SlideShare a Scribd company logo
CloudPassage Halo
    Installfest




                    1
Quick Intro

•   Thanks for coming out!
•   Enjoy the free food ☺
•   Focus on security issues with IaaS cloud
•   Interweave that with installing Halo
•   We’re here to help!
     – Ask questions
     – Staff will be handy if you need us
     – Any and all feedback greatly appreciated

              CloudPassage Halo Installfest       2
Where Can I Get
      These Slides?



community.cloudpassage.com




      CloudPassage Halo Installfest   3
Tonight’s Focus

• Infrastructure as a Service (IaaS)
  – Can apply to PaaS and SaaS from a
    provider’s perspective
• Mostly geared to public cloud
  – Although applicable to private
• Tenant security concerns
  – We’ll skip physical security
          CloudPassage Halo Installfest   4
What You Need For The Labs

• Laptop or tablet
• Root equiv access to a Linux VM
  – Local or public is fine
  – Spin up now if needed
• Internet access
  – Wifi settings: As Posted

          CloudPassage Halo Installfest   5
Houston…
We Have a Problem




                 All network security benefits
                 Lost in migration:
                 • Firewall – Filter port level access
                 • Firewall – Control rootkit transfer
                 • Proxy – Control app level data
                 • NIDS – Inspect stream for attacks
                 • Sniffer – Audit trail of network traffic

  CloudPassage Halo Installfest                               6
Delineation of Responsibility

             IaaS               PaaS SaaS
               Interface           Interface           Interface


              Application         Application         Application


             Solution Stack      Solution Stack      Solution Stack

Tenant     Operating System    Operating System    Operating System


              Hypervisor          Hypervisor          Hypervisor
Provider
           Compute & Storage   Compute & Storage   Compute & Storage


               Network             Network             Network


                Facility            Facility            Facility



                CloudPassage Halo Installfest                          7
What Are My Options?




   CloudPassage Halo Installfest   8
Issues to Address

• No firewall control
• Vulnerability management
• Provider image may not meet
  corporate standards
  – Configuration settings
  – Accounts
• Detect intrusions
          CloudPassage Halo Installfest   9
Extending The LAN
  Into The Cloud




 CloudPassage Halo Installfest   10
LAN Extended Challenges

• Increases load on corporate link
   – Today we’re mobile
   – Limits public cloud scaling
• Increase load on perimeter infrastructure
• Negates network benefits
   –   Provider load balancing
   –   Multi-peer points
   –   Geo-location DNS
   –   Higher latency
• No protection within virtual infrastructure

                 CloudPassage Halo Installfest   11
Virtual Appliance Management




       CloudPassage Halo Installfest   12
Virtual Appliance Architecture




       CloudPassage Halo Installfest   13
What About Introspection?

• Hypervisor based security
   – Has visibility into all VMs
• Single point of control
   – For a specific hypervisor deployment
• Public - Do you want other tenants to have
  access to your hypervisor?
• Do you want your provider to have non-
  auditable access to your VMs?
• Can break segregation of duties
               CloudPassage Halo Installfest   14
Host-Based Architecture

                        Consistent architecture
                        (and risk abatement)
                        regardless of deployment




    CloudPassage Halo Installfest                  15
Why Host Based Firewalls?

• Tenant controlled
  – Provider gains no additional access
• Mitigate potential risks from vswitch or VLANs
• Supported across all cloud infrastructures
  – Consistent management regardless of deployment
• Security Is portable with the VM
• This is the model supported by Halo


             CloudPassage Halo Installfest           16
Why restrict Admin Ports?

Dshield.org data

Green = # of IPs
looking for open
SSH ports

Red = # of IPs hit
by SSH scan



                     CloudPassage Halo Installfest   17
Halo Firewall Interface




Cloak the port till these users authenticate
         CloudPassage Halo Installfest         18
Issues to Address

• No firewall control
• Vulnerability management
• Provider image may not meet
  corporate standards
  – Configuration settings
  – Accounts
• Detect intrusions
          CloudPassage Halo Installfest   19
Image Deployment

• Provider images usually not patched
• Some 3rd party images are pre-patched
  – To the time of the image's release
  – Which 3rd parties can you trust?
• Auto-patching usually disabled
• Some known vulnerabilities may not yet
  be patched
  – But it may be possible to mitigate risk is known
             CloudPassage Halo Installfest             20
Vulnerability Wire Testing

