3 ms·
Looks like a nice tool, and it's great to see syscalls getting more attention. I don't fully get the argument for why on-host filtering is undesirable. Of cour
by henridf 10y ago
Looks like a nice tool, and it's great to see syscalls getting more attention.
I don't fully get the argument for why on-host filtering is undesirable. Of course naively filtering for curl-originated connections isn't a solid detection scheme for rootkit-installs! That's just a naive filter, which a naive user could mis-use in a centralized way or in a distributed way.
As for event correlation (#2 of the pros), it can be done on-host too. And back-testing (#3) of new rules is indeed a highly valuable feature! But you certainly don't have to log everything centrally to get that capability. E.g. in the case of Falco, you can capture trace files and re-run any number of rules/filters on them.
I do agree with the point on rules being exposed to an attacker.
[Disclaimer: author of the initial version of Sysdig Falco]
- akadien 10y agoRegarding on-host filtering (edge analytics), my experience has been it's because of performance, and I agree with the security angle, too.