Stefania Chaplin, GitLab | DevOps Experience 2022
At DevOps Experience 2022, Stefania Chaplin, Solutions Architect at GitLab, explains how to stay secure at the edge and beyond. `
Transcript
Hi everyone. Thank you for joining. Good morning.
Good afternoon. Good evening, or we're happy you're watching the recording from so I am Stefania Chaplin AKA deaf step ups and today. I'm going to talk about devsecops at the edge securing connected devices.
So I always keep my agenda a little bit vague. So who am I what am I here to talk about who is involved how we gonna get there? Why why are we here and to summarize and to make it a little bit fun as well?
I also have a couple of quizzes. So feel free to pop your answer in the chat write it down or just have a think as well. There won't be prizes.
But at least you will get the prize you'll get the Peace of Mind knowing if you've got things, right. so who am I? I started my career and development.
So python Java, I did a lot in rest apis. I'm one of those cool people that when you present a Jason to I know what which commands you need to do to get to the exact key or value that you're looking for. Then I moved to the wonderful world of security.
So looking at devsecops application security Cloud set. I was working at a company called secure code Warrior that do security for developers phonotype that do software composition analysis looking at your open source components. And then now I work at gitlab you one devops platform, but I'm not here to talk about them.
Outside of luck. I also do yoga. I'm very much into surfing as you can see from around me.
I have a lot of tropical plants. There are about 40 on this table around me. I now have about this much space for me and my laptop but with this, you know other I say other side to me.
I always like to think a lot about people and culture because we may be using Tech and especially with the edge. We're almost becoming embedded with tech but it's important to think about you know, how we interact as people and how we can get things secure. So what are we here to talk about and this comes to my first quiz?
So I've got a little timer. I'm going to be doing a little 15 seconds for anyone in the audience who wants to guess so quiz time. Starting timer.
What is the edge So I thought I start us off easy. I am hoping if you're in this call you're here for the right reasons. So you got another couple of seconds and time is going off.
So I thought I'd start to stop easy. What is the edge wrong answers only if you have thought of either YouTube or also the film from the 90s with Anthony Hopkins and Alec Baldwin and an Alaskan bear. Unfortunately, you were wrong.
This is not what I was looking and you may be in the wrong session. so Edge computing We have a couple of layers here that I'm going to talk through. So we have our cloud data center.
This can be a data center that exists within I say like on Prem within, you know, your your boundaries. This could be as part of one of the external Cloud providers such as AWS gcp as your And with these cloud data centers here, you have your long-term data analytics and data storage and there's usually a lot of you know, you've got a lot of compute in the clouds. So this is where you can do some quite sophisticated action, but if you're constantly connecting to your say to devices sometimes that can be latency and it's a lot of there's a lot of pinging So what we start to see is the introduction of edge Computing which is where you might have an intelligent Gateway you have local edges.
So whether that's for you know, say for example content delivery Network. It can be for data analytics processing short-term data storage. And these are kind of these are usually situated if you look at you know, the cloud provider model such as AWS.
They're going to have data centers, you know across the continent but they're gonna have many more edges. So maybe you have an edge in each City. So what happens when you have your smart devices whether it's your watches your mobile your cars your smart plug that makes you coffee every morning your CCTV for your for your smart doorbell.
These all will collect the data and then they usually have limited processing. So what they'll do is they'll communicate with the edge which is where you can start to get this analytics and data. processing from So when we look at Internet of Things, it covers quite a broad range.
So this is something that the Internet of Things Institute they came up with this I quite like this then for graphic about security targets because actually, you know, maybe we think oh, you know, it's it's just a smartwatch but actually iot is a lot more than that. So we're looking at I can go around a couple of them say for example with its industry so industry, you know creating Similar to cars these industrial facilities, they're becoming connects to the clouds. So security risk increases video cameras.
I'm not sure if anyone is familiar there was when there was an issue with AWS recently, maybe six months ago. I think all of a sudden people couldn't get into their houses their doorbell their Smart Systems weren't working because AWS was down so people could actually not get not get in because it all is also linked. Cyber, wet Warfare is a real I say question mark exclamation what we're seeing in the moment is if we look at the situation that's going on with Ukraine and with Russia, that's a lot of cyber warfare and both sides are leveling up because they are you know, it's a bit like it's a cyber warfare arms race and effect.
So what's gonna happen crossing my fingers as soon as possible when the war ends is especially the malicious actors. They're going to be like, oh, okay. I'm bored.
Now, who do I go after next and that's what you're seeing. Sometimes with hack is there was a recent Hotel case. I think it was a it was a board couple a cup of hack a couple it was either.
