Jimmy Mesta, KSOC | KubeCon + CloudNativeCon Europe 2023
At KubeCon, Jimmy Mesta, CTO and co-founder of KSOC, discusses Kubernetes security posture management and KSOC’s goal of bringing security up to the same level of Kubernetes innovation.
Transcript
This is texturing TV. Hello and welcome back to kubecon plus Cloud nativecon Europe. I'm here with Jimmy mesters the CTO for caseoc and we're talking about kubernetes security posture management, Jimmy.
Welcome the show right? Thanks for having me. You guys launched this at the show.
So why don't you give us a little explanation of what is the problem? You're trying to solve here. How does this thing work?
We did launch. Thanks. Yeah we so we deal with real-time kspm which may or may not be afraid you've heard of but we instrument kubernetes in real time and we've noticed a few issues over the years with point in time scanning and we're trying to address them.
So if you scan a cluster every 24 hours every four hours you're bound to miss things. So we instrument in the event stream coming from kubernetes in real time to give you a full life cycle of the problems you have and you can hopefully drive down those issues over time. Organizations have invested in all kinds of security tools over the years is securing kubernetes different as it require a different set of tools.
What's what should people be thinking about as they approach Security in the kubernetes space? Yeah, we believe it does require different set of tools. You can't bolt on things from the past that worked in just Cloud security posture management because kubernetes is ephemeral containers live for five minutes or less workloads come up and down and it's really easy to miss bad things happening in your cluster and scanning every 24 hours.
You're leaving a lot on the table from a security perspective. Every time there's a new innovation and a new platform. Everybody gets excited and then about A year or two later.
Somebody starts talking about security feels like we're doing that again and security feels like a little bit of an afterthought so is security catching up now with where people are with kubernetes. I think that's our goal of case stock right? We're trying to bring real Security Solutions into a platform that's evolving really fast.
So it is a bit of cat and mouse historically, but we're trying to get ahead of it this time. Are you seeing more attacks launched against kubernetes clusters? Because a lot of this stuff was always in experimental mode somewhere.
And now I think it's moving into production. So are the bad guys finding this. I think they are.
Yeah, we see cryptocurrency miners back doors malware data ex filtration. There are bad things happening in high impact clusters every day and we have a cve release last week pertaining to our back in kubernetes, which is kind of a first of its kind so that's going to be the trend this year for sure. Do you think that the security people are going to come and manage this or are we think that the devops slash devsecops people are gonna manage security along with it operations and everything else that they're trying to do.
I think it's a it's a better together story there for sure. I think security teams need to learn how to work with devops and SRE and platform teams and you know vice versa. I think the platform team ultimately will be implementing a lot of Security Solutions together.
Everybody is short-handed with looking for people when it comes to Security in General trying to find somebody who knows kubernetes security maybe even harder. So, you know, do we have a critical shortage of skills in this area? Because it seems like everybody's looking for the same person to hire.
It is a unicorn role for sure. I think the cncf does a great job with the Linux foundation with training certificates pertaining to security specifically, but we need intelligent tooling that can help augment the team right? There's not an unlimited set of humans that can come in and fix these problems.
So we need better solutions that filter out the noise. Walk down the street today without somebody leaping out to tell you about their great new AI thing. Will AI play a role in securing kubernetes and what might that look like in your imagination?
I think AI can process certain events and do certain computationally expensive, you know processes that we couldn't before. I don't think it's a replacement for proper security tooling and there's still a lot to be discovered on how secure AI is for this environment. What do we want to send sensitive data and rely on it for everything?
Probably not but it's going to be it's gonna play a big role in helping these tools get better. If we made you king of kubernetes for a day, what would you fix from a security perspective? What's that one thing you wish they the community would kind of look at and say guys, let's focus on this a little bit role base access control and our back in kubernetes is powerful yet underserved from a lot of angles and I would definitely talk about that.
I did yesterday here at the conference. I had to talk about our back and how to handle it from a security perspective and I think we have a lot of work to do there. Once your best advice then the people who are just starting out with security, they're gonna try to work with kubernetes.
What is it that you know now that you kind of wish you knew four or five years ago when you started up, Yeah, we have a lot more available. We have the means to build cluster securely at a large scale. So I think I would I would learn about what policies should govern and kind of, you know have the guardrails in place for developers to build but in a secure way and I learned the internals like it always to go back to square one of like what is a container.
How is it how does it work? And how does the kubernetes API interact with the rest of the ecosystem very fundamental things, but I think it's really important before we start applying security into your point. It seems to me at least that you know, when I look at all the things that somebody discovers a new vulnerability, it's like Well, yeah if that could be exploited on a Tuesday at three o'clock in February standing on your head.
But a lot of the fundamentals we don't seem to address. So what is our challenge with just getting the basics, right? We are trying to move as fast as possible.
Every organization has strict deadlines. They need the ship software yesterday and I think to go back and reassess fundamental knowledge. We don't give ourselves the time resources money and effort and I think it's that's gonna be a problem, right?
That's gonna come to Reckoning at some point. So Are we building and deploying applications too fast? Are we unsafe at any speed as well?
Somebody once said I think we're it at least a case stock. We're trying to let people move at Breakneck speeds while having the guardrails to stay secure. I can't speak for everyone but I think there's a lot of vendors here.
That would probably say the same. All right, cool. You heard it here folks guard rails are a good thing go get some because bad things can happen.
Otherwise Jimmy. Thanks for coming by. Thank you so much.
All right. Pleasure. Yep.
Appreciate it. All right, folks. We'll be back in a minute.





