Identity Governance as the Center of the Cloud Security Universe at Cloud Native 2024
In this session, we will explore the first crucial steps in protecting cloud-native applications, focusing on Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), Cloud Infrastructure Entitlement Management (CIEM), and Cloud-Native Application Protection Platforms (CNAPP). We will move beyond acronyms to show how an identity-first approach can quickly and effectively enhance cloud security by addressing the most critical risks. Attendees will learn about the significance of managing identities and entitlements in any cloud strategy and the potential consequences of neglecting them. We will highlight the tangible security and business benefits of CNAPPs, such as risk reduction, improved compliance, and greater agility in responding to threats. Additionally, we will demonstrate how a unified platform enables multiple stakeholders to achieve identity-driven visibility, risk prioritization, and remediation across complex multi-cloud and hybrid environments.
Transcript
Hi everyone. My name's Lior, and I'm the director of Cloud Security Advocacy for Tim. Thank you so much for joining us on this session, discussing the very important topic of cloud security.
What we're gonna talk about today is how managing your cloud security is. One, is an essential component of your cloud security strategy, why it's so important, and also understand why it's leveraging opportunities that we have today in the cloud opposed to the risks that it presents us as an infrastructure. So first of all, in order to get to this topic, we need to understand what is different about the cloud.
So when it comes to the cloud, and of course I think we all know what cloud infrastructure is when it comes to the cloud, there are two main things that you can think of that kind of make it different. So first of all, almost everything in the cloud became logical, right? A lot of activities that we used to have that were very, uh, hardware oriented or physical in nature, uh, also became, uh, logical.
So they are controlled by API calls. Now, that's one thing, right? So for example, if you wanna do network configuration, it's an API call.
If you wanna set up a server, that's an API call. Um, if you wanna do a lot of things that were naturally done physically, now they're being done logically. That's one thing that's different.
And the other thing is that there's a lot of distribution when it comes to the infrastructure itself. So what happens is that people for outdoor organization, namely developers or development managers, can now manage their own infrastructure. And there's a huge advantage to that when you think about it when it comes to the organization, because you can also distribute the responsibility.
However, this kind of distribution also creates a threat because they have more access, they have more ability in order to do management and also do, uh, mistakes, right? Don't wanna, uh, attribute malice or anything, um, and do mistakes in that kind of management and create gaping holes when it comes to security. So these are like the two main things, you know, overall high level, and you can look at the cloud and say, you know, this is what's different, um, composed to, uh, opposed to what we used to have.
And this really kind of presents us with both an opportunity and a threat when it comes to security standpoint. So the opportunity is that when you think about configurations of your environment and your logs, they're now ultra accessible, right? Things that are logical are naturally, um, more accessible because you can programmatically access them, you can program them, um, you can define them using texts, for example, as infrastructures code.
That's, that's huge, right? That gives us a lot of leverage. And also, as we mentioned, you can distribute the operation of it, um, and basically delegate a lot of the responsibility, which can also be huge.
However, this also presents us with a fret, right? You have more hands in the cookie jar as you may, uh, understand because that kind of delegation, that kind of potential also has a fret in it. Um, and the environment is super dynamic, right?
The changes that you can make logically, they're far, far, far faster, and, uh, more extensible than you can do them physically, right? Doing things faster is usually a problem, uh, when it comes to security, because it makes them a lot more susceptible for mistakes. And that is exactly the last point.
The infrastructure itself is more susceptible to mistakes than a lot of its layers. Now, what that means is that in this new environment can say it's new still, but it's becomes very, very, very, it prominent in this new environment, this new game that we have when it comes to infrastructure. Um, we have new challenges, right?
We have new attack vectors because we have new kinds of technology. Um, we still don't have a ton of expertise available because if you think about it, this is not, this is not technology that's been around forever. It's been around for a long time.
It's been around for something like, um, uh, 15 years, been prominent maybe for a little bit less than that, but it still hasn't been around for like four years, right? That we have an abundant of skill around it. And there are also a lot of tools, right?
There's a lot of tools around it. There's a lot of tools. When comes to security, there's sort of an inflation of the kind of things that you can do around it.
Um, and if you don't have a coherent strategy, you can kind of get overwhelmed. And in addition, you also need the collaboration of people within your organization. Because of this nature of distribution of responsibility, a lot more people are involved because they can be involved and you honestly, they should be involved, um, because there are so many services that usually the subject matter expert of the service is very well informed in them.
