SlideShare a Scribd company logo
1 of 43
De invloed van
“cloud” op het
dreigingslandschap…
Frank Breedijk – ISACA RISK event 2019
Legitimate a CC NC ND image by Seth Anderson
https://www.flickr.com/photos/44124372363@N01/7830947420/
o Frank Breedijk
o CISO Schuberg Philis
o Cloud and open source enthousiast
o Ik woon in een stal uit 1751
o fbreedijk@schubergphilis.com
3
> whoami
Opa verteld…
o Shared hosting vs decated hosting
o Intrede van virtualisatie
o Private / Community cloud
o Public cloud
5
1998 - 2012 6
Shared of ‘dedicated’ hosting
71924 Ford Model T Coupe '772U’ 1 a CC ND image by Jack Snell
https://www.flickr.com/photos/59972430@N00/23467122488/
o Met wie deel je je servers
o Nadruk op:
o Fysieke beveiliging
o Netwerk Segmentatie
o Scheiding van kritiek en niet kritiek
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
8
The fort ‘Datacenter’
IMG_20140829_140731 a CC image by Robert
https://www.flickr.com/photos/12967790@N00/14885417370/
Virtualisatie
o Nieuwe dreigingen:
o Delen van dezelfde hardware
o Verschillende machines
delen dezelfde kernel
o ”Opgeloste” dreigingen
o Software wordt niet meer op
software nivo gedeeld
9Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com
https://www.flickr.com/photos/91795203@N02/9228236784/
Virtualisatie
o Nadruk op:
o Fysieke beveiliging
o Hardware / kernel segmentatie
o Hypervisor escape
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o DDoS (2013)
10Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com
https://www.flickr.com/photos/91795203@N02/9228236784/
2012 - 2015 11
2015 12
MCC
NKNK
Private / “Community” cloud
13FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
o T.o.v. virtualisatie
o Hardware/kernel nu gedeeld met ”anderen”
o Orchestratie laag met een API
o T.o.v. public cloud
o Beperkte groep medehuurders
o Physieke locatie bekend
o Mogelijkheid tot audit
14
Wat is er anders…
FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
o Nadruk op:
o Hypervisor escape
o Hardward / kernel segmentatie
o Fysieke beveiliging
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o Applicatie security
15
Security
FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
2019 16
MCC
AWS
Azure
GCP
Office 365
Okta
Slack
Public cloud
17Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
o Je weet niet precies met wie je de ruimte deelt
o Je weet niet precies waar je data staat
o Grote cloud partijen kunnen niet iedere klant laten
auditen
o Buitenlandse partijen
18
Wat is er anders…
Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
o Nadruk op:
o Compliance
o Lock in
o Fysieke locatie
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o Niet juist inrichten van rechten
o Applicatie fouten
19
Security…
Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
Help?
20Sunny with a chance of meatballs
Sony Pictures Animation 2009
o Veel gevallen met kleine impact op para-
virtualisatie
o Paravirtualisatie niet populair meer
o Meltdown + Spectre
o Cloud vendors waren de eersten
21
Hypervisor escape
Incidenten?
o Niet patchen
o Gebrekkige access control
o Onbedoeld bloodstellen van gevoelige
services
o Ransomware
o Applicatiefouten
22
o It’s just someone else’s computer?
o Als dat zo is, waarom wil ”men” het dan zo graag?
o Is dit wel de juiste blik?
23
There is no cloud…
Laptop van een college, foto door Frank Breedijk
Moderne cloud infrastructuren…
24Golden gate bridge, San Fransisco USA - Original image from Carol M. Highsmith’s America, Library of Congress
collection. Digitally enhanced by rawpixel. A CC image by rawpixel
https://www.flickr.com/photos/153584064@N07/46201778672/
Beschikbaarheid
o Niet alleen meer uptime
o Beschikbaarheid van informatie is
functionaliteit
o Functionaliteit die de eind-gebruiker
niet bereikt is geen functionalitiet
o Bedrijven moeten ‘agile’ zijn om te
overleven
o Geen hele serverparken meer nodig
om b.v. A.I. te doen
25
Beschikbaar
IntegerVertrouwelijk
Agility?
o Met zo min mogelijk operations
mensen net zoveel operations
doen als nodig is
o Ontwikkelaars in staat stellen zo
veel mogelijk functionaliteit zo
snel mogelijk bij de eind-
gebruikers te krijgen
26150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet
https://www.flickr.com/photos/compacflt/20009404191/
