Jonathan Schreiber, Ram Kailasanathan, Rand Waldron – Cloud-Native Security Processes and Tools To Protect Modern Applications
Cloud-Native development with containers and serverless functions are being deployed at an increasing pace. This shift to cloud-native development puts more responsibility on developers to secure their applications and development toolchain. In this session, we will discuss how, where and when to apply a security-centric approach to application development. We will cover the security best practices followed within Oracle Cloud Infrastructure (OCI) as a case-study.
Transcript
Is your agency, your organization thinking of moving to Oracle Cloud, but you need to know more about how Oracle views cloud native security in this session is for you from California, then senior director of product management with Oracle Cloud and Jonathan Schreiber, product manager will share everything you need to know about desktops in Oracle Cloud. Hi, everybody, my name is Rand Waldron, I'm the vice president for the global government sector here at Oracle Cloud Infrastructure, and I spent my whole life building systems and developing tools for missions and for customers. And I really couldn't be happier to talk to all of you about how we can do exactly that for your customers.
This is a safe harbor clause. This tells you that all the things I'm going to say, I'm going to say. But they may not apply to your particular situation.
So I'll take that under advisement. We are sponsors here at the conference and we're fortunate here because we build tools. We build systems just like all of you that you and we want you to make sure that you know that.
And we are here for you as you take on your next challenge. And I know that after I speak, we're going to have Ron is going to come in and talk about our container tools, the Oracle container engine, Jonathan, going to come on and do a demo about companies and refine on how we bring all that together. I'm going to talk at the very end about some of our specialized solutions for some of the audience out there.
And then, of course, we're going to be available for questions. Take any of that at the end. And I think there will be live questions even right now.
So with that, I'm going to dive in. The first thing I want to tell everybody is the Oracle Cloud. The Oracle cloud infrastructure is real.
There are a lot of people out there that sometimes don't even know or forget that we have a real huge hyperscale cloud all over the world designed to serve the exact kind of solutions that you guys Bill. We've got twenty six regions live right now. We're building another 12 in the next year, which is frankly crazy.
This is a global presence like few other cloud providers have. And it's also really important to say that we are Oracle Cloud. We don't just do Oracle things.
We have all the Oracle stuff you know and love. So we have the Oracle database. We have amazing analytics.
If you want to bring data together, smash that data and figure out what it all means. There really is no better cloud, but we have everything else, too. We have a massive set of tools that are cloud native container native that are developer focused, focused on the dev ops problem.
And these these tools are out there in other cloud providers, but they're here with us too. And there's reasons to choose us over that. There's really a couple of big reasons.
I'm I'm not going to hit on all of these in depth right now. We have better performance, we have low and predictable pricing, we have expertise at the Enterprise. We are truly security first and in a really deep way that gets missed a lot.
We are deeply invested in the open environment. The first, a superior performance, we are based from a foundational level on bare metal compute, this gives us an ability to give performance to your applications that is faster than you can get essentially anywhere else. That's because we are not necessarily running VMS or any code on the machines that we provide to you.
That means as you put your own virtualization layers over it, whether it be our container engines, whether it be your container engines or somebody else's, you have the highest performance because that virtualization is running right on the bare metal. We also have the fastest networking. We have layer to networking in the cloud, which is essentially impossible.
Nobody else has it, but we do. And this means that your your application can talk to itself faster and can drive better performance. Our economics are just unbeatable, and we aren't cheaper by 10 or 20 percent, in many cases, we're cheaper by 50, 60, 90 percent.
I won't go into the details of this year, but it is absolutely worth checking out. Look at your workload. Go to our cost comparison site.
If you're running a workload that can run in our cloud and it can run in one of our competitors, cloud, check out our cost comparison. It's going to be radically cheaper in Oracle Cloud. We're going to talk more about this later, but we really took an entirely new approach to security and so we built zero trust in from the very beginning.
All of our virtualization is off the box. We cannot see your customer data. We cannot see into any of the things you're running on to our box.
You have the entire machine, should you want. We also have the VMS and all of that. We have the security built into every piece of the tools from the very.
This is really important. Oracle has built some of the most powerful software in the history of modern technology. We have also been a huge proponent and investor in the open architecture world.
We are massive participants in. We have fully embraced all of the cloud native technologies out there. And so we really have these tools embedded into our applications and into our cloud in a way that is cloud agnostic.