And, you know, one security person or security team even, uh, can't possibly understand all the, all the, um, all the, uh, intricacies of every service in the cloud. And that's also very necessary, um, for them to be secure. So that's a challenge when we have in the cloud.
Now, security naturally, um, and traditionally has been done in depth, right? It's been done in layers. There are many things that you need to take care of and you need to take care of each of them, right?
You can't just say, I'm gonna focus on this layer, I'm gonna secure that and everything's gonna be good. That's not the way it works when it comes to security. And the cloud is no different.
You need to secure, um, your identity. You need to secure your network, your data, uh, your computing resources, everything from end to end. And you need to do it, um, in all of the layers.
Now, just as an example, you can see that, for example, in the cloud, um, IM is a very, very important concern. A very, very important layers. And you can understand easily why that is, because you should remember we mentioned that almost everything is an API call.
And when almost everything is an API call, and your most essential, uh, components of your infrastructure are mostly behind a public API that can be made. What happens there is that the bad guys are basically one permission away, um, from being able to do very, very, very sensitive things. And these, these permissions, they're usually controlled by, uh, text files, right?
They're usually controlled by, uh, json files or code that defines them. And an asterisk in the wrong place can basically create an identity, which is very, very much overprivileged. And when that identity becomes compromised, then the fallout from that com from from that compromise is very, very, very significant, as much as it shouldn't be.
Um, and one thing that we found, you know, during our tenure as a, uh, a cloud security solution, is that there are so many privileged admin, even admin level, uh, users in cloud environments, that it's very, very likely that when cloud user is compromised, then a lot of the permissions that the malicious actor gets are not even necessary. So, for example, uh, almost 90% of cloud users were found to have admin or privilege access, and one third of those users did not even need them, right? This is an example of this kind of how the dynamic environment, the dynamic nature of an environment, because it's so easy to give high privilege access just to make things work, or to have a user be able to do something, and you don't want to go exactly into what it needs to, to end to how it needs to be defined, to give them that le kind of least privilege, um, that it's very, very easy to just hand them out with a lot of high privileges, not thinking about what would happen when they're get getting compromised.
That is one, uh, that's one example of such a layer that is very, very significant in the cloud. Now, another thing that happens in the cloud is workload protection, right? Or exposure to vulnerability that does not change, right?
And that is also something that's very, very traditional tenable, of course, being a leader, um, when it comes to this aspect of vulnerability management and workload. And that doesn't really change when it comes to the cloud. You have a lot of workloads in the cloud.
Um, there of course are very, very exposed to vulnerable vulnerabilities in, uh, operating systems and software packages and whatever. Um, and critical vulnerabilities take really a long time, uh, to get remediated, right? So for example, this is a quotation from, uh, from a survey, um, that only observed something in the neighborhood of 13% of vulnerabilities in environments actually getting remediated.
And even that took a, a very, very long time. Something in the neighborhood of, you know, nine months, right? 2 1, 271 days on average.
And we, this is something that we noticed that even in, uh, very mature environments, it takes a long time to remediate vulnerabilities and even critical vulnerabilities. So you have workloads that are very much exposed to, um, to software, uh, vulnerabilities. And that can be leveraged in order to gain that compromise and to have that access.
Okay? Now, the next thing are configurations that can be leveraged in order to gain access either to a resource or to your environment. So for example, one very clear misconfiguration, uh, could be network or firewall misconfigurations in some resources.
So for example, if you have a resource that is exposed that is, that have, for example, Kubernetes clusters with exposed APIs that we have here in this example, um, then it can be publicly available and can then be leveraged by malicious actors if, um, it enables, uh, that kind of access, right? It's publicly available. Now, this can be also other kinds of resources, or it can be, for example, uh, a storage, uh, bucket that is configured to be available from anywhere or by anyone.
And there are many kinds of these other types of misconfigurations, which is also a very, very important aspect of your cloud security posture right? Now. The thing is that those three things that we mentioned, um, can also be stringed together in order to create what is called a toxic combination.
So we can have, for example, a workload that has a vulnerability on it that can be leveraged in order to gain access. That vulnerability, um, can then allow an attacker to exploit a misconfiguration in order to make more grounds or have, uh, more control over the workload. The workload itself can have excessive permissions because that's the way it's configured.
