19
Ultra Secure Data Center on Amazon Cloud Lahav Savir, Architect & CEO Emind systems ltd. [email protected]

Ultra Secure Cloud Data Center on AWS

  • Upload
    newvewm

  • View
    630

  • Download
    0

Embed Size (px)

DESCRIPTION

This presentation is an introduction to Emind Systems' in-house best practice for an ultra-secure application deployment on the AWS cloud. This best practice is based on Emind's experience in performing dozens of infrastructure projects based on the Amazon Web Services’ platform.

Citation preview

Page 1: Ultra Secure Cloud Data Center on AWS

Ultra Secure Data Centeron Amazon Cloud

Lahav Savir, Architect & CEOEmind systems [email protected]

Page 2: Ultra Secure Cloud Data Center on AWS

About

Lahav Savir• 15+ years in on-line industry• Architect and CEO @ Emind Systems

Emind Systems (est. 2006)• Boutique system integrator• AWS solution provider• 100+ AWS customers

Page 3: Ultra Secure Cloud Data Center on AWS

Amazon (AWS) Certification

Amazon Solution Provider& Consulting Partner

https://aws.amazon.com/solution-providers/si/emind-systems-ltd

Page 4: Ultra Secure Cloud Data Center on AWS

What is secure data center ?

• Isolated and controlled• Firewalled• Secure access– VPN– SSL

• Audited• Intrusion detection &

prevention• Configuration analysis

• Data encryption• Antivirus• Frequent updates• User management– One time password

• One spot for monitoring– Centralized alerts and

notifications

• Regulatory compliance

Page 5: Ultra Secure Cloud Data Center on AWS

Emind’s best practice

Page 6: Ultra Secure Cloud Data Center on AWS

Access Management

• Control the data flow– AWS VPC– ACL– Routing– Handle all in/out traffic

• Access control– Security groups

• Identity access management– One-time-password– AWS IAM with MFA

Page 7: Ultra Secure Cloud Data Center on AWS

ACL & Routing in the VPC

7

Page 8: Ultra Secure Cloud Data Center on AWS

Emind’s best practice

8

VPC

IAM

Traffic

Page 9: Ultra Secure Cloud Data Center on AWS

Traffic Control

• Log in / out traffic• Terminate encrypted connection• Sanitize in / out packets– Real-time decisions– Accept / reject connections– Rate limiting

9

Page 10: Ultra Secure Cloud Data Center on AWS

Emind’s best practiceVPC

IAM

TrafficEncryption

Sanitize

Page 11: Ultra Secure Cloud Data Center on AWS

Anomalies detection

• Host based IDS– Detect configuration changes– Track running processes– Track file access– Resource access– Detect abnormal behavior !

• OS hardening• App cleanup

Page 12: Ultra Secure Cloud Data Center on AWS

Emind’s best practiceVPC

IAM

TrafficEncryption

Sanitize

Host IDS

Hardening

Page 13: Ultra Secure Cloud Data Center on AWS

Data Protection

• In-flight– SSL encryption– IPSec

• In-rest– Storage level encryption– Data base encryption

Page 14: Ultra Secure Cloud Data Center on AWS

Emind’s best practiceVPC

IAM

TrafficEncryption

Sanitize

Host IDS

Hardening

Data Enc.

Data Enc.

Page 15: Ultra Secure Cloud Data Center on AWS

Data aggregation

• Need to aggregate– VPN access logs– Traffic audit logs– Network IDS logs– Host IDS logs– Anti virus logs

• Detect patterns

15

Page 16: Ultra Secure Cloud Data Center on AWS

Emind’s best practiceVPC

IAM

TrafficEncryption

Sanitize

Host IDS

Hardening

Data Enc.

Data Enc.

Aggregate

Aggregate

Page 17: Ultra Secure Cloud Data Center on AWS

Security lifecycle management

• Ongoing log discovery & analysis– Access – Traffic– IDS– Anti virus– Encryption keys

• Act on analysis result• Revel and solve cloud infrastructure settings• Make them all orchestrate together !

17

Page 18: Ultra Secure Cloud Data Center on AWS

• goCloud – Emind’s optimal road to the cloud– Secure cloud architecture– Scalable & high-availability design– Customized system deployment– Orchestrating cloud and software– Cloud operation team– Monitoring and alerting– 24x7 SLA

18

Page 19: Ultra Secure Cloud Data Center on AWS

19

Contact me, [email protected] 054-4321688