SlideShare a Scribd company logo
1 of 52
Download to read offline
May 2nd 2018
#70PRESENTS
Sponsors:
Contact Us
hello@polarseven.com
DevOps Competition
12 Months Contract Services
Value = $60,000
http://p7-devops.io/DevOpsComp
Tonight:
● AWS Updates and News: PolarSeven - Darrell King
“Summit Overview”
● Session 1: Sumo Logic - Nikhil Singh
“Monitoring and Troubleshooting Complex Issues”
● Break – Networking, Beers & Pizza
● Session 2: Palo Alto Networks - Craig Dent
“AWS S3 Security: Your One Week Action Plan”
● Close
Networking & Prize Draw - Win an Amazon Dot.
Darrell King
PolarSeven
AWS Sydney Summit Updates
BUILD-A-THON
First Innovation Day at summit
120+ Attendees
Showcased: Serverless - Rekognition & Polly Demo
Serverless - Rekognition and Polly Demo
● Modern Company, Culture
● Artificial Intelligence
○ ML
○ SageMaker
○ AI applications
● Big Data / Analytics
● Containers
○ Kubernetes
○ EKS
● Serverless
○ Lambda
○ SAM
Session 1:
Nikhil Singh - Tektorch
“ Monitoring and Troubleshooting complex issues”
Using
TekTorch
Solutions
Finding Insights, Nimble Engineers
nikhil@tektorch.com.au
@techies
Agenda
Complex Problem(s)
Entry of Sumo Warrior
The Sumo Wrestling
Winner
Thank You
Complex Problems
● A business workflow App which is used by 100’s
of technicians.
● App & Data is mission critical, some hospital
SLA’s are < 15 min.
● Supports Offline.
● 3000+ forms, multiple workflows, photos,
signatures, barcode etc.
● Bad Network Coverage, Slow WiFi exacerbate the
problem.
● Add rogue human elements to this, who use
system to shield slacking off.
What If ...
● We knew exactly what a user was doing?
● What actions were performed, what time?
● Did the job was closed off or not?
● Was missing data due to application errors or user?
● Extract the missing data and apply reactively for old data.
● We could distinguish application issues and slacking.
Fully Elastic On Demand
Agility, Scale, Performance
No Painful Upgrades
New Features Weekly
Superior Performance
Guaranteed SLAs
Always Available
4 Geos, 12AZs, 6 X Replication
Real-Time, Full-Stack Visibility
From Source to Sumo Instantly
Secure by Design
Industry’s Most Secure Platform
Up & Running in Minutes
Reduce Time to Value by 90%
No Management Overhead
Reduce TCO > 50%
Introducing Sumo Logic
Comprehensive Collection & Integrations
CONFIG MGMT
IAAS & PAAS
CONTAINERS
CDN
SAAS
APP STACKS
INFRASTRUCTURE
COMPLIANCE &
SECURITY
Native AWS Integrations
Amazon CloudFront
AWS VPC Flow
AWS CloudTrail Amazon S3
AWS Elastic Load Balancing
Sumo Logic Kinesis + Lambda Connector
CloudTrail VPC Flow
Logs
CloudFrontELB S3 Kinesis
Sumo Logic AWS Apps and Connectors
Config
AWS Config
Log Reduce
Reduce MTTI by up to 90%,
MTTR by 50%
Anomaly Detection
Proactively identify new signatures
and abnormalities.
Outlier Detection
Monitor multi-dimensional metrics,
dynamic thresholds.
Predictive Analytics
Predict future trends.
Log Compare
Immediately see
deltas.
Sumo Logic: Advanced Analytics
AWS Architecture
Sumo Warrior
- Integrated with Sumo Logic
- We built entire data journey
- Data is entered by technician
- Stored in local storage
- API request is made
- API request is stored in outbox if offline
- Reconcilers are called when back online
- Logging the critical path of the system.
- Building complex queries to understand the data for an entity_form_fieldset_field and able to
reconcile where it got lost was gold.
- We extracted lost data and applied to the db without having technicians re do the jobs ($$).
- Understanding the use cases where the application was failing and fixing within days was
