Skip to content

[D4C] cloud_defend. Removed kubernetesPodId. Update docs. - #6112

Merged
mitodrummer merged 8 commits into
mainfrom
cloud_defend_v106
May 11, 2023
Merged

mitodrummer merged 8 commits into
mainfrom
cloud_defend_v106

Conversation

@mitodrummer

Copy link
Copy Markdown
Contributor

What does this PR do?

Removes documentation for an unimplemented selector condition.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

@elasticmachine

elasticmachine commented May 5, 2023 •

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-05-11T07:20:49.762+0000

  • Duration: 14 min 54 sec

Test stats 🧪

Test Results
Failed 0
Passed 7
Skipped 0
Total 7

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@elasticmachine

elasticmachine commented May 5, 2023 •

Copy link
Copy Markdown

🌐 Coverage report

Name Metrics % (covered/total) Diff
Packages 100.0% (0/0) 💚
Files 100.0% (0/0) 💚 2.894
Classes 100.0% (0/0) 💚 2.894
Methods 26.667% (4/15) 👎 -65.821
Lines 100.0% (0/0) 💚 7.98
Conditionals 100.0% (0/0) 💚

@mitodrummer
mitodrummer requested a review from norrietaylor May 5, 2023 23:49

@norrietaylor norrietaylor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@learhy

learhy commented May 10, 2023

Copy link
Copy Markdown
Contributor

Karl, I think the readme should also act as the source of truth for our feature compatibility matrix:

<style type="text/css"></style>

  EKS 1.24-1.26 (AL2022) GKE 1.24-1.26 (COS)
Process event exports ✅ ✅
Network event exports ✅ ✅
File event exports ✅ ✅
File blocking ✅ ✅
Process blocking Coming Soon Coming Soon
Network blocking ❌ ❌
Drift prevention ✅ ✅
Mount point awareness ✅ ✅

I also think we could replace the overview section with this text which I think does a better job of really describing the integration:

How Container Workload Protection Works
CWP is powered by a lightweight integration (Defend for Containers) that is bundled and configured by the Elastic Agent. The agent is installed as a daemonset on supported Kubernetes clusters and the integration uses eBPF LSM and tracepoint probes to produce system events. Events are evaluated against eBPF LSM hook points, enabling a configured policy to be evaluated before system activity is allowed to proceed.

The policy determines which system behaviors (for example, process executions, file creations or deletions, etc) will result in an action. Actions are simple: logging the behavior to Elasticsearch, creating an alert in Elasticsearch, or blocking the behavior.

Threat Detection
The system ships with a default policy configured featuring two selectors and responses. The first selector is designed to stream process telemetry events to the user’s Elasticsearch cluster. The policy uses the selector allProcesses which specifies fork and exec operations. This selector is mapped to the allProcesses response, which specifies a log action.

The resulting telemetry data is transformed into an ECS document and streamed back to the user’s Elasticsearch cluster, where the Elastic Security SIEM evaluates the data to detect malicious behavior.

Drift Detection & Prevention
The second selector is written to detect the modification of existing executables or the creation of new executables within a container (This is how Elastic detects “container drift”). The policy selector is named executableChanges and is mapped to a response section called executableChanges which specifies an alert action.

This policy is configured with an alert response, meaning that when drift conditions are detected, the matching event(s) are collected and written as an alert to the user’s Elasticsearch cluster. A prebuilt rule “escalation rule” in the SIEM watches for these alert documents and raises an alert in the SIEM when drift is detected. This policy can also be modified to block drift operations by changing the response action to block.

Policies
Users that want to use the full strength of CWP will benefit to understand the system’s policy syntax, which enables fine-grained policies to be constructed. Policies can be built to precisely match expected container behaviors– disallowing any unexpected behaviors– and thereby substantially hardening the security posture of container workloads.

Policies are composed of selectors and responses. A given policy must contain at least one selector and one response. Currently, the system supports two types of selectors and responses, file and process. Selectors tell the service what system operations to match and have a number of conditions that can be grouped together (using a logical AND operation) to provide precise control. Responses instruct the system on what actions to take when system operations match selectors.

@norrietaylor

Copy link
Copy Markdown
Contributor

@learhy I think your suggestions here are great, but they are outside the scope of the PR. I will transpose them into a new issue and we get them in the queue.

@learhy

learhy commented May 10, 2023 via email

Copy link
Copy Markdown
Contributor

@norrietaylor

norrietaylor commented May 10, 2023 •

Copy link
Copy Markdown
Contributor

My bad, I've created the new issue linked above for my own clerical reasons :)

@mitodrummer

Copy link
Copy Markdown
Contributor Author

Thanks for the comments @learhy I can make the change in this PR. This just avoids version churn as we're already at 1.0.5

@mitodrummer

Copy link
Copy Markdown
Contributor Author

@norrietaylor @learhy Did we want to add anything about having to uncomment "capabilities" in the yaml?

@mitodrummer mitodrummer changed the title [D4C] cloud_defend. Removed kubernetesPodId [D4C] cloud_defend. Removed kubernetesPodId. Update docs. May 10, 2023
@norrietaylor

norrietaylor commented May 10, 2023 via email

Copy link
Copy Markdown
Contributor

@mitodrummer
mitodrummer requested a review from norrietaylor May 11, 2023 16:11

@norrietaylor norrietaylor left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mitodrummer
mitodrummer merged commit b5996ff into main May 11, 2023
@elasticmachine

Copy link
Copy Markdown

Package cloud_defend - 1.0.6 containing this change is available at https://epr.elastic.co/search?package=cloud_defend

@andrewkroh andrewkroh added the Integration:cloud_defend Defend for Containers (BETA) label Jul 20, 2023
@andrewkroh andrewkroh added the Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] label Sep 18, 2024
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/sec-linux-platform (Team:Security-Linux Platform)

@norrietaylor
norrietaylor deleted the cloud_defend_v106 branch September 23, 2024 21:22
orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
* removed kubernetesPodId

* pr link update

* copy overhaul + support matrix

* beta

* formatting

* formatting

* formatting

* words
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:cloud_defend Defend for Containers (BETA) Team:Security-Linux Platform Linux Platform Security team [elastic/sec-linux-platform] v8.8.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants