The Container Escape Room: An Exploration of Container Escapes - Amit Schendel @OWASPGLOBAL
The Container Escape Room: An Exploration of Container Escapes - Amit Schendel  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 3 weeks ago
In this presentation, we will explore an innovative approach to improve the security of containerized applications using behavior analysis during continuous integration testing and generating native policies based on behavior. By leveraging behavioral analysis, we can replace tedious manual policy definitions which take long to define and can break easily. We will also discuss the importance of native policies, which allow us to enforce security policies directly within container orchestration tools like Kubernetes without relying on third-party tools.


We will focus on policies like seccomp profiles, network policies, AppArmor, and security context. We will cover hands-on practices for implementing this approach, including how to do behavioral analysis using eBPF-based tools, how to integrate this analysis into CI testing, and how to use native policies to enforce security policies.


By the end of this presentation, attendees will have a deeper understanding of how to leverage innovative approaches to security in Kubernetes clusters (and in containerized orchestration in general), and how to use behavioral analysis and native policies to protect their environments against the multiple threats.

-

Managed by the OWASP® Foundation
owasp.org
The Container Escape Room: An Exploration of Container Escapes - Amit SchendelOWASP Nettacker ProjectSanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail - Yaniv NizryPay the Maintainers: xz utils Hack Highlights the Dangers of OSS Maintainer Burnout - Matthew ArnowHow to Embed Privacy Threat Modeling in Agile Sprint Rituals Without Slowing Teams DownOWASP Global Board of Directors Meeting - August 20259125 Days of OWASP  Did We Make Software Safer?OWASP Global Board of Directors - April 2026Global AppSec USA 2025 Washington, D.C.2022 Global AppSec San Francisco: Swathi Joshi KeynoteIndirect Prompt Injection: Architectural Testing Approaches for Real World AI/ML SystemsUnlocking Secure Development: A Deep Dive into OWASP ASVS
OWASP Foundation |

The Container Escape Room: An Exploration of Container Escapes - Amit Schendel

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER