Join our colleague Constanze Roedig, key researcher at SBA Research, at Cloud Native Days Sofia, Austria, where she will give a deep dive titled Zoom in and you shall find: Adaptive Kubernetes SOC that stays sovereign and reduces data volume.
© Constanze Roedig
Abstract
The linux kernel through eBPF offers to unify the disparate fields security and observability through shared data structures. We show how a K8s Security Operations Center, organically composed of established eBPF projects can see signals that the individuals cannot.
We explain how we achieve both a comprehensive baseline and use independent signals to dial up/down coverage as suspicious indicators surface. The mutual independence of signals from across processes, file system, and network activity achieves a high signal-to-noise, enabling manageable data volumes and facilitating selective forensic storage.
You will see two shorts demos: (A) of a root-kit which is hard to detect for sys-call based security tools in their default configurations, however almost trivial to detect with our adaptive setup. (B) of an agentic AI attack that mimicks a cobalt-strike C2 server You ll also learn how our SOC architecture is node-local and can be airgapped. This means no data leaves the cluster and you remain sovereign and in control of your data.
About the event
Cloud Native Days Austria is a community-focused event bringing together cloud-native professionals, developers, and technology enthusiasts to exchange knowledge, share practical experiences, and explore the latest trends in Kubernetes, containers, DevOps, and cloud-native technologies.
