securing applications in containers pdfs/dd 18 präsentat… · securing applications in containers...

29
Copyright @ 2017 Aqua Security Software Ltd. All Rights Reserved. Securing Applications in Containers Aqua Container Security Platform

Upload: others

Post on 11-Jun-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

Copyright @ 2017 Aqua Security Software Ltd. All Rights Reserved.

Securing Applications in ContainersAqua Container Security Platform

Page 2: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

2

In 5 years ALL new software deployments will be based on containers, running in a hybrid environment

Page 3: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

3

GARTNER PREDICTS

By 2020, more than 50% of global organizations will be

running containerized applications in production, up from less

than 20% today.

Gartner’s 6 Best Practices for Creating a Container Platform Strategy

Page 4: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

Copyright @ 2017 Aqua Security Software Ltd. 4

Page 5: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

Copyright @ 2017 Aqua Security Software Ltd. 5

Page 6: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

6

What Are Containers?

New form of lightweight virtualization.

Makes applications think they have a

complete operating system for

themselves.

Container[kuhn-TAY-ner] , noun

Page 7: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

7

Containers: A New Approach to Computing

Host OS

App

Host

Host OS

App App

VOS VOS

Host

Host OS

Container engine

Host

SCALABILITY, DENSITY, COMPLEXITY

VIRTUALIZATION CONTAINERIZATION

Page 8: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

8

MAKING A CONTAINERIZED APPLICATION

< / >

.NET

Docker Image Docker Host

Page 9: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

9

MAKING A CONTAINERIZED APPLICATION

< / >

.NET

Docker Image Docker Host

Page 10: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

10

CHALLENGE #1: VISIBILITY

What is in the image?

What will it do?

Who made it?

Is Development making infrastructure decisions?

Page 12: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

12

CHALLENGE #2: PROCESS

Where to add security in the pipeline?

Is the image still the same when it gets to the hosts?

Who can run containers and manage them?

How to get inventory of what is running?

Page 13: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

13

RUNNING CONTAINERS ON THE HOST

Page 14: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

14

RUNNING CONTAINERS ON THE HOST

CPU

Page 15: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

15

CHALLENGE #3: CONTROL

What is each container doing? Is it what it’s supposed to?

How to limit user context and permissions?

What network connections is the container making?

How to give specific, sensitive, information to a container?

Page 16: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

16

CONTAINERS HAVE GREAT BENEFITS

Runs AnywhereUp in Seconds Massive Scale

Page 17: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

17

SECURITY IS A BARRIER TO ADOPTION

Page 18: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

18

BRIDGING THE GAP

Shift Left Automate Prevent

Page 23: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

23

CONTAINERS + AQUA = BETTER SECURITY

Page 24: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

24

THE SECURITY FOUNDATION FOR CONTAINERS

1. Image Assurance

2. Runtime Protection

3. Container Network Firewall

4. Secret Management

5. Access Control and Docker Compliance

Page 25: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

25

AQUA SECURITY: SNAPSHOT

TEAM

70 experienced, passionate innovators

FORTUNE 1000 CUSTOMERS

Banking Media

Insurance Healthcare

Retail Travel

Software & Internet Telecommunications

Investors

Light Ventures Capital Microsoft Ventures TLV PartnersShlomo Kramer

Tel Aviv San Francisco Boston

Page 26: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

26

DEPLOYMENT ARCHITECTURE

Center

Aqua Command Center

Aqua Cyber Intelligence

Linux/Windows OS

Aq

ua

En

forc

er

Co

nta

ine

r

Co

nta

ine

r

Container Engine

Public Registry

Private Registry

CI/CD SIEM / Analytics

Aqua Gateways

Page 27: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

TO THE DEMO

Page 28: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

28

For Additional Info

Our Resource Center: www.aquasec.com/resources/

Container Wiki: www.aquasec.com/wiki

Page 29: Securing Applications in Containers PDFs/DD 18 Präsentat… · Securing Applications in Containers Aqua Container Security Platform. 2 In 5 years ALL new software deployments will

WWW.AQUASEC.COM