Abhinav Mishra, Uptycs | KubeCon + CloudNativeCon North America 2023
Transcript
This is Textron tv. Hi everyone. Welcome back.
Hey, we are down to our last interview for Cube Con Chicago. This has been one of the better cube con we've done, you know, over the years we've, oh, I think this is the seventh or eighth Q con we've Done. Wow.
Um, but this one has really been a great one. You know, I think we are, we're finally past covid. We're finally into people coming to events, and it, it's been a great event.
I, I think for me, one of the things has been the continued maturation and evolution of the open source market, Uhhuh and of the cloud native ecosystem. Absolutely. It really is real now.
And, um, my next guest is Abinov Mishna. Did I get it right? That's right.
Yep. Yeah. And he's from Upticks.
Now Upticks is a company you've seen on Text Drunk tv, and all around our sites. We, we covered them a bunch, but we're going to, I, if you haven't heard of them, it's okay. We're going to tell you a little bit about 'em.
But before we get into upticks, what, what Abinav, what do you do at Upticks? Yeah, so, uh, thanks for the opportunity. I'm a director of product at Upticks and I lead their containers and Kubernetes security offering.
So, perfect. Yeah. And I guess that takes us into upticks, right?
Yeah, yeah. What do you do? Yeah, so we're a unified, uh, cloud and endpoint security platform.
Uh, we believe that, um, in order to have unified security, uh, you can't just look inside the cluster or inside a virtual machine. You have to look at all the attack surfaces. You have to look at the entire supply chain, starting from the developer laptop to your code and bid build systems and all the way to the cloud.
So we have a, a unified, uh, security solution. Uh, we do everything from, uh, compliance to vulnerabilities. And because of our EBPA Eeb PF sensor, we can do real runtime detections and correlate back to those two misconfigurations in your cloud assets.
That's really nice. Um, it's a lot of noise going on. I guess that's what happens at the end of the, the end of the day, everybody's letting off a steam steam.
Yeah. Um, so you guys, I, I happen to notice your booth on the way in. Yeah.
A big booth out here. Lot of announcements of around upticks share with our audience 'cause they're not here. Yeah, Absolutely.
So the first announcement is around, uh, Kubernetes supply chain security. Uh, we see customers having to tackle, um, issues in terms of protect. You saw the solar winds attack that happened, there's other attacks like Okta.
And so we're recognizing that there are other parts, not just looking at a Kubernetes like AEKS cluster, but other key components as part of your software development lifecycle. Whether it's your repositories, your Jenkins build systems, your container registries. And what customers want to do is integrate those security elements, not just in terms of the image bills, but independent CIS has some supply chain benchmarks.
For example, your GitHub is not a multifactor authenticated enabled. That's a problem. And we need to, uh, take those, uh, security measures or security postures and integrated as part of the overall security checks.
So what we have is we've announced Kubernetes supply chain security, where you can integrate the security posture of those supply chain components as part of your overall software development lifecycle. You can create policies where you can say, Hey, the lip curl vulnerability plus the supply chain security, integrate those as part of my image security and either audit those or fail the image build. So don't allow them to get to runtime.
And this will, what this really allows for is proactive remediations and of course easing this tension between, uh, development teams and security teams where they can agree on remediation guidelines and prioritize what is most critical, whether it's the supply chain security or critical vulnerabilities or malware. Let's agree on what those remediation guidelines are and come with policies that, you know, enable developer velocity. But with guardrails.
The Second big announcement we're doing is around, um, it's a more of a ecosystem play. There's a framework called Kubernetes goat, like, like the animal goat. It's actually, um, catching some of the most, uh, critical container detections, such as threats such as container breakouts and rback misconfigurations.
And so because of our eeb PF telemetry and the forensics, we can do, we not only detect those in real time, we can map them back to misconfigurations such as access control risks, network security risks, and we can apply different forensics. So if there's a attacker that's hiding behind a process that looks benign, it's called, or it's called uh, upticks, but it's actually like a doing a port scan, we can use Yara rule scanning to catch that signature of the process. So these are, and this is what really it makes uptakes unique because of those runtime security protections, right.
And where customers see a lot of the value, But, but the Kubernetes go is, is a community effort. It's a community effort. I Want to make clear everyone.
Yeah, exactly. Yeah. Thanks for the clarification.
Community effort. And one of our threat researchers actually helped build those. What we're taking, we're we're taking that valuable input from the community and making sure we can productize it, but then also add value on top.
And I think we're, um, we we're seeing so many customers really seeing the benefits of that. And, uh, you know, you don't know what you don't know. So we have to provide and seed that information and so they can start to leverage it.
Um, and the last big announcement we're doing is around, uh, Kubernetes, Kubernetes network security. So you, you're probably seeing a lot around is valent and cilium and network policies, because these, what they're doing is fantastic, and we want to add value on top is a lot of times the network policies are misconfigured because it's EMO, right? You're writing these files, you're checking them in, you're using GI ops to push them to your cluster.
