Although more than 90% of organizations have the open-source container orchestration tool Kubernetes deployed in their environments or will do so in the next two years, alarmingly few have integrated recommended security controls. According to recent polls conducted with IT teams managing Kubernetes:
1. Misconfigurations
According to the same security poll mentioned above, 60% of Kubernetes security problems originate from misconfigurations. Some of the most common misconfigurations that create vulnerabilities include:
2. Immutable Infrastructure
Developers spin Kubernetes and other container types from instances of immutable infrastructure, meaning the application or services are inalterable once iterated. Immutable infrastructure helps prevent configuration drift caused by different manual adjustments to applications running in different containers. Nevertheless, it also increases the rate at which development teams spin new containers, often outpacing security standards and oversights.
3. Lack of Runtime Visibility
Development teams often bypass pre-deployment security tasks such as vulnerability scans. Consequently, 97% of organizations lack runtime visibility into container vulnerabilities while they attempt to manually investigate an average of 2169 new application vulnerability notifications every month. While most alerts prove to be false positives, the overload of information often conceals real attacks that cannot be captured by traditional Linux monitoring tools.
Although these Kubernetes security concerns have different origins in the development lifecycle, they share in common the overloading of preventative security measures such as vulnerability scanning and configuration checklists. As the strain on security resources is set to continue for the foreseeable future, organizations need tools to shift from a purely preventative security posture to balance in active runtime visibility and intervention.
Using eBPF technology to thoroughly illuminate activities and processes across distributed, containerized environments, Spyderbat gives the ability to identify and stop attacks in real time. Spyderbat also captures workload behaviors and identifies new runtime deviations to alert or even take action.
Schedule a personalized Spyderbat demo today.