Cloud Security Podcast

What is CADR?

6 snips
Dec 5, 2024
In this discussion, Shauli Rozen, co-founder and CEO of ARMO Security and an expert in Kubernetes security, dives into the fascinating world of cloud application detection and response (CADR). He highlights the challenges faced in runtime security and critiques traditional CSPM tools. The conversation also covers the 'Four C's' of cloud security—cloud, cluster, container, and code—and emphasizes the crucial role of runtime data using eBPF. Shauli's insights shed light on how Kubernetes is transforming DevOps and security collaboration.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Runtime Security in Kubernetes

  • Runtime security analyzes real-time activity in a Kubernetes cluster, including system calls, code execution, and network events.
  • This differs from CSPM/KSPM, which primarily focus on static configurations and vulnerabilities.
INSIGHT

The Four C's of Cloud Security

  • CADR (Cloud Application Detection and Response) combines Cloud, Cluster, Container, and Code security.
  • It creates a comprehensive view of security by integrating CDR, KDR, ADR, enabling better threat detection and response.
ADVICE

Evaluating Security Tools

  • Question everything and test claims about security tools.
  • Evaluate EBPF agents by testing them against real-world attacks and analyzing false positives.
Get the Snipd Podcast app to discover more snips from this episode
Get the app