Hoe dan?
o Commodity / uitontwikkeld
o Services ipv servers
o IT voor IT
o Services, PaaS ipv servers
o “Onderscheidende” applicaties
o Cloud native of containers
27150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet
https://www.flickr.com/photos/compacflt/20009404191/
AWS I choose you
28
https://www.youtube.com/watch?v=zyP-pfij86s
Snoepwinkel
o De mogelijkheden /
functionaliteiten van een
moderne cloud provider zijn
(bijna) eindeloos
29Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris
https://www.flickr.com/photos/76224602@N00/4348333928/
30
Moderne cloud vs. IaaS
Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris
https://www.flickr.com/photos/76224602@N00/4348333928/
Colorful Gum Tabs a CC image by Marco Verch
https://www.flickr.com/photos/30478819@N08/45917981931/
Cloud security  IaaS security
31Colorful Gum Tabs a CC image by Marco Verch
https://www.flickr.com/photos/30478819@N08/45917981931/
Iedereen wil security…
32Werner Vogels tijdens AWS Summit 2018 in Den Haag
Door Frank Breedijk
SaaS kan helpen
o Als IT geen core business is
o Als IT wel je core business is,
maar de applicatie niet
“spannend” is
o Als de applicatie niet
“onderscheidend” is
33
De kracht van de API
34
o Een altijd up to date overzicht krijgen van alles in je
landschap
o Weten waar je data staat
o Weten dat je data versleuteld is
o Verkeerde configuraties detecteren
o én oplossen
35
Via de API kun je…
She thinks my json's sexy... Said no one ever a CC ND iamge by Matthew Ragan
https://www.flickr.com/photos/45199237@N04/21131398981/
Consolidatie
o Veel van de oplossingen nu nog
zelf bouw
o Derden zijn in dit gat gestapt
o Security is de dominante non-
functional voor clouds
o Verwacht dat cloud providers dit
gaan aanbieden
362983e2 P900 Wide-eyed wonder of Christmas a CC NC ND image by Jenny Pansing
https://www.flickr.com/photos/25171569@N02/23876843182/
Niet het einde van de wereld
37Sunny with a chance of meatballs
Sony Pictures Animation 2009
Cloud craftsmenship manifesto…
38The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I am a craftsman and I use cloud technologies,
because I apply my craftmanship to cloud
technologies, I am a Cloud Craftsman.
I recognize that cloud technologies, if applied
correctly, offer great benefits in terms of
availability, reliability, scalability and agility.
I recognize that, like any other technology, cloud
technology is not a silver bullet.
39
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that not all cloud solutions are created
equally. I will do my best to select the solution that
best fits my specific situation.
I recognize that, in the cloud, I will have to trust
and rely on the abilities of the provider. I will do
my best to validate this trust.
I recognize that effective, efficient and secure
usage of cloud technologies is a responsibility
that is shared between the user and the provider.
40
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that effective, efficient and secure
uadge of cloud technologies is in both the interest
of the user and provider.
I intend to read, understand and/or use the best
practices and tooling recommended by the
provider to the greatest extend possible in my
situation.
I intend to stand on the shoulders of giants. May
before us have developed tools and practices for
the effective, efficient and secure usage of cloud
technologies. I will adopt their work as much as I
can.
41
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that cloud technologies are repaidly
evolving, this means I will have to keep up with the
current state of the cloud technologies I intend to
use and are available to me. After all, a fool with a
tool is still a fool.
I recognize that automation is the key to reliability,
reproducability and recoverability. I will embrace
automation of my work as the way forward.
42
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that, in the cloud, I cannot just rely on
others to provide security for me.
I am a Cloud Craftsman, not because it is easy, but
because it is necessary and I am up for the
challenge.
43
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
http://craftsmanship.cloud
44The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/

