Top Banner
SESSION ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich Chris Hoff CTO @Bromium @simoncrosby SVP Product Docker, Inc CTO Azure Microsoft @markrussinovich VP & CTO Security Juniper Networks @beaker
15

Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

May 27, 2018

Download

Documents

trinhthu
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

SESSION ID:

#RSAC

MODERATOR: PANELISTS:

Containers vs VMs for Secure Cloud Applications

ASD-W04

Simon Crosby Scott Johnston

Mark Russinovich

Chris Hoff

CTO @Bromium

@simoncrosby

SVP Product

Docker, Inc

CTO Azure

Microsoft

@markrussinovich

VP & CTO Security

Juniper Networks

@beaker

Page 2: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

#RSAC

This is an “Intermediate” Level Panel

You know enough to be dangerous about

Docker/LXC, Windows, Linux, Virtualization

Private and Public Cloud Architectures

Our goals

1. Highlight security considerations / challenges for app delivery in VMs

and containers on Public & Private Clouds

2. Offer architectural guidelines to maximize containerized app security

3. Spotlight security roadmap for Docker, Azure, Micro-Services &

Micro-virtualization

2

Page 3: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

#RSAC

3

Page 4: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

4

Page 5: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

#RSAC

5

Page 6: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

6

OS [VM]

App Containers

Cloud Infrastructure

Container Orchestration

Page 7: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

7

Page 8: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

8

Page 9: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

9

Page 10: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

© Bromium 2014 10

Layered Multiplexing VMs Cloud

containers VMs

Page 11: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

11

Multiplexing = Shared Fate

Page 12: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

12

Multiplexing = Shared Fate

Page 13: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

13

Isolation = Protection

Page 14: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

#RSAC

Get involved!

docker.com/resources/security

If your organization is developing cloud apps using containers / VMs

Make security-first a design commitment

Understand the security differences & limitations of containers and VMs

Educate your dev-ops team on the security / compliance challenges of any shared infrastructure environment – even if it is a private cloud

Educate your team on the role of micro-services networking to help to secure cloud based applications

14

Apply What You Have Learned Today

Page 15: Containers vs VMs for Secure Cloud Applications ID: #RSAC MODERATOR: PANELISTS: Containers vs VMs for Secure Cloud Applications ASD-W04 Simon Crosby Scott Johnston Mark Russinovich

#RSAC