We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

seccomp — Your Next Layer of Defense

00:00

Formal Metadata

Title
seccomp — Your Next Layer of Defense
Title of Series
Number of Parts
49
Author
License
CC Attribution 4.0 International:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
Why should you allow all possible system calls from your application when you know that you only need some? If you have ever wondered the same then this is the right talk for you. We are covering: * What is seccomp in a nutshell and where could you use it. * Practical example with Docker, Elasticsearch, and Beats. * How to collect seccomp violations with Auditd. Because your security approach can always use an additional layer of protection.
Point cloudExt functorInformation securityMultiplication signCartesian coordinate systemAdditionComputer animationXMLUML
FlagElasticity (physics)Instance (computer science)Exploit (computer security)Figurate numberPoint (geometry)Data miningWordCAN busSingle-precision floating-point formatPanel paintingXMLUMLComputer animation
Elasticity (physics)Physical systemSystem callKernel (computing)AdditionSet (mathematics)WritingControl flowProcess (computing)Cartesian coordinate systemResource allocationConnected spaceComplete metric spacePhysical systemComputer fileProfil (magazine)Asynchronous Transfer ModeSystem callGame controllerKernel (computing)Control flowSoftwareGroup actionCodeVulnerability (computing)Remote procedure callSemiconductor memoryConfiguration spaceReal numberMountain passSuite (music)AngleOpen setSystem identificationRevision control2 (number)Uniform resource locatorForcing (mathematics)MassPhysical lawPole (complex analysis)XMLComputer animation
SineKernel (computing)System callPhysical systemWeb pageLine (geometry)CloningFlock (web browser)Physical systemForm (programming)Different (Kate Ryan album)Order (biology)System callNumberComputing platformInterface (computing)Bit
Metropolitan area networkMilitary operationPhysical systemSystem callProcess (computing)Thread (computing)CodeAsynchronous Transfer ModeNetwork socketBlock (periodic table)Sign (mathematics)Reading (process)Web pageLine (geometry)Pointer (computer programming)Digital filterNamespaceParameter (computer programming)CloningProfil (magazine)Execution unitRight angleAsynchronous Transfer ModeRoutingHypermediaCore dumpSoftwareComputer animationSource code
Digital filterFingerprintSystem callPhysical systemKernel (computing)AdditionNewton's law of universal gravitationCAN busGoogle ChromeComputer-integrated manufacturingSineCloningMilitary operationUser profileSpherical capMathematical singularityComputer architectureFilter <Stochastik>Cartesian coordinate systemRootkitLevel (video gaming)Default (computer science)System callNeuroinformatikPhysical systemProfil (magazine)EmailMultiplication signKernel (computing)Error messageElectronic mailing listRight angleBasis <Mathematik>SpacetimeBitGraphical user interfaceProcess (computing)Java appletNamespaceTerm (mathematics)Shared memoryThread (computing)Information securityComputer programmingOnline chatSimilarity (geometry)WindowResultantParameter (computer programming)AdditionVideo game consolePhysical lawArmGraph coloringReal numberMathematicsColor confinementView (database)Dimensional analysisSet (mathematics)Goodness of fitReduction of orderMessage passing2 (number)VotingProduct (business)PerimeterFigurate numberReading (process)Uniform resource locatorComputer animation
State of matterSystem callArithmetic mean2 (number)Physical systemProcess (computing)Point (geometry)Physical lawProduct (business)Different (Kate Ryan album)Multiplication signGame theoryPersonal digital assistantSampling (statistics)Beat (acoustics)Filter <Stochastik>Asynchronous Transfer ModeLoginComputer animation
State of matterSoftware developerSlide rulePhysical systemBeat (acoustics)Software developerSoftwareFilter <Stochastik>Phase transitionProduct (business)2 (number)Computer animation
FlagBeat (acoustics)Product (business)Open setConnectivity (graph theory)Profil (magazine)Insertion lossPoint (geometry)2 (number)Computer animation
Beat (acoustics)Electronic data interchangeSingle-board computerJava appletLogical constantSimilarity (geometry)Different (Kate Ryan album)System programmingOperations researchFingerprintHydraulic jumpLibrary (computing)Group actionString (computer science)Electronic mailing listTelnetDemo (music)Beat (acoustics)CodeProjective planeLibrary (computing)Binary codeMoving averageSource codeProcess (computing)BitImplementationMoment (mathematics)Remote procedure callMetric systemProfil (magazine)Group actionWindowFilter <Stochastik>Multiplication signComputing platformJava appletSoftwareDefault (computer science)Operating systemOpen sourceDrop (liquid)Physical systemRule of inferenceLoginRun time (program lifecycle phase)Event horizonData storage deviceInformation securityKeyboard shortcutElectronic mailing listCartesian coordinate systemRootkitComputer architectureRevision controlServer (computing)Exception handlingLatent heatFerry CorstenSystem callOctahedronGoodness of fitVideo gameSineSet (mathematics)MathematicsLimit (category theory)Physical lawProof theoryDigital electronicsFamilyWater vaporCASE <Informatik>Staff (military)Insertion lossTelecommunicationCategory of beingKey (cryptography)Source codeComputer animation