I can't remember. It's Philippines. Maybe Taiwan.
They were just bought so they went after one of the holiday. I don't think it was Marry it but it was a holiday organization and they were going around the service trying to do some real damage trying to do ransomware the incident response of the hotel organization with spotting them. So what did they do?
They just wiped the server. So I think especially in the day in the age we live in cyber warfare is going to become a bigger thing power grids and this comes into utilities as well. I was talking to a ciso in a Healthcare company and he said there are 50 people at my local, you know sewage utility company one in cyber if hacker start going after, you know, electricity after water after sewage.
This is gonna be a big problem and this kind of links to kind of buildings and cities as iot becomes more and more as we become more and more embedded Tech within our environment we need to do it securely because whether it's not being let into our houses, whether it's you know, our robotic fridges malfunctioning and and turning, you know, all the heat to hot or too cold. It's gonna be a case that we really do need to secure as well levels. Which kind of leads me on to medical devices?
I my mentor actually his father has a pacemaker and he does a lot of speaking and he often says the thing about pacemakers are you thinking about what open source is going in there? Yes, the pacemaker needs to call the hospital, but presumably, you know Bluetooth Wi-Fi, but is that being done securely? What if someone could hack a pacemaker?
Similarly add travel that was I'm so component. I think it was I can't remember the common collections or struts. It might have been struck.
So a Java components they knew they were using the vulnerable version and for like 60 days every plane when it landed had to have a little quick reboot and then was going out so that it wouldn't you know wouldn't be hacked. And and so when you look at this kind of along this spear from all the way from industry to retail to cyber warfare buildings personal data Etc, you know is everywhere. So it's really a case of now that edge Computing is going to be everywhere.
How do we how do we use the lessons that we've learned from devsecops to keep things secure? So next Quiz time to this load. Oh, no.
Sorry. Next Quiz time. What is devsecups gonna give a little answer?
I'm sorry little answer. You're gonna have a little 15 seconds and to go here. Like I said, I do like to start off easier with the questions.
We are gonna do a couple which are a little bit harder another couple of seconds here. Okay, and there goes my alarm. So I quite like this definition devsecops stands for development security and operations.
If you got that, right well done. Everyone gets a gold star. But actually I quite like this definition because it involves a lot of things.
So you've got culture you've got shared responsibility integrating security automation platform design across the entire it lifecycle. So it's a lot more holistic view. It's not a case of I would like to buy one devsecops, please or let's just do security scanning in the middle.
It's about people it's about culture shared responsibility automating Etc. Because like I said, this is the thing about death Cyclops, you're gonna have your developers who are usually involved in development and security is not just a case of scanning in the middle. It's about having it throughout And you have Ops on the side so examples of the security maybe maybe you have threat modeling and planning.
Maybe you have ID scans. So you have a scanning capabilities within the IDE and as you're building running all your tests, maybe you run unit and functional tests. Well are you doing your are you looking at your scanning your open source your code you're writing.
Are you doing Dynamic testing? Are you testing your apis and especially with? With internet of things apis are going to become very important because it's how we connect areas to each other.
looking at Ops So on the upside, this is where we're going to get for example logging and monitoring is very important incident response is very important making sure that we know, you know, when we get hacked we can react as quickly as possible to stop stop any Bad actors in their tracks and ideally Trace them and then, you know have have Justice Etc. So and why why is this important? Why do we talk about devsecups?
Because this is a chart the relatively cost to fix bugs based on time to detection. This is where shift left comes in. This is some of the emphasis of dubsecops.
It is a lot cheaper easier and faster to fix things in you know, whether it's requirements or coding than it is once it's in production or Post Release. So common pain points that we will have at the edge. Data privacy is a really big thing.
Especially what comes to my second point now, it's personal but when we're dealing with Edge Computing, it's a lot more b2c. It's a lot more consumers, especially when they're wearing these devices or using them on a regular basis. I say now, it's personal with a shark.
I actually found that quote is actually from Jaws 4, even though I thought it would be from somewhere else when we have consumers. They have a lot more cares about data privacy. They care about you know them.
It's no longer a case of oh, this is my credit card. It's okay. Okay.
Wow. Now this is my biometric. How easy is it for me to replace my thumb print or my eye scan.
Not that easy. And another fact which is which is quite common actually is unfortunately common is security as an afterthought. So, who are we here to talk about and we're coming to my next Quiz.
This one is I hope a little bit harder keep you on your toes so quiz. Start the timer. What is the difference between project mindset?
versus product mindset give you a couple more seconds. And the alarm goes off. So when we think about project mindset, so this is very much.
