SlideShare a Scribd company logo
©2015, Amazon Web Services, Inc. or its affiliates. All rights reserved
AWS Security Services Deep Dive
– Extended with Alert Logic
Patrick McDowell – Partner Solutions Architect, AWS
Ryan Holland - Cloud Platform Solution Director, Alert
Logic
AWS Network Security Primitives
Network Access Control
‱ Security Groups provide Stateful firewalls
around each Amazon EC2 Instance
‱ NACLs provide stateless firewalls around
subnets
‱ VPC Flow Logs provide traffic visibility
‱ No Broadcast, VIPs, Layer 2, or Network Taps
AWS Security Services
More tools to move fast and stay safe
‱ Amazon Inspector
‱ AWS WAF
‱ AWS Config Rules
The easy (Vulnerabilities) matter
"[With] any large network, I will tell you that
persistence and focus will get you in, we'll achieve that
exploitation without the zero days," he says. "There's
so many more vectors that are easier, less risky and
quite often more productive that going down that
route." This includes, of course, known vulnerabilities
for which a patch is available but the owner hasn't
installed it.
- Rob Joyce NSA TAO @ Enigma 2016
Amazon Inspector Features
Configuration Scanning Engine
Activity Monitoring
Built-in Content Library
Automatable via API
Fully Auditable
Amazon Inspector Rule Sets
CVE
Security Best Practices
Run Time Behavior Analysis
CIS Operating System Security Configuration
Benchmarks
Amazon Inspector and Alert Logic
‱ Amazon Inspector makes it easy to do the right
thing BEFORE your app goes into production
‱ Pairs point-in-time, host-based scans with
continous, whitelisted network scans
‱ Layering AWS Inspector Assessments, Alert
Logic Cloud Insight and Cloud Defender
provides full spectrum security visibility and
response
AWS WAF (Web Application Firewall)
AWS WAF Features
Web Filtering
CloudFront Integration
Centralized Rule Management
Real-Time Visibility
API Automation
AWS WAF Benefits
Increased Protection
Against Web Attacks
Ease of Deployment and
Maintenance
Security Embedded in
Development Process
AWS WAF in Action
AWS Management
ConsoleAdmins
Developers AWS API
Web App in
CloudFront
Define rules
Deploy
protection
AWS WAF
AWS Config Rules
AWS Config & Config Rules
AWS
Config
Amazon
Config
Rules
 Record configuration changes
continuously
 Time-series view of resource
changes
 Archive & Compare
 Enforce best practices
 Automatically roll-back unwanted
changes
 Trigger additional workflow
AWS Config Rules Benefits
Continuous monitoring for
unexpected changes
Shared Compliance
across your organization
Simplified management of
configuration changes
AWS Config Rules Features
Flexible Rules evaluated continuously and
retroactively
Dashboard and Reports for Common Goals
Customizable Remediation
API Automation
Advanced Compliance with Config Rules
‱ Open Source Rules
– https://github.com/awslabs/aws-config-rules
‱ Enforce encryption on all volumes
‱ Ensure CloudTrail is enabled globally for bucket X
‱ Confirm that no users have MFA disabled
‱ Create a rule that no security group can permit
0.0.0.0/0
‱ No Root Access Keys or logins without MFA
‱ All Instances Must be in VPC-ID X
AWS Config Rules and Alert Logic
‱ Lambda function used to add Config Rules
violations to Cloud Insight platform as
remediation tasks.
‱ Tight integration with JIRA to allow automatic
ticket routing to asset owner and validation
when tickets are closed.
Questions?

More Related Content

PPTX
#ALSummit: Realities of Security in the Cloud
Alert Logic
 
PPTX
#ALSummit: Architecting Security into your AWS Environment
Alert Logic
 
PPTX
#ALSummit: Amazon Web Services: Understanding the Shared Security Model
Alert Logic
 
PPTX
#ALSummit: SCOR Velogica's Journey to SOC2/TYPE2 Via AWS
Alert Logic
 
PDF
The Intersection of Security & DevOps
Alert Logic
 
PDF
The AWS Shared Responsibility Model in Practice
Alert Logic
 
PPTX
#ALSummit: Cyber Resiliency: Surviving the Breach
Alert Logic
 
PPTX
CSS 17: NYC - The AWS Shared Responsibility Model in Practice
Alert Logic
 
#ALSummit: Realities of Security in the Cloud
Alert Logic
 
#ALSummit: Architecting Security into your AWS Environment
Alert Logic
 
#ALSummit: Amazon Web Services: Understanding the Shared Security Model
Alert Logic
 