• Some providers have restrictions
  – May be limited by terms of service
  – May be limited to specific products
• Targeting concerns
  – What if your IP’s are not continuous?
  – What if the IP changes?
• Does not detect local exploits
          CloudPassage Halo Installfest     21
Host Based Vulnerability
            Checking
• Validate compliances within the VM itself
• Can check remote and local vulnerabilities
• Typically lower cost to deploy
   – Less billable utilization
• Can false negative if patch not loaded
   – Kernel updates
• This is the model Halo uses


            CloudPassage Halo Installfest      22
Halo Software Risks




  CloudPassage Halo Installfest   23
Issues to Address

• No firewall control
• Vulnerability management
• Provider image may not meet
 corporate standards
  – Configuration settings
  – Accounts
• Detect intrusions
          CloudPassage Halo Installfest   24
Configuration Settings

• Are only required processes running?
    – Are they securely configured?
•   Is password aging enforced?
•   Is root permitted direct SSH access?
•   Proper permissions on critical files?
•   Is sudo or wheel properly configured?
•   Any changes since deployment?

             CloudPassage Halo Installfest   25
Creating A Halo Check




   CloudPassage Halo Installfest   26
Halo Check Results




 CloudPassage Halo Installfest   27
System Accounts

• What accounts are on the system?
• Did the provider modify the default
  accounts?
  – ec2-user
• Which accounts have root level access?
• Who has accounts on which servers?
• How do you add/delete accounts for
  many servers simultaneously?
           CloudPassage Halo Installfest   28
Halo Server Access




 CloudPassage Halo Installfest   29
Expanded Details




 CloudPassage Halo Installfest   30
Issues to Address

• No firewall control
• Vulnerability management
• Provider image may not meet
  corporate standards
  – Configuration settings
  – Accounts
• Detect intrusions
          CloudPassage Halo Installfest   31
Clues To An Attack

•   Some file changes indicate a compromise
•   Static Web server files
•   /etc/passwd has new account
•   /etc/sudoers has new entries
•   ssh_known_hosts has new entries
•   authorized_keys has new entries
•   Halo uses SHA-256 to detect changes

             CloudPassage Halo Installfest    32
Define Files to Check




   CloudPassage Halo Installfest   33
Halo FIM Reporting




  CloudPassage Halo Installfest   34
Event Reporting




CloudPassage Halo Installfest   35
Alert Reporting




CloudPassage Halo Installfest   36
Lab Time




Let’s Install Halo!


   CloudPassage Halo Installfest   37
Start Here to
Create an Account




 CloudPassage Halo Installfest   38

More Related Content

What's hot (20)

PPTX
CENTRAL MANAGEMENT OF NETWORK AND CALL SERVICES
Nazmul Hossain Rakib
 
PPTX
Cloud Application Security: Lessons Learned
Jason Chan
 
PDF
Securing your telco cloud
OPNFV
 
PDF
F5 TMOS v13.0
MarketingArrowECS_CZ
 
PPTX
Reston Virtualization Group 9-18-2014
VMwareJenn
 
PPTX
Self service it with v realizeautomation and nsx
solarisyougood
 
PPTX
The Top 10 Most Common Weaknesses in Serverless Applications 2018
PureSec
 
PPTX
Protecting Your IP with Perforce Helix and Interset
Perforce
 
PDF
Sullivan heartbleed-defcon22 2014
Cloudflare
 
PDF
WebGoat.SDWAN.Net in Depth: SD-WAN Security Assessment
Sergey Gordeychik
 
PPTX
UCS Management APIs A Technical Deep Dive
Cisco DevNet
 
PDF
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
VMworld
 
KEY
Cloud Security at Netflix
Jason Chan
 
PPTX
Introduction to Zabbix - Company, Product, Services and Use Cases
Zabbix
 
PDF
Achieve Full API Lifecycle Management Using NGINX Controller – EMEA
NGINX, Inc.
 
PPTX
Extracting Credentials From Windows
NetSPI
 
PPTX
Perforce on Tour 2015 - Securing the Helix Platform at Citrix
Perforce
 
PPTX
Nsx security deep dive
solarisyougood
 
PPTX
ModSecurity and NGINX: Tuning the OWASP Core Rule Set (Updated)
NGINX, Inc.
 