This is time budget deliverables if you remember Gantt shots, so we have our different flows of work that go across and there's a real focus on execution and outputs and as we evolve and move into a product mindset and this actually has originally come from if you've read or if you've heard of my Martin Fowler, he says nine awesome things about microservices. It's not actually called that it's like nine things about microservices. He mentions this a lot because when you get to product mindset, it's a lot more about outcomes.
So we're talking about increasing customer value and it's a real, you know product mindset. So you have productivision you have the product strategy roadmap and because it's very product focused security becomes part of the product security is a quality check when you look at projects security is a tick box. It's normally left at the end of Gantt charts and then, you know people just Excuse me, tick off enough risk when they get there.
So what you end up with this product product mindset is quicker business outcomes improved customer experience reduced fiction friction and more flexibility. So why am I talking about this because we're going to have our silos. We always have our silos unfortunately.
So we've got developers. They will be writing the code for these applications. Maybe they're also creating the infrastructure.
They could be creating the way that we communicate between the edge the Computing the iot devices. They can be doing the data analytics. What kind of involved in those processes so I could also but you know data Engineers within the development kind of silo.
Then you have security security will be everything. I just mentioned I me at myself. I see lines and I'm like every single line when something moves from one plane to another that's the potential attack, you know, potential attack vector and then you have opts up.
So trying to keep everything stable. And and one thing that we don't want to get to is when our silos go over when they get a bit unstable. This is not an ideal State of Affairs.
So my second question and this one it might hopefully catch you unawares. Let me get my timer. Who will we missing?
I've talked about death's second Ops and this is very much related to the edge Computing and I've mentioned it before my little clue. My Easter egg is is the Jaws quotes that I mentioned a few slides ago timer. Who are we missing us?
the people the consumer so if we look at the left side, so I'm going to call it a Iot now, it's personal. A lot of these devices are literally either on our body or you can see it there and kind of in the middle subcutaneous senses. These might be embedded literally within our skin.
So whether it's clothing well wearing hearing aids pacemakers is another one. It's you know, like I said now it's personal. So this is why I say this is the one person we need to take into account because once consumers have these devices maybe they want to play around with that like for example with Peloton I've seen online that Peloton people want to no longer want to do just the Peloton exercises.
Maybe they want to watch YouTube or Netflix. So they Hack That Peloton or what you see with cars is that you get I saw one. I can't remember the Geo Toyota Hyundai, but there's one called Green Luigi and he just hears how you hack your car and how he did it.
So it becomes almost like a Bravado. It's like oh, yeah. I have the thing that we all use.
And because all these devices are personal you can see by the second picture that look at all these connections. So you've got your body area network. That's Bluetooth into your smartphone.
You have Wi-Fi to your router that's going to your internet your cell site. And as I describe before as someone who works in security all these different lines on the right hand side. I'm like potential security risk how we securing how we securing so it's really important to think, you know at the at each level.
You know, it's like basic threat modeling what are our assets? What are our protection and what are our threats? So how we how we securing our Bluetooth how we securing our Wi-Fi what information is allowed to go across can can anything imitate can we do man in the middle Etc?
Because like I said now it's personal so it's a lot more of a Trying to think of the best words without you know being polite. It's a lot more of a mind. I'm gonna say mind flop and but it's a lot more you have to think a lot more about these things now, it's more personal.
So, how are we gonna get here? So oh, I just gave away the quiz quiz. Um, so how are we going to keep the edge secure I'll give you a bit of extra time because I actually just ruined slot.
That was my bad. And and this is quite an interesting one because I don't think there's like one approach because the edge is so big and we had all those layers. So I think that's kind of lots of correct answers what I'm gonna do and the time it goes it's talk through summer some of the examples.
So, how are we gonna keep the edge secure so keeping the edge secure Devsecops practices can help when I go back to my image original slide with the infinity having security at each stage shifting left with security depops that using using that approach. So okay, maybe we're not securing applications. We're securing embedded devices but using these best of practices best in breed can help.
Also, you don't have to reinvent the wheel your security team has internal standards and policies to help you out. Especially check out sassy. So um, if you're looking at having, you know networking and having secure devices, I'm not actually going to talk about it today, but feel free to go Google that because you know, that's some good best practice.
And if you are not working in security, I would say reach out to your security team and if you are working in security, then yeah check out sassy. It's it's a good approach because I don't want you to reinvent the wheel. I'm not gonna give you all of the answers.
I'll point you in some of the right directions. so configuration configuration configuration everywhere. So when we're looking at configuration a good a good start is comparing the current configuration versus the desired state so that way we can ensure that the edge nodes are operating correctly.
So basically configuration management, there are tools out there. I'm a bit Rusty on this. I was looking at this a few years ago.
