Knox Anderson, Sysdig | KubeCon + CloudNativeCon Europe 2023
The cloud has fundamentally changed the anatomy and nature of modern applications, IT infrastructures, and processes involved. It creates a dynamic and growing attack surface of interdependent cloud workloads, services, and identities. Until recently, discussions about cloud security centered on the acronym soup of CWPP, CSPM, CIEM, and on and on. What do you actually need to secure your cloud environment? Knox Anderson is here to talk about how cloud security is consolidating and the role open source plays in cloud security.
Transcript
This is texturing TV. All right, we're back. We're back here in Amsterdam.
We are all right gets well into almost the end of the day actually isn't there an is there a thing tonight on the floor? I think there's a thing tonight on the floor and then pretty much every night. There's different about this crazy parties, but no tonight opening night on the Expo floor.
I think there's some sort of event or whatever happy hour whatever it is. So but anyway, I want to introduce you to Knox Anderson knox's with cystic. Hey, if you're a regular Watcher of tech strong TV, we covered this thing a whole bunch.
I know it knocks. I I was testing off camera. I recently did an interview with I guess it's like she's a form of gardener person.
I think or something right who works in your research team there. Yeah. Annabelic.
Yeah. Fantastic. Yep did a nice report on the survey report that you guys had done but Knox welcome man here to techstrong TV live in kubecon.
Thanks happy to be on again. So let's start with this. For people maybe don't remember you.
Sure, everyone remembers you at least your mom you you significant other someone's watching right? But for besides them tell people a little bit about your story. Yeah, so I run product management statistic.
I've been here seven and a half years. So this is probably My 13th or 14th cubecon, if we're looking at North America and Europe, but systic is a counting the virtual ones. Yeah.
Okay, maybe the in person. Oh really? Pretty Linux Foundation Cube.
Consider. Oh, okay my belt so very cool. It's been a while.
But yeah, sistigue provides container and kubernetes security and we're really differentiated around the runtime side. So you probably heard of Falco which is our open source project. Yes, and that provides threat detection for containerizing human as well.
And but correctly book Falco is not a cncf project or it is it is a cncf project. We're in the yeah incubation, correct? Yep.
Very quiet. Did we covered that on textual TV as well? com for anybody wants to get more information and they could you know catch the Falco project via the cloud Nate.
Cloud native Computing Foundation site or from the cystic site too. I believe. org or the GitHub Pages now, they're easy right?
org. Yeah. So Knox, you mentioned you've been to a lot of Cubes.
I've been to probably not as many as you I think I've been to. I want to say eight. It's a good amount.
Yeah. Yeah, eight or nine. I could take off my shoes and do my you know, but something like that but this one it feels it feels like it's back.
Right? What's your impression? Yeah, really even started yesterday where you had a lot of the different Hands-On events.
So we ran like a Hands-On Falco Workshop where people are seeing active threats trying to detect them. What are you next? And so I think the energy you feel about people getting hands on people going by the booth people are just happy to learn but I'm also surprised by the amount of first timers here.
That's something I always ask and probably 50% of the people. It's their first kubecon. So absolutely, you know, what you're the second person who's brought this up today.
I think part of that is Part of that is just this industry, right? There's always new people coming in. But I think another big part of it is because of what we've gone through the last couple years with covid.
There have been people who? Okay, just listening to that. There have been people sort of who have been in like a suspended animation, right?
They got into this industry two years ago two and a half years ago. Normally you would have seen over the last two and a half years. You would have seen a percentage of these people being first-timers at each of the shows.
But because it was either virtual or if it was in person. It was not as dense. You don't you didn't they didn't go?
So now all of a sudden it's like you built up this pent up demand for two years three years. And people are here. So it's probably a little probably a little of that.
Here's another observation that I've heard from people. And from what I've seen and I if you want to chime in is that older kubecon's were 75 85% Developers We're seeing a lot more platform engineers sres. CIS admins Ops folks And even security folks joining and well here welcome Securities always been here.
Security's been parted. I'll give on that right they Security people knew they had to be here. Yeah.
It's the only place to learn for a long time. Absolutely, but but security for the platform Engineers for the srees for all of these new. kind of expertise these new job functions is here in a big way as well including system.
Yeah, and I think the reason why platform teams are becoming more important is kubernetes is kind of the operating system of the cloud. Yeah. So more people are being pushed for multi-cloud people are being pushed for hybrid cloud, and I think it was kind of fake until Kubernetes adoption got real and then you can actually go across these different environments.
