Loading…
February 1-2, 2023 | Seattle, WA
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for CloudNativeSecurityCon North America 2023 to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Standard Time (PST), UTC -8. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Thursday, February 2 • 11:50am - 12:25pm
CSI Container: Can You DFIR It? - Alberto Pellitteri & Stefano Chierici, Sysdig

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Digital Forensics and Incident Response (DFIR) capabilities are crucial to quickly containing the impact of an incident and preventing the cyberattack from becoming a cyber crisis. Indeed, when criminals get into your environment, it is crucial to adopt well defined DFIR techniques in order to minimize the incident impact. However, identifying and containing an incident was challenging enough in virtual machines, now with containerized applications becoming mainstream it is even more difficult. Following a brief introduction to DFIR, outlining its importance, a comparison between the traditional DFIR approach in on-premises infrastructures and the new way to be taken with containers will be presented. This will provide a better understanding of how needs and challenges have changed, particularly from the Kubernetes perspective. In addition, after a practical demonstration, the audience will get a clear picture of the best practices to adopt during the response phase - such as storing the evidence of a compromised pod remotely, highlighting and extracting the filesystem changes, and much more. To close out, it will be discussed how DFIR is evolving in Kubernetes, talking about the latest Kubernetes features and what capabilities they bring to forensics and incident response.

Speakers
avatar for Alberto Pellitteri

Alberto Pellitteri

Security Engineer, Sysdig
Alberto Pellitteri is a security engineer with a speciality in Kubernetes and Docker technologies. Currently a security engineer at Sysdig, Alberto researches malware and attacks that target cloud infrastructure and vulnerable environments. As a contributor to open source projects... Read More →
avatar for Stefano Chierici

Stefano Chierici

Threat Research Lead Manager, Sysdig
Stefano Chierici is a security researcher at Sysdig, where his research focuses on defending containerized and cloud environments from attacks ranging from web to kernel. Stefano is one of the Falco contributors, an incubation level CNCF project. He studied cyber security in Italy... Read More →



Thursday February 2, 2023 11:50am - 12:25pm PST
Room 612