Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019

535 views

Published on

How does the cloud foster innovation? Join Vice President and Distinguished Engineer Eric Brandwine as he details why there is no better time than now to be a pioneer in the AWS Cloud, discussing the changes that next-gen technologies such as quantum computing, machine learning, serverless, and IoT are expected to make to the digital and physical spaces over the next decade. Organizations within the large AWS customer base can take advantage of security features that would have been inaccessible even five years ago; Eric discusses customer use cases along with simple ways in which customers can realize tangible benefits around topics previously considered mere buzzwords. 

  • I've Saved Over $400 On Batteries! I can't believe how simple your reconditioning steps are! My old (and once dead) car batteries, cell phone battery, drill battery, camera battery and tons of other batteries are all reconditioned and working great again! Since starting your program I've saved over $400 on batteries!  http://t.cn/AiFAb0DL
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • Be the first to like this

Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019

  1. 1. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Leadership session: Aspirational security Pioneering on the Security Trail Eric Brandwine Vice President and Distinguished Engineer Amazon Web Services S E P 3 1 8 - L
  2. 2. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. The Living Computer Museum LIVING COMPUTERS museum + labs | SODO 2245 First Avenue South Seattle, WA 98134
  3. 3. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Macintosh SE/30
  4. 4. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. The Oregon Trail
  5. 5. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  6. 6. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. A spectrum
  7. 7. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. A spectrum
  8. 8. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. “What are cloud?” “Should we cloud?” “Windows Millennial Edition Will Change Everything.”“Y2K will end us all anyway. Good luck without a power grid!” “This 14.4k modem cooks.” “Are Cloud Dangerous?” “No, you just download any song.” “Tell me you didn’t click that link.” “I gotta tell ya, I don’t think there was a prince behind this email at all.” “Because Moore’s Law, friend. That’s why.” “There’s no way I’m giving the Internet my credit card number. Thanks anyway.” “No, I said ‘cat memes’. Well, why would there be cat mimes?” “You might wanna give that the ol’ rebootskie”
  9. 9. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Though taking risks did have some benefits…
  10. 10. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Expedia has become more agile by going all in on AWS Ellie Mae, Inc. is going all-in on the world’s leading cloud Lyft goes all-in on AWS Time Inc. goes all in on AWS Barclays 'all-in' move to AWS cloud Shutterfly goes all-in on AWS Use cases inform our road map
  11. 11. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Learning from the explorers
  12. 12. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Learning from the explorers
  13. 13. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Learning from the explorers
  14. 14. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. “We need this.” “How can we cloud more?” “Faster, cheaper, more secure. And you can be home for supper.”“How are others tackling this?” “Do you even quantum?” “Let’s secure the cloud.” “Have you seen the latest feature release?” “It’s more secure than on-prem.” “Just set up a Lambda function.” “Everyone else is doing it, why can’t we?” “I don’t know, I just know it’s automagic.” “Welcome to the age of cloud.”
  15. 15. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Nitro card Nitro security chip Nitro hypervisor Local NVMe storage Elastic Block Storage Networking, monitoring, and security Integrated into motherboard Protects hardware resources Lightweight hypervisor Memory and CPU allocation Bare metal-like performance Innovation enabled by AWS Nitro System Modular building blocks for rapid design and delivery of Amazon EC2 instances
  16. 16. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  17. 17. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  18. 18. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon GuardDuty
  19. 19. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty getting started
  20. 20. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty active finding types Backdoor Behavior CryptoCurrency PenTest Persistence Policy PrivilegeEscalation Recon ResourceConsumption Stealth Trojan Unauthorized
  21. 21. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  22. 22. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Partners
  23. 23. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Identity, directory, and access IAM Manage user access and encryption keys Single Sign-On Cloud single sign-on for AWS accounts and business apps Directory Service Host and manage Microsoft Active Directory Organizations Manage settings for multiple accounts Resource Access Manager Share resources across multiple accounts Secrets Manager Rotate, manage, and retrieve secrets Cognito Identity management for your apps Detective controls and management Security Hub Centrally view/manage security alerts & automate compliance checks GuardDuty Continuous threat detection & monitoring Service Catalog Create and use standardized products Launch Templates Standardize deployments across resources Config Track resource inventory and changes CloudTrail Track user activity and API usage CloudWatch Monitor resources and applications Inspector Analyze application security Artifact Self-service for AWS compliance reports Data protection Key Management Service Manage creation and control of encryption keys Certificate Manager Provision, manage, and deploy SSL/TSL certificates ACM Private CA Private certificate authority CloudHSM Hardware-based key storage Macie Discover, classify,and protect data Server-side encryption Flexible data encryption options Encrypted Boot & EBS volumes Networking and infrastructure Virtual Private Cloud Isolated cloud resources VPC flow logs Web Application Firewall Filter malicious web traffic Shield DDoS protection Firewall Manager Manage WAF rules across accounts PrivateLink Securely access services hosted on AWS Best security building blocks in the cloud
