
Terenceli
@Terenceliqiang
Followers
141
Following
2K
Media
0
Statuses
479
Joined March 2013
RT @gnawux: Actually the entire work was done by infra security team of AntGroup, where @Terenceliqiang come from. And our container infra….
0
1
0
We are thrilled to announce the release of the AntCWPP Whitepaper, which details Ant Group's innovative approach to container runtime security.
We (@ant_oss) and @openinfradev just launched the second white paper of @katacontainers in AntGroup by our infra security team and container runtime team. This white paper is about improving infra security with kata containers + eBPF:
1
1
7
最近在学习赖总的PVM(,发现其融合了lguest、xen、kvm等技术,特别是lguest的思想,所以需要深入研究lguest,首先就遇到一个跑不起来。记录了一下跑不动的bug和解法。.
github.com
Miscellaneous resource about PVM. Contribute to virt-pvm/misc development by creating an account on GitHub.
0
0
2
Does landlock have a roadmap to support network access control based ip/ipblock/domain ? There are lots of requirements for this. I have implemented a sandbox which have nearly perfect process/file access control. But the networking(ip/domain) solution is not perfect currently.
#Landlock: From a security mechanism idea to a widely available implementation.Full article and slides explaining all steps from design to upstreaming: #sstic #sstic2024.
0
0
0
gVisor is quite powerful, we have used it in behaviour monitor and access control.
#HITB2023HKT D1T2 - gVisor: Modern Linux Sandboxing Technology - Li Qiang -
0
1
4
Oh, just notice my post was referenced in this. It's
🚨 BREAKING: Wiz Research discovered #GameOverlay — two local privilege escalation vulnerabilities in Ubuntu, affecting 40% of Ubuntu Linux workloads in the cloud 👀. a TL;DR thread 🧵
0
0
1
I have a topic in this year's @HITBSecConf next month. Build a process-level sandbox based VM, and with networking and system-level security policy.
Getting closer to my ideal setup. Running individual applications, browsers etc in separate KVM-based VMs leveraging the seccomp-based QEMU sandbox to further reduce the attack surface towards the host. Using the SPICE protocol for viewing the application running within the VM.
0
5
10
RT @rhatdan: A little more then one week until the #containerplumbing conference. March 22nd and 23rd, 1300 UTC to 1800 UTC. 9:00-1:00 EDT.….
containerplumbing.org
The Conference for The Plumbing That Makes The Cloud Work
0
15
0
Just see that Falco has support gVisor .Then any plan to support Kata? @sysdig 😂.
falco.org
Learn how to integrate gVisor and Falco on Docker and GKE
0
0
0