清单文件是如何欺骗你的以及为什么 eBPF 是你最好的测谎仪?.pdf

编号:981765 PDF 17页 1.95MB 下载积分:VIP专享
下载报告请您先登录!

清单文件是如何欺骗你的以及为什么 eBPF 是你最好的测谎仪?.pdf

1、#SECTORCA SecTorCAHow Manifest Files Are Lying to You,and Why eBPF Is Your Best Lie Detector?Aleksandr Krasnov#SECTORCA SecTorCAsectorcan:$whoami-Security Engineer-Independent Researcher-DevSecOps&“The Office”geekIntroduction#SECTORCA SecTorCAsectorcan:$less Threat LandscapeSolarWinds Orion Attack-2

2、020a.$1B lost in market value,$18M lost in additional costs like legal fees+settlementsb.https:/www.sec.gov/ix?doc=/Archives/edgar/data/1739942/000162828020017451/swi-20201214.htmPyPI Typosquatting Attack-2019a.Unknown loss in value due to affecting numerous customersb.https:/ NPM Library Hack-2021a

3、.Over$20M lost in audits,system remediation,and security patchingb.https:/ Why:Threat Landscape#SECTORCA SecTorCAsectorcan:$grep-ri“shift left”Well,of course there is Shift Left#SECTORCA SecTorCAsectorcan:$ls/opt/my-appThe What:SDLCDesignDevelopBuildDeployManifest File:-Metadata-Dependencies-Configu

4、ration Information-Entry Points#SECTORCA SecTorCAsectorcan:$bpftool prog showShort Intro:eBPFSource:ebpf.io/what-is-ebpf#SECTORCA SecTorCAsectorcan:$cd/opt/my-app&eval$stageShort Intro:Build Processnpm init-ynpm run buildnpm updateSounds easy?Nope.#SECTORCA SecTorCAsectorcan:$nc-lvnp 8080Attackers P

5、erspectiveIdentify Package NameRegister a malicious package on public repositoryDependency Resolution+Code Execution#SECTORCA SecTorCAsectorcan:$cat risk_classificationRisk ClassificationStaleSketchyHijackedInconclusive#SECTORCA SecTorCAsectorcan:$more architecture.txtArchitectural Weaknesses Enviro

6、nmentCodeLibrary3rd party serverMalicious C2Legit#SECTORCA SecTorCAsectorcan:$find/-type f-name“*attack*”Example of eBPF control:ScenarioEnvironmentCodeLibrariesMalicious C257.129.63.131:8080Everything Else#SECTORCA SecTorCAsectorcan:$vim/cilium/program.cExamp

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(清单文件是如何欺骗你的以及为什么 eBPF 是你最好的测谎仪?.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