Restricted Address Spaces for Container Security
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore container security through restricted address spaces in this 30-minute conference talk by IBM experts Mike Rapoport and James Bottomley. Delve into topics such as container images, hardware resolution, vulnerability, and parent namespaces. Examine network namespaces, unmapped management, and related use cases. Gain insights into kernel page tables, direct mapping, and benchmarks. Investigate cache considerations, GFP and Lab exclusives, metadata, and the networking stack. Conclude with testing methodologies and key takeaways for enhancing container security through address space restrictions.
Syllabus
Introduction
Container images
Container hardware resolution
Container vulnerability
Parent namespace
Network namespace
Unmapped
Management
Related Use Cases
Kernel Page Tables
Direct Map
Benchmarks
Cache
GFP Exclusive
Lab Exclusive
Metadata
Networking Stack
Conclusion
Testing
Taught by
Linux Foundation
Tags
Related Courses
Maintaining Deployment Security in Microsoft AzurePluralsight Microsoft Azure Security Engineer: Configure Advanced Security for Compute
Pluralsight Microsoft Azure Security Technologies (AZ-500) Cert Prep: 2 Implement Platform Protection
LinkedIn Learning Securing Containers and Kubernetes Ecosystem
LinkedIn Learning Performing DevSecOps Automated Security Testing
Pluralsight