unbelievable.
Winner
- SumoLogic
- React/Redux/iOS
- Awesome Engineering
Questions & Thank You
Prize Draw:
Sign In On Your Smart Device To Win an Amazon Dot
» https://p7-devops.io/aws-ug
Sponsored by
Break & Networking:
• Refresh your drink
• Grab some pizza
• Make new contacts
• Enter the prize draw!
Session 2:
Craig Dent
Consulting Engineer
“AWS S3 Security: Your One Week Action Plan”
User Group
Craig Dent
Consulting Engineer
Palo Alto Networks (formerly Evident.io)
AWS S3 Security:
Your One Week Action Plan
User Group
MO BUCKETS, MO
PROBLEMS.
Are your S3 Buckets Secure?
359+ Million
Records Leaked
NEW IMPROVEMENTS & GUARDRAILS HELP…
ONE WEEK ACTION PLAN FOR S3 SECURITY
Day 1: Audit Your AWS Accounts
Day 2: Identify Key S3 Risks
Day 3: Divide and Conquer
Day 4: Get Risks Down to Zero
Day 5: Repeat, Repeat, Repeat
User Group
What are the key risks?
OPTIONS FOR APPLYING
PERMISSIONS
•  IAM Policies
•  Bucket Policies
•  ACL
•  One-time URL
TIP:
Don’t give the
bad guys the
keys...or the
treasure map!
•  Global ACL view – 1% fail
•  Global ACL edit – 0.5% fail
•  Global ACL permissions
– 4.2 % fail
•  Global List ACL – 4.3% fail
•  Global List (bucket
policy) – 1.7% fail
WHO CAN VIEW/EDIT
MY S3 BUCKET
POLICIES?
Global GET – fail 7.16%
Global PUT
Global DELETE – fail
6.4%
Global LIST
Consider instead:
IAM Policies
One-time links
WHO CAN ACCESS
THE OBJECTS IN MY
BUCKETS?
Global Upload
and Delete
MFA Delete
S3-Delete IAM
Global Delete (via
bucket policy)
WHO CAN DELETE
MY DATA AND
CONTENT?
QUESTION:
How do I
prevent
someone from
deleting
something
important?
This operational
control is used
only about 50%
of the time
IS OBJECT VERSIONING
ENABLED IN MY S3
BUCKETS?
WILL I BE ABLE TO AUDIT
THE ACTIVITY IN MY S3
BUCKETS?
QUESTION:
Without logs,
what
happens
when a
breach
occurs?
This
operational
control fails
55.5% of the
time
ACTION PLAN
Day 1: Audit Your AWS Accounts
Day 2: Identify Key S3 Bucket Risks
Day 3: Divide and Conquer
Day 4: Get Risks Down to Zero
Day 5: Repeat, Repeat, Repeat
User Group
Day 1: Audit Your AWS Accounts
DO YOU KNOW ALL YOUR AWS ACCOUNTS
•  Identify teams using AWS
•  Identify teams that might be using AWS for siloed apps
(marketing, customer support, sales)
•  Leverage procurement to find AWS expenses
User Group
Day 2: Identify Key Risks
IDENTIFY RISKS: MANUALLY OR WITH EVIDENT
SECURE STORAGE SERVICES
•  Discover and classify data
within containers and
buckets
•  Evaluate exposure based
on policy
•  Auto-remediate publicly
exposed data
•  Quarantine malware
Amazon S3
User Group
Day 3: Divide & Conquer
START WITH HIGH PRIORITY ACCOUNTS OR HIGH RISKS
User Group
Day 4: Keep Going to Get to Zero
TRACK YOUR SECURITY PROGRESS
User Group
Day 5: Repeat
EVIDENT ARCHITECTURE
Threat Detection Guided
Remediation
Cloud Control Plane
All Services, Regions & Accounts
Role-based Access Controls
EVIDENT SECURITY MONITORING AND COMPLIANCE
Dashboards, Reports, Alerts
Real-time Risk Analysis Engine
Audit & Compliance
Custom
Signatures &
Policies
Continuous
Monitoring
Security
Analytics
Cross-account IAM using
STS Assume Role Function
RESTAPIIntegrations
SDK3rdPartySecOps
AWS LAMBDAAWS SNS
AUTOMATED POLICY
ENFORCEMENT
Event Hub APIs
S3 BUCKET FITNESS REPORT
EVIDENT SECURITY MONITORING AND COMPLIANCE
Start a Free
Trial
User Group
Thank You
Thanks For Coming:
Join Us Next Month – June 6th 2018
AWS Presenting on Kubernetes
Plus
Commvault & Talend
>> Register @ http://www.meetup.com/AWS-Sydney/ <<
p7-devops.io/webinars-q2 p7-devops.io/DevOpsComp p7-devops.io/k8s-hands-on-days

