July 13, 2023, 9:04 p.m. | fwd:cloudsec

fwd:cloudsec www.youtube.com

Abstract: gVisor is an application kernel, written in Go, that implements a substantial portion of the Linux system call interface. It provides an additional layer of isolation between running applications and the host operating system.

In this talk, we will dive into the architecture and some of the platforms of gVisor, and what security boundaries it provides for untrusted workloads. Next, we will explain its threat model and Google’s approach to continuously securing it. Finally, we will do a case …

application applications architecture call container container security dive future host interface isolation kernel linux nguyen operating system platforms running security system written

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Application Security Engineer - Enterprise Engineering

@ Meta | Bellevue, WA | Seattle, WA | New York City | Fremont, CA

Security Engineer

@ Retool | San Francisco, CA

Senior Product Security Analyst

@ Boeing | USA - Seattle, WA

Junior Governance, Risk and Compliance (GRC) and Operations Support Analyst

@ McKenzie Intelligence Services | United Kingdom - Remote

GRC Integrity Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City