falco-security Cloud Native Runtime Security开源项目

我要开发同款
匿名用户2021年11月26日
128阅读

技术信息

行业分类
云计算
开源地址
https://github.com/darklife/darkriscv
授权协议
Apache-2.0 License

作品详情

 

CloudNativeRutimeSecurity.

Wattotalk?Joiusothe#falcochaelitheKuberetesSlack.

Latestreleases

Readthechagelog.

 developmetstablerpmdebbiary

TheFalcoProject,origiallycreatedbySysdig,isaicubatigCNCFopesourcecloudativerutimesecuritytool.Falcomakesiteasytocosumekerelevets,aderichthoseevetswithiformatiofromKuberetesadtherestofthecloudativestack.FalcohasarichsetofsecurityrulesspecificallybuiltforKuberetes,Liux,adcloud-ative.Ifaruleisviolatediasystem,Falcowillsedaalertotifyigtheuseroftheviolatioaditsseverity.

IstalligFalco

IfyouwouldliketoruFalcoiproductiopleaseadheretotheofficialistallatioguide.

Kuberetes

ToolLikNoteHelmChartRepositoryTheFalcocommuityoffersregularhelmchartreleases.MiikubeTutorialTheFalcodriverhasbeebakeditomiikubeforeasydeploymet.KidTutorialRuigFalcowithkidrequiresadriverothehostsystem.GKETutorialWesuggestusigtheeBPFdriverforruigFalcooGKE.Developig

Falcoisdesigedtobeextesiblesuchthatitcabebuiltitocloud-ativeapplicatiosadifrastructure.

FalcohasagRPCedpoitadaAPIdefiediprotobuf.TheFalcoProjectsupportsvariousSDKsforthisedpoit.

SDKs

LaguageRepositoryGocliet-goRustcliet-rsPythocliet-pyWhatcaFalcodetect?

FalcocadetectadalertoaybehaviorthativolvesmakigLiuxsystemcalls.Falcoalertscabetriggeredbytheuseofspecificsystemcalls,theirargumets,adbypropertiesofthecalligprocess.Forexample,Falcocaeasilydetecticidetsicludigbutotlimitedto:

AshellisruigisideacotaierorpodiKuberetes.Acotaierisruigiprivilegedmode,orismoutigasesitivepath,suchas/proc,fromthehost.Aserverprocessisspawigachildprocessofauexpectedtype.Uexpectedreadofasesitivefile,suchas/etc/shadow.Ao-devicefileiswritteto/dev.Astadardsystembiary,suchasls,ismakigaoutboudetworkcoectio.AprivilegedpodisstartediaKuberetescluster.Documetatio

TheOfficialDocumetatioisthebestresourcetolearaboutFalco.

JoitheCommuity

TogetivolvedwithTheFalcoProjectpleasevisitthecommuityrepositorytofidmore.

Howtoreachout?

Joithe#falcochaelotheKuberetesSlackJoitheFalcomailiglistReadtheFalcodocumetatioCotributig

SeetheCONTRIBUTING.md.

SecurityAudit

AthirdpartysecurityauditwasperformedbyCure53,youcaseethefullreporthere.

Reportigsecurityvulerabilities

Pleasereportsecurityvulerabilitiesfollowigthecommuityprocessdocumetedhere.

LiceseTerms

FalcoislicesedtoyouudertheApache2.0opesourcelicese.

功能介绍

Cloud Native Runtime Security. Want to talk? Join us on the #falco channel in the Kubernetes Slac...

示例图片

声明:本文仅代表作者观点,不代表本站立场。如果侵犯到您的合法权益,请联系我们删除侵权资源!如果遇到资源链接失效,请您通过评论或工单的方式通知管理员。未经允许,不得转载,本站所有资源文章禁止商业使用运营!
下载安装【程序员客栈】APP
实时对接需求、及时收发消息、丰富的开放项目需求、随时随地查看项目状态

评论