Loading…
February 1-2, 2023 | Seattle, WA
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for CloudNativeSecurityCon North America 2023 to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Standard Time (PST), UTC -8. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Keynote Sessions [clear filter]
Wednesday, February 1
 

9:00am PST

Keynote: Welcome + Opening Remarks - Priyanka Sharma, Executive Director, Cloud Native Computing Foundation
Speakers
avatar for Priyanka Sharma

Priyanka Sharma

Executive Director, Cloud Native Computing Foundation
Priyanka is the Executive Director of the Cloud Native Computing Foundation (CNCF) which serves as the vendor-neutral home for 100+ of the fastest-growing open source projects, including Kubernetes, Prometheus, and Envoy. She is also a co-creator of the Inclusive Naming Initiative... Read More →


Wednesday February 1, 2023 9:00am - 9:15am PST
Room 6AB

9:15am PST

Keynote: Fighting The Next War - Future Threats to OSS and Software Supply Chain Security - Brian Behlendorf, Managing Director, Open Source Security Foundation
Buffer overflows, typo-squatting, leaked credentials - many of the biggest problems in securing software today are the same greatest-hits since the 1990s. More or less once a year we see a novel kind of security attack, taking advantage of some new centralized service, a weakness we incorrectly assumed could not be exploited, or a new IT advancement that changes everything. As a keynote speech given at a 2023 Q1 conference, we are now legally required to mention ChatGPT, but ignoring the hype, the prospect of AI enabling uncanny spearfishing or automating mass pull requests with backdoors seems much less sci-fi today than it would have a year ago. What other new kinds of attacks could emerge, and what should OSS projects do to prepare?

Speakers
avatar for Brian Behlendorf

Brian Behlendorf

Chief Technology Officer, Open Wallet Foundation
Brian has served most recently as General Manager and CTO of the Open Source Security Foundation (OpenSSF), has served as Executive Director of Hyperledger, and formerly as CTO of the World Economic Forum. He currently serves on the boards of the Electronic Frontier Foundation (EFF... Read More →


Wednesday February 1, 2023 9:15am - 9:30am PST
Room 6AB

9:30am PST

Sponsored Keynote: Cloud Security’s Hidden Force: Threat Detection - Loris Degioanni, Founder and CTO, Sysdig
Threats to containers and cloud services are growing. All it takes is a vulnerable dependency, or a configuration mistake, and the entire environment is compromised. Guarding against every unknown is impossible: that’s why providing security teams with solid visibility of threats, and a path for responding to them, is so important. Threat detection is a powerful opportunity for the cloud native security community. Together, we can defend against vulnerabilities that security teams haven’t yet addressed.

In this keynote, Loris Degioanni, Founder and CTO of Sysdig, will talk about why your last line of defense is just as important as your first (and likely more so).

Speakers
avatar for Loris Degioanni

Loris Degioanni

Loris Degioanni, Founder and CTO, Sysdig, Sysdig
Loris (he/him) is the Chief Technology Officer & Founder of Sysdig. He is also the creator of the popular open source troubleshooting tool, sysdig, and the open source container security tool Falco. He is the co-author of a new book, Practical Cloud Native Security with Falco. Prior... Read More →


Wednesday February 1, 2023 9:30am - 9:35am PST
Room 6AB

9:35am PST

Keynote: Picture this! Solving Security Problems Visually with eBPF - Liz Rice, Chief Open Source Officer, Isovalent
eBPF is a wonderful platform for the next generation of security tools, but there can be a big gap between detailed events at the kernel level, and meaningful, understandable information that security and platform teams can act on. Let’s look at some of examples of graphs and visualizations that aggregate information collected through eBPF, that can help us answer security-relevant questions much more easily than wading through logs.

Speakers
avatar for Liz Rice

Liz Rice

Chief Open Source Officer, Isovalent
Liz Rice is Chief Open Source Officer with eBPF specialists Isovalent, creators of the Cilium project. She was chair of the CNCF's Technical Oversight Committee 2019-2022, and Co-Chair of KubeCon + CloudNativeCon in 2018. She is also the author of O'Reilly books "Learning eBPF" and... Read More →


Wednesday February 1, 2023 9:35am - 9:50am PST
Room 6AB

9:50am PST

Sponsored Keynote: From Google to NIST — The Future of Cloud Native Security - Zack Butcher, Founding Engineer in Product, Tetrate
Learn about the latest trends on cloud native security from creators of the NIST microservices standards. In this talk, Zack Butcher from Tetrate will dive into the driving forces behind the new standards of microservices security, how the standards are evolving, and what you must know about projects such as Istio & Envoy to get ahead of the curve.

