Terenceli Profile
Terenceli

@Terenceliqiang

Followers
141
Following
2K
Media
0
Statuses
479

Joined March 2013
Don't wanna be here? Send us removal request.
@Terenceliqiang
Terenceli
9 days
RT @gnawux: Actually the entire work was done by infra security team of AntGroup, where @Terenceliqiang come from. And our container infra….
0
1
0
@Terenceliqiang
Terenceli
12 days
Through this whitepaper, we aim to share the insights and practical implementations behind AntCWPP, contributing to the evolution of the container security ecosystem and raising awareness of the security risks associated with AI agent runtime environments.
0
0
0
@Terenceliqiang
Terenceli
12 days
This solution is designed to support traditional workloads—both online and offline—while offering exceptional value for AI agent workloads, addressing their unique security challenges.
1
0
1
@Terenceliqiang
Terenceli
12 days
By integrating the strong isolation capabilities of Kata Containers with the reliable, security feature rich of eBPF, AntCWPP represents a significant leap forward in next-generation container security.
1
0
0
@Terenceliqiang
Terenceli
12 days
We are thrilled to announce the release of the AntCWPP Whitepaper, which details Ant Group's innovative approach to container runtime security.
@gnawux
gnawux
12 days
We (@ant_oss) and @openinfradev just launched the second white paper of @katacontainers in AntGroup by our infra security team and container runtime team. This white paper is about improving infra security with kata containers + eBPF:
1
1
7
@Terenceliqiang
Terenceli
3 months
初学者的角度记录了调试transformer的推理过程。《大模型是如何进行推理的?-transformer的一点代码调试分析》
0
0
1
@Terenceliqiang
Terenceli
8 months
下一个 项目起名,这个也是痛中通.
@hikerell
hikerell
8 months
我的第一个出海工具站上线了,Logo Spark,一款提供logo灵感的产品,10秒钟16个创意LOGO,支持多种设计风格,欢迎大家免费试用。.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
0
0
@Terenceliqiang
Terenceli
10 months
Worth read, Netflix debug story is always quite interesting.
@medawsonjr
Mark E. Dawson, Jr.
10 months
Interesting Netflix Performance investigation which began at a WebSocket and ended in the Linux kernel:.
0
0
0
@Terenceliqiang
Terenceli
11 months
最近在学习赖总的PVM(,发现其融合了lguest、xen、kvm等技术,特别是lguest的思想,所以需要深入研究lguest,首先就遇到一个跑不起来。记录了一下跑不动的bug和解法。.
Tweet card summary image
github.com
Miscellaneous resource about PVM. Contribute to virt-pvm/misc development by creating an account on GitHub.
0
0
2
@Terenceliqiang
Terenceli
1 year
Does landlock have a roadmap to support network access control based ip/ipblock/domain ? There are lots of requirements for this. I have implemented a sandbox which have nearly perfect process/file access control. But the networking(ip/domain) solution is not perfect currently.
@l0kod
Mickaël Salaün
1 year
#Landlock: From a security mechanism idea to a widely available implementation.Full article and slides explaining all steps from design to upstreaming: #sstic #sstic2024.
0
0
0
@Terenceliqiang
Terenceli
1 year
The FIM in production is not easy. I also thought of the inode-based method, but don't find a way to monitor the inode change. Seems the answer is also eBPF.
@kkourt
Kornilios Kourtis
1 year
Wrote a blog about how we do File Monitoring with BPF in Tetragon:
0
0
2
@Terenceliqiang
Terenceli
2 years
最近分析了gVisor的一个问题,细看之下是 在容器中mount procfs的问题,简单记录一下。当然,主要目的还是为了让blog在2023的文章不为空。. 《mount procfs in unprivileged container》.
0
0
2
@Terenceliqiang
Terenceli
2 years
gVisor is quite powerful, we have used it in behaviour monitor and access control.
@HITBSecConf
HITBSecConf
2 years
#HITB2023HKT D1T2 - gVisor: Modern Linux Sandboxing Technology - Li Qiang -
0
1
4
@Terenceliqiang
Terenceli
2 years
Oh, just notice my post was referenced in this. It's
@wiz_io
Wiz
2 years
🚨 BREAKING: Wiz Research discovered #GameOverlay — two local privilege escalation vulnerabilities in Ubuntu, affecting 40% of Ubuntu Linux workloads in the cloud 👀. a TL;DR thread 🧵
Tweet media one
0
0
1
@Terenceliqiang
Terenceli
2 years
I have a topic in this year's @HITBSecConf next month. Build a process-level sandbox based VM, and with networking and system-level security policy.
@OwariDa
Joel Eriksson
2 years
Getting closer to my ideal setup. Running individual applications, browsers etc in separate KVM-based VMs leveraging the seccomp-based QEMU sandbox to further reduce the attack surface towards the host. Using the SPICE protocol for viewing the application running within the VM.
0
5
10
@Terenceliqiang
Terenceli
2 years
RT @rhatdan: A little more then one week until the #containerplumbing conference. March 22nd and 23rd, 1300 UTC to 1800 UTC. 9:00-1:00 EDT.….
containerplumbing.org
The Conference for The Plumbing That Makes The Cloud Work
0
15
0
@Terenceliqiang
Terenceli
3 years
看到北京这一波感染之后,我的观点从“早阳早浪”变成了“能苟一天是一天”😂😂😂.
0
0
0
@Terenceliqiang
Terenceli
3 years
Interesting vul. Also it seems that the redhat portal is totally wrong referenced to another issue:
@trailofbits
Trail of Bits
3 years
Earlier this year, one of our interns found a vulnerability that affects applications using the SQLite library API. We are publicly disclosing that vuln today.
0
0
1
@Terenceliqiang
Terenceli
3 years
开源社区的同行也是形形色色的。我前段时间花了两天一晚定位了kprobe的一个bug,发了patch 也一直在pending,催了两次一直没merge,懒得管了。.
0
0
2
@Terenceliqiang
Terenceli
3 years
Just see that Falco has support gVisor .Then any plan to support Kata? @sysdig 😂.
Tweet card summary image
falco.org
Learn how to integrate gVisor and Falco on Docker and GKE
0
0
0