56
© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc. Updating Security Operations For The Cloud Mark Nunnikhoven Vice President, Cloud & Emerging Technologies Trend Micro 26-Mar-2014

Updating Security Operations for the Cloud

Embed Size (px)

DESCRIPTION

Learn how to increase the effectiveness of your security operations as you move to the cloud. We will discuss how your current incident response, forensic investigations, monitoring, and audit response tactics have to change in the cloud. Pulling from experiences helping clients move to the cloud, industry research, and the school of hard knocks, this talk will help provide practical advice you can apply today.

Citation preview

Page 1: Updating Security Operations for the Cloud

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

Updating Security Operations For The CloudMark Nunnikhoven Vice President, Cloud & Emerging Technologies Trend Micro

26-Mar-2014

Page 2: Updating Security Operations for the Cloud

Overview

Page 3: Updating Security Operations for the Cloud

Strategy Tactics

Page 4: Updating Security Operations for the Cloud

Tactics

Page 5: Updating Security Operations for the Cloud

Tactics

Auditing

Monitoring

Incident Response

Forensic Investigations

Page 6: Updating Security Operations for the Cloud

Traditional Responsibility Model

!

Operating System

Application

Account Management*

You

Facilities

Physical Security

Physical Infrastructure

Network Infrastructure

Virtualization Infrastructure

Page 7: Updating Security Operations for the Cloud

Shared Responsibility Model

You

Operating System

Application

Account Management*

Security Groups*

Network Configuration*

AWS

Facilities

Physical Security

Physical Infrastructure

Network Infrastructure

Virtualization Infrastructure

Page 8: Updating Security Operations for the Cloud

Our story

Page 9: Updating Security Operations for the Cloud

Hybrid architecture

On-premises Cloud

Page 10: Updating Security Operations for the Cloud

Full architecture

Payment

Client Data

On-premises

AWS

Payment

Games

Store

Logs

Content

Viewers

Client Data

Page 11: Updating Security Operations for the Cloud

Full architecture, expansion

AWS

Payment

Games

Store

Logs

Content

Viewers

Client Data

Payment

Client Data

On-premises

Page 12: Updating Security Operations for the Cloud

Full architecture, AWS services

AWS

Payment

Games

Store

Logs

Content

Viewers

Client Data

Amazon EC2

Amazon EC2

Amazon EC2

Amazon CloudFront

Amazon S3

Amazon EC2Amazon RDS

Payment

Client Data

On-premises

Page 13: Updating Security Operations for the Cloud

Before After

Structure

Bonus

Page 14: Updating Security Operations for the Cloud

Auditing

Page 15: Updating Security Operations for the Cloud

PCI Compliance

Page 16: Updating Security Operations for the Cloud

Requirements

Encrypting data at rest (3.4.1)

Address new threats & vulnerabilities (6.6)

Log external facing services & defences (10.2, 10.5.4)

Protect systems against malware (5.1)

* PCI has many, many more requirements, this is just a sample

Page 17: Updating Security Operations for the Cloud

Creating an audit trail, before

Servers

Storage Area Network

On-premises

Firewall

IPS

Central logging

Page 18: Updating Security Operations for the Cloud

Payment

Client Data

On-premises AWS

Amazon CloudTrail

EC2 instances

Central management

Amazon S3

Amazon CloudFrontAmazon RDS

Creating an audit trail, after

Page 19: Updating Security Operations for the Cloud

Creating an audit trail, bonus points

You get

Record of changes via AWS CloudTrail

Security control reporting via Deep Security’s API

Why it matters

Regular assurance controls are in place

Page 20: Updating Security Operations for the Cloud

In action…

Page 21: Updating Security Operations for the Cloud
Page 22: Updating Security Operations for the Cloud

Monitoring

Page 23: Updating Security Operations for the Cloud

Visibility

Page 24: Updating Security Operations for the Cloud

Requirements

Basic event info (4W+H)

Context of the event

Consistent identity across environments

Timely

Page 25: Updating Security Operations for the Cloud

Visibility, before

On-premises

FirewallIPS

Central logging SIEM

SwitchSwitchSwitchDirectory Server

Page 26: Updating Security Operations for the Cloud

AWS

Amazon CloudTrail

EC2 instances

Amazon S3 Bucket

Amazon CloudFrontAmazon RDS

Visibility, after

Central loggingSIEM

Amazon S3

Page 27: Updating Security Operations for the Cloud

Visibility, bonus points

You get

More work to put together events

Richer context around events

Why it matters

Visibility is key to your security practice

Page 28: Updating Security Operations for the Cloud

In action…

Page 29: Updating Security Operations for the Cloud
Page 30: Updating Security Operations for the Cloud
Page 31: Updating Security Operations for the Cloud
Page 32: Updating Security Operations for the Cloud

Incident Response

Page 33: Updating Security Operations for the Cloud

Under pressure

Page 34: Updating Security Operations for the Cloud

SANS incident response process

Preparation

Identification

Containment

EradicationRecovery

Lessons Learned

Get ready!

What is it?

Did we get it?

Is it gone?Again?

Get better, fast!

Page 35: Updating Security Operations for the Cloud

Requirements

Quickly identify affected area

Minimize impact

Recovery quickly

Page 36: Updating Security Operations for the Cloud

Server

On-premises

Analysis Report

Incident Response, before

Replacement

Improve

Page 37: Updating Security Operations for the Cloud

AWS

Incident Response, after

Server

Analysis Report

Replacement

Improve

Page 38: Updating Security Operations for the Cloud

Incident Response, bonus points

You get

Faster return to production

More time for analysis

Why it matters

Every minute of downtime counts

Page 39: Updating Security Operations for the Cloud

In action…

Page 40: Updating Security Operations for the Cloud
Page 41: Updating Security Operations for the Cloud

Server Analysis Report

Analyst

Optimized Response

LogProcessor

Replacement

API Improve

Page 42: Updating Security Operations for the Cloud

Forensic Investigations

Page 43: Updating Security Operations for the Cloud

Rinse & Repeat

Page 44: Updating Security Operations for the Cloud

Perception

Page 45: Updating Security Operations for the Cloud

Reality

Page 46: Updating Security Operations for the Cloud

Reality, visualized

Page 47: Updating Security Operations for the Cloud

Requirements

Repeatable

Account for & prove each step

Not get in the way of recovery

Heavily documented

Page 48: Updating Security Operations for the Cloud

Forensics, before

Server

On-premises

Logs Analysis Testimony

Page 49: Updating Security Operations for the Cloud

AWS

Forensics, after

Instance

Logs Analysis Testimony

Page 50: Updating Security Operations for the Cloud

Forensics, bonus points

You get

Faster analysis & lower costs

Ability to replicate entire environment

Why it matters

Legal requirements

Better defences

Page 51: Updating Security Operations for the Cloud

In action…

Page 52: Updating Security Operations for the Cloud

Original

Concurrent Analysis

Examiner

Copy 0

Copy 1

Copy 2

Commands

Page 53: Updating Security Operations for the Cloud

Keys

Page 54: Updating Security Operations for the Cloud

Auditing Monitoring IR Forensics

Page 55: Updating Security Operations for the Cloud
Page 56: Updating Security Operations for the Cloud

Thank you.

Mark Nunnikhoven [email protected] @marknca