YOU ARE DOWNLOADING DOCUMENT

Please tick the box to continue:

Transcript
Page 1: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

SESSION ID:

#RSAC

Hadar Freehling

Automation and Virtualization Simplify Life: Can They Simplify Security?

TECH-R03

Staff Security StrategistVmware@dfudsecurity

Rob RandellDirector, NSBU System EngineeringVmware

Page 2: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

What can we do today?

Page 3: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Security and Automation

Policy - What do I allow or don’t allow?

Triggers - Event, activity, baseline differentials, etc.

Actions - Block, log, accept, etc..

Timer - How long should the change last?

Reset - What is post incident normal?

3

Page 4: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Security and Automation

Policy - No SSH within the Data center

Triggers - SSH process started on a server

Actions - Block traffic via firewall

Timer - Check for alerts in near real time

Reset - 5 minutes before firewall rule is removed

4

Page 5: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Demo

5

Page 6: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

And now some history

Page 7: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Background on Virtualization

7

Virtual datacenterVirtual private

cloudServer

Page 8: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Laydown the Network

Internet

Page 9: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Internet

Add Compute

Page 10: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Internet

Now For The Complex Part

Page 11: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Mixing of Workloads

11

PCI Non-PCI Private

Page 12: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Compute and Automation

Deploy from gold image

PowerShell

Scripts

Puppet Chef

Package deployments

12

Page 13: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Security and Virtualizing

Gen 1 virtual security

Virtual appliances – Functional, but limited

Agentless AV

Most enforcement still outside the virtual environment

13

Page 14: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

“We cannot solve our problems with the same way of thinking that created them.”

14

- Albert Einstein

Page 15: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Modern Attack: Targeted, Interactive, Stealthy

Stop Infiltration

80% of the investment is focused on preventing intrusion

The attack surface is simply too wide

Stop Exfiltration

20% of the investment is focused on addressing propagation, extraction and exfiltration.

Organizations lack the visibility and control inside their data center

Intrusion Propagation Extraction Exfiltration

Attack Vector / Malware

Delivery Mechanism

Entry Point Compromise

Escalate Privileges

Install C2* Infrastructure

Lateral Movement

Break Into Data Stores

Network Eavesdropping

App Level Extraction

Parcel & Obfuscate

Exfiltration

Cleanup

Page 16: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Modern Attack: Targeted, Interactive, Stealthy

Stop Infiltration

80% of the investment is focused on preventing intrusion

The attack surface is simply too wide

Intrusion

Attack Vector / Malware

Delivery Mechanism

Entry Point Compromise

Page 17: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Modern Attack: Targeted, Interactive, Stealthy

Stop Exfiltration20% of the investment is focused on

addressing propagation, extraction and exfiltration.

Organizations lack the visibility and control inside their data center

Intrusion PropagationAttack Vector / Malware

Delivery Mechanism

Entry Point CompromiseEscalate Privileges

Install C2* Infrastructure

Lateral Movement

Page 18: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Modern Attack: Targeted, Interactive, Stealthy

Stop Exfiltration20% of the investment is focused on

addressing propagation, extraction and exfiltration.

Organizations lack the visibility and control inside their data center

Intrusion ExtractionAttack Vector / Malware

Delivery Mechanism

Entry Point Compromise

Break Into Data Stores

Network Eavesdropping

App Level Extraction

Page 19: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Modern Attack: Targeted, Interactive, Stealthy

Stop Exfiltration20% of the investment is focused on

addressing propagation, extraction and exfiltration.

Organizations lack the visibility and control inside their data center

Intrusion ExfiltrationAttack Vector / Malware

Delivery Mechanism

Entry Point CompromiseParcel & Obfuscate

Exfiltration

Cleanup

Page 20: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

The Security Tool Belt

20

SECURITY SERVICES MANAGEMENTVisibility, Provisioning, and Orchestration

SOCSIEM, Security Analytics, Forensics

GOVERNANCE/COMPLIANCEVul Management, Log Management, GRC,

Posture Management, DLP

NETWORKFW, IDS/IPS, NGFW, WAF, AMP, UTM, DDoS

STORAGEEncryption, Key Management, Tokenization

COMPUTEAV, HIPS, AMP, Encryption, Exec/Device

Control

Security Infrastructure

IDENTITY CONTROLSAdvanced Authentication, SSO, Authorization, User Provisioning

APP/DATABASE CONTROLSVulnerability Management, Storage Security, Web Services Security,

Secure OS

Page 21: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Impact of Architecture

21

Distributed application architectures

Comingled on a common infrastructure

Massive misalignment

1. Hyper-connected compute base

2. Distributed policy problem

Page 22: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

How do we fix this?

Page 23: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Security and Virtualizing Gen 2

Virtualization security is a reality

NextGen Firewalls and IPS systems are integrating into the fabric

Endpoint and network monitoring leverage virtualization

23

Page 24: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Automating and Security

New levels of information and visibility

RestAPI is common

Why not leverage this?

24

Page 25: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Leveraging Virtualization

1 32

Traditional Data Center

Static service chain

Virtualized Data Center

Dynamic service chain

Page 26: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Design and Leverage

Enhanced security and service insertions

Automatic remediation & automatic response

Network isolation on demand

DMZ anywhere

26

Page 27: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Adaptable Security Response

All this based on changing meta data of your systems….

What it was is not what it is today...

Adaptable security for an ever adapting world

27

Page 28: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Security and Automation [PTATR]

Policy - What do I allow or don’t allow?

Triggers - Event, activity, baseline differentials, etc.

Actions - Block, log, accept, etc..

Timer - How long should the change last?

Reset - What is post incident normal?

28

Page 29: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

The Automation Security Workflow

29

Alert sent

Automation workflow

InvestigateRemediatePatchDestroy

ValidateRe-Scan

Change Happens

Security Policy changed

Detected

Security Policy changed

Page 30: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Automation Risk Reduction

How long does it take to respond?

What is the size of team?

Can you reduce remediation time and time to investigate ?

30

Page 31: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

31

Things to consider?

Is your organization ready for this?

What is your hypervisor?

How much are your virtualized?

Is IT silo or integrated

What is your automation platform, if you have one?

Are there low hanging fruit we can attack with this?

How to get started

Page 32: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

32

Next Step:

Talk to your virtualization team and find out what you have deployed

Build a plan:

Understand the integration points with your security products and your hypervisor

Define remediation workflows (PTATR)

Put it into action:

Deploy a initial security remediation workflow to help with non-business critical systems security alerts

Increase integration points and develop playbooks for security remediation automation

Apply What You Have Learned Today

Page 33: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Why Not Now

Stateless built fashion

Wipe at random (just in case) – temporary systems

Containers and read only systems

Why write?

Change control paradigm change

Auto updates/changes based on automation....

33

Page 34: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Future is Bright

Automate based on dynamic variables

Encryption on the fly

Enhanced trusted context from the endpoint

Look at app memory via hypervisor

Honeypot on demand

Integrate into development

34

Page 35: TECH-R03 Rob Randell Automation and Virtualization · Automation and Virtualization ... Puppet Chef Package ... Increase integration points and develop playbooks for security remediation

#RSAC

Q&A

Hadar Freehling [email protected] Randell [email protected]


Related Documents