Speakers
avatar for Zack Butcher

Zack Butcher

Founding Engineer, Tetrate, Tetrate
Zack helps large enterprises adopt Envoy and Istio. An early engineer building Istio at Google, he served on its Steering Committee and co-authored “Istio: Up and Running” (O'Reilly). He works with NIST and co-authored a series of Special Publications defining microservice security... Read More →


Wednesday February 1, 2023 9:50am - 9:55am PST
Room 6AB

9:55am PST

Keynote: Learn by Hacking: How to Run a 2,500 Node Kubernetes CTF - Andrew Martin, CEO, ControlPlane & Andrés Vega, VP of Operations, ControlPlane
TAG Security has run a CTF at Cloud Native Security events since 2020, but with a twist: instead of dastardly black hat hackers duelling for the title of Ultimate Kuberninja, we’ve focused on helping everybody to hack, teaching approachable security principles to increase the industry’s level of cloud native security expertise in novel and engaging ways.   In this talk, Andrés and Andy detail their learnings, techniques, and often last-minute fixes needed to run Kubernetes CTFs with thousands of nodes, hundreds of cloud native hackers, and buckets of coffee.  During these distributed orchestration challenges the events have seen servers burned, scenarios shredded, and authentication bypassed in all sorts of nefarious ways by the willing and able players of the game.   In this talk we detail our experience and discuss:  - How to build a tumultuous and exciting CTF challenge - Why hands-on practice is the best way to ingrain security concepts - When automating a chaotic cluster pipeline doesn't scale - Why points don’t always win prizes - And how sharing knowledge helps us grow together 

Speakers
avatar for Andres Vega

Andres Vega

Founder, M42
avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →


Wednesday February 1, 2023 9:55am - 10:10am PST
Room 6AB

10:10am PST

Sponsored Keynote: Why Developer Laptop Security is Key to Securing Your CI/CD Pipeline - Saurabh Wadhwa, Senior Solutions Engineer, Uptycs
Your developer’s laptop is only one hop away from cloud infrastructure and crown-jewel data and services.
                                                       
When it comes to securing cloud applications, security teams need to consider how they can secure the arc of application development. It often begins when a developer signs into an identity provider using their laptop, then pulls open-source code from a Git repository. Developers use Chrome extensions for development tasks, then push code through their build, test, and deploy processes using automation servers, Kubernetes, and public cloud services like AWS. At each stage, there are multiple points an attacker can target.

This session will cover the requirements for visibility into the entire development supply chain, from laptop to cloud, including:
  • Why developer laptops are often an entry point for attackers—now more than ever                 
  • How to gather real-time "device integrity" or security hygiene checks for zero-trust access 
  • How to audit for malicious Chrome extensions or vulnerable software packages 
  • How to tie together identity and GitHub activity on the laptop with CI/CD actions


Speakers
avatar for Saurabh Wadhwa

Saurabh Wadhwa

Senior Solutions Engineer, Uptycs
Saurabh is a Senior Solutions Engineer at Uptycs focusing on securing cloud and container workloads. Saurabh has been passionate about working in the cybersecurity industry for the last 11+ years having worked in the UEBA, SIEM, Threat Intelligence, XDR, and CSPM spaces. He graduated... Read More →



Wednesday February 1, 2023 10:10am - 10:15am PST
Room 6AB

10:15am PST

Keynote: Closing Remarks - Emily Fox, Security Engineer, Apple; Liz Rice, Chief Open Source Officer, Isovalent; Brandon Lum, Software Engineer, Google
Speakers
avatar for Liz Rice

Liz Rice

Chief Open Source Officer, Isovalent
Liz Rice is Chief Open Source Officer with eBPF specialists Isovalent, creators of the Cilium project. She was chair of the CNCF's Technical Oversight Committee 2019-2022, and Co-Chair of KubeCon + CloudNativeCon in 2018. She is also the author of O'Reilly books "Learning eBPF" and... Read More →
avatar for Emily Fox

Emily Fox

Security Lead - Emerging Technologies, Security Community Architect - OSPO, Red Hat
Emily Fox is a DevOps enthusiast, security unicorn, and advocate for Women in Technology. She has worked in security for over 13 years to drive a cultural change where security is unobstructive, natural, and accessible to everyone. Serving as chair on the Cloud Native Computing Foundation’s... Read More →
avatar for Brandon Lum

Brandon Lum

Software Engineer, Google
Brandon loves designing and implementing computer systems (with a focus on Security, Operating Systems, and Distributed/Parallel Systems). Brandon is Co-chair Emeritus of the CNCF Security TAG, and as a part of Google’s Open Source Security Team, he works on improving the security... Read More →