#ALSummit: SCOR Velogica's Journey to SOC2/TYPE2 Via AWS
Alert Logic
 
The Intersection of Security & DevOps
Alert Logic
 
The AWS Shared Responsibility Model in Practice
Alert Logic
 
#ALSummit: Cyber Resiliency: Surviving the Breach
Alert Logic
 
CSS 17: NYC - The AWS Shared Responsibility Model in Practice
Alert Logic
 

What's hot (20)

PPTX
Introduction to Security in the Cloud - Mark Brooks, Alert Logic
Alert Logic
 
PDF
Realities of Security in the Cloud
Alert Logic
 
PDF
Reducing Your Attack Surface & Your Role in Cloud Workload Protection
Alert Logic
 
PPTX
CSS 17: NYC - Building Secure Solutions in AWS
Alert Logic
 
PPTX
CSS17: Atlanta - Realities of Security in the Cloud
Alert Logic
 
PDF
CSS17: Houston - Introduction to Security in the Cloud
Alert Logic
 
PPTX
CSS 17: NYC - Realities of Security in the Cloud
Alert Logic
 
PPTX
CSS 17: NYC - Protecting your Web Applications
Alert Logic
 
PDF
Security Spotlight: The Coca Cola Company - CSS ATX 2017
Alert Logic
 
PDF
Extending Amazon GuardDuty with Cloud Insight Essentials
Alert Logic
 
PPTX
Shared Security Responsibility for the Azure Cloud
Alert Logic
 
PPTX
Silver Lining: An Everyman's Journey to Cloud Security - Sven Skoog, Monotype
Alert Logic
 
PDF
Managed Threat Detection & Response for AWS Applications
Alert Logic
 
PDF
Securing Healthcare Data on AWS for HIPAA
Alert Logic
 
PDF
Css sf azure_8-9-17-intro to security in the cloud_mark brooks_al
Alert Logic
 
PDF
The AWS Shared Responsibility Model in Practice
Alert Logic
 
PDF
CSS17: Houston - Protecting Web Apps
Alert Logic
 
PPTX
#ALSummit: Live Cyber Hack Demonstration
Alert Logic
 
PDF
Css sf azure_8-9-17-stories_from_the_soc_paul fletcher_al
Alert Logic
 
PDF
Css sf azure_8-9-17-protecting_web_apps_stephen coty_al
Alert Logic
 
Introduction to Security in the Cloud - Mark Brooks, Alert Logic
Alert Logic
 
Realities of Security in the Cloud
Alert Logic
 
Reducing Your Attack Surface & Your Role in Cloud Workload Protection
Alert Logic
 
CSS 17: NYC - Building Secure Solutions in AWS
Alert Logic
 
CSS17: Atlanta - Realities of Security in the Cloud
Alert Logic
 
CSS17: Houston - Introduction to Security in the Cloud
Alert Logic
 
CSS 17: NYC - Realities of Security in the Cloud
Alert Logic
 
CSS 17: NYC - Protecting your Web Applications
Alert Logic
 
Security Spotlight: The Coca Cola Company - CSS ATX 2017
Alert Logic
 
Extending Amazon GuardDuty with Cloud Insight Essentials
Alert Logic
 
Shared Security Responsibility for the Azure Cloud
Alert Logic
 
Silver Lining: An Everyman's Journey to Cloud Security - Sven Skoog, Monotype
Alert Logic
 
Managed Threat Detection & Response for AWS Applications
Alert Logic
 
Securing Healthcare Data on AWS for HIPAA
Alert Logic
 
Css sf azure_8-9-17-intro to security in the cloud_mark brooks_al
Alert Logic
 
The AWS Shared Responsibility Model in Practice
Alert Logic
 
CSS17: Houston - Protecting Web Apps
Alert Logic
 
#ALSummit: Live Cyber Hack Demonstration
Alert Logic
 
Css sf azure_8-9-17-stories_from_the_soc_paul fletcher_al
Alert Logic
 
Css sf azure_8-9-17-protecting_web_apps_stephen coty_al
Alert Logic
 
Ad

Viewers also liked (14)

PPT
AWS Presentation
jlechowicz
 
PDF
Full Stack Automation with Katello & The Foreman
Weston Bassler
 
PPTX
Intro to Netflix's Chaos Monkey
Michael Whitehead
 
PPT
Cloud Security Summit (Boston) - Live Hack Demo
Alert Logic
 
PPTX
Compliance as Code: Velocity with Security - Fraser Pollock, Chef
Alert Logic
 