More Related Content

More from PolarSeven Pty Ltd

Amazon Web Services User Group Sydney - March 2018
Amazon Web Services User Group Sydney - March 2018Amazon Web Services User Group Sydney - March 2018
Amazon Web Services User Group Sydney - March 2018PolarSeven Pty Ltd
 
Amazon Web Services User Group Sydney - February 2018
Amazon Web Services User Group Sydney - February 2018Amazon Web Services User Group Sydney - February 2018
Amazon Web Services User Group Sydney - February 2018PolarSeven Pty Ltd
 
Deep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and AutomationDeep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and AutomationPolarSeven Pty Ltd
 
Securing Traffic Leaving A VPC
Securing Traffic Leaving A VPCSecuring Traffic Leaving A VPC
Securing Traffic Leaving A VPCPolarSeven Pty Ltd
 
Telstra Programmable Networks & Scaling a Serverless Team with Automation
 Telstra Programmable Networks & Scaling a Serverless Team with Automation Telstra Programmable Networks & Scaling a Serverless Team with Automation
Telstra Programmable Networks & Scaling a Serverless Team with AutomationPolarSeven Pty Ltd
 
AWS User Group Sydney - Meetup #60
AWS User Group Sydney - Meetup #60AWS User Group Sydney - Meetup #60
AWS User Group Sydney - Meetup #60PolarSeven Pty Ltd
 
Visibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud ServicesVisibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud ServicesPolarSeven Pty Ltd
 
AWS OpsWorks for Chef Automate
AWS OpsWorks for Chef AutomateAWS OpsWorks for Chef Automate
AWS OpsWorks for Chef AutomatePolarSeven Pty Ltd
 
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...PolarSeven Pty Ltd
 
AWS User Group Sydney - Atlassian 5-10-16
AWS User Group Sydney - Atlassian 5-10-16AWS User Group Sydney - Atlassian 5-10-16
AWS User Group Sydney - Atlassian 5-10-16PolarSeven Pty Ltd
 
The Internet of Things - PolarSeven
The Internet of Things - PolarSevenThe Internet of Things - PolarSeven
The Internet of Things - PolarSevenPolarSeven Pty Ltd
 
How our AWS account got hacked and what we did to ensure it never happened ag...
How our AWS account got hacked and what we did to ensure it never happened ag...How our AWS account got hacked and what we did to ensure it never happened ag...
How our AWS account got hacked and what we did to ensure it never happened ag...PolarSeven Pty Ltd
 
Brocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentationBrocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentationPolarSeven Pty Ltd
 
What we learned from the AWS Outage
What we learned from the AWS OutageWhat we learned from the AWS Outage
What we learned from the AWS OutagePolarSeven Pty Ltd
 

More from PolarSeven Pty Ltd (20)

AWS User Group September
AWS User Group September AWS User Group September
AWS User Group September
 
Amazon Web Services User Group Sydney - March 2018
Amazon Web Services User Group Sydney - March 2018Amazon Web Services User Group Sydney - March 2018
Amazon Web Services User Group Sydney - March 2018
 
Amazon Web Services User Group Sydney - February 2018
Amazon Web Services User Group Sydney - February 2018Amazon Web Services User Group Sydney - February 2018
Amazon Web Services User Group Sydney - February 2018
 
Deep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and AutomationDeep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and Automation
 
Securing Traffic Leaving A VPC
Securing Traffic Leaving A VPCSecuring Traffic Leaving A VPC
Securing Traffic Leaving A VPC
 
Telstra Programmable Networks & Scaling a Serverless Team with Automation
 Telstra Programmable Networks & Scaling a Serverless Team with Automation Telstra Programmable Networks & Scaling a Serverless Team with Automation
Telstra Programmable Networks & Scaling a Serverless Team with Automation
 
AWS User Group Sydney - Meetup #60
AWS User Group Sydney - Meetup #60AWS User Group Sydney - Meetup #60
AWS User Group Sydney - Meetup #60
 
Shared Security in AWS
Shared Security in AWSShared Security in AWS
Shared Security in AWS
 
Visibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud ServicesVisibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud Services
 
AWS OpsWorks for Chef Automate
AWS OpsWorks for Chef AutomateAWS OpsWorks for Chef Automate
AWS OpsWorks for Chef Automate
 
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...
AWS CloudFormation Automation, TrafficScript, and Serverless architecture wit...
 
AWS User Group December 2016
AWS User Group December 2016AWS User Group December 2016
AWS User Group December 2016
 
AWS User Group Sydney - Atlassian 5-10-16
AWS User Group Sydney - Atlassian 5-10-16AWS User Group Sydney - Atlassian 5-10-16
AWS User Group Sydney - Atlassian 5-10-16
 
The Internet of Things - PolarSeven
The Internet of Things - PolarSevenThe Internet of Things - PolarSeven
The Internet of Things - PolarSeven
 
How our AWS account got hacked and what we did to ensure it never happened ag...
How our AWS account got hacked and what we did to ensure it never happened ag...How our AWS account got hacked and what we did to ensure it never happened ag...
How our AWS account got hacked and what we did to ensure it never happened ag...
 