Wednesday February 1, 2023 10:15am - 10:20am PST
Room 6AB
 
Thursday, February 2
 

9:00am PST

Keynote: Opening Remarks - Liz Rice, Chief Open Source Officer, Isovalent
Speakers
avatar for Liz Rice

Liz Rice

Chief Open Source Officer, Isovalent
Liz Rice is Chief Open Source Officer with eBPF specialists Isovalent, creators of the Cilium project. She was chair of the CNCF's Technical Oversight Committee 2019-2022, and Co-Chair of KubeCon + CloudNativeCon in 2018. She is also the author of O'Reilly books "Learning eBPF" and... Read More →


Thursday February 2, 2023 9:00am - 9:05am PST
Room 6AB

9:05am PST

Keynote: Panic in San Francisco: The Critical Vulnerability That Wasn't - Shane Lawrence, Staff Infrastructure Security Engineer, Shopify
In October, the OpenSSL team found a critical vulnerability in an open source library used by millions. They warned that they would disclose the bug and release patch a week later. Their early warning and quick resolution were commendable, but in the intervening days a flurry of speculation and concern set the blogosphere ablaze and Twitter atalking. On release day, some websites promising to report details of the vulnerability struggled to keep up with the traffic as herds of security specialists, developers, and sysadmins-turned-devops-turned-platform-engineers refreshed the page in anticipation.  When details became available, many of us started to threat model the bug, evaluating how it might be used to harm our sytems. And most of us came to the same conclusion: it couldn't. The panic subsided, and the distraction arguably cost more than an exploit could have.  In this talk, Shane will summarize the vulnerability and some of his team's efforts to prepare for and respond to it, then consider lessons learned from the experience. Attendees will hear suggestions for implementing strong security programs that allow rapid evaluation and response to supply chain threats so they can be prepared for the next vulnerability, whether it turns out to be a major risk or none at all.

Speakers
avatar for Shane Lawrence

Shane Lawrence

Senior Staff Security Engineer, Shopify
Shane is a Senior Staff Infrastructure Security Engineer at Shopify, where he's working on a multi-tenant platform that allows developers to securely build scalable apps and services for crafters, entrepreneurs, and businesses of all sizes.


Thursday February 2, 2023 9:05am - 9:20am PST
Room 6AB

9:20am PST

Sponsored Keynote: OpenClarity: A Community-Led Approach to Cloud-Native Application Security - Sarabjeet Chugh, Senior Director, Global Head of Product-Led Growth, Cisco
The complexity and distributed nature of modern apps have increased the number of attack vectors. As more mission critical workloads move to cloud native architectures, there is an urgent need to protect new attack surfaces that arise. Yet, there is no single commercial tool that can comprehensively secure cloud native apps. Developers need flexible and extensible tools that are cloud native, and not a bolt on from the legacy world. And because no one knows more about what developers need than developers, it makes sense to come together as a community to create tools that developers love. Security for developers by developers. That’s what the OpenClarity suite of OSS offers - a comprehensive solution to cloud native security. Come hear all about how Cisco is leading the charge on community-powered innovation in cloud native security, AI/ML, API security, observability, network automation, and more.

Speakers
avatar for Sarabjeet Chugh

Sarabjeet Chugh

Senior Director, Global Head of Product-Led Growth, Cisco
Sarabjeet Chugh is the Global Head of Product-Led Growth for Panoptica and Calisti products at Cisco’s business incubation group. He obsesses over delightful developer experience for his products and loves to build engaging content that provides value to users and engineers community... Read More →


Thursday February 2, 2023 9:20am - 9:25am PST
Room 6AB

9:25am PST

Keynote: It Takes a Community to Raise a Conference: From Security Day to CloudNativeSecurityCon - Emily Fox, Security Engineer, Apple
Our baby colo has grown up and ventured out on its own! How did this happen? They grow up so fast!  In less than 4 years we’ve held 7 events in Europe and North America — reaching thousands of practitioners online and in person.  All from a community member’s idea and the passionate volunteers that pulled together to make it real. Emily will share her experience coordinating Security Day - now grown into CloudNativeSecurityCon - and her aspirations for the future of this conference and cloud native security.

Speakers
avatar for Emily Fox

Emily Fox

Security Lead - Emerging Technologies, Security Community Architect - OSPO, Red Hat
Emily Fox is a DevOps enthusiast, security unicorn, and advocate for Women in Technology. She has worked in security for over 13 years to drive a cultural change where security is unobstructive, natural, and accessible to everyone. Serving as chair on the Cloud Native Computing Foundation’s... Read More →


Thursday February 2, 2023 9:25am - 9:40am PST
Room 6AB

9:40am PST

Keynote: Back to the Future: Next-Generation Cloud Native Security - Matt Jarvis, Director of Developer Relations, Snyk
This talk will be a look into one possible future, taking into account multiple strands of emerging technology, and viewed through an almost certainly subjective lens of folks who’ve both been around through multiple technology iterations over the last decade or more and have the t-shirts and scars to prove it. We’ll probably be wrong, but we might get some things right, and we aim to at least be thought provoking. An eye on the future over the hill is always a good idea in our humble opinion, and thinking about those propositions can often engender change in the present !