PDF
The AWS Shared Responsibility Model in Practice - Nirav Kothari, AWS
Alert Logic
 
PDF
Netflix security monkey overview
Ryan Hodgin
 
PDF
Mini-Training: Netflix Simian Army
Betclic Everest Group Tech Team
 
PDF
System Hardening Using Ansible
Sonatype
 
PDF
The New Economics of Cloud Security
Alert Logic
 
PDF
DevSecOps: Taking a DevOps Approach to Security
Alert Logic
 
PDF
Deep Dive: Amazon Relational Database Service (March 2017)
Julien SIMON
 
PDF
AWS Security Best Practices (March 2017)
Julien SIMON
 
PPTX
AWS security - NULL meet chennai
vinoth kumar
 
AWS Presentation
jlechowicz
 
Full Stack Automation with Katello & The Foreman
Weston Bassler
 
Intro to Netflix's Chaos Monkey
Michael Whitehead
 
Cloud Security Summit (Boston) - Live Hack Demo
Alert Logic
 
Compliance as Code: Velocity with Security - Fraser Pollock, Chef
Alert Logic
 
The AWS Shared Responsibility Model in Practice - Nirav Kothari, AWS
Alert Logic
 
Netflix security monkey overview
Ryan Hodgin
 
Mini-Training: Netflix Simian Army
Betclic Everest Group Tech Team
 
System Hardening Using Ansible
Sonatype
 
The New Economics of Cloud Security
Alert Logic
 
DevSecOps: Taking a DevOps Approach to Security
Alert Logic
 
Deep Dive: Amazon Relational Database Service (March 2017)
Julien SIMON
 
AWS Security Best Practices (March 2017)
Julien SIMON
 
AWS security - NULL meet chennai
vinoth kumar
 
Ad

Similar to #ALSummit: Alert Logic & AWS - AWS Security Services (7)

PDF
Security and Compliance Better on AWS_John Hildebrandt
Helen Rogers
 
PPTX
AWS Security Best Practices for Effective Threat Detection & Response
AlienVault
 
PDF
Segurança de Ponta a Ponta na AWS
Alexandre Santos
 
PPTX
Delivering High-Availability Web Services with NGINX Plus on AWS
NGINX, Inc.
 
PPTX
Infrastructure Provisioning & Automation For Large Enterprises
Tensult
 
PDF
1. aws security and compliance wwps pre-day sao paolo - markry
Amazon Web Services LATAM
 
PPTX
Introduction to AWS WAF and AWS Firewall Manager
Akesh Patil
 
Security and Compliance Better on AWS_John Hildebrandt
Helen Rogers
 
AWS Security Best Practices for Effective Threat Detection & Response
AlienVault
 
Segurança de Ponta a Ponta na AWS
Alexandre Santos
 
Delivering High-Availability Web Services with NGINX Plus on AWS
NGINX, Inc.
 
Infrastructure Provisioning & Automation For Large Enterprises
Tensult
 
1. aws security and compliance wwps pre-day sao paolo - markry
Amazon Web Services LATAM
 
Introduction to AWS WAF and AWS Firewall Manager
Akesh Patil
 

More from Alert Logic (20)

PDF
Managed Threat Detection and Response
Alert Logic
 
PDF
Extending Amazon GuardDuty with Cloud Insight Essentials
Alert Logic
 
PDF
Security Implications of the Cloud
Alert Logic
 
PDF
Reducing Your Attack Surface
Alert Logic
 
PDF
Reality Check: Security in the Cloud
Alert Logic
 
PDF
The Intersection of Security & DevOps
Alert Logic
 
PDF
The AWS Shared Responsibility Model in Practice
Alert Logic
 
PDF
Security Spotlight: Presidio
Alert Logic
 
PDF
Security Spotlight: Rent-A-Center
Alert Logic
 
PDF
The Intersection of Security & DevOps
Alert Logic
 
PDF
Security Spotlight: Presidio
Alert Logic
 
PDF
Security Implications of the Cloud
Alert Logic
 
PDF
Reducing Your Attack Surface & Your Role in Cloud Workload Protection
Alert Logic
 
PDF
Realities of Security in the Cloud
Alert Logic
 
PDF
CSS 2018 Trivia
Alert Logic
 
PDF
The AWS Shared Responsibility Model in Practice
Alert Logic
 
PDF
Realities of Security in the Cloud
Alert Logic
 
PDF
The Intersection of Security and DevOps
Alert Logic
 
PDF
Security Spotlight: The Coca Cola Company
Alert Logic
 
PDF
Reducing Your Attack Surface and Yuor Role in Cloud Workload Protection
Alert Logic
 