Uh, what we want to do is mark, which network policies are insecure and are leading the internet exposure and show them on a graph so we can say these specific pods or these specific namespace have internet exposure or have critical vulnerabilities. And that has basically, uh, allowing for, you know, better security and, and, uh, staying on top of your internet exposure risks. And so, uh, we see a lot of value, uh, with that solution.
And as we go down, we're gonna tackle things like multi-tenancy, namespace isolation, using those cilium network policies. Love it. Yeah.
Good stuff. Yeah. What else?
What else? I mean, I think, um, it's, we're actually doing a webinar next week on CubeCon in terms of the trends and connecting that back to security aspects. And it's been a fascinating CubeCon, uh, you know, at Amsterdam, um, I was at another company back at the time, we were looking at platform engineering.
And now being in upticks, I'm starting to see platform engineering and security actually come together, uh, where with platforms, they're basically providing the golden templates methodology on how to do things. And I think security becomes a natural part of the process where we're not just looking at data, but we're trying to really operationalize and create a dev developer self-service workflow, uh, around security. And you see other companies like Chain Guard where they're saying, Hey, secure on security on day zero.
Don't even look at CVEs. Look at your, look at using secure container images. And, and for us, it's the same way.
When we're building our platform, we're really not just looking at the data, but how to make those workflows very simple from a DevSecOps point of view. And that's really exciting for us. So look, so I have 25 years in security.
Yeah. But I've been doing cube con's for a long time. Yeah.
Um, I I I, I noticed it in Amsterdam. A a definite shift from like a very developer focus to a ops focus. Yeah.
And a security focus. Yeah. Now platform engineering, everybody was buzzing on platform engineering.
In my mind, we call it now platform engineering, but what it is we've been doing a long time. Exactly. Yep.
And, but security needs to be built, I don't care whether we're at the developer or the platform engineer or the ops or the dev set or the DevOps or the SRE. Yep. Security is embedded across that.
Exactly. Now, those of us in the security space, we've been preaching that for years. We are just terrible at it.
But I think we're starting to see it. We saw it in Amsterdam and, and we're definitely seeing it here in Chicago. Yep.
Security is a big part of cloud native. Yep. Absolutely.
Whether we're talking about the app, the data, the infrastructure, it's gotta be secure. Yep. Absolute.
It's gotta be In there. It's part of your fabric. And I think it's, it's one of those things where we've talked about it for a long time and we have a lot of data, but if you can make it operational, I think that's where, and with the cloud native, It's gotta be prioritized to do it.
That's always been the problem is everyone talks, it's a priority, but it's not. Now it, you know, we do a, an RSA conference. Yeah, yeah, yeah.
Security every year for the, the last eight or nine years we put on the DevSecOps event with the RSA folks on Monday of RSA week Yep. At the Moscone Center. Yep.
Last year our theme was DevOps is DevSecOps. Yeah. Agreed.
DevSecOps is DevOps. Yep. I think it's the same thing for cloud native.
Yeah. Security is part of is cloud native. Absolutely.
You can't absolutely have cloud native without it. Yeah. Like concepts, like automation for example, or, or you know, GI ops principle, they have to have security enabled by default.
And so it doesn't become an afterthought. It becomes whatever code you're building, whatever infrastructure is code you're building to, you know, it's those security is naturally built into that process. Yeah.
Um, and so I think the industry, you know, of course you still have your CVEs, you'll always have those kinds of concepts, but I think where customers are starting to think about it is, how do I just build this as part of my process? So it's not an afterthought. It's not something that I'm having to, uh, you know, think about from a secondary point of view.
It's just, it's what we do. Right. And I think, and, and That that, yeah, that's a key piece of it right there.
Yeah. Hey, you know what we didn't mention for people want to get more information about Upticks. Yeah.
Where do they go? Yeah, Absolutely. com.
Uh, Spell that for us. U-P-T-Y-C-S. Um, and if you go on our products, you can go to our containers in Kubernetes security, or you can look at what we do for cloud security and endpoints as well.
Uh, we also have our Mastering Kubernetes security ebook that we just released. Uh, it was a great thought leadership in there was a blog post. Very cool.
Yeah. So we looked at our backs and networking And everything. com and went to container Yeah.
Kubernetes security, you get the Book there, you can find it right there. Exactly. And from our blogs as well, so, okay.
Yeah. That's excellent. Yeah.
Thank you very much for joining us, man. Thanks so much. com.
Check them out. Hey, we're wrapping our coverage here in Chicago. Uh, we will be, well our next, our next event is actually reinvent.
Yeah. I don't know if you guys are gonna be, We'll be there. We'll have a big presence there.
Um, we're gonna talk around a lot of the, you know, cloud security, what we're doing for risks and attack paths and supply chain as well. So, uh, be sure to visit us there At the reinvent booth. We'll be doing live video.
Maybe you can step up in reinvent. Yeah, absolutely. We're not on the show floor there.
We're off in a suite at the wind. Yep. But we'll reach out.
Yep. We'll see you at reinvent. com.
Cloud native now, security Boulevard Digital CXO Techstrong, a AI or Techstrong tv. I'm back in the studio next week, but for now, that's a wrap.