More Related Content

Similar to De invloed van "cloud" op het dreigingslanschap

Situation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySituation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySimon Wardley
 
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Binu Ramakrishnan
 
Revolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityRevolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityChijioke “CJ” Ejimuda
 
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...Mark Smith
 
企業導入雲端
企業導入雲端企業導入雲端
企業導入雲端Carlo Li
 
Short story about your information processing - cloud part
Short story about your information processing -  cloud partShort story about your information processing -  cloud part
Short story about your information processing - cloud partArtur Marek Maciąg
 
Let’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsLet’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsT.Rob Wyatt
 
Security Tips to run Docker in Production
Security Tips to run Docker in ProductionSecurity Tips to run Docker in Production
Security Tips to run Docker in ProductionGianluca Arbezzano
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...Patrick Thomas
 
Security Theatre - PHP UK Conference
Security Theatre - PHP UK ConferenceSecurity Theatre - PHP UK Conference
Security Theatre - PHP UK Conferencexsist10
 
Cfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreCfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreJulien Pivotto
 
Security Theatre - Confoo
Security Theatre - ConfooSecurity Theatre - Confoo
Security Theatre - Confooxsist10
 
Seamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsSeamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsDynatrace
 
IoThings you don't even need to hack
IoThings you don't even need to hackIoThings you don't even need to hack
IoThings you don't even need to hackSlawomir Jasek
 
AI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikAI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikSergey Gordeychik
 
Security Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPSecurity Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPxsist10
 
Casino In The Clouds
Casino In The CloudsCasino In The Clouds
Casino In The Cloudsgojkoadzic
 
Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Christian Deger
 

Similar to De invloed van "cloud" op het dreigingslanschap (20)

Situation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySituation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesday
 
Simon Wardley
Simon WardleySimon Wardley
Simon Wardley
 
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
 
Revolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityRevolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure Connectivity
 
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
 
企業導入雲端
企業導入雲端企業導入雲端
企業導入雲端
 
Short story about your information processing - cloud part
Short story about your information processing -  cloud partShort story about your information processing -  cloud part
Short story about your information processing - cloud part
 
Let’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsLet’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal Clouds
 
Security Tips to run Docker in Production
Security Tips to run Docker in ProductionSecurity Tips to run Docker in Production
Security Tips to run Docker in Production
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
 
Security Theatre - PHP UK Conference
Security Theatre - PHP UK ConferenceSecurity Theatre - PHP UK Conference
Security Theatre - PHP UK Conference
 
Cfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreCfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymore
 
Security Theatre - Confoo
Security Theatre - ConfooSecurity Theatre - Confoo
Security Theatre - Confoo
 
Attack eu 2021 attack4cvc
Attack eu 2021 attack4cvcAttack eu 2021 attack4cvc
Attack eu 2021 attack4cvc
 
Seamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsSeamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related Problems
 
IoThings you don't even need to hack
IoThings you don't even need to hackIoThings you don't even need to hack
IoThings you don't even need to hack
 
AI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikAI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey Gordeychik
 
Security Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPSecurity Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHP
 
Casino In The Clouds
Casino In The CloudsCasino In The Clouds
Casino In The Clouds
 
Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24
 

Recently uploaded

A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)Christopher H Felton
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一Fs
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsThierry TROUIN ☁
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一3sw2qly1
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012rehmti665
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607dollysharma2066
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts servicesonalikaur4
 
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With RoomVIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Roomdivyansh0kumar0
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Deliverybabeytanya
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITMgdsc13
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Lucknow
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girlsstephieert
 

Recently uploaded (20)

A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
 
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls KolkataVIP Call Girls Kolkata Ananya 🤌  8250192130 🚀 Vip Call Girls Kolkata
VIP Call Girls Kolkata Ananya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
 
AlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with FlowsAlbaniaDreamin24 - How to easily use an API with Flows
AlbaniaDreamin24 - How to easily use an API with Flows
 
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
定制(CC毕业证书)美国美国社区大学毕业证成绩单原版一比一
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
 
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
FULL ENJOY Call Girls In Mayur Vihar Delhi Contact Us 8377087607
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
 
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance VVIP 🍎 SERVICE
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SERVICECall Girls Service Dwarka @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SERVICE
Call Girls Service Dwarka @9999965857 Delhi 🫦 No Advance VVIP 🍎 SERVICE
 
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With RoomVIP Kolkata Call Girl Dum Dum 👉 8250192130  Available With Room
VIP Kolkata Call Girl Dum Dum 👉 8250192130 Available With Room
 
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on DeliveryCall Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
Call Girls In Mumbai Central Mumbai ❤️ 9920874524 👈 Cash on Delivery
 
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
sasti delhi Call Girls in munirka 🔝 9953056974 🔝 escort Service-
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITM
 
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja VipCall Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
Call Girls Service Adil Nagar 7001305949 Need escorts Service Pooja Vip
 
