YoVDO

Using SmartNICs to Provide Better Data Center Security

Offered By: 44CON Information Security Conference via YouTube

Tags

44CON Courses Network Security Courses Data Center Security Courses SmartNICs Courses

Course Description

Overview

Explore a comprehensive conference talk on enhancing data center security using SmartNICs, delivered by Jack Matheson at 44CON 2018. Dive into the challenges faced by traditional security models and discover how SmartNIC-based solutions address performance and security issues in edge-centric policy enforcement. Learn about a novel SmartNIC-based reference architecture for network layout and examine examples of SmartNIC security controls with their corresponding threat models. Uncover an innovative technique for tamper-proof host introspection, leveraging SmartNICs' unique position to analyze and inspect host memory. Gain insights into how this approach complements network controls, enhancing workload integrity measurement and improving overall data center security compared to traditional software-only controls.

Syllabus

Introduction
Agenda
The Problem
The Attack Surface
Traditional Host Security
Time and Persistence
SmartNICs
MustHaves
Typical SmartNIC
Isolation
Checklist
OVS Model
Connection Tracking Rules
Embedding
OVS
OBS
Memory Access
Putting it all together
Demonstration


Taught by

44CON Information Security Conference

Related Courses

FlexTOE - Flexible TCP Offload with Fine-Grained Parallelism
USENIX via YouTube
Rearchitecting the TCP Stack for I-O-Offloaded Content Delivery
USENIX via YouTube
QEMU Storage Daemon and libblkio: Exploring New Frontiers for the QEMU Block Layer
Linux Foundation via YouTube
Using Kubernetes with Data Processing Units to Offload Infrastructure
CNCF [Cloud Native Computing Foundation] via YouTube
Enhancing K8s Networking with SmartNICs
CNCF [Cloud Native Computing Foundation] via YouTube