Control with Linux Security Modules/SE Linux

Deploying Secure Registry

* Controlling Communication and Auth for Self-hosted Registry

Speaker

Pankaj Mouriya

Timing

Starts at Saturday September 28 2019, 11:25 AM. The sessions runs for about 1 hour.

Resources