Secure Your AWS Workloads From Code to Cloud at Cloud Native Now 2024
In the evolving landscape of AI and cloud computing, ensuring the security of your AWS workloads is more critical than ever. Discover how enhanced visibility can help you establish robust data security measures, mitigating the risks associated with unauthorized access and data breaches. This technical solutions session will give you the knowledge to confidently protect your trade secrets, proprietary information, and customer data.
Key Points:
– Enhanced Security Practices: Learn how to implement comprehensive security strategies for your AWS AI workloads from development through deployment.
– Visibility into AI Workloads: Understand how to gain critical visibility into your AI operations, helping you to identify and mitigate potential security risks.
– Risk Management: Explore effective methods to manage and reduce risks associated with AI workloads, ensuring your data remains secure and compliant.
– Security in Action: Discover how Sydsig’s AI Workload Security to AWS AI services, including Amazon Bedrock, Amazon SageMaker, and Amazon, bolsters the security of AI workloads in the cloud.
Transcript
Hello, and welcome to today's event, secure your AWS workloads from code to cloud. We have two great speakers joining us today. Eric Carter, director, product marketing at Cystic and Thermo Dilio, the security partner solutions architect from Amazon Web Services.
I know they've got some great content for you, as well as a demo to kind of see everything in action, so I'm gonna turn it over to them. To get started, Security remains a top priority. Leaders have traditionally viewed security as cumbersome through the process of innovation.
This is complicated by a global shortage of security professionals and expertise in cloud environments. The evolving threat landscape in the street, increasing demands around data protection and pharmacy. So how do we approach this at AWS today?
It is possible to automate many of the basic security tasks like patching with the right tooling to gain the visibility needed to accurately identify and monitor critical assets and data. With the cloud, all of this is made much easier so you can stay agile while maintaining, and in many cases, improving security by providing highly integrated longing and monitoring, as well as integrate, automate secure security functions. Organizations can use AWS to innovate quickly and maintain their security posture.
Customers need to be confident that they are migrating and building on Secure Cloud Foundation. Finally, customers need trusted partners to extend the benefits of the cloud with consulting expertise managed services, and in, in the case of cs, dig, innovative technology, making sure that their organization is secure from end to end. As organizations migrate and build on the cloud, they need to, they need assurance that they have secure foundations.
AWS has the most proven operational expertise of any cloud provider. Our cloud infrastructure is highly trusted and secure by design, giving customers the confidence to accelerate innovation. Customers benefit from a cloud network architecture built to meet the requirements of most security sensitive organizations, including governments, financial services, and healthcare.
Security is the central pillar around which AWS infrastructure and services are designed and managed. Building securely should be the path of least resistance with no trade off between security, with speed, with security automation team speed, there are limited time on the highest value task, reduce human error and scale security best practices across the organization. AWS provides organization-wide controls that automate infrastructure and application security checks to continually enforce security and compliance controls.
Organizations require powerful capabilities designed and built by experts, which encode years of experience, knowledge, and best practices all available at their fingertips. They don't want to navigate these changing threats and compliance landscapes alone. AWS security services and solutions help customers implement every step of their organizations optimal security posture from identifying risk to remediations, customers can extend the benefits of AWS by using security technology and consulting services from, and in the case of sig, the AWS partner network.
So we look after the security of the cloud. So all of the components and infrastructure within the cloud is managed by AWS, and we rely on our customers and our partners to, to look after the security in the cloud. AWS responsibility, security of the cloud.
AWS is responsible for predicting the infrastructure that runs all of the services offered in the AWS cloud. This infrastructure is composed of the hardware, software, networking and facilities that run AWS cloud services. Customers are responsible.
Responsibility will be determined by the AWS cloud services that a customer chooses to select. This determines the amount of configuration work the customer has perform as part of their security responsibilities. For example, services such as Amazon EC2 or Elastic Compute Cloud, Amazon VPC or Virtual Private Cloud and Amazon S3 are simple storage are categorized as infrastructure, as services, and as such, require the customer to perform all of the necessary security configurations and management tasks.
If a customer deploys an Amazon EC2 instance, they are responsible for management of the guest operating system, including updates and security badges, any application software or utilities installed by the customer on the instances and the configuration of AWS provided firewalls called a security group on each instance. Lastly, AWS is your guide to understanding executing best practices to manage and reduce security risk and protect your networks and data built by experts. AWS security identity and compliance services give you the confidence to keep building and innovate.
We have five pillars that all comprise of this five security domains and each service, which we work with our security partners to help implement in each particular use case, leveraging each of our. Lastly, here are some customer examples that we choose to highlight that of customers leveraging our security service to make sure that their cloud foundations, that their applications running on on the cloud are secure and protected. Now, I'll pass it over to Eric so that he can talk a little bit more about how AWS Andy work together to deliver for our customers.
Hey, thank you, Theo. And it's, it's good to sort of see the insight around security from AWS the solutions you offer, and I'm glad you're still using the slide about shared responsibility, because that is the, that is the, uh, opening, if you will, for, for us to help those customers make sure they're doing all the right things for those workloads that they are securely running on, on AWS and together. Really that's what the purpose of this little phrase is, right?
We want not just to help them be secure, but to help accelerate their innovation. You, you started it out with a great picture, which was used to be, you know, you can deliver fast, uh, or you're gonna slow down because of security. Now you, now you can do both and time and the element of time around both innovation and security is a key for, for sig and for those of you who aren't familiar with our solution, you know, there's this term out there.
Many of us probably would choose something else, but it's called cdap, right? Cloud native application protection net. Net is what that means is, you know, OO over time, different practices have emerged.