You can use our streaming data service and it isn't just a a fourth version of Kafka, it is Kafka. You can use our serverless applications form and you can run them in our cloud and you can run them on your premises or in somebody else's cloud. That's not the case with a lot of our competitors, where if you deeply invest in their cloud native technologies, you are stuck in their system.
This is just another picture of that of the tools that we have that are truly proud, native and focused on you builders building the tools, using the tools you need to build the applications in the way you want to build them. And the key of all this is you don't have to take my word for it. Just try it.
We have absolutely always free here and we have free trials. And this is not a free tier that's neutered and only gives you a few things. You have lot less power in this free tier database, instances of compute storage, networking, bouncing, and you have a lot of all of it.
Try it out, see what our top need of tools are like and you will be impressed. Good afternoon, everyone. Welcome to Oracle Cloud Cloud Security Session.
This is from Kyla's. Nothing Here. I'm senior director of product management at Oracle Cloud.
When we look at the security landscape. One of the biggest aspects is expertise, finding experienced cybersecurity professionals has become a tough challenge. On top of it, most enterprises are having to constantly innovate to keep up.
This has led to the emergence and rapid adoption of new technologies such as cloud natal drops and deficit jobs, and the need of the hour is to democratize security across all aspects of the lifecycle, drilling specifically into cloud data security. Did you know that 20 percent of the top thousand images have at least one critical vulnerability, 20 percent of the top thousand darker images have no account password. Containers are interesting in that they share the OS kernel, this leads to better utilization.
However, lack of proper isolation is a huge security risk. Privilege continues running as root can be exploited by a malicious user. Containers created from images using open source are third party software could contain known vulnerabilities.
Container sprawl is another key challenge, mainly caused by a combination of limited visibility and free and lightweight nature of containers, Agile took us from months to days to deliver software. There were obstacles from months to minutes to deploy software. And we are seeing that more and more applications are becoming mission critical.
It is the need of the hour that we incorporate security across the various aspects of the lifecycle and desktops is essentially the methodology of integrating security tools within the database process. In an automated fashion deficit is not just about tooling, it is also about the people and process aspects of things. This ultimately leads to a culture change.
Within the entire organization, essentially becoming upscaled to think and act upon security. This also allows them to collaborate more efficiently and thereby creating a security culture. An important element of deficit jobs is the pipeline.
Here is one example from Getler. We have a similar one that we use internally at Oracle. There are many other examples available from other Cloudera vendors as well.
It essentially starts with a developer ID, a source code repository, moving to a CIC over a binary repository for storing your images, a container images, a stage and environment, production and monitoring environments. And all of this leads to a fairly efficient and a highly automated way of producing innovation in software, but this also provides us with an opportunity to embed security at every stage within this pipeline. Take a look at comic hooks, for example.
It avoids leakage of sensitive information, storing credentials in configuration files within a secret vault, a secure and secret vault. All of your secrets encrypted is highly efficient from a security standpoint. Every piece of code is tested upon it.
And so now as part of the security code review, you can look at look for a sequel injection crosseyed scripting using automated tools. Developers can correct these errors much earlier in the lifecycle. In addition, Web application scanners are available for some dynamic testing and vulnerability assessments, vulnerability assessment is a very important aspect.
Klare is a popular open source. Cloudera tool that scans the are screen images and gives us an exhaustive report on vulnerabilities. Equally important, our observability tools that provide us with critical monitoring and remediation capabilities, ultimately we want to get to a complaint as a code environment so everything is automated and streamlined.
Shifting gears, I want to focus my next part on best practices that we follow within within our team and also what recommendations we particularly offer to several public sector and government cloud customers. Let's first take a look at what is Cloud Naidoo at Oracle. This is an overview of the various cloud data services that we offer with an Oracle cloud.
It covers key services within the adopt category, including console and marketplace to the built tools, including API design and cloud infrastructure as code that we offer to our resource managers service to deploy tools including Humanitas and Serverless, to operate tools including monitoring and logging and taking Occy as an example. But this applies to all the services that we build with an Oracle Cloud data organization. We deliver tools and services that are complete, integrated and based on open source, the key is open source.
We actively participate in community to an open source, container technologies we invest in and leverage open source technologies as the fundamental basis for portability, portability, OK, offers and enterprise great and developer friendly container orchestration service based on Kubernetes. It is fully managed and. Integrated with the private registry and available in all Oracle Cloud commercial regions.
All of this leads to reduce time to value and faster time to market, since as a developer, you don't have to worry about infrastructure or container orchestration or the application availability. All of this come built in. OK, team follows the following best practices.
