SlideShare une entreprise Scribd logo
1  sur  43
De invloed van
“cloud” op het
dreigingslandschap…
Frank Breedijk – ISACA RISK event 2019
Legitimate a CC NC ND image by Seth Anderson
https://www.flickr.com/photos/44124372363@N01/7830947420/
o Frank Breedijk
o CISO Schuberg Philis
o Cloud and open source enthousiast
o Ik woon in een stal uit 1751
o fbreedijk@schubergphilis.com
3
> whoami
Opa verteld…
o Shared hosting vs decated hosting
o Intrede van virtualisatie
o Private / Community cloud
o Public cloud
5
1998 - 2012 6
Shared of ‘dedicated’ hosting
71924 Ford Model T Coupe '772U’ 1 a CC ND image by Jack Snell
https://www.flickr.com/photos/59972430@N00/23467122488/
o Met wie deel je je servers
o Nadruk op:
o Fysieke beveiliging
o Netwerk Segmentatie
o Scheiding van kritiek en niet kritiek
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
8
The fort ‘Datacenter’
IMG_20140829_140731 a CC image by Robert
https://www.flickr.com/photos/12967790@N00/14885417370/
Virtualisatie
o Nieuwe dreigingen:
o Delen van dezelfde hardware
o Verschillende machines
delen dezelfde kernel
o ”Opgeloste” dreigingen
o Software wordt niet meer op
software nivo gedeeld
9Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com
https://www.flickr.com/photos/91795203@N02/9228236784/
Virtualisatie
o Nadruk op:
o Fysieke beveiliging
o Hardware / kernel segmentatie
o Hypervisor escape
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o DDoS (2013)
10Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com
https://www.flickr.com/photos/91795203@N02/9228236784/
2012 - 2015 11
2015 12
MCC
NKNK
Private / “Community” cloud
13FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
o T.o.v. virtualisatie
o Hardware/kernel nu gedeeld met ”anderen”
o Orchestratie laag met een API
o T.o.v. public cloud
o Beperkte groep medehuurders
o Physieke locatie bekend
o Mogelijkheid tot audit
14
Wat is er anders…
FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
o Nadruk op:
o Hypervisor escape
o Hardward / kernel segmentatie
o Fysieke beveiliging
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o Applicatie security
15
Security
FARM:shop private hire party a CC NC image by Laura Billings
https://www.flickr.com/photos/14784969@N08/6225824429/
2019 16
MCC
AWS
Azure
GCP
Office 365
Okta
Slack
Public cloud
17Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
o Je weet niet precies met wie je de ruimte deelt
o Je weet niet precies waar je data staat
o Grote cloud partijen kunnen niet iedere klant laten
auditen
o Buitenlandse partijen
18
Wat is er anders…
Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
o Nadruk op:
o Compliance
o Lock in
o Fysieke locatie
o Oorzaak van de meeste incidenten
o Malware
o Niet patchen
o Niet juist inrichten van rechten
o Applicatie fouten
19
Security…
Holi. a CC NC ND image by ¡arturii!
https://www.flickr.com/photos/7617410@N02/16805986366/
Help?
20Sunny with a chance of meatballs
Sony Pictures Animation 2009
o Veel gevallen met kleine impact op para-
virtualisatie
o Paravirtualisatie niet populair meer
o Meltdown + Spectre
o Cloud vendors waren de eersten
21
Hypervisor escape
Incidenten?
o Niet patchen
o Gebrekkige access control
o Onbedoeld bloodstellen van gevoelige
services
o Ransomware
o Applicatiefouten
22
o It’s just someone else’s computer?
o Als dat zo is, waarom wil ”men” het dan zo graag?
o Is dit wel de juiste blik?
23
There is no cloud…
Laptop van een college, foto door Frank Breedijk
Moderne cloud infrastructuren…
24Golden gate bridge, San Fransisco USA - Original image from Carol M. Highsmith’s America, Library of Congress
collection. Digitally enhanced by rawpixel. A CC image by rawpixel
https://www.flickr.com/photos/153584064@N07/46201778672/
Beschikbaarheid
o Niet alleen meer uptime
o Beschikbaarheid van informatie is
functionaliteit
o Functionaliteit die de eind-gebruiker
niet bereikt is geen functionalitiet
o Bedrijven moeten ‘agile’ zijn om te
overleven
o Geen hele serverparken meer nodig
om b.v. A.I. te doen
25
Beschikbaar
IntegerVertrouwelijk
Agility?
o Met zo min mogelijk operations
mensen net zoveel operations
doen als nodig is
o Ontwikkelaars in staat stellen zo
veel mogelijk functionaliteit zo
snel mogelijk bij de eind-
gebruikers te krijgen
26150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet
https://www.flickr.com/photos/compacflt/20009404191/