AWS Meetup August 2016
AWS Meetup August 2016AWS Meetup August 2016
AWS Meetup August 2016
 
Brocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentationBrocade AWS user group Sydney presentation
Brocade AWS user group Sydney presentation
 
What we learned from the AWS Outage
What we learned from the AWS OutageWhat we learned from the AWS Outage
What we learned from the AWS Outage
 
How to Reduce Your AWS Bill
How to Reduce Your AWS BillHow to Reduce Your AWS Bill
How to Reduce Your AWS Bill
 
Aws Meetup April 2016
Aws Meetup April 2016Aws Meetup April 2016
Aws Meetup April 2016
 

Recently uploaded

Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 

Recently uploaded (20)

Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 

Amazon Web Services User Group Sydney - May 2018

  • 3. Contact Us hello@polarseven.com DevOps Competition 12 Months Contract Services Value = $60,000 http://p7-devops.io/DevOpsComp
  • 4. Tonight: ● AWS Updates and News: PolarSeven - Darrell King “Summit Overview” ● Session 1: Sumo Logic - Nikhil Singh “Monitoring and Troubleshooting Complex Issues” ● Break – Networking, Beers & Pizza ● Session 2: Palo Alto Networks - Craig Dent “AWS S3 Security: Your One Week Action Plan” ● Close Networking & Prize Draw - Win an Amazon Dot.
  • 6. BUILD-A-THON First Innovation Day at summit 120+ Attendees Showcased: Serverless - Rekognition & Polly Demo
  • 7. Serverless - Rekognition and Polly Demo
  • 8. ● Modern Company, Culture ● Artificial Intelligence ○ ML ○ SageMaker ○ AI applications ● Big Data / Analytics ● Containers ○ Kubernetes ○ EKS ● Serverless ○ Lambda ○ SAM
  • 9. Session 1: Nikhil Singh - Tektorch “ Monitoring and Troubleshooting complex issues” Using
  • 10. TekTorch Solutions Finding Insights, Nimble Engineers nikhil@tektorch.com.au @techies
  • 11. Agenda Complex Problem(s) Entry of Sumo Warrior The Sumo Wrestling Winner Thank You
  • 12. Complex Problems ● A business workflow App which is used by 100’s of technicians. ● App & Data is mission critical, some hospital SLA’s are < 15 min. ● Supports Offline. ● 3000+ forms, multiple workflows, photos, signatures, barcode etc. ● Bad Network Coverage, Slow WiFi exacerbate the problem. ● Add rogue human elements to this, who use system to shield slacking off.
  • 13. What If ... ● We knew exactly what a user was doing? ● What actions were performed, what time? ● Did the job was closed off or not? ● Was missing data due to application errors or user? ● Extract the missing data and apply reactively for old data. ● We could distinguish application issues and slacking.
  • 14. Fully Elastic On Demand Agility, Scale, Performance No Painful Upgrades New Features Weekly Superior Performance Guaranteed SLAs Always Available 4 Geos, 12AZs, 6 X Replication Real-Time, Full-Stack Visibility From Source to Sumo Instantly Secure by Design Industry’s Most Secure Platform Up & Running in Minutes Reduce Time to Value by 90% No Management Overhead Reduce TCO > 50% Introducing Sumo Logic
  • 15. Comprehensive Collection & Integrations CONFIG MGMT IAAS & PAAS CONTAINERS CDN SAAS APP STACKS INFRASTRUCTURE COMPLIANCE & SECURITY
  • 16. Native AWS Integrations Amazon CloudFront AWS VPC Flow AWS CloudTrail Amazon S3 AWS Elastic Load Balancing Sumo Logic Kinesis + Lambda Connector CloudTrail VPC Flow Logs CloudFrontELB S3 Kinesis Sumo Logic AWS Apps and Connectors Config AWS Config
  • 17. Log Reduce Reduce MTTI by up to 90%, MTTR by 50% Anomaly Detection Proactively identify new signatures and abnormalities. Outlier Detection Monitor multi-dimensional metrics, dynamic thresholds. Predictive Analytics Predict future trends. Log Compare Immediately see deltas. Sumo Logic: Advanced Analytics
