November 2023 Summaries
6 posts from Sysdig
Filter
Month:
Year:
Post Summaries
Back to Blog
Sysdig's November 2023 update introduces several enhancements and new features across its cloud security platform, emphasizing improved threat detection and response capabilities. Notably, Sysdig released the 5/5/5 Benchmark for Cloud Detection and Response at SANS CyberFest 2023, setting standards for cloud attack detection and response times. The update also includes a revamped Home page for Sysdig Secure, enabling clearer visualization of critical issues and tasks, alongside enhanced compliance view tracking. New browser support details, a serverless agent hotfix, and updates to various Sysdig tools such as the CLI, Terraform provider, and Prometheus integrations are highlighted. Additional enhancements involve improved exception UI for threat detection rules, enriched user experience for the PromQL Query Explorer, and extended support for image registry scanning in Nexus and Google Artifact Registry. Falco threat detection rules have been updated to reduce false positives and introduce new rules, while Sysdig continues to expand its educational resources and events to bolster cloud security knowledge.
Nov 30, 2023
1,715 words in the original blog post.
Sysdig has achieved the Amazon EKS Ready designation from Amazon Web Services (AWS), signifying that its cloud-native application protection platform (CNAPP) is validated to integrate seamlessly with Amazon EKS and Amazon EKS Anywhere. This designation is part of the AWS Service Ready Program, which ensures that software products built by AWS Partners adhere to AWS best practices and are technically sound. Sysdig's platform, which leverages open-source Falco, helps users of Amazon EKS quickly identify and resolve security issues by correlating signals across cloud workloads, identities, and services, thereby enhancing real-time security insights and reducing the attack surface. Joint customers, such as ICG Consulting, have reported improved efficiency and competitiveness by utilizing Sysdig in tandem with Amazon EKS, highlighting the benefits of this partnership in delivering faster and more secure cloud solutions.
Nov 29, 2023
523 words in the original blog post.
Vulnerability management is a challenging and evolving area in cybersecurity, with Sysdig introducing innovations to improve the accuracy of vulnerability detection, particularly in the vulnerability matching stage of the scanning process. By focusing on affected libraries rather than broader software categories, Sysdig has reduced false positives and improved detection accuracy by leveraging trusted data sources like GitHub and GitLab, along with additional feeds from Ruby, Python, and PHP. This approach has led to significant reductions in the number of affected libraries for specific vulnerabilities, such as Log4shell and SpringShell. Sysdig's strategy of integrating multiple data sources and employing automated testing enhances the reliability and precision of vulnerability detection, emphasizing the importance of precision and adaptability in managing cybersecurity threats.
Nov 24, 2023
809 words in the original blog post.
In the cloud computing era, where Linux distributions dominate virtual hosts, traditional Endpoint Detection and Response (EDR) solutions face challenges in detecting kernel-level threats, such as the injection of Berkeley Packet Filter (BPF) backdoor programs, due to their limited visibility and reliance on high-level activity monitoring. These kernel attacks allow adversaries to manipulate host behavior undetected, compromising system integrity and data confidentiality. Sysdig addresses these shortcomings by emphasizing deep system call visibility, enabling real-time detection of subtle deviations in system behavior and enhancing response times. By correlating host and cloud audit data, Sysdig improves security readiness and response, overcoming the limitations of traditional EDRs that often fail to ingest critical Kubernetes and cloud audit logs. This approach is crucial in preventing sophisticated attacks on cloud infrastructure, ensuring the protection of sensitive data and system reliability.
Nov 16, 2023
1,506 words in the original blog post.
As organizations rapidly transition to cloud environments, traditional endpoint detection and response (EDR) systems, originally designed for workstations, struggle to keep pace with the unique demands of cloud security due to their limited visibility and response capabilities. The article argues that traditional EDRs are inadequate for cloud environments, where attacks occur quickly and across complex infrastructures like containers and Kubernetes. Sysdig's Cloud-Native Application Protection Platform (CNAPP) offers a more effective solution by integrating detection, investigation, and response capabilities tailored to the cloud, enabling security teams to handle threats at "cloud speed." With tools like the Sysdig 5/5/5 framework, which emphasizes rapid detection and correlation, Sysdig facilitates a more proactive and responsive security posture by leveraging cloud-native tools and processes for comprehensive threat management. The platform's ability to provide rich context and automate responses highlights the importance of cloud-specific solutions over traditional methods, which often fall short in correlating and contextualizing multi-dimensional incidents.
Nov 16, 2023
1,600 words in the original blog post.
Sysdig's recent renewal of the Red Hat Vulnerability Scanner certification enhances its ability to provide consistent and accurate container vulnerability scanning results for Red Hat-published images and related packages. This certification, achieved through collaboration with Red Hat, allows Sysdig to offer features like the Sysdig Risk Spotlight, which uses runtime insights to help detect, prioritize, and address Common Vulnerabilities and Exposures (CVEs) effectively. The partnership emphasizes the importance of standardization in vulnerability risk assessments, addressing inconsistencies that arise from varying security data sources. Sysdig Secure utilizes the Red Hat OVAL v2 security data feed to understand vulnerabilities in Red Hat-supported packages and determine available patches. This approach aligns with the "shift left" security practice, encouraging earlier detection of vulnerabilities in the development lifecycle to minimize security risks. The Sysdig 2023 Cloud-Native Security and Usage Report highlights the tendency for a significant portion of images to be scanned at runtime, underscoring the need for runtime insights to handle security threats efficiently.
Nov 10, 2023
1,006 words in the original blog post.