And those permissions can eventually allow it, um, to have access to, for example, sensitive data and then basically gain the payload within the environment. Now, what we understand from this is that this kind of what we call toxic combinations is one of the most important things to look into. 'cause for example, you can have a scan that will give you a list of hundreds or thousands even of vulnerability exposures within your environment.
But what you wanna know is you wanna know which ones can be leveraged in the most effective way by malicious actors. And for that, you need to string it with this information from other aspects of your environment, from, for example, from configurations and from entitlements and whatever. That's number one.
And the second thing that we can see here is that permissions are very, very much of an important layer, right? When you think about it, as we mentioned from before, when almost everything is logical, then almost everything is one permission away. And that is also a very complicated layer in your environment to understand.
Then having a deep understanding of that layer is very, very much significant. Locking it down, having least privilege. Um, so you mitigate and you minimize the fallout from potential breaches within your environment.
That's the number two thing to take from this slide. Now, unfortunately, what we've seen in the wild is that a lot of environments actually have this exact kind of toxic combinations in them. So a lot of environments that we've seen have, uh, resources that would be vulnerable, uh, privileged, that is have a lot of entitlements attached to 'em, and also internet facing.
Um, and that kind of toxic combination is exactly what malicious actors, um, t Now finding these and being able to prioritize and understanding the exact context of each aspect of the domains that we talked about is a real challenge. And it's always been a real challenge when you think about cybersecurity, uh, even on the, on-prem days. But now, when it comes to cloud environments, we have the potential, and this is where the opportunity sets in.
We have the potential in order to do this kind of analysis across all of these different kinds of domains in one place using the same kind of technology because of the programmatic access we have to all of these aspects, right? Because, for example, the configuration of entitlement since is done in the same way, in the same language, if you will, of the configurations of the resources themselves. Um, and that can also be attached with scanning for vulnerabilities and scanning for, for example, Kubernetes, um, uh, configurations.
Then all of this put together can go into one holistic protection type of solution. And that is the exact purpose of a relatively new category of products called Cena, or a cloud native application protection platform that allows you to take all this information together, analyze it together, and create a prioritization of the findings in the context of, of our findings, making them a lot more vulnerable. So for example, if you have a vulnerability, you don't just look at that vulnerability detected as a vulnerability, but you look at it in the context says, does it run on a workload that is public to the internet?
Does it run on a workload that has a lot of entitlements attached to it? For example, referring to the example that we saw before? And Tenable doesn't just provide a synaps solution providing Synaps solution, also relying on an industry leadership ability in Kim or cloud infrastructure, ENT intolerance management, which focuses a lot and have cutting eligibility on that analysis of entitlements and permission as a very, very important and often overlooked layer of, uh, cloud security.
So this is what Tenable cloud security does. It provides you with analysis on all the layers that we talked about on vulnerability management as a leader in the vulnerability manage, uh, uh, management space. It provides with detailed, uh, analysis of permissions and the usage and the ability to get to least privilege also on posture and, uh, configurations and analysis of logs.
And all of these things put together, um, to be analyzed in order to detect what is called toxic combinations, to allow you to prioritize the kind of exposure that you have in your environment and have actionable intelligence of the kind of security gaps that you have in your environment in order for you to focus your very precious cloud security researches. Now, all of this is also contextualized in the articles of very popular compliance and best practices standards, so you can easily understand how you adhere to them and what you need to fix in order to meet them, uh, in a better way. Now, tenable is a market leader when it comes to, and you probably know the name, um, when it comes to exposure management and portability management.
Um, it's a security innovator and leads in exposure resource, um, for all these different kind of, uh, stats. I'm just gonna go into each and every one of them. And to summarize what we talked about today, um, the cloud actually presents us with both challenges and opportunity 'cause of its nature, because of what makes it up.
Now, you need to employ, um, at a certain scale, of course, but if you're on this call, of course you probably have reached that scale. Um, you need to employ a synapse solution in order to leverage these opportunities and leverage what the cloud presents you with, um, and mitigate the former, right? You need to have this, this, this opportunity in order to leverage it.
It's, it's difficult unless you have the right kind of technology that allows you to take, uh, those specific configuration to make this kind of analysis, uh, and have these kinds of insights and then leverage them in an effective way. Um, so you need to have that kind of technology and preferably, um, get it from one of the most trusted brands, um, in the cybersecurity market, um, and try out Tenable Cloud security. So thank you so much for joining our session today.
My name is Lyor, uh, and if you have any more questions, I'd love for you to reach out. Thank you so much. I.