YoVDO

Relational Observability for Cloud-Native Security and Data Science

Offered By: Linux Foundation via YouTube

Tags

Cloud-Native Security Courses Data Science Courses Python Courses Kubernetes Courses Telemetry Courses Security Analysis Courses Observability Courses eBPF Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a comprehensive conference talk on SysFlow, a runtime observability framework for cloud-native security and data science. Delve into how SysFlow elevates system call events collected via eBPF into process behaviors, creating a powerful open telemetry format. Learn about its ability to record interactions between processes, containers, and Kubernetes pods with their environment, including network, filesystem, and inter-process communications. Discover how SysFlow's compact format enables the creation of stateful system behavioral graphs from streaming data, providing crucial context for security analysis. Understand how this framework addresses common issues in system call data collection, such as the lack of security semantics and excessive data volume. Gain insights into the full suite of open-source tools for collecting and processing SysFlow, including a self-contained library for creating SysFlow consumers, Python APIs, and an interactive Jupyter environment for security data science tasks. Witness a practical application of SysFlow in Kubernetes security monitoring, where declarative security policies identify attack behaviors and perform threat investigations using process-level provenance tracking in interactive playbooks.

Syllabus

Relational Observability for Cloud-Native Security and Data Science- Frederico Araujo & Teryl Taylor


Taught by

Linux Foundation

Tags

Related Courses

Analyzing Postgres Performance Problems Using Perf and eBPF
Microsoft via YouTube
Citus Con - An Event for Postgres - Americas Livestream
Microsoft via YouTube
EBPF - The Next Power Tool of SREs
USENIX via YouTube
Kernel Tracing With EBPF
media.ccc.de via YouTube
Building Observability for 99% Developers
Docker via YouTube