Defending Your Cloud Native Apps Against the Serverless Top 10 with Raz Probstein

  Рет қаралды 76

DevSecCon

DevSecCon

Жыл бұрын

As serverless gains adoption, would-be attackers come prowling - and this means serverless security needs to level up. That said, serverless security know-how is still not a commodity, as most current security tools, apps and practices are targeted at more legacy architecture patterns, making it challenging to ramp up security at the pace of engineering.
Excellent resources have been created over the years, including the OWASP Serverless Top 10, however, understanding how to practically apply these takes time and research if you aren't a domain expert. In this talk, we'll take a deep dive on what a typical serverless app composed of lambda functions and containers looks like, including the various layers it's comprised of: code, infrastructure , runtime and its supply chain. We'll map each of these to the possible risks based on the OWASP Top 10 list, and demo through excellent opens source tools how you can defend your application against these threats on each of your app's layers.

Пікірлер
Tech Talk: What is Public Key Infrastructure (PKI)?
9:22
IBM Technology
Рет қаралды 107 М.
Wait for the last one! 👀
00:28
Josh Horton
Рет қаралды 160 МЛН
That's how money comes into our family
00:14
Mamasoboliha
Рет қаралды 9 МЛН
Самое Романтичное Видео ❤️
00:16
Глеб Рандалайнен
Рет қаралды 6 МЛН
Дибала против вратаря Легенды
00:33
Mr. Oleynik
Рет қаралды 5 МЛН
Chrome Exposes Scary System Functions To All Google Domains
25:58
Theo - t3․gg
Рет қаралды 7 М.
Do NOT Learn Kubernetes Without Knowing These Concepts...
13:01
Travis Media
Рет қаралды 246 М.
Good Presentation VS Bad Presentation *
5:13
Project IDEA
Рет қаралды 4,3 МЛН
5 Of The Most Dangerous Jobs In The World | Big Business | Business Insider
24:13
Robotaxis | Big Ideas 2024
9:41
ARK Invest
Рет қаралды 51 М.
"Sell Me This Pen” - Best 2 Answers (Part 1)
4:51
Amro_Dubai
Рет қаралды 9 МЛН
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
VMware got Broadsided and Alternatives in the Post ESXi Era
1:00:57
Everything MSP
Рет қаралды 12 М.
OWASP ML Security Top 10
57:09
DevSecCon
Рет қаралды 190
Не плавайте тут! 🏊🚫
0:24
Взрывная История
Рет қаралды 2 МЛН
100❤️
0:19
MY💝No War🤝
Рет қаралды 14 МЛН
Оказался НЕНУЖНЫМ и Его БРОСИЛИ🐶💀
0:38
ИССЛЕДОВАТЕЛЬ
Рет қаралды 4,4 МЛН