Top Banner
Edward L. Haletky, TVP Strategy Principal Analyst Mike Foley, VMware vSphere Technical Marketing SER1361BU #VMworld #SER1361BU Security Operations for VMware vSphere with VMware vRealize Log Insight VMworld 2017 Content: Not for publication or distribution
21

SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Aug 03, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Edward L. Haletky, TVP Strategy Principal AnalystMike Foley, VMware vSphere Technical Marketing

SER1361BU

#VMworld #SER1361BU

Security Operations for VMware vSphere with VMware vRealize Log Insight

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 2: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

• This presentation may contain product features that are currently under development.

• This overview of new technology represents no commitment from VMware to deliver these features in any generally available product.

• Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind.

• Technical feasibility and market demand will affect final delivery.

• Pricing and packaging for any new technologies or features discussed or presented have not been determined.

Disclaimer

2#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 3: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Agenda

4

1 Introduction – The Why!

2 Users (Admin vs. Root vs. Service Accounts)

3 Shell commands

4 RBAC changes

5 Reconfiguration Events

6 Stump the Chump

7 Something Special!

8 Q&A

#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 4: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

The Why!Enact the guidance

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 5: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Mike’s “Why Did We Do This?”

• IT needs have changed

– Need more information to make better decisions

• Security is now on EVERYONES radar

– Need more information to

• avoid security incidents

• analyze them after the fact

• Existing tools have been inadequate

– Logs “sucked”

– SIEM tools are only as good as what you put in them

• But they have no focus on virtualization

6#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 6: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Edward’s “Why Did We Do This?”

• Existing tools have been inadequate

– …

• Best Practices are difficult to show

– SOC was to show off best practices

• Logs are difficult to read

– Visualization is better

• Bridge between Administrators, Ops, and Security

– We can show security what is happening

– Start of more discussions, everyone on the same page

7#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 7: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

vSphere 6.5 Enhanced Logging

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 8: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Logs Transform in vSphere 6.5

Pre-6.5: Logs used for GSS/Troubleshooting

9

6.5: Logs include VC Events – Audit Quality and Actionable

#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 9: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

vSphere Logging Today: 5.x / 6.0 Virtual Machine Reconfigure

10

Logs really need improvement. I know a change was made, but what happened? What changed?

#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 10: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Actionable Logging

11

Who, What, When, How

#SER1361BU CONFIDENTIAL

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 11: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: Users Who not to see here!?

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 12: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: Shell CommandsWhat not to see here!?

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 13: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: RBACHow did these change!?

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 14: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: Reconfiguration EventsWhat changed!?

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 15: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: Stump the ChumpWhat do you want to see:

• VM Encryption Actions? • Secure Boot on VM? (UEFI Firmware)• Scale of Changes (move the dial)• Cluster Dashboard (internal vs external)?• ???

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 16: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Demo: Something SpecialSecureESX AddOn Bundle

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 17: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Q&AWhat are your questions?

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 18: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

vSphere Security HOL HOL-1811-04-SDC

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 19: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

Thank YouEdward L. Haletky: [email protected], @Texiwill

Mike Foley: [email protected], @mikefoley

SOC Content Pack and information: Security Operations for VMware vSphere using VMware vRealize Log Insight

SecureESX AddOn Bundle: Contact [email protected], @Texiwill

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 20: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

VMworld 2017 Content: Not fo

r publication or distri

bution

Page 21: SER1361BU Security Operations for VMware vSphere with or ......1 Introduction –The Why! 2 Users (Admin vs. Root vs. Service Accounts) 3 Shell commands 4 RBAC changes 5 Reconfiguration

VMworld 2017 Content: Not fo

r publication or distri

bution