Protecting your web applications built on Kubernetes
Download resourcesAbout this session
Tomer Rozentvaig, who leads application security product management at Radware, explains why conventional application protection struggles with microservices on Kubernetes and how Radware's Kubernetes WAAP is built for it. With 77 percent of organisations on microservices and 69 percent running Kubernetes in production, he argues that complexity is the vulnerability: dozens of components, third-party images and tools, CI/CD pipelines and many people with direct access widen the penetration surface, while 86 percent of traffic is east-west and largely unmonitored, letting malware move laterally during a dwell time that can last months. Perimeter defence and micro-segmentation are necessary but insufficient, and a service mesh enforces mTLS and authorisation yet cannot inspect the HTTP traffic that carries most attacks. The missing piece is layer-7 inspection at the microservice level, which must integrate natively with Kubernetes (Helm, GitOps, autoscaling) and add negligible latency. He describes Radware's low-footprint agent, learned positive and negative security policies, air-gapped operation and a Fortune 500 hybrid deployment. Q&A covers sidecar mode, VM workloads, latency, black-box applications and offline licensing; the session ends with a prize draw.
More and more DevOps teams rely on Kubernetes when developing their next-gen containerized applications. Learn how you can keep a high level of security without slowly down your fast-paced development cycles using frictionless cyber security solutions.
Key takeaways
- Assume penetration can come from the back end (developer laptops, third-party images, CI/CD tools), not only the internet-facing edge, and plan detection for the lateral-movement phase where malware is noisiest.
- Get visibility on east-west traffic between microservices; with 86 percent of traffic internal and mostly on HTTP, port-level controls cannot separate legitimate from malicious calls.
- Keep the service mesh for mTLS and authorisation, but add layer-7 inspection at the microservice level to catch web and API attacks inside the cluster.
- Require any in-cluster security tool to deploy via Helm, follow GitOps, scale with Kubernetes and expose APIs and event export, or DevSecOps teams will route around it.
- Measure the added latency of inspection and use limits on inspection time and size to balance security against user experience.
Speakers
Tomer is a 25-year Hi-Tech industry Expert. He has been actively involved in developing, inventing and leading product development for distributed heterogeneous networks environments for military and paramilitary organizations. His Career has been… Read moreRead less
Tomer is a 25-year Hi-Tech industry Expert. He has been actively involved in developing, inventing and leading product development for distributed heterogeneous networks environments for military and paramilitary organizations. His Career has been focused on 3 main aspects: providing value to customers, excellent user experience and security. In his various roles, Tomer was leading all Security Risk Analysis tasks and was responsible to implement mitigation solutions at every layer of the network.