Detection Policies
Falco uses syscall-based detection policies to monitor low-level kernel events and identify suspicious behavior in Kubernetes workloads. By defining custom rules that target specific syscalls, you can create fine-grained security policies tailored to your environment. This section demonstrates how to configure Falco to monitor syscalls for runtime security events.
Defining Syscall Rules in Falco¶
Falco policies are defined in the falco.yaml configuration file (typically located at /etc/falco/falco.yaml). Rules are structured using the rules section, where each rule specifies a syscall, conditions, and alerting logic.
Example: Monitoring File Access¶
- rule: Unauthorized File Access
desc: Detect attempts to read sensitive files
condition: (open.filename contains "/etc/passwd") and (open.flags contains "O_RDONLY")
output: "Process {{ pid }} ({{ comm }}) attempted to read {{ open.filename }}"
priority: medium
tags: [k8s, file]
This rule triggers when a process opens /etc/passwd in read-only mode, which could indicate reconnaissance activity.
Enabling Kubernetes Context in Rules¶
Falco can integrate with Kubernetes to filter events based on pod metadata. Use the k8s.pod.namespace and k8s.pod.name fields to scope alerts to specific workloads:
- rule: Suspicious Exec in Production Namespace
condition: (execve.filename contains "/usr/bin/curl") and (k8s.pod.namespace = "production")
output: "Pod {{ k8s.pod.name }} executed {{ execve.filename }} in production namespace"
priority: high
tags: [k8s, network]
To enable Kubernetes context, start Falco with the --k8s-apiserver flag and ensure it runs as a privileged container or with appropriate SELinux/AppArmor policies.
Testing and Validating Rules¶
After configuring rules, test them by simulating events:
Verify Falco alerts:
Use falco --help to explore additional testing options, such as replaying audit logs or simulating syscalls.
Key Takeaways¶
- Define rules using
conditionto target specific syscalls and contextual metadata. - Leverage Kubernetes fields like
k8s.pod.namespaceto scope alerts to workloads. - Test rules with
falco --testto ensure they trigger expected alerts. - Adjust priorities and tags to align with your organization's security policies.