PPTX
Going outside the application
Matthew Saltzman
 
CENTRAL MANAGEMENT OF NETWORK AND CALL SERVICES
Nazmul Hossain Rakib
 
Cloud Application Security: Lessons Learned
Jason Chan
 
Securing your telco cloud
OPNFV
 
F5 TMOS v13.0
MarketingArrowECS_CZ
 
Reston Virtualization Group 9-18-2014
VMwareJenn
 
Self service it with v realizeautomation and nsx
solarisyougood
 
The Top 10 Most Common Weaknesses in Serverless Applications 2018
PureSec
 
Protecting Your IP with Perforce Helix and Interset
Perforce
 
Sullivan heartbleed-defcon22 2014
Cloudflare
 
WebGoat.SDWAN.Net in Depth: SD-WAN Security Assessment
Sergey Gordeychik
 
UCS Management APIs A Technical Deep Dive
Cisco DevNet
 
VMworld 2013: Technical Deep Dive: Build a Collapsed DMZ Architecture for Opt...
VMworld
 
Cloud Security at Netflix
Jason Chan
 
Introduction to Zabbix - Company, Product, Services and Use Cases
Zabbix
 
Achieve Full API Lifecycle Management Using NGINX Controller – EMEA
NGINX, Inc.
 
Extracting Credentials From Windows
NetSPI
 
Perforce on Tour 2015 - Securing the Helix Platform at Citrix
Perforce
 
Nsx security deep dive
solarisyougood
 
ModSecurity and NGINX: Tuning the OWASP Core Rule Set (Updated)
NGINX, Inc.
 
Going outside the application
Matthew Saltzman
 

Similar to Halo Installfest Slides (20)

PPTX
Security and Compliance for Enterprise Cloud Infrastructure
CloudPassage
 
PPTX
Meeting PCI DSS Requirements with AWS and CloudPassage
CloudPassage
 
PPT
Securing Servers in Public and Hybrid Clouds
RightScale
 
PPTX
BayThreat Why The Cloud Changes Everything
CloudPassage
 
PPTX
CloudPassage Overview
CloudPassage
 
PPTX
Securing Your Cloud Servers with Halo NetSec
CloudPassage
 
PPTX
Integrating Security into DevOps
CloudPassage
 
PPT
Introduction to Cloud Computing
Tom Eberle
 
PPTX
Delivering Secure OpenStack IaaS for SaaS Products - OpenStack 2012.pptx
OpenStack Foundation
 
PPTX
Delivering Secure OpenStack IaaS for SaaS Products
CloudPassage
 
PPTX
Automating Security for the Cloud - Make it Easy, Make it Safe
CloudPassage
 
PPTX
Cloud Security Topics: Network Intrusion Detection for Amazon EC2
Alert Logic
 
KEY
EMEA OpenStack Day, July 13th 2011 in London - Jim Curry intro
Open Stack
 
PDF
Cloud: Unleashing On-demand IT
Steven_Jackson
 
PDF
Cloud Security: Perception Vs. Reality
Internap
 
ZIP
EMEA OpenStack Day Intro, July 13th 2011 in London
Mark Collier
 
PDF
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
Ixia
 
PPTX
stackArmor - Security MicroSummit - McAfee
Gaurav "GP" Pal
 
PPTX
Architecting a Private Cloud - Cloud Expo
smw355
 
PDF
Securing a public cloud infrastructure : Windows Azure
vivekbhat
 
Security and Compliance for Enterprise Cloud Infrastructure
CloudPassage
 
Meeting PCI DSS Requirements with AWS and CloudPassage
CloudPassage
 
Securing Servers in Public and Hybrid Clouds
RightScale
 
BayThreat Why The Cloud Changes Everything
CloudPassage
 
CloudPassage Overview
CloudPassage
 
Securing Your Cloud Servers with Halo NetSec
CloudPassage
 
Integrating Security into DevOps
CloudPassage
 
Introduction to Cloud Computing
Tom Eberle
 
Delivering Secure OpenStack IaaS for SaaS Products - OpenStack 2012.pptx
OpenStack Foundation
 
Delivering Secure OpenStack IaaS for SaaS Products
CloudPassage
 
Automating Security for the Cloud - Make it Easy, Make it Safe
CloudPassage
 
Cloud Security Topics: Network Intrusion Detection for Amazon EC2
Alert Logic
 
EMEA OpenStack Day, July 13th 2011 in London - Jim Curry intro
Open Stack
 
Cloud: Unleashing On-demand IT
Steven_Jackson
 
Cloud Security: Perception Vs. Reality
Internap
 
EMEA OpenStack Day Intro, July 13th 2011 in London
Mark Collier
 
BreakingPoint & Juniper RSA Conference 2011 Presentation: Securing the High P...
Ixia
 
stackArmor - Security MicroSummit - McAfee
Gaurav "GP" Pal
 
Architecting a Private Cloud - Cloud Expo
smw355
 
Securing a public cloud infrastructure : Windows Azure
vivekbhat
 
Ad

More from CloudPassage (16)

