confraria security 17 june - cloud security

21
Cloud Computing Cloud Computing Security Security by Vitor Domingos intrepid and professional basher http://vitordomingos.com

Upload: vitor-domingos

Post on 10-Dec-2014

2.428 views

Category:

Technology


0 download

DESCRIPTION

Cloud Computing Security in Confraria Security & IT, 3rd meeting in Lisbon

TRANSCRIPT

Page 1: Confraria Security 17 June - Cloud Security

Cloud ComputingCloud ComputingSecurity Security

by Vitor Domingosintrepid and professional basher

http://vitordomingos.com

Page 2: Confraria Security 17 June - Cloud Security

* as seen on regular weather channel

Page 3: Confraria Security 17 June - Cloud Security
Page 4: Confraria Security 17 June - Cloud Security
Page 5: Confraria Security 17 June - Cloud Security

Cloud Computing is ?Cloud Computing is ?- Network as a “cloud”

- Network is the computer (SUN moto)

- TCP/IP abstraction (1st cloud)

- www data abstraction (2nd cloud)

- Virtualization (3rd cloud)

Bottom line:

- Virtualization done right, with webservices

Page 6: Confraria Security 17 June - Cloud Security

Cloud Computing is !Cloud Computing is !- on-demand self-service

- ubiquitous network access

- location independent resource pooling

- rapid elasticity

- measured service

- pay as you go

- abstract resources

Page 7: Confraria Security 17 June - Cloud Security

CCaaSCCaaS- Software as a Service

- SalesForce

- Platform as a Service

- Google App Engine- Microsoft Azure

- Infrastructure as a Service

- Rackspace Mosso- Amazon Web Services

Page 8: Confraria Security 17 June - Cloud Security

Cloud Computing leveragesCloud Computing leverages- Virtualization

- Multi-Tenancy

- Massive Scale

- Autonomic Computing

- Distributed Environment

- Security Technologies

- Service Oriented

Page 9: Confraria Security 17 June - Cloud Security

Security in the CloudSecurity in the Cloud

Page 10: Confraria Security 17 June - Cloud Security

Only the paranoid survive!Only the paranoid survive!- Key issues

trust, trust, multi-tenancy, trust, encryption, compliance

- Massive complex systems running on functional units

- Certification & Audit

- Loss of physical control

- Interoperability

- Accountability

Page 11: Confraria Security 17 June - Cloud Security

please, keep in mind thatplease, keep in mind that- Shared hell:

- Hardware- Memory- Disks- NIC's (Virtual)

- Cache Snooping- Hypervisor Attacks- Persistent Root Kits- Password Cracking

- Broken or stolen key rings / authorization federation

- Never ending logs

Page 12: Confraria Security 17 June - Cloud Security
Page 13: Confraria Security 17 June - Cloud Security

Great things do comeGreat things do come- Provisioning

- Rapid reconstitution of services

- Storage fragmented

- Security layers (auth, firewall, logging, …)

- Network and Security perimeters

- Virtual Zoning

- Fault tolerance

Page 14: Confraria Security 17 June - Cloud Security

ChallengesChallenges- Data dispersal and international privacy laws

- Isolation management & Multi-Tenancy

- Certification (SAS 70 Type II audits and ISO 27001)

- Data ownership

- QoS & SLA's garantees

- Secure Hypervisors

Page 15: Confraria Security 17 June - Cloud Security

ChallengesChallenges- Massive outages

- Service bottle necks; DNS as your best friend

- Encryption needscloud resources, applications, storage, services

- Disaster recovery and contingency plans

- If you have it on Auto mode, you won't see it coming

- Honey for hackers

Page 16: Confraria Security 17 June - Cloud Security
Page 17: Confraria Security 17 June - Cloud Security

ToDoToDo- Network with VPN and VLAN's

- SLA's; read the fine prints

- Backup and recover often; Risk assessment

- Log (out of there) as if the world ended tomorrow

- Plan for failure

- YOU secure!!!

- Sandbox, Sandbox, Sandbox

Page 18: Confraria Security 17 June - Cloud Security

You're not aloneYou're not alone- Security Groups

IBM; SUN; Amazon; ISV

- Cloud Security Alliance (awesome guide!!)

- OpenCloud Manifesto & Amazon Security Paper

- Cloud Computing ML at Google Groups

- Legal Cloud's

- Vivek Kundra, USA CTO, did it, so as Facebook,New York Times and Nasdaq (on AWS)

Page 19: Confraria Security 17 June - Cloud Security
Page 20: Confraria Security 17 June - Cloud Security

Wrap upWrap up- Plan

- Encrypt

- Backup

- Secure

- Audit

- Sandbox (check my last year sapo codebits talk)- http://codebits.sapo.pt/files/aws_23.pdf

- Trust

Page 21: Confraria Security 17 June - Cloud Security

?mail: mail: [email protected]@prt.scsite: http://vitordomingos.comsite: http://vitordomingos.com