  24. 24. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Identity, directory, and access IAM Manage user access and encryption keys Single Sign-On Cloud single sign-on for AWS accounts and business apps Directory Service Host and manage Microsoft Active Directory Organizations Manage settings for multiple accounts Resource Access Manager Share resources across multiple accounts Secrets Manager Rotate, manage, and retrieve secrets Cognito Identity management for your apps Detective controls and management Security Hub Centrally view/manage security alerts & automate compliance checks GuardDuty Continuous threat detection & monitoring Service Catalog Create and use standardized products Launch Templates Standardize deployments across resources Config Track resource inventory and changes CloudTrail Track user activity and API usage CloudWatch Monitor resources and applications Inspector Analyze application security Artifact Self-service for AWS compliance reports Data protection Key Management Service Manage creation and control of encryption keys Certificate Manager Provision, manage, and deploy SSL/TSL certificates ACM Private CA Private certificate authority CloudHSM Hardware-based key storage Macie Discover, classify,and protect data Server-side encryption Flexible data encryption options Encrypted Boot & EBS volumes Networking and infrastructure Virtual Private Cloud Isolated cloud resources VPC flow logs Web Application Firewall Filter malicious web traffic Shield DDoS protection Firewall Manager Manage WAF rules across accounts PrivateLink Securely access services hosted on AWS Best security building blocks in the cloud
  25. 25. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Security blocks
  26. 26. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. In real life…
  27. 27. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty active finding types Persistence: IAMUser/NetworkPermissions IAMUser/ResourcePermissions IAMUser/UserPermissions Persistence:IAMUser/NetworkPermissions = A principal invoked an API commonly used to change the network access permissions for security groups, routes, and ACLs in your AWS account. This finding informs you that a specific principal in your AWS environment is exhibiting behavior that is different from the established baseline. This principal has no prior history of invoking this API.
  28. 28. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. GuardDuty active finding types Stealth: IAMUser/PasswordPolicyChange IAMUser/CloudTrailLoggingDisabled IAMUser/LoggingConfigurationModified Stealth: IAMUser/PasswordPolicyChange = Your AWS account password policy was weakened. For example, it was deleted or updated to require fewer characters, not require symbols and numbers, or required to extend the password expiration period. This finding can also be triggered by an attempt to update or delete your AWS account password policy. The AWS account password policy defines the rules that govern what kinds of passwords can be set for your IAM users.
  29. 29. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Firewalls Vulnerability management Soar Siem Endpoint Compliance MSSP Other Security Hub partner integrations
  30. 30. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  31. 31. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Ecosystem
  32. 32. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Ecosystem
  33. 33. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Ecosystem
  34. 34. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Machine learning
  35. 35. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Using Amazon SageMaker, GE Healthcare developed an ML model that can learn from thousands of medical scans to detect anomalies more accurately and efficiently. Convoy builds and trains ML models to optimize driver schedules and to ensure load balancing, capacity planning, pricing, and payments.
  36. 36. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Data Mining Deep Learning Python Analytics Data Lakes Optical Character Reader Yottabyte Artificial Neural Networks Predictive Analysis Chatbots Data Modeling Natural Language Processing
  37. 37. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Use case: Amazon.com Lithium-ion battery explosion is an industry-wide challenge. US CPSC (Consumer Product Safety Commission) receives hundreds of lithium-ion battery explosion reports from multiple retailers every year. Built and engineered by: Wei Xiang Global Product Safety and Compliance Fedor Zhdanov Amazon Research Chance Kelch Global Product Safety and Compliance
  38. 38. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. 8.6% 86.7% Improved suppression rate from 8.6% to 86.7% How?
  39. 39. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Feedback Classification through keyword-based text mining Human validation Human investigation Input Validation Engineering Third-party information SMEs Customer surveys Data scrubbing Testing Data to create data elements used by the ML model to calculate predictions
  40. 40. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Algorithmselection Decision tree Random forest XGBoost Logistic regression Measurement The purpose of feature analysis is to understand which attribute or combination of attributes has the most impact on the model precision and recall. Dropping engineered attributes one by one Re-training the model Re-calculate precision and recall
  41. 41. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. ML frameworks & infrastructure AI services Rekognition image Polly Transcribe Translate Comprehend LexRekognition video Vision Speech Language Chatbots Amazon SageMaker Build Train Forecast Forecasting Textract Personalize Recommendations Deploy Pre-built algorithms & notebooks Data labeling (ground truth) One-click model training & tuning Optimization (NEO) One-click deployment & hosting ML services Frameworks Interfaces Infrastructure EC2 P3 & P3N EC2 C5 FPGAs Greengrass Elastic inference Reinforcement learningAlgorithms & models (AWS Marketplace for machine learning) The Amazon ML stack: Broadest & deepest set of capabilities
  42. 42. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. The AWS range of ML options
  43. 43. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Using Amazon SageMaker, a tool to easily build, train, and deploy machine learning models, engineers at Coinbase developed a machine learning-driven system that recognizes mismatches and anomalies in sources of user identification, allowing them to quickly take action against potential sources of fraud.
  44. 44. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  45. 45. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. When quantum happens…
  46. 46. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  47. 47. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.
  48. 48. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. …even well-meaning gatekeepers slow innovation. When a platform is self-service, even the improbable ideas can get tried, because there’s no expert gatekeeper ready to say “that will never work!” And guess what— many of those improbable ideas do work, and society is the beneficiary of that diversity.
  49. 49. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Fitting the business curve
  50. 50. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Fitting the business curve
  51. 51. © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved. Pioneers with comfy pillows
  52. 52. Thank you! © 2019,Amazon Web Services, Inc. or its affiliates. All rights reserved.

×