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls KolkataLow Rate Call Girls Kolkata Avani 🤌  8250192130 🚀 Vip Call Girls Kolkata
Low Rate Call Girls Kolkata Avani 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Russian Call girls in Dubai +971563133746 Dubai Call girls
Russian  Call girls in Dubai +971563133746 Dubai  Call girlsRussian  Call girls in Dubai +971563133746 Dubai  Call girls
Russian Call girls in Dubai +971563133746 Dubai Call girls
 

De invloed van "cloud" op het dreigingslanschap

  • 1. De invloed van “cloud” op het dreigingslandschap… Frank Breedijk – ISACA RISK event 2019 Legitimate a CC NC ND image by Seth Anderson https://www.flickr.com/photos/44124372363@N01/7830947420/
  • 2.
  • 3. o Frank Breedijk o CISO Schuberg Philis o Cloud and open source enthousiast o Ik woon in een stal uit 1751 o fbreedijk@schubergphilis.com 3 > whoami
  • 4. Opa verteld… o Shared hosting vs decated hosting o Intrede van virtualisatie o Private / Community cloud o Public cloud 5
  • 6. Shared of ‘dedicated’ hosting 71924 Ford Model T Coupe '772U’ 1 a CC ND image by Jack Snell https://www.flickr.com/photos/59972430@N00/23467122488/
  • 7. o Met wie deel je je servers o Nadruk op: o Fysieke beveiliging o Netwerk Segmentatie o Scheiding van kritiek en niet kritiek o Oorzaak van de meeste incidenten o Malware o Niet patchen 8 The fort ‘Datacenter’ IMG_20140829_140731 a CC image by Robert https://www.flickr.com/photos/12967790@N00/14885417370/
  • 8. Virtualisatie o Nieuwe dreigingen: o Delen van dezelfde hardware o Verschillende machines delen dezelfde kernel o ”Opgeloste” dreigingen o Software wordt niet meer op software nivo gedeeld 9Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com https://www.flickr.com/photos/91795203@N02/9228236784/
  • 9. Virtualisatie o Nadruk op: o Fysieke beveiliging o Hardware / kernel segmentatie o Hypervisor escape o Oorzaak van de meeste incidenten o Malware o Niet patchen o DDoS (2013) 10Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com https://www.flickr.com/photos/91795203@N02/9228236784/
  • 12. NKNK Private / “Community” cloud 13FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 13. o T.o.v. virtualisatie o Hardware/kernel nu gedeeld met ”anderen” o Orchestratie laag met een API o T.o.v. public cloud o Beperkte groep medehuurders o Physieke locatie bekend o Mogelijkheid tot audit 14 Wat is er anders… FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 14. o Nadruk op: o Hypervisor escape o Hardward / kernel segmentatie o Fysieke beveiliging o Oorzaak van de meeste incidenten o Malware o Niet patchen o Applicatie security 15 Security FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 16. Public cloud 17Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 17. o Je weet niet precies met wie je de ruimte deelt o Je weet niet precies waar je data staat o Grote cloud partijen kunnen niet iedere klant laten auditen o Buitenlandse partijen 18 Wat is er anders… Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 18. o Nadruk op: o Compliance o Lock in o Fysieke locatie o Oorzaak van de meeste incidenten o Malware o Niet patchen o Niet juist inrichten van rechten o Applicatie fouten 19 Security… Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 19. Help? 20Sunny with a chance of meatballs Sony Pictures Animation 2009
  • 20. o Veel gevallen met kleine impact op para- virtualisatie o Paravirtualisatie niet populair meer o Meltdown + Spectre o Cloud vendors waren de eersten 21 Hypervisor escape
  • 21. Incidenten? o Niet patchen o Gebrekkige access control o Onbedoeld bloodstellen van gevoelige services o Ransomware o Applicatiefouten 22
  • 22. o It’s just someone else’s computer? o Als dat zo is, waarom wil ”men” het dan zo graag? o Is dit wel de juiste blik? 23 There is no cloud… Laptop van een college, foto door Frank Breedijk
  • 23. Moderne cloud infrastructuren… 24Golden gate bridge, San Fransisco USA - Original image from Carol M. Highsmith’s America, Library of Congress collection. Digitally enhanced by rawpixel. A CC image by rawpixel https://www.flickr.com/photos/153584064@N07/46201778672/
  • 24. Beschikbaarheid o Niet alleen meer uptime o Beschikbaarheid van informatie is functionaliteit o Functionaliteit die de eind-gebruiker niet bereikt is geen functionalitiet o Bedrijven moeten ‘agile’ zijn om te overleven o Geen hele serverparken meer nodig om b.v. A.I. te doen 25 Beschikbaar IntegerVertrouwelijk
