Loading…
June 26-27, 2024 | Seattle, WA
View More Details | Registration Information

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for CloudNativeSecurityCon North America 2024 to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Daylight Time (PDT), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

The schedule is subject to change.
Wednesday June 26, 2024 11:00am - 11:35am PDT
445
Container sandboxing is one of the best approaches we have to securing high-risk or untrusted container workloads. In the AI-first world, demand for these types of workloads, whether it be running untrusted LLM-generated code or training on proprietary datasets, is growing fast. In this talk you will learn about the different approaches to sandboxing containers and tradeoffs associated with them. Then Lucas will dive deep into the implementation of the open source gVisor sandbox and container runtime. Lucas will discuss new sandboxed hardware accelerator support in gVisor, implementation trade-offs, the ways gVisor is being used to mitigate AI/ML security risks, and the work the gVisor team has done to reduce the performance costs of sandboxing.
Speakers
avatar for Lucas Manning

Lucas Manning

Software Engineer, Google
Lucas is a software engineer at Google, working on the gVisor project since 2021. His work spans across the entire gVisor ecosystem, including hardware accelerator support, virtual filesystem compatibility, and networking performance.
Wednesday June 26, 2024 11:00am - 11:35am PDT
445
  Supply Chains + Containers + Application Security
Feedback form is now closed.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link