$30 off During Our Annual Pro Sale. View Details »

AWS Cloud Security Fundamentals

AWS Cloud Security Fundamentals

Workshop presented at OWASP BASC 2019 by Rami McCarthy and Joshua Dow

Abstract:

"As comfort and familiarity with cloud computing is now more mainstream, companies are leaning more and more on cloud resources to host and run even their most-sensitive technical assets. With these new technologies/innovations come new (and old!) security concerns. In this workshop, we will take participants through a baseline understanding of cloud security - with a focus on AWS security fundamentals.

First, we will briefly outline the cloud security model, the similarities across platforms, and the shared responsibility model that Amazon employs. From there, we will introduce participants to open-source tooling for AWS account auditing and hardening, including NCC's own ScoutSuite. We will provide access to an intentionally vulnerable AWS environment, to allow workshop attendees to follow along and explore misconfigurations with their own eyes. We also will support attendees who want to immediately dive into auditing their own AWS accounts/environments.

Next, we'll highlight easy wins for AWS security, that the audience will be able to immediately apply to their own environments. Following that, we'll speak to Amazon's built-in security tooling, including:

Security Hub
Trusted Advisor
CloudTrail
Inspector
GuardDuty
Macie (and why it's probably wrong for you!)

We'll focus on actionable guidance to walk away and be able to use these tools to harden your own posture. Subsequently, we'll work with attendees through the misconfigurations that led to the Capital One breach, via the CloudGoat scenario. Wrapping up, we'll provide a easy to follow cheatsheet of best practices, easy wins, and open source tools that attendees can reference to improve their own environments. "

Rami McCarthy

October 19, 2019
Tweet

More Decks by Rami McCarthy

Other Decks in Technology

Transcript

  1. AWS: Cloud Security
    Fundamentals
    Josh Dow
    Rami McCarthy

    View Slide

  2. This Workshop

    View Slide

  3. Agenda
    o Introduction
    o Hands-on with Built-ins
    15 minute break
    o Hands-on Self-Auditing
    o Cheatsheet
    o Closing Questions

    View Slide

  4. The Cloud

    View Slide

  5. The "Big Three"

    View Slide

  6. Why focus
    on AWS?
    https://www.parkmycloud.com/blog/aws-vs-azure-vs-google-cloud-market-share/

    View Slide

  7. http://www.chriswatterston.com

    View Slide

  8. View Slide

  9. •Services
    •Regions
    AWS

    View Slide

  10. •Encryption
    •External Exposure
    •IAM
    •Logging/Auditing
    AWS Security

    View Slide

  11. https://cloudonaut.io/aws-security-primer/

    View Slide

  12. View Slide

  13. Environment Access

    View Slide

  14. aws iam list-users –output table

    View Slide

  15. AWS Built-in
    Security Tools

    View Slide

  16. View Slide

  17. View Slide

  18. View Slide

  19. Logging is a component of compliance
    with:
    • ISO 27001 – A.12.4
    • PCI DSS - Requirement 10

    View Slide

  20. View Slide

  21. View Slide

  22. View Slide

  23. View Slide

  24. View Slide

  25. View Slide

  26. View Slide

  27. View Slide

  28. View Slide

  29. View Slide

  30. View Slide

  31. AWS Configuration
    Easy Wins

    View Slide

  32. Enable
    Amazon
    Tools

    View Slide

  33. Secure
    Logging

    View Slide

  34. Secure
    Public Access

    View Slide

  35. Secure
    Authentication

    View Slide

  36. Secure
    MFA

    View Slide

  37. View Slide

  38. Third-Party Tools

    View Slide

  39. Free Third-Party
    Tools

    View Slide

  40. https://github.com/toniblyx/prowler​

    View Slide

  41. https://github.com/nccgroup/scoutsuite

    View Slide

  42. https://github.com/duo-labs/cloudmapper

    View Slide

  43. Get on your balaclavas

    View Slide

  44. CloudGoat
    Walkthrough

    View Slide

  45. Cheatsheet

    View Slide

  46. Credit to prior art; check these people out to learn more!
    Corey Quinn - https://www.lastweekinaws.com - @QuinnyPig
    Teri Radichel - https://2ndsightlab.com/ - @TeriRadichel
    Scott Piper – https://summitroute.com/ - @0xdabbad00
    Toni de la Fuente - https://github.com/toniblyx/my-arsenal-of-aws-security-tools- @ToniBlyx
    Rhino Security - https://rhinosecuritylabs.com/blog/?category=aws
    Cloudonaut - https://cloudonaut.io/aws-security-primer/

    View Slide

  47. AWS resources for secure architecture
    Well-Architected Framework: Security Pillar
    AWS Cloud Adoption Framework
    Aligning to NIST

    View Slide

  48. Questions?
    Come chat at the Social Hour
    (we're sponsoring!)

    View Slide