Managed Threat Detection and Response
Alert Logic
 
Extending Amazon GuardDuty with Cloud Insight Essentials
Alert Logic
 
Security Implications of the Cloud
Alert Logic
 
Reducing Your Attack Surface
Alert Logic
 
Reality Check: Security in the Cloud
Alert Logic
 
The Intersection of Security & DevOps
Alert Logic
 
The AWS Shared Responsibility Model in Practice
Alert Logic
 
Security Spotlight: Presidio
Alert Logic
 
Security Spotlight: Rent-A-Center
Alert Logic
 
The Intersection of Security & DevOps
Alert Logic
 
Security Spotlight: Presidio
Alert Logic
 
Security Implications of the Cloud
Alert Logic
 
Reducing Your Attack Surface & Your Role in Cloud Workload Protection
Alert Logic
 
Realities of Security in the Cloud
Alert Logic
 
CSS 2018 Trivia
Alert Logic
 
The AWS Shared Responsibility Model in Practice
Alert Logic
 
Realities of Security in the Cloud
Alert Logic
 
The Intersection of Security and DevOps
Alert Logic
 
Security Spotlight: The Coca Cola Company
Alert Logic
 
Reducing Your Attack Surface and Yuor Role in Cloud Workload Protection
Alert Logic
 

Recently uploaded (20)

PPT
Coupa-Kickoff-Meeting-Template presentai
annapureddyn
 
PDF
Beyond Automation: The Role of IoT Sensor Integration in Next-Gen Industries
Rejig Digital
 
PDF
Brief History of Internet - Early Days of Internet
sutharharshit158
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
PDF
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
REPORT: Heating appliances market in Poland 2024
SPIUG
 
PPTX
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
PPTX
Comunidade Salesforce SĂŁo Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira JĂșnior
 
PPTX
IoT Sensor Integration 2025 Powering Smart Tech and Industrial Automation.pptx
Rejig Digital
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PDF
This slide provides an overview Technology
mineshkharadi333
 
PDF
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
PDF
Orbitly Pitch DeckA Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
Coupa-Kickoff-Meeting-Template presentai
annapureddyn
 
Beyond Automation: The Role of IoT Sensor Integration in Next-Gen Industries
Rejig Digital
 
Brief History of Internet - Early Days of Internet
sutharharshit158
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
REPORT: Heating appliances market in Poland 2024
SPIUG
 
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
Comunidade Salesforce SĂŁo Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira JĂșnior
 
IoT Sensor Integration 2025 Powering Smart Tech and Industrial Automation.pptx
Rejig Digital
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
This slide provides an overview Technology
mineshkharadi333
 
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
Orbitly Pitch DeckA Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 

