Kubernetes Audit Log Gotchas: Challenges in Multi-Cloud Detection and Forensics
fwd:cloudsec via YouTube
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore a comprehensive conference talk that delves into the complexities and challenges of implementing Kubernetes audit logging across different cloud environments. Learn about the critical role of K8s audit logs in detecting security events and API server activities, while understanding the practical difficulties encountered when working with various Cloud Service Providers (CSPs). Discover the limitations of default logging policies, format inconsistencies between cloud vendors, and performance considerations that impact security monitoring. Gain valuable insights into potential blind spots in attack detection, rule triggering issues, and alternative logging sources that can enhance your security posture. Master the nuances of audit log management in both managed and unmanaged Kubernetes clusters, with specific focus on platforms like EKS, AKS, GKE, and OKE.
Syllabus
Kubernetes Audit Log Gotchas ~ Shay Berkovich
Taught by
fwd:cloudsec