cloud security monitoring at auth0 - security bsides seattle

35
Cloud Security Monitoring Security BSides Seattle Eugene Kogan - @eugk - February 4, 2017 (for startups, mostly)

Upload: eugene-kogan

Post on 16-Apr-2017

128 views

Category:

Software


2 download

TRANSCRIPT

Page 1: Cloud Security Monitoring at Auth0 - Security BSides Seattle

Cloud Security Monitoring

Security BSides Seattle Eugene Kogan - @eugk - February 4, 2017

(for startups, mostly)

Page 2: Cloud Security Monitoring at Auth0 - Security BSides Seattle

1. Who

2. Why

3. What

4. How

5. When

Page 3: Cloud Security Monitoring at Auth0 - Security BSides Seattle

1. Who

Page 4: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 5: Cloud Security Monitoring at Auth0 - Security BSides Seattle

CloudSecurityAlliance.org

Page 6: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 7: Cloud Security Monitoring at Auth0 - Security BSides Seattle

2. Why

Page 8: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 9: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 10: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 11: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 12: Cloud Security Monitoring at Auth0 - Security BSides Seattle

3. What

Page 13: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 14: Cloud Security Monitoring at Auth0 - Security BSides Seattle

–President Ronald Reagan

Trust, but verify.

Page 15: Cloud Security Monitoring at Auth0 - Security BSides Seattle

Awareness

Visualization

Misuse detection

Change detection

Incident detection

Incident response

Page 16: Cloud Security Monitoring at Auth0 - Security BSides Seattle

Splunk Graylog

Elastic Stack Loggly

Logentries Fluentd

Sumo Logic

AWS G Suite Dropbox GitHub GitLab Slack Zendesk Salesforce Jenkins Syslog Webhooks

Page 17: Cloud Security Monitoring at Auth0 - Security BSides Seattle

4. How

Page 18: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 19: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 20: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 21: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 22: Cloud Security Monitoring at Auth0 - Security BSides Seattle

_sourceCategory=cloudtrail_aws_logs* | json auto | where event_name matches "*Trail" or event_name matches "StartLogging" or event_name matches "StopLogging" | lookup awsaccountname from /shared/awsaccounts on recipient_account_id = awsaccountid | count as count by event_name, recipient_account_id, awsaccountname, user_name, principle_id, accesskey_id

Page 23: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 24: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 25: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 26: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 27: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 28: Cloud Security Monitoring at Auth0 - Security BSides Seattle
Page 29: Cloud Security Monitoring at Auth0 - Security BSides Seattle

github.com/auth0/audit-droid

Page 30: Cloud Security Monitoring at Auth0 - Security BSides Seattle

github.com/a2o/snoopy

Page 31: Cloud Security Monitoring at Auth0 - Security BSides Seattle

github.com/nccgroup/Scout2

Page 32: Cloud Security Monitoring at Auth0 - Security BSides Seattle

5. When

Page 33: Cloud Security Monitoring at Auth0 - Security BSides Seattle

You should be doing cloud security monitoring

today.

Page 34: Cloud Security Monitoring at Auth0 - Security BSides Seattle

Action items

Know which cloud services your organization uses

Have a modern platform for collection, analysis, alerting

Collect the right data from cloud and internal systems

Use this data wisely

Ensure your staff has the right skills to do all of the above

Page 35: Cloud Security Monitoring at Auth0 - Security BSides Seattle

The end 🖖

auth0.engineering/tagged/security

twitter.com/eugk