Hoe dan?
o Commodity / uitontwikkeld
o Services ipv servers
o IT voor IT
o Services, PaaS ipv servers
o “Onderscheidende” applicaties
o Cloud native of containers
27150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet
https://www.flickr.com/photos/compacflt/20009404191/
AWS I choose you
28
https://www.youtube.com/watch?v=zyP-pfij86s
Snoepwinkel
o De mogelijkheden /
functionaliteiten van een
moderne cloud provider zijn
(bijna) eindeloos
29Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris
https://www.flickr.com/photos/76224602@N00/4348333928/
30
Moderne cloud vs. IaaS
Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris
https://www.flickr.com/photos/76224602@N00/4348333928/
Colorful Gum Tabs a CC image by Marco Verch
https://www.flickr.com/photos/30478819@N08/45917981931/
Cloud security  IaaS security
31Colorful Gum Tabs a CC image by Marco Verch
https://www.flickr.com/photos/30478819@N08/45917981931/
Iedereen wil security…
32Werner Vogels tijdens AWS Summit 2018 in Den Haag
Door Frank Breedijk
SaaS kan helpen
o Als IT geen core business is
o Als IT wel je core business is,
maar de applicatie niet
“spannend” is
o Als de applicatie niet
“onderscheidend” is
33
De kracht van de API
34
o Een altijd up to date overzicht krijgen van alles in je
landschap
o Weten waar je data staat
o Weten dat je data versleuteld is
o Verkeerde configuraties detecteren
o én oplossen
35
Via de API kun je…
She thinks my json's sexy... Said no one ever a CC ND iamge by Matthew Ragan
https://www.flickr.com/photos/45199237@N04/21131398981/
Consolidatie
o Veel van de oplossingen nu nog
zelf bouw
o Derden zijn in dit gat gestapt
o Security is de dominante non-
functional voor clouds
o Verwacht dat cloud providers dit
gaan aanbieden
362983e2 P900 Wide-eyed wonder of Christmas a CC NC ND image by Jenny Pansing
https://www.flickr.com/photos/25171569@N02/23876843182/
Niet het einde van de wereld
37Sunny with a chance of meatballs
Sony Pictures Animation 2009
Cloud craftsmenship manifesto…
38The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I am a craftsman and I use cloud technologies,
because I apply my craftmanship to cloud
technologies, I am a Cloud Craftsman.
I recognize that cloud technologies, if applied
correctly, offer great benefits in terms of
availability, reliability, scalability and agility.
I recognize that, like any other technology, cloud
technology is not a silver bullet.
39
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that not all cloud solutions are created
equally. I will do my best to select the solution that
best fits my specific situation.
I recognize that, in the cloud, I will have to trust
and rely on the abilities of the provider. I will do
my best to validate this trust.
I recognize that effective, efficient and secure
usage of cloud technologies is a responsibility
that is shared between the user and the provider.
40
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that effective, efficient and secure
uadge of cloud technologies is in both the interest
of the user and provider.
I intend to read, understand and/or use the best
practices and tooling recommended by the
provider to the greatest extend possible in my
situation.
I intend to stand on the shoulders of giants. May
before us have developed tools and practices for
the effective, efficient and secure usage of cloud
technologies. I will adopt their work as much as I
can.
41
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that cloud technologies are repaidly
evolving, this means I will have to keep up with the
current state of the cloud technologies I intend to
use and are available to me. After all, a fool with a
tool is still a fool.
I recognize that automation is the key to reliability,
reproducability and recoverability. I will embrace
automation of my work as the way forward.
42
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
I recognize that, in the cloud, I cannot just rely on
others to provide security for me.
I am a Cloud Craftsman, not because it is easy, but
because it is necessary and I am up for the
challenge.
43
Cloud craftsmenship
manifesto…
The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/
http://craftsmanship.cloud
44The blacksmith a CC NC ND image by psaRas
https://www.flickr.com/photos/148231543@N08/36198187330/

