Cloud Security
An IAM GAME
Nathaniel Beckstead
Cloud Security An IAM GAME Nathaniel Beckstead whoami I am here - - PowerPoint PPT Presentation
Cloud Security An IAM GAME Nathaniel Beckstead whoami I am here because I love to give presentations. @scriptingislife https:/ /scriptingis.life https:/ /glimpseid.com 2 What is the cloud? 3 What is the cloud? 4 What is the cloud? 5
Nathaniel Beckstead
I am here because I love to give presentations. @scriptingislife https:/ /scriptingis.life https:/ /glimpseid.com
2
3
4
5
▪ EC2 - Virtual Machine but in the cloud ▪ S3 - Key-value storage (mostly for files) ▪ DynamoDB - NoSQL database
6
7
▪ It’s not
8
9
▪ Speed ▪ IaaS, PaaS, SaaS ▪ No rules!
10
11
https://www.episerver.com/learn/resources/blog/fred-bals/pizza-as-a-service/
▪ Identity and Access Management ▪ Users, API Keys, Roles, Policies ▪ Omnipresent in the cloud
12
▪ Like a user, but can be assumed by anyone who needs it.
13
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html
14
▪ Defines permissions for an action.
15
https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#targetText=Policies%20and%20Permissio ns,or%20resource%2C%20defines%20their%20permissions.
▪ Used for programmatic access
16
17
https://blog.trendmicro.com/the-code-spaces-nightmare/
▪ It’s complicated.
18
19
20
21
22
23
24
▪ It’s preventive.
25
Every developer using the
26
27
▪ Some application was vulnerable to SSRF ▪ WAF let SSRF through ▪ Role had read access to all S3 buckets
28
▪ Cloud is special ▪ Least privilege is best privilege ▪ Monitor API key usage ▪ Automate, automate, automate
29
30
AWS Access Advisor
https:/ /flaws.cloud https:/ /flaws2.cloud https:/ /expel.io/blog/
32