PDF
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
CloudPassage
 
PPTX
CloudPassage Careers
CloudPassage
 
PPTX
Transforming the CSO Role to Business Enabler
CloudPassage
 
PPTX
Rethinking Security: The Cloud Infrastructure Effect
CloudPassage
 
PPTX
Webinar compiled powerpoint
CloudPassage
 
PPTX
SecDevOps: The New Black of IT
CloudPassage
 
PPTX
Technologies You Need to Safely Use the Cloud
CloudPassage
 
PPT
Cloud Security: Make Your CISO Successful
CloudPassage
 
PDF
Secure Cloud Development Resources with DevOps
CloudPassage
 
PPTX
45 Minutes to PCI Compliance in the Cloud
CloudPassage
 
PPTX
Comprehensive Cloud Security Requires an Automated Approach
CloudPassage
 
PPTX
Security that works with, not against, your SaaS business
CloudPassage
 
PDF
What You Need To Know About The New PCI Cloud Guidelines
CloudPassage
 
PPTX
What You Haven't Heard (Yet) About Cloud Security
CloudPassage
 
PPTX
PCI and the Cloud
CloudPassage
 
PPTX
BSides SF - Automating Security for the Cloud
CloudPassage
 
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
CloudPassage
 
CloudPassage Careers
CloudPassage
 
Transforming the CSO Role to Business Enabler
CloudPassage
 
Rethinking Security: The Cloud Infrastructure Effect
CloudPassage
 
Webinar compiled powerpoint
CloudPassage
 
SecDevOps: The New Black of IT
CloudPassage
 
Technologies You Need to Safely Use the Cloud
CloudPassage
 
Cloud Security: Make Your CISO Successful
CloudPassage
 
Secure Cloud Development Resources with DevOps
CloudPassage
 
45 Minutes to PCI Compliance in the Cloud
CloudPassage
 
Comprehensive Cloud Security Requires an Automated Approach
CloudPassage
 
Security that works with, not against, your SaaS business
CloudPassage
 
What You Need To Know About The New PCI Cloud Guidelines
CloudPassage
 
What You Haven't Heard (Yet) About Cloud Security
CloudPassage
 
PCI and the Cloud
CloudPassage
 
BSides SF - Automating Security for the Cloud
CloudPassage
 
Ad

Recently uploaded (20)

PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PPTX
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PDF
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
Per Axbom: The spectacular lies of maps
Nexer Digital
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 
PDF
Market Insight : ETH Dominance Returns
CIFDAQ
 
PPTX
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
PPTX
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
PPTX
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Per Axbom: The spectacular lies of maps
Nexer Digital
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 
Market Insight : ETH Dominance Returns
CIFDAQ
 
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
Farrell_Programming Logic and Design slides_10e_ch02_PowerPoint.pptx
bashnahara11
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 