Contenu connexe

Similaire à De invloed van "cloud" op het dreigingslanschap

Situation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySituation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySimon Wardley
 
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Binu Ramakrishnan
 
Revolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityRevolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityChijioke “CJ” Ejimuda
 
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...Mark Smith
 
企業導入雲端
企業導入雲端企業導入雲端
企業導入雲端Carlo Li
 
Short story about your information processing - cloud part
Short story about your information processing -  cloud partShort story about your information processing -  cloud part
Short story about your information processing - cloud partArtur Marek Maciąg
 
Let’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsLet’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsT.Rob Wyatt
 
Security Tips to run Docker in Production
Security Tips to run Docker in ProductionSecurity Tips to run Docker in Production
Security Tips to run Docker in ProductionGianluca Arbezzano
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...Patrick Thomas
 
Security Theatre - PHP UK Conference
Security Theatre - PHP UK ConferenceSecurity Theatre - PHP UK Conference
Security Theatre - PHP UK Conferencexsist10
 
Cfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreCfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreJulien Pivotto
 
Security Theatre - Confoo
Security Theatre - ConfooSecurity Theatre - Confoo
Security Theatre - Confooxsist10
 
Seamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsSeamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsDynatrace
 
IoThings you don't even need to hack
IoThings you don't even need to hackIoThings you don't even need to hack
IoThings you don't even need to hackSlawomir Jasek
 
AI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikAI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikSergey Gordeychik
 
Security Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPSecurity Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPxsist10
 
Casino In The Clouds
Casino In The CloudsCasino In The Clouds
Casino In The Cloudsgojkoadzic
 
Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Christian Deger
 

Similaire à De invloed van "cloud" op het dreigingslanschap (20)

Situation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesdaySituation Normal - Presentation at NottTuesday
Situation Normal - Presentation at NottTuesday
 
Simon Wardley
Simon WardleySimon Wardley
Simon Wardley
 
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...Securing Application Deployments in CI/CD Environments (Updated slides: http:...
Securing Application Deployments in CI/CD Environments (Updated slides: http:...
 
Revolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure ConnectivityRevolutionizing Crtitical Infrastructure Connectivity
Revolutionizing Crtitical Infrastructure Connectivity
 
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
AusNOG 2013 - The Rapid Rise of the Mobile Multihomed Host, and What it Might...
 
企業導入雲端
企業導入雲端企業導入雲端
企業導入雲端
 
Short story about your information processing - cloud part
Short story about your information processing -  cloud partShort story about your information processing -  cloud part
Short story about your information processing - cloud part
 
Let’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal CloudsLet’s Get Cirrus About Personal Clouds
Let’s Get Cirrus About Personal Clouds
 
Security Tips to run Docker in Production
Security Tips to run Docker in ProductionSecurity Tips to run Docker in Production
Security Tips to run Docker in Production
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
 
Security Theatre - PHP UK Conference
Security Theatre - PHP UK ConferenceSecurity Theatre - PHP UK Conference
Security Theatre - PHP UK Conference
 
Cfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymoreCfgmgmt Challenges aren't technical anymore
Cfgmgmt Challenges aren't technical anymore
 
Security Theatre - Confoo
Security Theatre - ConfooSecurity Theatre - Confoo
Security Theatre - Confoo
 
Attack eu 2021 attack4cvc
Attack eu 2021 attack4cvcAttack eu 2021 attack4cvc
Attack eu 2021 attack4cvc
 
Seamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related ProblemsSeamlessly Detect and React to IT-Service Related Problems
Seamlessly Detect and React to IT-Service Related Problems
 
IoThings you don't even need to hack
IoThings you don't even need to hackIoThings you don't even need to hack
IoThings you don't even need to hack
 
AI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey GordeychikAI for security or security for AI - Sergey Gordeychik
AI for security or security for AI - Sergey Gordeychik
 
Security Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHPSecurity Theatre - AmsterdamPHP
Security Theatre - AmsterdamPHP
 
Casino In The Clouds
Casino In The CloudsCasino In The Clouds
Casino In The Clouds
 
Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24Building Microservices in the cloud at AutoScout24
Building Microservices in the cloud at AutoScout24
 

Dernier

( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...nilamkumrai
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdfMatthew Sinclair
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...nirzagarg
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...Neha Pandey
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...SUHANI PANDEY
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...SUHANI PANDEY
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubaikojalkojal131
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋nirzagarg
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...SUHANI PANDEY
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftAanSulistiyo
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"growthgrids
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...SUHANI PANDEY
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLimonikaupta
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...tanu pandey
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...roncy bisnoi
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...SUHANI PANDEY
 

Dernier (20)

( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Salem Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
Sarola * Female Escorts Service in Pune | 8005736733 Independent Escorts & Da...
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 

