Upgrade to Pro — share decks privately, control downloads, hide ads and more …

State of OpenStack Security

State of OpenStack Security

Bryan Payne

May 01, 2014
Tweet

More Decks by Bryan Payne

Other Decks in Technology

Transcript

  1. ©2014 Nebula, Inc. All rights reserved.
    State of OpenStack Security
    Bryan D. Payne
    Director of Security Research
    May 1, 2014

    View Slide

  2. ©2014 Nebula, Inc. All rights reserved.
    My Background
    • Focused on security my entire career
    • Spent a few years in school

    View Slide

  3. ©2014 Nebula, Inc. All rights reserved.
    Nebula One
    DevOPs/Test
    Apps & Workloads
    Media
    Apps & Workloads
    Other …
    Apps & Workloads
    Social
    Collaboration Apps
    & Workloads
    Big Data
    + Analytics
    Apps & Workloads
    Mobile
    Apps & Workloads
    Compute Storage Network
    Identity/Security
    Management/Orchestration/API Interface
    Turnkey Infrastructure as a Service
    (IaaS)
    Block Object
    1000+  companies  contributing  to  OpenStack
    Industry Standard Servers

    View Slide

  4. ©2014 Nebula, Inc. All rights reserved.
    OSSG HISTORY

    View Slide

  5. View Slide

  6. View Slide

  7. View Slide

  8. View Slide

  9. View Slide

  10. View Slide

  11. View Slide

  12. View Slide

  13. View Slide

  14. View Slide

  15. View Slide

  16. View Slide

  17. View Slide

  18. View Slide

  19. View Slide

  20. View Slide

  21. View Slide

  22. View Slide

  23. View Slide

  24. View Slide

  25. View Slide

  26. View Slide

  27. View Slide

  28. View Slide

  29. View Slide

  30. View Slide

  31. View Slide

  32. View Slide

  33. View Slide

  34. View Slide

  35. View Slide

  36. View Slide

  37. ©2014 Nebula, Inc. All rights reserved.
    LOOKING FORWARD

    View Slide

  38. ©2014 Nebula, Inc. All rights reserved.
    Key OSSG Projects
    • OpenStack Security Guide (aka “the book”)
    • OpenStack Security Notes (OSSN)
    • Threat Modeling & Analysis

    View Slide

  39. ©2014 Nebula, Inc. All rights reserved.
    Mid-Term Goals
    • Quality work in three key projects
    • More formal acceptance in community
    • Increase collaboration with core devs

    View Slide

  40. ©2014 Nebula, Inc. All rights reserved.
    OpenStack Projects “The Glue”
    Improve available security
    Document best practices
    Simplify security compliance
    Work with builders, ops, users

    View Slide

  41. ©2014 Nebula, Inc. All rights reserved.
    QUESTIONS
    Email: [email protected]
    Twitter: @bdpsecurity

    View Slide