Halo Installfest Slides

  • 1. CloudPassage Halo Installfest 1
  • 2. Quick Intro • Thanks for coming out! • Enjoy the free food ☺ • Focus on security issues with IaaS cloud • Interweave that with installing Halo • We’re here to help! – Ask questions – Staff will be handy if you need us – Any and all feedback greatly appreciated CloudPassage Halo Installfest 2
  • 3. Where Can I Get These Slides? community.cloudpassage.com CloudPassage Halo Installfest 3
  • 4. Tonight’s Focus • Infrastructure as a Service (IaaS) – Can apply to PaaS and SaaS from a provider’s perspective • Mostly geared to public cloud – Although applicable to private • Tenant security concerns – We’ll skip physical security CloudPassage Halo Installfest 4
  • 5. What You Need For The Labs • Laptop or tablet • Root equiv access to a Linux VM – Local or public is fine – Spin up now if needed • Internet access – Wifi settings: As Posted CloudPassage Halo Installfest 5
  • 6. Houston… We Have a Problem All network security benefits Lost in migration: • Firewall – Filter port level access • Firewall – Control rootkit transfer • Proxy – Control app level data • NIDS – Inspect stream for attacks • Sniffer – Audit trail of network traffic CloudPassage Halo Installfest 6
  • 7. Delineation of Responsibility IaaS PaaS SaaS Interface Interface Interface Application Application Application Solution Stack Solution Stack Solution Stack Tenant Operating System Operating System Operating System Hypervisor Hypervisor Hypervisor Provider Compute & Storage Compute & Storage Compute & Storage Network Network Network Facility Facility Facility CloudPassage Halo Installfest 7
  • 8. What Are My Options? CloudPassage Halo Installfest 8
  • 9. Issues to Address • No firewall control • Vulnerability management • Provider image may not meet corporate standards – Configuration settings – Accounts • Detect intrusions CloudPassage Halo Installfest 9
  • 10. Extending The LAN Into The Cloud CloudPassage Halo Installfest 10
  • 11. LAN Extended Challenges • Increases load on corporate link – Today we’re mobile – Limits public cloud scaling • Increase load on perimeter infrastructure • Negates network benefits – Provider load balancing – Multi-peer points – Geo-location DNS – Higher latency • No protection within virtual infrastructure CloudPassage Halo Installfest 11
  • 12. Virtual Appliance Management CloudPassage Halo Installfest 12
  • 13. Virtual Appliance Architecture CloudPassage Halo Installfest 13
  • 14. What About Introspection? • Hypervisor based security – Has visibility into all VMs • Single point of control – For a specific hypervisor deployment • Public - Do you want other tenants to have access to your hypervisor? • Do you want your provider to have non- auditable access to your VMs? • Can break segregation of duties CloudPassage Halo Installfest 14
  • 15. Host-Based Architecture Consistent architecture (and risk abatement) regardless of deployment CloudPassage Halo Installfest 15
  • 16. Why Host Based Firewalls? • Tenant controlled – Provider gains no additional access • Mitigate potential risks from vswitch or VLANs • Supported across all cloud infrastructures – Consistent management regardless of deployment • Security Is portable with the VM • This is the model supported by Halo CloudPassage Halo Installfest 16
  • 17. Why restrict Admin Ports? Dshield.org data Green = # of IPs looking for open SSH ports Red = # of IPs hit by SSH scan CloudPassage Halo Installfest 17
  • 18. Halo Firewall Interface Cloak the port till these users authenticate CloudPassage Halo Installfest 18
  • 19. Issues to Address • No firewall control • Vulnerability management • Provider image may not meet corporate standards – Configuration settings – Accounts • Detect intrusions CloudPassage Halo Installfest 19
  • 20. Image Deployment • Provider images usually not patched • Some 3rd party images are pre-patched – To the time of the image's release – Which 3rd parties can you trust? • Auto-patching usually disabled • Some known vulnerabilities may not yet be patched – But it may be possible to mitigate risk is known CloudPassage Halo Installfest 20
  • 21. Vulnerability Wire Testing • Some providers have restrictions – May be limited by terms of service – May be limited to specific products • Targeting concerns – What if your IP’s are not continuous? – What if the IP changes? • Does not detect local exploits CloudPassage Halo Installfest 21
  • 22. Host Based Vulnerability Checking • Validate compliances within the VM itself • Can check remote and local vulnerabilities • Typically lower cost to deploy – Less billable utilization • Can false negative if patch not loaded – Kernel updates • This is the model Halo uses CloudPassage Halo Installfest 22
  • 23. Halo Software Risks CloudPassage Halo Installfest 23
  • 24. Issues to Address • No firewall control • Vulnerability management • Provider image may not meet corporate standards – Configuration settings – Accounts • Detect intrusions CloudPassage Halo Installfest 24
  • 25. Configuration Settings • Are only required processes running? – Are they securely configured? • Is password aging enforced? • Is root permitted direct SSH access? • Proper permissions on critical files? • Is sudo or wheel properly configured? • Any changes since deployment? CloudPassage Halo Installfest 25
  • 26. Creating A Halo Check CloudPassage Halo Installfest 26
  • 27. Halo Check Results CloudPassage Halo Installfest 27
  • 28. System Accounts • What accounts are on the system? • Did the provider modify the default accounts? – ec2-user • Which accounts have root level access? • Who has accounts on which servers? • How do you add/delete accounts for many servers simultaneously? CloudPassage Halo Installfest 28
  • 29. Halo Server Access CloudPassage Halo Installfest 29
  • 30. Expanded Details CloudPassage Halo Installfest 30
  • 31. Issues to Address • No firewall control • Vulnerability management • Provider image may not meet corporate standards – Configuration settings – Accounts • Detect intrusions CloudPassage Halo Installfest 31
  • 32. Clues To An Attack • Some file changes indicate a compromise • Static Web server files • /etc/passwd has new account • /etc/sudoers has new entries • ssh_known_hosts has new entries • authorized_keys has new entries • Halo uses SHA-256 to detect changes CloudPassage Halo Installfest 32
  • 33. Define Files to Check CloudPassage Halo Installfest 33
  • 34. Halo FIM Reporting CloudPassage Halo Installfest 34
  • 37. Lab Time Let’s Install Halo! CloudPassage Halo Installfest 37
  • 38. Start Here to Create an Account CloudPassage Halo Installfest 38