  • 25. Agility? o Met zo min mogelijk operations mensen net zoveel operations doen als nodig is o Ontwikkelaars in staat stellen zo veel mogelijk functionaliteit zo snel mogelijk bij de eind- gebruikers te krijgen 26150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet https://www.flickr.com/photos/compacflt/20009404191/
  • 26. Hoe dan? o Commodity / uitontwikkeld o Services ipv servers o IT voor IT o Services, PaaS ipv servers o “Onderscheidende” applicaties o Cloud native of containers 27150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet https://www.flickr.com/photos/compacflt/20009404191/
  • 27. AWS I choose you 28 https://www.youtube.com/watch?v=zyP-pfij86s
  • 28. Snoepwinkel o De mogelijkheden / functionaliteiten van een moderne cloud provider zijn (bijna) eindeloos 29Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris https://www.flickr.com/photos/76224602@N00/4348333928/
  • 29. 30 Moderne cloud vs. IaaS Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris https://www.flickr.com/photos/76224602@N00/4348333928/ Colorful Gum Tabs a CC image by Marco Verch https://www.flickr.com/photos/30478819@N08/45917981931/
  • 30. Cloud security  IaaS security 31Colorful Gum Tabs a CC image by Marco Verch https://www.flickr.com/photos/30478819@N08/45917981931/
  • 31. Iedereen wil security… 32Werner Vogels tijdens AWS Summit 2018 in Den Haag Door Frank Breedijk
  • 32. SaaS kan helpen o Als IT geen core business is o Als IT wel je core business is, maar de applicatie niet “spannend” is o Als de applicatie niet “onderscheidend” is 33
  • 33. De kracht van de API 34
  • 34. o Een altijd up to date overzicht krijgen van alles in je landschap o Weten waar je data staat o Weten dat je data versleuteld is o Verkeerde configuraties detecteren o én oplossen 35 Via de API kun je… She thinks my json's sexy... Said no one ever a CC ND iamge by Matthew Ragan https://www.flickr.com/photos/45199237@N04/21131398981/
  • 35. Consolidatie o Veel van de oplossingen nu nog zelf bouw o Derden zijn in dit gat gestapt o Security is de dominante non- functional voor clouds o Verwacht dat cloud providers dit gaan aanbieden 362983e2 P900 Wide-eyed wonder of Christmas a CC NC ND image by Jenny Pansing https://www.flickr.com/photos/25171569@N02/23876843182/
  • 36. Niet het einde van de wereld 37Sunny with a chance of meatballs Sony Pictures Animation 2009
  • 37. Cloud craftsmenship manifesto… 38The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 38. I am a craftsman and I use cloud technologies, because I apply my craftmanship to cloud technologies, I am a Cloud Craftsman. I recognize that cloud technologies, if applied correctly, offer great benefits in terms of availability, reliability, scalability and agility. I recognize that, like any other technology, cloud technology is not a silver bullet. 39 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 39. I recognize that not all cloud solutions are created equally. I will do my best to select the solution that best fits my specific situation. I recognize that, in the cloud, I will have to trust and rely on the abilities of the provider. I will do my best to validate this trust. I recognize that effective, efficient and secure usage of cloud technologies is a responsibility that is shared between the user and the provider. 40 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 40. I recognize that effective, efficient and secure uadge of cloud technologies is in both the interest of the user and provider. I intend to read, understand and/or use the best practices and tooling recommended by the provider to the greatest extend possible in my situation. I intend to stand on the shoulders of giants. May before us have developed tools and practices for the effective, efficient and secure usage of cloud technologies. I will adopt their work as much as I can. 41 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 41. I recognize that cloud technologies are repaidly evolving, this means I will have to keep up with the current state of the cloud technologies I intend to use and are available to me. After all, a fool with a tool is still a fool. I recognize that automation is the key to reliability, reproducability and recoverability. I will embrace automation of my work as the way forward. 42 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 42. I recognize that, in the cloud, I cannot just rely on others to provide security for me. I am a Cloud Craftsman, not because it is easy, but because it is necessary and I am up for the challenge. 43 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 43. http://craftsmanship.cloud 44The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/