Chapter 14. PaC and the Software Supply Chain
The software supply chain (SSC) includes activities involved in the creation and delivery of software solutions for in-house use, commercial sale, and OSS development. These activities—arranged into processes and automated pipelines—build, test, and maintain software components. As an industry, we have increased our focus over the past several years on securing the SSC and avoiding attacks and exploitations, made possible through known and unknown vulnerabilities.
At the time of this writing, there are many emerging technologies and approaches being used and espoused that promise to improve how we manage SSC. These technologies and approaches come on the heels of some very well-known SSC attacks. I think we need to look at these and similar attacks in general, and imagine how we could help detect or even prevent them with the correct application of PaC solutions.
Attacking Normal
Years ago, when I was surveying Kubernetes security tools, I reviewed a network tool that functioned by first learning the network behavior of Pods. Once Pod network behavior was recorded and characterized, the solution would alert of possible aberrant network behavior and even quarantine Pods found to be “misbehaving.” This use case is common in the realm of network security, though it was new to internal Kubernetes cluster networking at the time.
As it turns out, cybersecurity attacks are frequently detected when operations of systems and components stray ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access