Speaker
Description
This talk explores how to secure cloud workloads using a practical stack of open source tools. We'll look at how services like NGINX can serve as a secure reverse proxy and web gateway, IPS/IDS like Suricata can provide high-performance network intrusion detection and prevention, and utilities like fail2Ban can automatically respond to malicious behavior by blocking abusive clients. We'll also discuss additional open source components that complement this stack, such as CrowdSec for collaborative threat intelligence, Wazuh for host-based detection and monitoring, and Netfilter/nftables for modern Linux firewalling.
Rather than focusing on individual tools in isolation, the session demonstrates how these components can work together to build layered, enterprise-grade security for cloud-native and traditional workloads. Through real-world deployment patterns, architecture diagrams, and practical examples, attendees will learn how to detect threats, reduce attack surfaces, automate incident response, and improve visibility across their infrastructure.
Whether you're running workloads on public cloud, private cloud, or Kubernetes, you'll leave with a blueprint for building a cost-effective security stack using open source technologies—without compromising on capability or scalability.
Session author's bio
Bala is the Co-founder and chief architect at CISOGenie. He has been a free software user and evangelist for over 20 years.
| Level of Difficulty | Intermediate |
|---|---|
| In Person Attendance | Remote |
| Agree to Privacy Policy and Notice | I agree |
| Please confirm that there are included headshots of all speakers in their profiles | Yes |