Speakers
avatar for Matt Jarvis

Matt Jarvis

Director, Developer Relations, Snyk
Matt Jarvis is a Director of Developer Relations at Snyk. Matt has spent more than 15 years building products and services around open source software, on everything from embedded devices to large scale distributed systems. Most recently he has been focused on the open cloud infrastructure... Read More →


Thursday February 2, 2023 9:40am - 9:55am PST
Room 6AB

9:55am PST

Sponsored Keynote: Trust and Risk in the Software Supply Chain - Emmy Eide, Director, Product Security, Red Hat
Building a trusted software supply chain that minimizes risk starts at the very beginning of the development process and continues through the application life cycle. Administering security tests at the end of the development and production cycle or patching running applications is counterproductive to how cloud-native applications are built and secured. Just as automation is key for cloud native development, it’s also critical for cloud native software supply chain security. 
In this talk, we will explore balancing trust and risk throughout the entire supply chain using open source projects. We will look at why trusted supply chains are necessary, what it means to reduce risk continuously, and how Red Hat is building trust in its own software supply chain using open source technologies.

Speakers
avatar for Emmy Eide

Emmy Eide

Director, Red Hat Product Security - Supply Chain, Red Hat
Emmy Eide started at Red Hat in May 2021, forming and then leading the group responsible for software supply chain security at Red Hat. Eide is from the Pacific Northwest in the United States and has been leading in security since 2011.



Thursday February 2, 2023 9:55am - 10:00am PST
Room 6AB

10:00am PST

Keynote: The Next Steps in Software Supply Chain Security - Brandon Lum, Software Engineer, Google
We've made a lot of progress in the realm of supply chain security in recent years! However, there is still much to do. A lot of efforts have been put into developing the "producing" aspects of the Software Supply Chain - SLSA, Tekton (and other build systems), Software Bill of Materials (SBOM). This has led to a much higher fidelity security metadata than we've ever seen. As we move forward, the "consuming" aspects of the Software Supply Chain will need to be developed.

Policy, Aggregation and Synthesis are key aspects of this side of the problem. We will share some ongoing open source effort to address them and highlight gaps within the space that need to be filled.

Speakers
avatar for Brandon Lum

Brandon Lum

Software Engineer, Google
Brandon loves designing and implementing computer systems (with a focus on Security, Operating Systems, and Distributed/Parallel Systems). Brandon is Co-chair Emeritus of the CNCF Security TAG, and as a part of Google’s Open Source Security Team, he works on improving the security... Read More →



Thursday February 2, 2023 10:00am - 10:15am PST
Room 6AB

10:15am PST

Sponsored Keynote: Kubernetes is the Perfect Platform for Enforcing Zero Trust Security - Fei Huang, VP Security Product Strategy, SUSE
Zero Trust security is a hot topic these days, in more than just cloud native deployments. But with most new applications and infrastructure development being done with cloud native tools and infrastructure, zero trust is the single most critical security strategy that should be employed to secure Kubernetes environments.

In this talk, Fei Huang, VP of Security Strategy at SUSE and co-founder of NeuVector, talks about what is a zero trust strategy built around cloud native, and where zero trust protections can be enforced with examples from the ecosystem.

Speakers
FH

Fei Huang

VP Security Product Strategy, SUSE
Fei Huang has a rich history in technology, including founding 2 startups, Sr. Architect / Director at Trend Micro, CloudVolumes, and VMware, co-founder of NeuVector, and currently VP of Security Strategy at SUSE. Fei holds several patents in security, virtualization and software... Read More →



Thursday February 2, 2023 10:15am - 10:20am PST
Room 6AB

10:20am PST

 
  • Timezone
  • Filter By Date CloudNativeSecurityCon North America 2023 Feb 1 - 2, 2023
  • Filter By Venue Seattle, WA, USA
  • Filter By Type
  • 101 Track
  • Architecture + Identity + Multi-tenancy + Isolation
  • Badge Pick-Up
  • Breaks
  • Capture The Flag
  • ⚡Lightning Talks
  • Detections + Incidents + Response
  • GRC
  • Keynote Sessions
  • Security Education + Teaming
  • Solutions Showcase
  • Supply Chains
  • Tutorials
  • Content Experience Level
  • 🦝 TAG Security Recommended
  • Presentation Slides Attached

Filter sessions
Apply filters to sessions.