So yeah. The way to do it right is to have a platform team that makes it as easy as developer to onboard to the platform as possible. And so we're having really good conversations with them about baking and security into your like IC flow.
So as soon as you develop a Helm chart make sure that's secure remediate that from production and to source and so these platform teams are kind of a facilitator through a bunch of different groups and I think the companies who have seen do kubernetes right always have some type of dedicated platform game a great Another observation. I just sit here and observe. I should be like an observability person but a loaded terms.
Yeah, I think I was throwing it out there for the audience. But another observation we've seen and I've heard from people sitting where you're sitting today Knox is We used to try to really focus on shift left. So move security.
Let's say to the developer move cicd to the developer move testing towards the development. Everything was being shifted left to the developer. I think part of what we're seeing in today's Cloud native world with everything is we're asking developers to shift, right?
Yeah, right. So they're working with the platform team. They're working with the srees.
They're moving as much as we're coming to them. They're moving. This way as well and the thing I think that's really related to that is even if you shift left you still have the noise problem.
So you're uncovering the same Vols that you would have seen in production. You're just doing a little bit earlier. Yeah, so that noise issue and that just I have 80,000 vulnerabilities to fix is something that is still there if you shift left and so the shifting right part is really important because runtime context is what allows you to understand what to fix and that's one of the main ways we're helping users right now.
And it's also a good part of our partnership with sneak is we can tell people. Hey this vulnerability is in a package. Your application is actually using and that cuts up to 85% of the noise.
So the last thing people want to do is just Create more noise by shifting left get another pile of gear tickets. And so but really focusing on what's happening in the right and what's going on. You can prioritize a lot better as well.
I I agree with you 100% man. So I gave you all my observations. Let's hear some more of yours.
Yes, I think that. Operational and right focus is something that's coming more into play. So the past couple years.
There's been a lot of hey do I have kubernetes up and running in my onboarding teams? And now I think that's handled well, but it's okay. I need to get fedramp compliant.
I need to be PCI Compliant. I need to manage the cost of my kubernetes environment. So like getting kubernetes stable.
It's a most of this this audience knows how to do and now it's all right. My CFO is asking for chargebacks. I need to meet this new Regulatory Compliance standard and So you're seeing kind of the day two problems, right?
Which is it's a good sign. Yeah good sign. It's a sign of maturity and evolution of it.
So that's huge. That's huge. Hey, we mentioned you guys recently did a survey and a report which I think the state of cloud security.
Yep. Anything big in there. You just want to throw out to the audience.
Yeah. So one of the interesting points we found is a 72% of containers run for five minutes or less and this also brings up some of the needs for runtime security and that right Focus. If you're using like a traditional cspm product, are you doing scanning and you scan once a day you're gonna miss almost everything.
Yeah. And so you really need some type of active runtime monitoring and runtime security to get that real-time nature against those those 72% of containers that are running five minutes or less the other interesting part that it's kind of depressing is we've seen on average customers run 16 Damon sets and so you're basically running 16 tools. On a node for a kubernetes environment and on average we're seeing 64 containers.
So that's basically saying like 25% of my node is just boot up tooling and the main mistake that I see with a lot of customers is they think about host security or host monitoring and container security and container monitoring is different things and you really need to try to consolidate those as much as possible like at the end of the day your kubernetes containers are still running on a server somewhere and you should consolidate that protection. And so that's where I think cost is now forcing people to step back and look like oh wait there's something scanning my host. If something scanning my containers, maybe I should just use one and that 16% or 16 Damon sets number was the thing that definitely personally surprised me the most in that survey.
I absolutely they could get that survey. It's just the calm. Yes this thing calm we're promoting it.
The other big thing we found is waste that's happening. So over 60% of containers don't even have requests. And limits Define right?
And so you're running all these workloads. You might be over provisioning them. You might not even be putting limits in place.
So they're unbounded and so there's just That those day two problems of how do I write size my workloads? How do I have the right cluster? There's a lot of benefits from kubernetes from a cost perspective.
But if you're not using the native constructs, you can't realize any of them. And so that I think that's been a bigger Focus just as a c different booths. You're here in cost.
Everyone's obviously paying attention to the macro environment and that's something that in the past six months. We've also had a focus on it's just how do you write sizes work clothes and make cost management much easier in a kubernetes perspective, of course the board of course the board man. Hey not someone to thank you for stopping by.
Yeah. It's a great conversation. com check them out.
We're live here. I think we got like, oh maybe another hour almost of interviews. So stay tuned.
We'll be right back in a minute.





