hunt for a computer hacker who broke into a computer at the Lawrence Berkeley National Laboratory (LBNL). Elliot Alderson, a cybersecurity engineer and hacker with social anxiety disorder and clinical depression. Elliot is recruited by an insurrectionary anarchist known as "Mr. Robot" to join a group of hacktivists called "fsociety".
survivability for a wide variety of catastrophes. Adversaries in the security context are human; their actions are calculated to affect the target system in an undesirable way.
working finding vulnerabilities. • Participate in Vulnerability Reward Programs Bug bounties. • Motivated to make systems better, allies to organizations. • Red Teams and penetration testers. www.yurynino.dev
• Scientists and ethicists are designing machines might be capable enough to learn how to attack each other. • Developers need to consider resilient system design. www.yurynino.dev
not a true predictor of success. Attackers aren’t always afraid of being caught. Don’t underestimate your adversary. Attribution is hard. Considerations www.yurynino.dev
Blue Teaming. • They are an evolution of Red Team exercises by delivering a more cohesive experience between teams. • The goal: collaboration of offensive and defensive tactics to improve the effectiveness of both groups. • Purple Teams increase transparency and allow to learn about how effective engineers are. www.yurynino.dev How do we mitigate them?
failures through proactive experimentation to build confidence in the system’s ability to defend against malicious conditions in production. Chaos Engineering Book. 2020
Red and Purple Team Exercises or other security testing methods. With Security Chaos Engineering we can introduce false positives to check if procedures are capable of identifying security failures under controlled conditions. Security Chaos Journey www.yurynino.dev
to give players a chance to put their skills to the test in a real-world, gamified, risk-free environment. A Chaos GameDay is a practice event, and although it can take a whole day, it usually requires only a few hours. The goal is to practice how your team supports your systems with real-world turbulent conditions.
a style • Decide who • Decide where • Decide when • Document • Get approval! Understand the adversary: Motivations, profiles and methods. Reconsider the roles: Do you need consultant and google? Choose an style with adversaries: Dungeons & Dragons with at least 2 teams.
controls. • Drop a folder like a script would do in production. • Software secret clear text disclosure. • Permission collision in a shared IAM role policy. • Disable service event logging. • API gateway shutdown. • Unencrypted Bucket. • Disable MFA.
was connected to the Active Directory. When an employee left the company his account is dropped and we lost the access to Google. Side Effect: Thinking in this scenario allows to consider another applications connected to Active Directory. www.yurynino.dev https://www.yurynino.dev/ Hypothesis: After the owner of Root account in Google Cloud left the company, we could use our cloud in a normal way.
that the attacker exploited, and also recognizes opportunities for improved incident handling. Document the time frames and efforts associated with these action items, and decide which action items.
the process. • Adjust metrics. • Validate CMM position. • Adapt next Gameday. • Continuous Verification. Continuous Verification encourages both of these requirements in a way that proactively educates engineers about the systems they operate. It is emerging as a crucial practice for navigating complex software systems. Continuous Verification is a game changer for complex software system management. In the future it will fundamentally change the scale and types of systems that we even consider building.
remains as an open challenge. Security may be included in the Chaos Maturity Model since combining a CMM and Security Chaos GameDays help newcomers to start their CE efforts and allow to build resilience on security. It’s an exciting time to be working on this space. For the Future www.yurynino.dev