Misconfigurations continue to be the primary culprits for Kubernetes security snafus, according to a new report from Sysdig.
The security firm's latest "Container Security and Usage Report” found that despite 74% of Sysdig customers scanning images in the build phase, the majority of container images are still configured to be overly permissive with 58% of them running as root. Sysdig founder and CTO Loris Degioanni identified this as “the most alarming finding” from the report.
“Developers will run images as root because it’s easier, but the number of images running this way tells us that there may be a false sense of security in containers,” Degioanni said. “The number of containers running as root points to the need to not only fix risky configurations, but also for teams to implement runtime threat detection as a safety net. If an attacker gains root access, they have the ability to take over your entire environment. The reality is that shifting left is needed, but it’s not enough and companies are leaving themselves vulnerable.”
Aaron Newcomb, director of product marketing at Sysdig and the author of the report, said the survey shows how container density – which refers to the number of containers that a single server can run at one time – has increased over the past four years. Despite container density increasing just 33% year-over-year compared with the 100% increase of last year's report, Newcomb said this still signals adoption is maturing.
“Organizations are no longer focused on just getting their applications into containers, but now they are refining their approach, focusing on efficiency and cost savings,” he added.
At the same time, the report found that 77% of respondents are using Kubernetes, up from 75% last year, with 60% having deployed one cluster compared to 55% the previous year.
Overall, 55% of all organizations are running fewer than 250 containers. While Docker (50%) continues to be the most widely employed container runtime, usage is down 27% from last year. “Not shocking, but we are also seeing a mass exit from Docker,” Newcomb said.
The Kubernetes project recently announced it will be depreciating the use of Docker in late 2021. Containerd (33%) and CRI-O (17%) experienced significant growth over the past year, up from 18% and 4% respectively.
Runtime SecurityDealing with containers in a production or runtime environment, however, can be tricky. Analysts have warned against attempting to tamper with those running containers as that can impede the supported application. Instead, they recommend organizations keep their hands off containers in production. This requires a greater focus on securing the content that makes up a running container before that content is distributed or outside of a running container.
Making security part of the container runtime allows organizations to speed the deployment of containers in production by removing gaps between developers and security teams.
Open Source ToolsIn turn, analysis shows open source tools are gaining momentum as they tap into the community to accelerate innovation, Newcomb explained. “This tells us that organizations are realizing the need for runtime security and that open source is driving container security standardization," Newcomb said.
With container density growing again this year, organizations are shifting toward Prometheus as the standard way to monitor these environments. The report notes there has been a significant increase in the reliance on Prometheus, which grew 35% year over year. Additionally, adoption of Falco, an open source runtime security project contributed by Sysdig to the Cloud Native Computing Foundation (CNCF), saw a 300% increase in adoption and more than 22 million downloads.
Security Focus IncreasingThe cloud-native ecosystem continues to blossom as enterprises increasingly look toward taking greater advantage of their cloud infrastructure to speed up their internal operations and support for external services. However, the complexity of monitoring and securing remain some of the most daunting barriers to the adoption of cloud-native technologies like containers, microservices, or Kubernetes, according to Sysdig.
Nevertheless, 2020 was a good year to be a Kubernetes-focused startup, especially for those looking to be acquired. And if that focus happened to be in the security space, well then forget about it.
Red Hat’s recent announcement that it will acquire StackRox marked the fourth Kubernetes security acquisition in less than a year. Fernando Montenegro, principal analyst for information security at 451 Research, sees this latest Kubernetes-security transaction as “yet another signal that organizations are expecting that modern platforms will have the necessary security features for properly securing their workloads.”
“We are excited by this news because it is another sign that container security is being taken seriously,” said Sysdig’s CEO Suresh Vasudevan. “It validates the massive opportunity unfolding in the security world as Red Hat realizes security and compliance are major barriers to cloud-native adoption and the importance of security for successful container platform deployments.”
Comments