Gastropod shellLoginCartesian coordinate systemMessage passingKeyboard shortcutDifferent (Kate Ryan album)TelecommunicationProduct (business)Video gameInstance (computer science)WeightComputer animation
Demo (music)System callStatisticsSpeicherschutzTotal S.A.Network socketMultiplication signBinary codeKeyboard shortcutElectronic mailing listPhysical systemQuantum state1 (number)CASE <Informatik>Spectrum (functional analysis)Computer programmingArmRow (database)Error messageSystem callProfil (magazine)Right angleCartesian coordinate systemFerry CorstenInteractive televisionComputer animation
System callWeightNamespaceDemo (music)Computer programmingPhysical systemData storage deviceLibrary (computing)Process (computing)CuboidProfil (magazine)System callCodeKeyboard shortcutBoolean algebraTraffic reportingCartesian coordinate systemProjective planeXMLUMLComputer animation
Total S.A.SpeicherschutzNetwork socketInformationBinary codeKeyboard shortcutPhysical systemMixed realityProfil (magazine)System callProcess (computing)Electronic mailing listCartesian coordinate systemProcedural programmingOrder (biology)Quantum stateSource codeComputer animation
MathematicsServer (computing)Digital filterFlagBeat (acoustics)Filter <Stochastik>Run time (program lifecycle phase)Proof theoryRemote procedure callKeyboard shortcutSystem callCodeMultiplication signProfil (magazine)MathematicsData structurePoint (geometry)Number1 (number)Rule of inferenceBeat (acoustics)Cartesian coordinate systemPhysical systemBitBinary code2 (number)WordOrder (biology)DemosceneTape driveRight angleRepetitionMoving averageComputer animation
FlagLibrary (computing)Limit (category theory)DemonBinary codeFunction (mathematics)Open sourceLibrary (computing)Cartesian coordinate systemFile formatBeat (acoustics)Order (biology)Form (programming)Computer animation
Meta elementEvent horizonPoint cloudNetwork topologyFingerprintComputer reservations systemField (computer science)FlagProcess (computing)Group actionComputer-generated imageryDigital filterOpen setPrice indexACIDRevision controlComputer networkCountingTable (information)Mach's principleSystem callTime zoneMessage passingModule (mathematics)Service (economics)Kernel (computing)Local area networkHaar measureInformationArchitectureSoftware bugAuthenticationOperations researchPhysical systemPlastikkarteSource codeMusical ensembleDrop (liquid)AdditionTimestampStructural loadWeb browserWindowFamilyInformation securityTouchscreenComputer programmingPhysical systemProfil (magazine)Event horizonInstance (computer science)Binary codeInformationOperating systemLoginCloud computingAddress spaceProcess (computing)Type theoryMedical imagingMessage passingReal numberBitGroup action1 (number)Latent heatBefehlsprozessorOrder (biology)RoutingOffice suiteData managementRoundness (object)Goodness of fitInternet service providerHuman migrationCrash (computing)Software testingPole (complex analysis)Service (economics)Beat (acoustics)Wave packetComa BerenicesAliasingBit rateSurgeryComputer animation
Similarity (geometry)Elasticity (physics)ZugriffskontrolleInterface (computing)Independence (probability theory)System callKernel (computing)CAN busPhysical systemInformation securityCartesian coordinate systemProcess (computing)BitCoefficient of determinationPhysical systemCore dumpRule of inferenceCross-platformKernel (computing)Slide ruleProjective planeLevel (video gaming)Profil (magazine)Set (mathematics)Mobile appWindowAuthorizationSensitivity analysisOnline helpSystem callBinary codeArmVideo game2 (number)Web browserXMLComputer animation
Digital filterProcess (computing)Event horizonMessage passingGroup actionTimestampStructural loadElasticity (physics)Observational studyBinary codeHypermediaPhysical law2 (number)Process (computing)Profil (magazine)Reading (process)Information securityRight angleRule of inferenceTwitterArithmetic meanMereologyCollaborationismVideo gameCASE <Informatik>Data managementSelf-organizationQuicksortLevel (video gaming)BitProgramming languageMultiplication signModel checkingWeb applicationInterface (computing)Configuration spaceCartesian coordinate systemJava appletSlide ruleMultiplicationMobile appSoftware bugShared memoryGraphical user interfaceServer (computing)RootkitDirectory serviceComputer fileGeneric programmingProjective planeSimilarity (geometry)WritingControl flowMiniDiscLatent heatComputer animationXMLUML
Point cloudJSONXMLUML
Transcript: English(auto-generated)