World Congress 2024 • Aug 20, 2024 • Session details

A Hitchhikers Guide to Container Security - Automotive Edition 2024

Reinhard

Can a compromised software container hijack a car's physical hardware? Watch a live instrument cluster hack. Then, discover how eBPF acts as both a defensive shield and stealthy threat.

Pause
Mute Enter Fullscreen
#1 about 3 min

Analyzing past internet attacks on distributed vehicle systems

Early attacks leveraged command injection and port scanning to compromise independent electronic control units via infotainment networks.

#2 about 3 min

Overcoming physical wiring constraints in legacy automotive networks

Traditional vehicle architectures rely on deeply segmented networks of microcontrollers connected by complex wire harnesses.

#3 about 2 min

Centralizing vehicle networks with high performance computers

Modern automotive architectures adopt cloud-like centralized computing and operating systems to facilitate regulatory updates and virtualization.

#4 about 2 min

Deploying isolated container runtimes on embedded Linux systems

Running standard bare metal hypervisors and container orchestration engines introduces resource friction on constrained embedded chips.

#5 about 4 min

Injecting network messages directly from compromised container environments

Exposing physical hardware interfaces directly to Docker networks allows process environments to manipulate mission-critical systems like brakes and dashboard speedometers.

#6 about 3 min

Protecting hardware access controls using eBPF security hooks

Compiling secure byte code logic within the Linux kernel stops rogue system calls and network packets without altering local processes.

#7 about 4 min

Intercepting and filtering automotive network traffic with eBPF

Integrating standard cloud egress monitoring with embedded vehicle protocols enables software-defined networking oversight across local vehicle interfaces.

#8 about 2 min

Blocking unauthorized peripheral updates via SPI bus monitoring

Programming kernel-level listeners selectively drops volatile bus transactions before hardware flashing overwrites root device partitions.

#9 about 3 min

Uncovering stealthy offensive eBPF rootkits in critical infrastructure

Offensive kernel interventions manipulate memory states dynamically and suppress application tracing mechanisms while leaving little to no defensive footprint.

Matching moments

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:13 min

Ecosystem of tooling and future capabilities of eBPF

Mohammed Aboullaite Mohammed Aboullaite · World Congress 2024

52 sec

Introduction to eBPF as a secure virtual machine

Ayesha Kaleem · World Congress 2023

9:13 min

Tackling functional complexity with localized vehicle electronic architectures

Hans-Jürgen Eidler · LIVE

5:56 min

Interfacing with core vehicle systems and handling software permissions

Stephan Schuster · World Congress 2022

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 2

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 4

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar