moloch & amazon vpc traffic mirroring · who am i? •erik freeland...

12
2 # Moloch & Amazon VPC Traffic MIrroring

Upload: others

Post on 24-Mar-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

2‹#›

Moloch & Amazon VPC Traffic MIrroring

Page 2: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

What Am I Presenting?

• Complete cloudformation template for AWS installation of Moloch• Preview of official AWS Quickstart

• Core Requirements:• Cloud native components that can all autoscale independently• Decouple Elasticsearch from capture & viewer• Centralize all packet storage on S3• Allow for multi-viewer support• Allow for installation into new & existing VPCs

Page 3: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

Who Am I?

• Erik Freeland • @ejfreeland [email protected]

• 25+ years in computing, networking, & security.• Working on Banyan Vines to AWS

• Currently Director of Customer Success for Nubeva• Nubeva has solved OOB TLS Decryption in the “cloud”

Page 4: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

Why Should I Care?

• https://medium.com/wardleymaps

Page 5: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to
Page 6: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

Actual Demo Diagram

Page 7: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

Availability

• Now• www.nubeva.com

• New VPC -https://nubevalabs.s3.amazonaws.com/quickstart/templates/nubeva-master.template.yaml

• Existing VPC -https://nubevalabs.s3.amazonaws.com/quickstart/templates/nubeva.template.yaml

Page 8: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

But Wait There’s More

Page 9: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to
Page 10: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

But Wait There’s More

Page 11: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

Nubeva TLS Decryption

Unencrypted Traffic

Encrypted Traffic

Application cluster

Clients

AppNubeva TLS SensorsDiscover Individual

Session Final Secrets from Memory in Realtime

Universal Software Decryptor (Container)

Decrypt Anywhere, Anytime,To Any Tool or Files

Using Any Packet Source

Copies of PacketsRealtime Streams

and Historical PCAPs

Encrypted Key Plane

Page 12: Moloch & Amazon VPC Traffic MIrroring · Who Am I? •Erik Freeland •@ejfreelanderik@nubeva.com •25+ years in computing, networking, & security. •Working on Banyan Vines to

13

‹#›

Thanks