Securing Distributed Cache: Achieving Secure-by-Default with Key Challenges & Insights

Thursday, March 27, 2025 - 11:05 am–11:50 am PDT

Akashdeep Goel, Sriram Rangarajan, and Samuel Fu, Netflix Inc

Abstract:

In this session, we'll discuss a distributed caching system used at Netflix in multiple regions on a public cloud, handling 400 million requests per second and managing 14 petabytes of data. We'll focus on the intricacies of securing this system, including certificate lifecycle management, spurious policy lookup calls, and securing proxy calls for polyglot clients. We will walk you through our debugging journey with tools like CPU profiling and memory dumps, share key takeaways, and demonstrate how these techniques can be applied in any organization. This session will provide valuable lessons on retrofitting high-leverage systems for security compliance and executing global-scale rollouts effectively.