meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

It's still possible to find ways to break out. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, Technology, News, Daily News

4.81.1K Ratings

🗓️ 10 October 2020

⏱️ 19 minutes

🧾️ Download transcript

Summary

Containers offer speed, performance, and portability, but do they actually contain? While they try their best, the shared kernel is a disturbing attack surface: a mere kernel vulnerability may allow containerized processes to escape and compromise the host. This issue prompted a new wave of sandboxing tools that use either unikernels, lightweight VMs or userspace-kernels to separate the host OS from the container's OS. One of these solutions is Kata Containers, a container runtime that spawns each container inside a lightweight VM, and can function as the underlying runtime in Docker and Kubernetes. Kata's virtualized containers provide two layers of isolation: even if an attacker breaks out of the container, he is still confined to the microVM. Joining us in this week's Research Saturday to discuss the research is Yuval Avrahami from Palo Alto Networks Unit 42. The research presented at Black Hat USA 2020 can be found here:  Escaping Virtualized Containers Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's research Saturday.

1:25.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts

1:29.0

tracking down threats and vulnerabilities, solving some of the hard problems of protecting ourselves in a rapidly

1:35.2

evolving cyberspace.

1:37.3

Thanks for joining us.

1:38.3

We are talking about the containers sandboxes, which is actually a technology for

1:46.4

a sandboxing and isolating containers. That's Yoval Avrahami, he's a

1:51.9

principal security researcher at Palo Alto Networks with Unit 42.

1:56.8

The research we're discussing today is titled escaping virtualized containers.

2:01.4

It's part of a presentation that he gave at Black Hat 2020.

2:07.0

You can sense to glory. If this is started something.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.