De invloed van "cloud" op het dreigingslanschap

  • 1. De invloed van “cloud” op het dreigingslandschap… Frank Breedijk – ISACA RISK event 2019 Legitimate a CC NC ND image by Seth Anderson https://www.flickr.com/photos/44124372363@N01/7830947420/
  • 2.
  • 3. o Frank Breedijk o CISO Schuberg Philis o Cloud and open source enthousiast o Ik woon in een stal uit 1751 o fbreedijk@schubergphilis.com 3 > whoami
  • 4. Opa verteld… o Shared hosting vs decated hosting o Intrede van virtualisatie o Private / Community cloud o Public cloud 5
  • 6. Shared of ‘dedicated’ hosting 71924 Ford Model T Coupe '772U’ 1 a CC ND image by Jack Snell https://www.flickr.com/photos/59972430@N00/23467122488/
  • 7. o Met wie deel je je servers o Nadruk op: o Fysieke beveiliging o Netwerk Segmentatie o Scheiding van kritiek en niet kritiek o Oorzaak van de meeste incidenten o Malware o Niet patchen 8 The fort ‘Datacenter’ IMG_20140829_140731 a CC image by Robert https://www.flickr.com/photos/12967790@N00/14885417370/
  • 8. Virtualisatie o Nieuwe dreigingen: o Delen van dezelfde hardware o Verschillende machines delen dezelfde kernel o ”Opgeloste” dreigingen o Software wordt niet meer op software nivo gedeeld 9Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com https://www.flickr.com/photos/91795203@N02/9228236784/
  • 9. Virtualisatie o Nadruk op: o Fysieke beveiliging o Hardware / kernel segmentatie o Hypervisor escape o Oorzaak van de meeste incidenten o Malware o Niet patchen o DDoS (2013) 10Install XenServer on VMware Player - Select Installation Source a CC image by xmodulo.com https://www.flickr.com/photos/91795203@N02/9228236784/
  • 12. NKNK Private / “Community” cloud 13FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 13. o T.o.v. virtualisatie o Hardware/kernel nu gedeeld met ”anderen” o Orchestratie laag met een API o T.o.v. public cloud o Beperkte groep medehuurders o Physieke locatie bekend o Mogelijkheid tot audit 14 Wat is er anders… FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 14. o Nadruk op: o Hypervisor escape o Hardward / kernel segmentatie o Fysieke beveiliging o Oorzaak van de meeste incidenten o Malware o Niet patchen o Applicatie security 15 Security FARM:shop private hire party a CC NC image by Laura Billings https://www.flickr.com/photos/14784969@N08/6225824429/
  • 16. Public cloud 17Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 17. o Je weet niet precies met wie je de ruimte deelt o Je weet niet precies waar je data staat o Grote cloud partijen kunnen niet iedere klant laten auditen o Buitenlandse partijen 18 Wat is er anders… Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 18. o Nadruk op: o Compliance o Lock in o Fysieke locatie o Oorzaak van de meeste incidenten o Malware o Niet patchen o Niet juist inrichten van rechten o Applicatie fouten 19 Security… Holi. a CC NC ND image by ¡arturii! https://www.flickr.com/photos/7617410@N02/16805986366/
  • 19. Help? 20Sunny with a chance of meatballs Sony Pictures Animation 2009
  • 20. o Veel gevallen met kleine impact op para- virtualisatie o Paravirtualisatie niet populair meer o Meltdown + Spectre o Cloud vendors waren de eersten 21 Hypervisor escape
  • 21. Incidenten? o Niet patchen o Gebrekkige access control o Onbedoeld bloodstellen van gevoelige services o Ransomware o Applicatiefouten 22
  • 22. o It’s just someone else’s computer? o Als dat zo is, waarom wil ”men” het dan zo graag? o Is dit wel de juiste blik? 23 There is no cloud… Laptop van een college, foto door Frank Breedijk
  • 23. Moderne cloud infrastructuren… 24Golden gate bridge, San Fransisco USA - Original image from Carol M. Highsmith’s America, Library of Congress collection. Digitally enhanced by rawpixel. A CC image by rawpixel https://www.flickr.com/photos/153584064@N07/46201778672/
  • 24. Beschikbaarheid o Niet alleen meer uptime o Beschikbaarheid van informatie is functionaliteit o Functionaliteit die de eind-gebruiker niet bereikt is geen functionalitiet o Bedrijven moeten ‘agile’ zijn om te overleven o Geen hele serverparken meer nodig om b.v. A.I. te doen 25 Beschikbaar IntegerVertrouwelijk
  • 25. Agility? o Met zo min mogelijk operations mensen net zoveel operations doen als nodig is o Ontwikkelaars in staat stellen zo veel mogelijk functionaliteit zo snel mogelijk bij de eind- gebruikers te krijgen 26150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet https://www.flickr.com/photos/compacflt/20009404191/
