UPDATED 14:30 EDT / NOVEMBER 26 2019

SECURITY

Designing security for an open-source, containerized, cloud-native world

Data security is the big issue facing enterprise today. Forget fancy social media campaigns, customer loyalty, and sales figures. One data breach can damage brand reputation in minutes, and trust takes years to rebuild.

Cloud computing and open-source development have made traditionally security measures, such as firewalls and gateways, obsolete. And the multitudes of connected devices have created a potential attack surface that grows larger by the minute.

“Security is super critical, and more so now as folks are deploying more and more mission-critical applications on the Kubernetes-based platform,” said Amit Gupta (pictured, center), vice president of business development and product management at Tigera Inc.

Gupta; Loris Degioanni (pictured, right), founder and chief technology officer of Sysdig Inc.; and Knox Anderson (pictured, left), director of product management at Sysdig, spoke with Stu Miniman (@stu), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, during the KubeCon + CloudNativeCon event in San Diego, California. They discussed how security is different in an open-source, cloud-native environment. (* Disclosure below.)

Cloud-native security requires distributed architecture

As monolithic architectures disappear, software is also changing. Instead of singular large applications, cloud-native applications are architected from hundreds of microservices operating in a dynamic and distributed fashion. This is more efficient, but “this also means that, securing, monitoring, troubleshooting infrastructures becomes much different,” Degioanni said.

As legacy security tools become obsolete, new security approaches, such as those provided by open-source projects Calico and Falco, are the way forward, Degioanni added.

Sysdig is the original creator of Falco, which Degioanni described as an open-source Cloud Native Computing Foundation phased anomaly detection system that’s based on collecting high granular data from a running Kubernetes environment.

The big challenge in the Kubernetes space is around incident response and audit,” Anderson said.

Tigera and Sysdig have collaborated to manage security within Kubernetes workflows, creating products that provide security across the entire container lifecycle. “So, at build time, making sure your images are properly configured, free of vulnerabilities at run time, looking at all the activity that’s happening,” Anderson stated.

So as enterprise architecture is designed, organizations must think about how to design security across the entire infrastructure “in a distributed fashion or done in the early stages of your projects,” Gupta pointed out. “Just like your applications are being deployed in an automated fashion, your security has to be done in that fashion. So, policy as code, infrastructure as code, and the security is just baked in as part of that process. It’s critical you design that way to get the best outcomes.”

Watch the complete video interview below, and be sure to check out more of SiliconANGLE’s and theCUBE’s coverage of the KubeCon + CloudNativeCon event. (* Disclosure: Sysdig Inc. sponsored this segment of theCUBE. Neither Sysdig nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.