Upgrade to Pro — share decks privately, control downloads, hide ads and more …

はじめよう DevSecOps

はじめよう DevSecOps

みなみテック第0回の LT 資料です。
https://minami.connpass.com/event/140690/

Avatar for yu fujioka

yu fujioka

August 19, 2019
Tweet

More Decks by yu fujioka

Other Decks in Programming

Transcript

  1. whoami yu fujioka: ॴଐɿCypherTec Inc. ɾSoftware Engineer ݉ Security Engineer

    ɾιϑτ΢ΣΞ։ൃ΍ηΩϡϦςΟ਍அۀ຿Λ୲౰ ɾGo ͱ Docker ͱαʔόʔϨεΞʔΩςΫνϟ͕޷͖ ͜ͷ LT ͷ಺༰͸ݸਓͷݟղͰ͋Γɺ ॴଐ͢Δ૊৫ͷݟղͱඞͣ͠΋Ұக͢Δ΋ͷͰ͸͋Γ·ͤΜɻ
  2. Development ։ൃ Security ηΩϡϦςΟ Operations ӡ༻ 2018೥ࠒ͔ΒDevOps ʹ͓͚ΔηΩϡϦςΟͷॏཁੑΛڧௐ͢ ΔͨΊɺDevSecOps ͱ͍͏ݴ༿͕࢖ΘΕ࢝Ίͨɻ

    ͔͠͠ɺݩʑ DevOps ͸ηΩϡϦςΟ΋ؚΊͨ޿ൣͳ֓೦Ͱ͋ Γɺ࣮͸໨৽͍͠࿩Ͱ͸ͳ͍ɻ ὎ 2016ࠒ͔ΒɺRugged DevOps ΍ DevOpsSec ͱ͍͏ݴ༿ ͸ଘࡏ͍ͯ͠Δɻ ίϯςΩετ͕ҟͳΔ͚ͩͰɺ࣮࣭తʹ DevOps == DevSecOps ͱཧղ͍ͯ͠Δɻ
  3. ߴػೳͳ੡඼͸҆͘͸ͳ͍Ͱ͢Ͷɾɾɾ ্ه͸ 9 Great DevSecOps Tools for Dev Teams to

    Integrate Throughout the DevOps Pipeline Ͱ঺հ͞Ε͍ͯͨπʔϧΛௐ΂ͨՁ֨ද ઌ݄ͷ Software Design ʹࡌ͍ͬͯͨ WhiteSource ΋ $4,000~ ͱ͓ߴΊ Qiita ʹ຋༁هࣄΛ౤ߘ͍ͯ͠·͢ɻ ɹ὎։ൃνʔϜͷͨΊͷ DevOps ύΠϓϥΠϯΛ౷߹͢Δͭ̕ͷ༏Εͨ DevSecOps πʔϧ Product Price Remarks IriusRisk ASK Ձ֨͸ΞϓϦ਺ຖɻCommunity Edition ͕͋Δ ThreatModeler ASK Evident.io(ESP) $199 per month and scale to support AWS environment Checkmarx ASK? Contrast Security ASK Community Edition ͕͋Δɻ೔ຊͷ୅ཧళ΋͋Δ IMMUNIO Free~$999 Aqua Security GCP Marketplace Ͱ $0.33/hour Dome9 Security ASK WhiteSource $4,000~
  4. ଟ෼Ͱ͖Δʂ ্ه͸ Future Architect ࣾΒͷϝϯόʔͷʮ΅͘ͷߟ͍͖͑ͨ͞ΐ͏ͷDevSecOpsʯΑΓൈਮ ὎ૉ੖Β͍͠ࢿྉɻ΍Γ͍ͨ͜ͱશ෦ॻ͍ͯ͋ͬͨɻ OSS Ͱ͸ଞʹ΋ Nikto ΍

    OWASP Benchmarkɺ͞·͟·ͳπʔϧ͕͋Γ·͢ɻ
 OWASP ͷ Free for Open Source Application Security Tools ʹ΋·ͱ·͍ͬͯ·͢ɻ
  5. Ͱ͖Δ͜ͱ͸୔ࢁ͋Δʂ ɾશ෦ΛҰ౓ʹ΍Ζ͏ͱͨ͠ΒΤϯδχΞ͕ࢮ͵ ɹΠϯϑϥɺίʔυɺϥΠϒϥϦɺΞϓϦέʔγϣϯɺ ɹͦΕͧΕʹదͨ͠ηΩϡϦςΟπʔϧΛҰͭͣͭ ɹಋೖ͍͖ͯ͠ɺগͣͭ͠Ͱ΋վળ͍ͯ͘͜͠ͱ͕େࣄɻ ɾnpm audit ίϚϯυΛఆظతʹ࣮ߦ͢Δ͜ͱ΍ɺ ɹGitHub ͷ

    Security Alert ʹͪΌΜͱରԠ͢Δ͜ͱ΋ ɹཱ೿ͳηΩϡϦςΟରࡦͱݴ͑Δɻ ηΩϡΞίʔσΟϯά΋େࣄͩ͠ɺηΩϡΞͳݴޠͷ࠾༻ͳͲ΋ॏཁɻ Go ͸ΤϥʔϋϯυϦϯά΍ςετۦಈ։ൃ͕͠қ͍ݴޠͳͷͰ͓͢͢Ί
  6. ɾThe DevOps ϋϯυϒοΫ ཧ࿦ɾݪଇɾ࣮ફͷ͢΂ͯ ɾDevOpsͱ͸Կ͔ʁ ͦͷπʔϧͱ૊৫จԽɺΞδϟΠϧͱͷҧ͍ ɾDevOps(Wikipedia) ɾRedHat : DevSecOps

    ͱ͸ ɾ9 Great DevSecOps Tools for Dev Teams to Integrate Throughout the DevOps Pipeline ɾ։ൃνʔϜͷͨΊͷ DevOps ύΠϓϥΠϯΛ౷߹͢Δͭ̕ͷ༏Εͨ DevSecOps πʔϧ ɾ΅͘ͷߟ͍͖͑ͨ͞ΐ͏ͷDevSecOps ɾNikto ɾOWASP Benchmark ɾFree for Open Source Application Security Tools ɾIPA: ৘ใηΩϡϦςΟ10େڴҖ 2018 referenceɹ The Go gopher was designed by Renée French.