  • 26. Hoe dan? o Commodity / uitontwikkeld o Services ipv servers o IT voor IT o Services, PaaS ipv servers o “Onderscheidende” applicaties o Cloud native of containers 27150725-F-YW474-128 a CC NC image by U.S. Pacific Fleet https://www.flickr.com/photos/compacflt/20009404191/
  • 27. AWS I choose you 28 https://www.youtube.com/watch?v=zyP-pfij86s
  • 28. Snoepwinkel o De mogelijkheden / functionaliteiten van een moderne cloud provider zijn (bijna) eindeloos 29Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris https://www.flickr.com/photos/76224602@N00/4348333928/
  • 29. 30 Moderne cloud vs. IaaS Ren Ren Le Bao’an Boulevard Shenzhen a CC NC image by Chris https://www.flickr.com/photos/76224602@N00/4348333928/ Colorful Gum Tabs a CC image by Marco Verch https://www.flickr.com/photos/30478819@N08/45917981931/
  • 30. Cloud security  IaaS security 31Colorful Gum Tabs a CC image by Marco Verch https://www.flickr.com/photos/30478819@N08/45917981931/
  • 31. Iedereen wil security… 32Werner Vogels tijdens AWS Summit 2018 in Den Haag Door Frank Breedijk
  • 32. SaaS kan helpen o Als IT geen core business is o Als IT wel je core business is, maar de applicatie niet “spannend” is o Als de applicatie niet “onderscheidend” is 33
  • 33. De kracht van de API 34
  • 34. o Een altijd up to date overzicht krijgen van alles in je landschap o Weten waar je data staat o Weten dat je data versleuteld is o Verkeerde configuraties detecteren o én oplossen 35 Via de API kun je… She thinks my json's sexy... Said no one ever a CC ND iamge by Matthew Ragan https://www.flickr.com/photos/45199237@N04/21131398981/
  • 35. Consolidatie o Veel van de oplossingen nu nog zelf bouw o Derden zijn in dit gat gestapt o Security is de dominante non- functional voor clouds o Verwacht dat cloud providers dit gaan aanbieden 362983e2 P900 Wide-eyed wonder of Christmas a CC NC ND image by Jenny Pansing https://www.flickr.com/photos/25171569@N02/23876843182/
  • 36. Niet het einde van de wereld 37Sunny with a chance of meatballs Sony Pictures Animation 2009
  • 37. Cloud craftsmenship manifesto… 38The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 38. I am a craftsman and I use cloud technologies, because I apply my craftmanship to cloud technologies, I am a Cloud Craftsman. I recognize that cloud technologies, if applied correctly, offer great benefits in terms of availability, reliability, scalability and agility. I recognize that, like any other technology, cloud technology is not a silver bullet. 39 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 39. I recognize that not all cloud solutions are created equally. I will do my best to select the solution that best fits my specific situation. I recognize that, in the cloud, I will have to trust and rely on the abilities of the provider. I will do my best to validate this trust. I recognize that effective, efficient and secure usage of cloud technologies is a responsibility that is shared between the user and the provider. 40 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 40. I recognize that effective, efficient and secure uadge of cloud technologies is in both the interest of the user and provider. I intend to read, understand and/or use the best practices and tooling recommended by the provider to the greatest extend possible in my situation. I intend to stand on the shoulders of giants. May before us have developed tools and practices for the effective, efficient and secure usage of cloud technologies. I will adopt their work as much as I can. 41 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 41. I recognize that cloud technologies are repaidly evolving, this means I will have to keep up with the current state of the cloud technologies I intend to use and are available to me. After all, a fool with a tool is still a fool. I recognize that automation is the key to reliability, reproducability and recoverability. I will embrace automation of my work as the way forward. 42 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 42. I recognize that, in the cloud, I cannot just rely on others to provide security for me. I am a Cloud Craftsman, not because it is easy, but because it is necessary and I am up for the challenge. 43 Cloud craftsmenship manifesto… The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/
  • 43. http://craftsmanship.cloud 44The blacksmith a CC NC ND image by psaRas https://www.flickr.com/photos/148231543@N08/36198187330/