  • 19. Sumo Warrior - Integrated with Sumo Logic - We built entire data journey - Data is entered by technician - Stored in local storage - API request is made - API request is stored in outbox if offline - Reconcilers are called when back online - Logging the critical path of the system. - Building complex queries to understand the data for an entity_form_fieldset_field and able to reconcile where it got lost was gold. - We extracted lost data and applied to the db without having technicians re do the jobs ($$). - Understanding the use cases where the application was failing and fixing within days was unbelievable.
  • 22. Prize Draw: Sign In On Your Smart Device To Win an Amazon Dot » https://p7-devops.io/aws-ug Sponsored by
  • 23. Break & Networking: • Refresh your drink • Grab some pizza • Make new contacts • Enter the prize draw!
  • 24. Session 2: Craig Dent Consulting Engineer “AWS S3 Security: Your One Week Action Plan”
  • 25. User Group Craig Dent Consulting Engineer Palo Alto Networks (formerly Evident.io) AWS S3 Security: Your One Week Action Plan
  • 26. User Group MO BUCKETS, MO PROBLEMS.
  • 27. Are your S3 Buckets Secure? 359+ Million Records Leaked
  • 28. NEW IMPROVEMENTS & GUARDRAILS HELP…
  • 29. ONE WEEK ACTION PLAN FOR S3 SECURITY Day 1: Audit Your AWS Accounts Day 2: Identify Key S3 Risks Day 3: Divide and Conquer Day 4: Get Risks Down to Zero Day 5: Repeat, Repeat, Repeat
  • 30. User Group What are the key risks?
  • 31. OPTIONS FOR APPLYING PERMISSIONS •  IAM Policies •  Bucket Policies •  ACL •  One-time URL
  • 32. TIP: Don’t give the bad guys the keys...or the treasure map! •  Global ACL view – 1% fail •  Global ACL edit – 0.5% fail •  Global ACL permissions – 4.2 % fail •  Global List ACL – 4.3% fail •  Global List (bucket policy) – 1.7% fail WHO CAN VIEW/EDIT MY S3 BUCKET POLICIES?
  • 33. Global GET – fail 7.16% Global PUT Global DELETE – fail 6.4% Global LIST Consider instead: IAM Policies One-time links WHO CAN ACCESS THE OBJECTS IN MY BUCKETS?
  • 34. Global Upload and Delete MFA Delete S3-Delete IAM Global Delete (via bucket policy) WHO CAN DELETE MY DATA AND CONTENT? QUESTION: How do I prevent someone from deleting something important?
  • 35. This operational control is used only about 50% of the time IS OBJECT VERSIONING ENABLED IN MY S3 BUCKETS?
  • 36. WILL I BE ABLE TO AUDIT THE ACTIVITY IN MY S3 BUCKETS? QUESTION: Without logs, what happens when a breach occurs? This operational control fails 55.5% of the time
  • 37. ACTION PLAN Day 1: Audit Your AWS Accounts Day 2: Identify Key S3 Bucket Risks Day 3: Divide and Conquer Day 4: Get Risks Down to Zero Day 5: Repeat, Repeat, Repeat
  • 38. User Group Day 1: Audit Your AWS Accounts
  • 39. DO YOU KNOW ALL YOUR AWS ACCOUNTS •  Identify teams using AWS •  Identify teams that might be using AWS for siloed apps (marketing, customer support, sales) •  Leverage procurement to find AWS expenses
  • 40. User Group Day 2: Identify Key Risks
  • 41. IDENTIFY RISKS: MANUALLY OR WITH EVIDENT
  • 42. SECURE STORAGE SERVICES •  Discover and classify data within containers and buckets •  Evaluate exposure based on policy •  Auto-remediate publicly exposed data •  Quarantine malware Amazon S3
  • 43. User Group Day 3: Divide & Conquer
  • 44. START WITH HIGH PRIORITY ACCOUNTS OR HIGH RISKS
  • 45. User Group Day 4: Keep Going to Get to Zero
  • 48. EVIDENT ARCHITECTURE Threat Detection Guided Remediation Cloud Control Plane All Services, Regions & Accounts Role-based Access Controls EVIDENT SECURITY MONITORING AND COMPLIANCE Dashboards, Reports, Alerts Real-time Risk Analysis Engine Audit & Compliance Custom Signatures & Policies Continuous Monitoring Security Analytics Cross-account IAM using STS Assume Role Function RESTAPIIntegrations SDK3rdPartySecOps AWS LAMBDAAWS SNS AUTOMATED POLICY ENFORCEMENT Event Hub APIs
  • 50. EVIDENT SECURITY MONITORING AND COMPLIANCE Start a Free Trial
  • 52. Thanks For Coming: Join Us Next Month – June 6th 2018 AWS Presenting on Kubernetes Plus Commvault & Talend >> Register @ http://www.meetup.com/AWS-Sydney/ << p7-devops.io/webinars-q2 p7-devops.io/DevOpsComp p7-devops.io/k8s-hands-on-days