Hacking Kubernetes: Threat-Driven Analysis and Defense
暫譯: 駭客攻擊 Kubernetes:威脅驅動的分析與防禦

Martin, Andrew, Hausenblas, Michael

  • 出版商: O'Reilly
  • 出版日期: 2021-11-16
  • 定價: $2,270
  • 售價: 8.8$1,998 (限時優惠至 2025-02-02)
  • 語言: 英文
  • 頁數: 314
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1492081736
  • ISBN-13: 9781492081739
  • 相關分類: Kubernetes駭客 Hack
  • 立即出貨 (庫存=1)

買這商品的人也買了...

相關主題

商品描述

Want to run your Kubernetes workloads safely and securely? This practical book provides a threat-based guide to Kubernetes security. Each chapter examines a particular component's architecture and potential default settings and then reviews existing high-profile attacks and historical Common Vulnerabilities and Exposures (CVEs). Authors Andrew Martin and Michael Hausenblas share best-practice configuration to help you harden clusters from possible angles of attack.

This book begins with a vanilla Kubernetes installation with built-in defaults. You'll examine an abstract threat model of a distributed system running arbitrary workloads, and then progress to a detailed assessment of each component of a secure Kubernetes system.

  • Understand where your Kubernetes system is vulnerable with threat modelling techniques
  • Focus on pods, from configurations to attacks and defenses
  • Secure your cluster and workload traffic
  • Define and enforce policy with RBAC, OPA, and Kyverno
  • Dive deep into sandboxing and isolation techniques
  • Learn how to detect and mitigate supply chain attacks
  • Explore filesystems, volumes, and sensitive information at rest
  • Discover what can go wrong when running multitenant workloads in a cluster
  • Learn what you can do if someone breaks in despite you having controls in place

商品描述(中文翻譯)

想要安全地運行您的 Kubernetes 工作負載嗎?這本實用的書籍提供了一個基於威脅的 Kubernetes 安全指南。每一章都檢視特定組件的架構和潛在的預設設定,然後回顧現有的高知名度攻擊和歷史上的常見漏洞與暴露(Common Vulnerabilities and Exposures, CVEs)。作者 Andrew Martin 和 Michael Hausenblas 分享最佳實踐配置,幫助您從可能的攻擊角度加固叢集。

本書從一個使用內建預設的基本 Kubernetes 安裝開始。您將檢視一個運行任意工作負載的分散式系統的抽象威脅模型,然後深入評估安全 Kubernetes 系統的每個組件。

- 了解您的 Kubernetes 系統在哪裡存在漏洞,使用威脅建模技術
- 專注於 pods,從配置到攻擊和防禦
- 保護您的叢集和工作負載流量
- 使用 RBAC、OPA 和 Kyverno 定義和執行政策
- 深入探討沙箱和隔離技術
- 學習如何檢測和減輕供應鏈攻擊
- 探索檔案系統、卷和靜態敏感資訊
- 發現在叢集中運行多租戶工作負載時可能出現的問題
- 學習如果有人突破控制措施,您可以採取什麼行動

作者簡介

Andrew Martin is CEO of ControlPlane.

Michael Hausenblas is Product Developer Advocate Amazon Web Service.

作者簡介(中文翻譯)

安德魯·馬丁(Andrew Martin)是 ControlPlane 的執行長。

邁克爾·豪森布拉斯(Michael Hausenblas)是亞馬遜網路服務(Amazon Web Service)的產品開發倡導者。