We keep up with the community and support the latest released version of Cuban. It is always, always applied the least privileged security controls for closer access. Apply very strong network policies to ensure highest levels of security when a good example here is placing worker nodes on private subnets.
Isolate sensitive workload's with a combination of our back and name space's. Encrypt and safeguard our secrets. And leverage audit logs and other observability tools for continuous monitoring and remediation.
I want to talk about some of the security capabilities that Ocky offers. It starts with the foundation, which is the infrastructure. Oracle, OK, is built on highly secure second generation Oracle Cloud, as Jonathan earlier mentioned, this offers the highest levels of infrastructure and data security.
Oracle cloud infrastructure is fully SORKH one to ISO twenty seven thousand, one compliant it includes. The best of capabilities from a data encryption standpoint, we encrypt data while at rest and offer capabilities to encrypt data in transit and also take care of key management capabilities as well. Strong access controls for operator access, coupled with in-depth auditing.
Console and security includes, no matter how you interact with Osseo Resources, you will have to go through proper authentication and authorization checks. Control and home security includes a combination of access controls, but for patching and monitoring tasks, another important takeaway for for this slide is isolation. Different isolation boundaries available are available based on the different needs that you might have.
And you need to pick the one that works best for you. We offer resus, isolation at the regional level, at the compartment level, at the availability domain level and at the host level. This is a key tenet of our overall security approach.
This essentially includes isolation at pretty much all the varying levels that you can think of. Shifting gears now, talking about security controls, security controls, it is an extremely important it is extremely important to have a rich set of security controls to choose from, and one size does not fit all. So the key here is to provide a bunch of choices to our customers and let you pick the right options for a given use case.
This includes everything from Iame policies, authorisation controls, secure keys, certificates, API gateway for secure API ingress. Ontime pouching of CVE's, and multifactor authentication for customers who need that second level of validation, transitioning to network security. Now again, network security is the foundation for any of the security architectures that we can think of.
And particularly more important from a cloud standpoint, our cloud provides key capabilities, including security roundtables we see and subnet network segmentation, VPN support and a whole slew of capabilities for network security. This is the foundation. On top of it, Occy offers several cloud data security capabilities.
It supports the concept of service mesh to run on top of key. It can it could be estriol or any third party service mesh. There's also also supports networking tools such as Khalikov.
Public sector and government cloud customers who leverage O'Chee can now take advantage of private workloads with no public epis. Basically, it is the ability to limit the network traffic on top of it. Customers can also take advantage of port security policies with load balances and Web application firewall pretty much covering the entire gamut of use cases that we can think of.
The last set of categories include data security, visibility and audit. Encryption tearless enabled InterAction's and in-transit and encryption of continuer images in Austria registry service are important. Set of tools within the data security category that we offer is equally important to offer observability tools, particularly on monitoring, audit, logging and and several other popular add ons that we hear from our customers to essentially cover other data today and use cases with an Oracle cloud.
Our compliance thinking starts from day one, and there's a strong emphasis to support compliance certifications across both commercial and public sector aspects of things. And so we have everything from federal certification to cloud certification. And our approach to this data center design, as well as the deficit Gob's helps us approach compliance in a unified way for each regulation and framework, passing it to everybody.
I'm Jonathan Schreiber. I'm a product manager at Cloud and I'm working on our developer services. I want to show you today one piece of a continuous delivery pipeline that will help customers meet their deficit obstacles.
So if we think about a pipeline and automating replumb, often customers want to be able to ensure that their governance requirements are met in their pipeline. And those checks are often manual then. So one piece that we wanted to show today is how we can automate delivery using a system to to validate the artifacts before the deployed to communities.
And we're going to do that using the Grafeas Medidata API. So this is an open source project that we're going to integrate in with the API with with OK in our demo. So what we're going to show is just a simple deployment going to our cluster and where to use surface to record a note.
So this works in which there are types, the metadata that our notes and then instances of metadata are occurrences and we're going to enable and mission control or web hooked. OK, so this is part of the security service that is provides where we can validate based on our own sort of logic what's allowed to be deployed as a opposed. All right, let's jump in.
So here I've opened up Cloud Shell. So Cloud chose in in the console. So here we are and I'm going to use this to talk commands.
Ok, so first of all, let me just show you that I'm running graphics so locally and my cluster can be run sort of in your cluster or in another location. And I've already set up the signature web hook that is going to that's going to validate our deployment. So the first thing I want to show is just that we we've we've set this up so we can't just deploy any container, the container which needs to be verified before it's allowed.