So for example, I know ansible puppet they're very good for configuration management. If we're looking at our servers, you know with all the awesome. This is Dev suck Ops, we it's better to have configuration as code versus having manual configuration.
So just checking status. Just making sure that everything is as it should be Number two communication. So I talk a little bit about encryption.
There are a couple of things you can do. So ensuring all your Communications between Edge agents and management hubs are encrypted also using cryptographic signing key having a having a key pair and rotating it periodically. So that can be a good approach.
You want to think when I say communication that's I was describing those lines. There's a communication that's one I'm gonna say thing one if one thing talks to another thing. How secure is that conversation or what?
What are they? What are those things talking about with each other? So what data is being transferred is that data encrypted who has access to that data?
What would happen if that data got lost? You know, is it just how is it? You need to think about you know, what's going across and does does it need to be doesn't need to go across raw.
I was gonna say rule rule law of least privilege or rule of least privilege. So yes, exactly encryption and access control and the final one is gonna take a drink So this is something that I've mentioned a couple of times this talk is devsecups. So making sure that you have security each stage as you're planning your environment and looking at these different layers and and who will talk to who what talks to what Having threat modeling for your developers as their coding whether they're doing, you know Robotics and using embedded whether they're provisioning the environment and doing the 5G networks.
Are they scanning within their IDE or at least as part of their build, you know, if you're gonna write unit functional integration system tests. You should really be doing API testing security testing sass. That's Etc.
So it's good to remember security is a quality check if you have insecure code, that's low quality code. And then as I mentioned moving into Ops logging so so important. It's like I sometimes I think I'm vegan.
Sometimes I think security is like eating your fruits and vegetables. It's like best practice do all your scans, you know, authenticate verify all of these like things that on paper sound fairly easy. It's just about upholding and this best practice.
So why why are we here? Why is this important? Why devsecups?
So there's a couple here. I don't usually read off the screen but I am going to because I think these are pretty good and this is actually come from an IBM article and I forgot to mention in the last few. There's a really good blog that I had at the link at the bottom that you should read.
But um, why devsecups incorporating security into devops helps speed up and iterations and what does that mean? If we have faster iterations we can innovate faster we can listen to our customers. We can take customer feedback.
We can translate that into better products and then we can gain market share outperform our competitors because we all know we listen to our customers. Our customers make customers happy. They bring other customers then they're loyal if we don't listen to our customers or our service goes down guess what customers are going to leave.
So having sped up iterations is really fundamental to that. Coming to security vulnerabilities are identified earlier which helps to avoid cyber attacks and I've kind of mentioned a lot about cyber warfare, you know cyber attacks in the news. That's what I've actually noticed in the last two years.
It's been what I've inside security for a while and now cyber attacks and mainstreams whether it was the gas pipeline last year, whether it's you know, different hotel chains Airlines Etc. It's now becoming something that even I say in inverter Thomas normal people are aware of and finally it helps improve communication and collaboration between teams because if we're all working together on the same issues, then we can you know, we'll be happier better communication collaboration. Nobody wants to be on the front page.
We want to avoid friction and finger pointing and we want to you know work on problems whilst they're still small. Oh, I found a problem as part of my future Branch. Let's fix it not.
Oh there's a problem that's in production and someone's life hacking us right now. That's not the problems. We want to well, we do want to communicate and collaborate on those but we want to catch those earlier.
so to summarize Have security procedures in place for all assets edges and devices. I often talk about Asset Management. If you're working in organization, you're going to have a list of all your people.
I hope HR probably does they're gonna have contracts. So do you have a list of all your Hardware you have a list of all your software and within that for example, if you're using Cloud if you have land a processes, you know processes that have power these different lines that I've mentioned so many times. Do you know do you have a list?
Do you have security procedures in place for all of those that you can you know, make sure that you're secure all ages and devices. Second one focusing I say on my three C's I've mentioned them so configuration communication and and encryption. So especially when it comes to communication you'll probably notice a thread maybe I should have had a massive line here, but when we're traveling through these lines through these data flows information flows.
Are we are we can are we encrypting how our configurations how we communicating? And finally reach out to your security teams. They are your seat belts.
I heard a great analogy security teams are not your brakes. We want you to drive as fast as you can but there your seat belt we want you to do it safely. So, thank you so much for listening for joining.
Please feel free to reach out on my website. I've got my email Twitter LinkedIn always welcome to your feedback. I do a lot of public speaking.
So if you want to come to your company to your event to your children's school, I'm always up for improving diversity or evangelizing security and thank you so much for your time and hopefully see you again soon.





