Top Banner
How to lead better security t hrough our MINI Hardening Project Kazuki Tsubo Cloud Support Engineer Amazon Web Services Ireland
40

How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Jun 23, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

How to lead better securitythrough our MINI Hardening Project

Kazuki TsuboCloud Support Engineer

Amazon Web Services Ireland

Page 2: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Kazuki Tsubo• Mini Hardening Organizer

• OWASP Japan marketing team

• Job history– NIKKEI

• Web Development Department

– Amazon Web Services Japan

– Amazon Web Services Ireland

• Cloud Support Engineer

Page 3: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

https://aws.amazon.com/

Page 4: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Relationship with OWASP

Page 5: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

OWASP Japan has branch

Page 6: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Agenda1. About Hardening Project2. Original and Mini Hardening3. What is Mini Hardening?

a. Our motivationb. Passed competitionsc. Technical elements

4. Create own event5. Conclusion

Page 7: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

1. About Hardening Project

Page 8: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Lots of security risks in real business

Page 9: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

CTF

Page 10: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Where is the profit?

Page 11: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Hardening Project is business focused

Page 12: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Rules

Page 13: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Expected investigation• Improving vulnerable environment

• Avoid stopping

• Treating stakeholder

Page 14: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Attack from professional team

Attack

Professional team

Attendees

Page 15: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Evaluated by crawler

Evaluate SLASimulate Customer

Professional team

Crawler

Page 16: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

16

Stakeholders

OrderMalicious Email

Professional team

Crawler

Stakeholders

Page 17: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

2. Original and Mini

Page 18: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Hardening Project• Original

– Since 2012

– Business focused competition

• Mini

– Very similar concept but smaller

– Frequent

Page 19: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

DifferenceMIN

Team Member 3-4 person 6-8 person

Competition time 3 hours 8 hours

Feedback time 1 hours 8 hours

Nodes per team 2-3 nodes 20-30 nodes

Security issues 10-20 issues 50-60 issues

Attackers 3-4 person Over 10 person

Frequency Seasonal Yearly

Page 20: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

3. What is Mini Hardening?

Page 21: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

a: Motivation to create “Mini”• Experience

– Attack from the other

• Easy to attend, easy to start

– 1 day only

– Common and simple security issues

– Requirement is not team

Page 22: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

b. Past 8 competitions• Mini Hardening #1.x

– 2015/03/07: #1.0– 2015/05/23: #1.1– 2015/08/29: #1.2– 2015/10/31: #1.3 at Osaka– 2016/02/27: Mini in OWASP DAY

• Mini Hardening #2.x– 2016/12/04: #2.0– 2017/03/26: #2.1– 2017/05/06: 078 Hardening at Kobe (Collaborated with “078” event)

Page 23: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Timeline• 10:30 Door open• 11:00 Opening - Start explanation & Ice break• 12:00 Start competition• 15:00 End competition• 16:00 Feedback & Recognition• 17:00 Ending• 17:45 Start drinking• 20:00 End of all activities

Page 24: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

c. Technical Elements

Page 25: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Infrastructure• Using AWS

– VPC / EC2

– Send request of simulated events

Page 26: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Professional team

Attendees

Page 27: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Vulnerable environment• Old versions

– bash, httpd, openssl…

• Known issue

– Weak password

– Not tuned configuration

– SSL certificate expiration

Page 28: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Harder attacks

Just 1 min movie here(attacker’s declaration)

Page 29: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Rushing• Reboot infected nodes

• Stopping daemons

• DDoS attack

• Ransomware

Page 30: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Scoring• Reading reports

• Verifying nodes

Page 31: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Score sheet

Vulnerabilities

Expected investigation

Checkpoint

Base score

Team scores- fix- Report

Page 32: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Crawler• Simulating customer

• Crawling

– Connection

– Content

– Latency

– Port

Page 33: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

4. Create own event

Page 34: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Our case• Sponsored by WASForum

• Online meeting every Wednesday

– Slack

– Google doc / Hang out

Page 35: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Is it easy? No.• Tasks

– Organize

– Implement vulnerabilities

– Ready to evaluate

– Attack

– Evaluate&Feedback

Page 36: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Core members• 4 core members at start

– Easy to talk

– High context

• Today 7 members except me

– Splitted role

Page 37: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Benefits– For me

• Networking opportunity

• Feeling my growth

• Enjoyable with others

Page 38: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

5. Conclusion

Page 39: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

First small steps• We can start training by using some tools

– Broken Web Application Project• Easy to break

• Try to fix

– OWASP Zed Attack Proxy Project• Handful tool for evaluating

Page 40: How to lead better security through our MINI Hardening ... to lead... · –OWASP Zed Attack Proxy Project •Handful tool for evaluating. Thank you for listening today! twitter:

Thank you for listening today!

twitter: @TSB_KZKFacebook/LinkedIn: Kazuki Tsubo