So I've got a sample deployment here of my sequel. So I'm going to show you this. So this is just going to deploy the Marsico image is specific to specific version, a 12 cluster.
To see here that the deployment is not allowed, so we can look at we can look at the logs. See why. So you can see here that no matching signatures for the container.
So that's part of revalidation, that's the negative case where it's not allowing the container image to be pulled. If there's not a signature to match, the signature is we're going to sign using the hash. So that's going to be our unique signature.
That's going to be checked by the machine. So let's go sign this and then push that to our Tyga API. So you can see here the shore that I've got the my image got my school image, but luckily we can see here that this is the shop.
So it's going to take this. And signup. Ok, and just come on the.
All right, let me check the signature. Greg, so we've got a signature now. And he use that signature to make an occurrence in graphics.
First, MR.. Set up. Ok, so you're going to make the occurrence for this specific container image tag.
So here it is to that resource with this insurance. And then make sure that we can talk to. Chrysanths.
And then we'll post. Great, so now we have an occurrence, and so now the signature exists, which would be able to deploy MySQL. Well, we're happy about that.
So now we say that it succeeded and I there. Look at the logs and see what happened. So it validated.
And the signature is verified. So there we go, if we try to deploy a different container or a different tag, it should be denied so it can show that again, just SQL Server latest. No control, no sequel, because there's no signature that matches.
So there we go. So we showed using the graphics, open source projects, metadata, API and how we can automate the artifact verification per container images that are going to cluster. All right, thanks.
Hi, everybody. I'm back to talk about some of our specialized capabilities in the Oracle Cloud for the government and public sector. So we have twenty nine regions all around the world that we have built for customers of all sorts.
But in the United States, we have built we are building nine regions of the US government. Five of them are already built in line. They have been around high accreditation and they have the five accreditation.
And we're building it right now for regions where the US government, secret and top secret to those regions at secret and top secret are coming in right now. They're actually in accreditation and they're getting along the US government's classified networks right now. It's really important to understand the way we've approached this because it is different from some of our competitors.
We have completely physical separation between each of these. We call them realms, which are collections of regions. So our IL five USDOT realm, which serves the Department of Defense, the national security community at the highest level of unclassified security, is completely physically separated from our realm designed to serve the rest of the US government.
Ephedrin upon that physical separation is a really big deal and a complete isolation from other tenants that you may not want next to you. The same thing is obviously the case is secret and top secret. Our secret realm is on the US government's large secret network, as is our top secret realm, and the two are completely isolated from the Internet and from each other.
That may not mean a lot to a lot of you, but those secret and top secret regions, we call them national security regions, Oracle National Security Regions is a really big deal. So these are facilities that are hardened to government requirements and have isolation from radio signals, specific power supplies, all that. They are connected to the US government's top secret and secret networks and completely isolated from the Internet by they're operated solely by SDI personnel from within a skiff, which gives them the highest level of security.
And really importantly, because, again, it's a differentiator from how we are approaching this. We have a strategy called everything everywhere. That means that a service cannot go geet generally available in our commercial regions until it has a path into our government and national security regions.
What that means, net effect for you is that all of our services are available in our regions and available in our secret and top secret regions, and that is a huge differentiator. And finally, as I've talked about, we meet the highest standards of compliance bedroom high five, and we're working on our accreditation for all six and top secret, which can meet the tightest sap and are requirements. I'll just close out on one last recap of why it's worth at least trying out the Oracle Cloud, we have bare metal and networking that make migration easy and you can't get anywhere else.
We have vendor agnostic cloud native technology that allows you to build in a very cloud native way, but also move those workloads in and out of the Oracle cloud. And we are priced for scale. We know that the customers that are going to come to us are going to come to us with applications of scale and we have made that affordable.
We've made that makes sense versus staying on premise and versus our competitors out there. We have all the key resources, compute, networking, block store. They are faster, they are cheaper, and we have better lives than our competitors.
On top of all of them, we have the cloud native technologies like you've just been hearing about from Grafana and Kubernetes and functionalist serverless functions and all of those tools that you use to build with every day. I know that there's some question, some Q&A time after this presentation. We also have a virtual booth and we have a ton of resources to feed you as you want to explore this.
But the best way to explore is to just try it. It literally costs you nothing. Take a few minutes to check out the only three tier.
Check out our services. You'll be impressed. Thank you.