Crossing the Bridge - A Journey Through Attack Vectors in Managed Kubernetes Services

Crossing the Bridge - A Journey Through Attack Vectors in Managed Kubernetes Services

Source: YouTube · SANS Cloud Security · published Nov 28, 2023 · 30:48

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Summary of Attack Vectors in Managed Kubernetes Environments

The presentation explores critical attack vectors in managed Kubernetes environments like AWS EKS, focusing on how an attacker who has compromised a pod can pivot to gain control over the underlying cloud infrastructure.

Key Takeaways:
• The speakers, Chris and Nick from Datadog, introduce the scope of discussing cloud security, specifically targeting AWS, GCP, and Azure, with a primary focus on AWS EKS 0:06.
• The operational context involves worker nodes running pods, where the attacker's initial position is a compromised pod with the ability to exploit local vulnerabilities 0:50.
• The primary objective of the attack chain is to pivot from the compromised Kubernetes pod to the underlying cloud account (AWS, GCP, or Azure) to escalate privileges and access broader resources 1:00.

Understanding these pivot paths is essential for securing managed Kubernetes clusters against cloud-native threats.

Sources:

  • 0:06 Introduction of speakers and topic overview.
  • 0:50 Definition of the EKS and pod environment context.
  • 1:00 Explanation of the attacker's goal to pivot to cloud accounts.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

thanks Jonathan um hi everyone thank you for being here today we're going to be discussing attack Victors in in manage cuberes environments so my name is Chris K repair I'm French living in Switzerland and I'm working at data dog mostly focusing on open source and and Cloud security and container security topics hey everyone my name is Nick forat I'm a security researcher also a data dog I specialize in AWS offensive security great so uh today we're going to maybe set the stage a little bit we're going to be in the cloud and we're going to use mostly AWS as an example but we'll also talk about gcp and Asia um so we're going to talk about EK which is the managed offering for kubernetes in AWS and so in that context we're going to be inside uh in2 uh in2 worker nodes that are running um that…