#ALSummit: Alert Logic & AWS - AWS Security Services

  • 1. ©2015, Amazon Web Services, Inc. or its affiliates. All rights reserved AWS Security Services Deep Dive – Extended with Alert Logic Patrick McDowell – Partner Solutions Architect, AWS Ryan Holland - Cloud Platform Solution Director, Alert Logic
  • 2. AWS Network Security Primitives
  • 3. Network Access Control ‱ Security Groups provide Stateful firewalls around each Amazon EC2 Instance ‱ NACLs provide stateless firewalls around subnets ‱ VPC Flow Logs provide traffic visibility ‱ No Broadcast, VIPs, Layer 2, or Network Taps
  • 5. More tools to move fast and stay safe ‱ Amazon Inspector ‱ AWS WAF ‱ AWS Config Rules
  • 6. The easy (Vulnerabilities) matter "[With] any large network, I will tell you that persistence and focus will get you in, we'll achieve that exploitation without the zero days," he says. "There's so many more vectors that are easier, less risky and quite often more productive that going down that route." This includes, of course, known vulnerabilities for which a patch is available but the owner hasn't installed it. - Rob Joyce NSA TAO @ Enigma 2016
  • 7. Amazon Inspector Features Configuration Scanning Engine Activity Monitoring Built-in Content Library Automatable via API Fully Auditable
  • 8. Amazon Inspector Rule Sets CVE Security Best Practices Run Time Behavior Analysis CIS Operating System Security Configuration Benchmarks
  • 9. Amazon Inspector and Alert Logic ‱ Amazon Inspector makes it easy to do the right thing BEFORE your app goes into production ‱ Pairs point-in-time, host-based scans with continous, whitelisted network scans ‱ Layering AWS Inspector Assessments, Alert Logic Cloud Insight and Cloud Defender provides full spectrum security visibility and response
  • 10. AWS WAF (Web Application Firewall)
  • 11. AWS WAF Features Web Filtering CloudFront Integration Centralized Rule Management Real-Time Visibility API Automation
  • 12. AWS WAF Benefits Increased Protection Against Web Attacks Ease of Deployment and Maintenance Security Embedded in Development Process
  • 13. AWS WAF in Action AWS Management ConsoleAdmins Developers AWS API Web App in CloudFront Define rules Deploy protection AWS WAF
  • 15. AWS Config & Config Rules AWS Config Amazon Config Rules  Record configuration changes continuously  Time-series view of resource changes  Archive & Compare  Enforce best practices  Automatically roll-back unwanted changes  Trigger additional workflow
  • 16. AWS Config Rules Benefits Continuous monitoring for unexpected changes Shared Compliance across your organization Simplified management of configuration changes
  • 17. AWS Config Rules Features Flexible Rules evaluated continuously and retroactively Dashboard and Reports for Common Goals Customizable Remediation API Automation
  • 18. Advanced Compliance with Config Rules ‱ Open Source Rules – https://github.com/awslabs/aws-config-rules ‱ Enforce encryption on all volumes ‱ Ensure CloudTrail is enabled globally for bucket X ‱ Confirm that no users have MFA disabled ‱ Create a rule that no security group can permit 0.0.0.0/0 ‱ No Root Access Keys or logins without MFA ‱ All Instances Must be in VPC-ID X
  • 19. AWS Config Rules and Alert Logic ‱ Lambda function used to add Config Rules violations to Cloud Insight platform as remediation tasks. ‱ Tight integration with JIRA to allow automatic ticket routing to asset owner and validation when tickets are closed.

Editor's Notes

  • #7: Why we built Inspector What uses cases does it cover Makes it easy to do the very basics, which gives you a lot Easier Barrier to entry AL CI = Builds on top of basic primitives we offer
  • #8: Checks both OS + Apps
  • #9: CVE – Most Common Targets Security Best Practices – From AWS AppSec, e.g. SSH allows root logins Run Time Bheavior Analysis – Long Running Analysis, can affect the severity of the findings CIS – Industry Standard guide to hardening your OS, biggest customer ask we had
  • #10: Emphasize dev-test AL is for prod AL also has IDS, no concept of IDS on AWS natively
  • #13: Can Programmatically add rules from logs you mined # of 400 errors -> Bad Bot and you can automatically ingest those Bad Ips Sources from other Systems (E.g. FinServ) Make the ‘Rules’ Part of your ‘Infrastructure as Code’
  • #14: AWS WAF can protect the edge, AL can do it at the origin ->Provides intelligence and complex rules/logic that our WAF does not come out of the box with ->Auto-Scales to meet your needs
  • #16: Config: . It allows you to get an inventory of all resources in AWS, discover new and deleted resources, record those changes continuously, and get notified when configurations change. Author custom rules using AWS Lambda
  • #17: Puts Guard Rails into place across the Enterprise/Production If something falls out of compliance, automatically, rolls back to compliance standards set You can not do this on premises.
  • #18: Lambda Functions are the custom rules that get triggered Triggers are Time or Resource Based. Invoked automatically for continuous assessment (single pane of glass) Use dashboard for visualizing compliance and identifying offending changes
  • #20: For the AWS Config Rules service we have created a custom Lambda function that allows Cloud Insight to ingest violations of rules that have been created and we present these as remediation tasks along side other remediations for a particular asset in AWS. One key part of how these remediations are presented is that the AWS metadata and other information we collect from the environment is used to help provide the best means for remediating a violation, for example if multiple instances are launched without a required tag or using encrypted volumes and they are all part of the same AutoScaling group by understanding the environment and maintaining a continuously updated asset model we direct the remediation to update that ASLC/G rather than the individual instances since in that case simply applying a fix to the instances will not fix the root of the issue. Also as I touched on previously our API and integrations with tools such as JIRA allows violations from Config Rules as well as any other remediations to be directed automatically to the owner of the instance through a ticket in JIRA and the plugin is bi-directional meaning that when the owner marks the ticket as closed we will go and validate that the remediation has actually been completed and if needed re-open the ticket. this automation means that your security teams don’t need to spend time tracking down who owns a particular instance and to perform manual validation of the fix once the tickets are marked complete.