Some of the solutions Theno showed, uh, from AWS will, will help you with many of these little black ovals here. You know, whether you're needing to manage vulnerabilities, configurations, permissions, uh, from a prevention standpoint, or do things like understand active risk right now, issues with my workloads and so on. And, and the platform approach is simply this.
What if we could consolidate these things, have much more of a, um, a correlation between these things, because often they rise together. And part of the promise of this session was code to cloud, right? Sometimes a vulnerability makes its way through to production.
You really wanna, when you're dealing in the code world to solve those things there if you can, but every day new ones emerge. And so therefore you might end up with something in production that you need to, um, manage or keep an eye on or something bad happens, right? You want to know that, right?
And so from a cystics perspective, and I'll show you in the demo, is we're trying to bring these things together, give you a, a view of risk prioritized, and help you understand the, the different correlation between any one of these practices. So CA platforms bring together a group of practices, um, to help you kind of move faster so you don't have to jump context between tools, um, and to give you sort of a, a, uh, a view into all of these things in a single pane. And so that's what CYSTIC brings, um, to the, to the table, if you will.
And let's take another look at it, you know, starting with the left hand side, it's a bit about where, where theto, um, spoke, uh, you know, we wanna be able to manage the posture of our environments, right? We want to know if I'm a company that deals in the world of credit cards, am I set up correctly in order to achieve the goal of PCI compliance, for instance, payment card industry standard, right? Or others, you know, there's new standards in in Europe, NIST and Nora, and different things around finr, right?
So the idea is, look, when I'm responsible for part of the security, I might actually not configure something correctly and just not know. And so we want to be able to understand, yes, this is something that as configured, puts you at risk. And so you can measure those things.
You can measure against standards, which all this is typically tied together, have right controls in place. Um, are they doing the thing they're supposed to do? And can I turn and tell auditors or management that this is what we're up to, right?
Uh, addressing vulnerabilities. I touched on that a little bit, but you know, the more and more in the world of containers, for instance, right? We're grabbing things from open source repositories and we're using them.
It, it, it helps us with these building blocks, but it's on us to be able to scan those things. We wanna scan them early. That's the whole shift left concept, right?
Scan them early in our pipelines in our registry, but we also want to continue scanning because there's so many new vulnerabilities reported every day. So how can we understand those things, but then also filter and prioritize because there are so many, and I'll show you in Cystic how we can help with that. We wanna be able to prioritize so that we are narrowing the scope of what we actually have to fix and not drowning in a sea of vulnerabilities.
Access is another one, right? AWS provides a lot of access controls, access analyzer helps you with that. But the, the, the bottom line is, you know, it all starts with permissions.
We, we have machines and we have humans and services that may be given too many permissions, and a lot of times that's the door in and we need to manage that, right? If I've given Erno admin access to everything, but he doesn't need it, then I've probably, you know, uh, made a mistake, right? And expose ourselves to it.
So this idea of Kim Cloud infrastructure, entitlement management and being able to measure and monitor that is key also for security. And then, you know, the key, uh, uh, I would say pillar around which cystic began its life is really around monitoring for active risk, right? So think about the term like cloud detection and response, threat detection, runtime security, right?
You really wanna be able to watch that running environment, and that's a key part of that shared responsibility model, right? To know when something is happening, to be able to understand what that thing is that's happening, and potentially even see what additional risk does this thing that triggered pose for my business and help, help deal with that. So again, the concept of, uh, a platform approach or synap is to correlate across these things and provide that picture.
Now, along the way, when I'm in the demo, I'll show you this, but one of the things that CYSTIC has been, uh, establishing in the market, because things move so quickly in the cloud, again, back to Theo's point, right? The, the same technology we're using to deliver applications faster, you know, adversaries are also leveraging. And so, you know, in 10 minutes or less, there can be damage caused.
And so the benchmark that I think businesses are now striving toward is the ability to, in 10 minutes or less, be able to, to deal with an issue, at least take our first steps of response. So, can I detect in real time five seconds or less, right? If it's longer than that, um, if it takes 15 minutes in order to see something happen, that's already five minutes too long, right?
So can I detect in five seconds? Can I, then I'll then spend five minutes trying to understand, investigate, correlate, deal with what's going on, and then jump into what is the best response to stop the issue? And then we can, we can take it from there.
And so I would encourage you to read about this benchmark. I've put the quick link there for you. And everything we're doing at, uh, cystic Together with AWS is to help organizations move toward this standard.
It's not easy, trust me, there's a lot of things that have to, to line up, but this is where we want to be in order to not just keep pace with adversaries, but to stay ahead of them. Alright? And one thing before I jump into the demo, I'm excited.
Theo and I were together last week in Philadelphia, or, uh, the AWS security show reinforced, and we announced, um, what we call AI workload security for AWS and I'll show you a little bit of flavor of this in the demo, but for those of you who are starting to move into the world of gen ai, large language models, um, first of all, AWS is doing a ton of work here. And you see some of the solutions on screen here, like bedrock as your sort of foundation or, or things like SageMaker and ML that it provides, and Amazon q sort of your interface to all these things. So there's a lot of tools that you can use.
There's a lot of apps you can build against these things. And so what is our goal? Our goal is cystic like any application, but also acutely for ai because of the sensitivity typically of the data, we're, we are here to help you understand that it's being used, right?
Understand what the activity is, and then again, what I'll show you is to be able to correlate, correlate insights around the things that are, that are happening in the environment, whether it's a static risk or whether it's something more active, right? Our goal is to help you what, to achieve that goal of fast response security, fast security so that we take care of the issues and move forward with our business. So streamlining and helping to reduce response time is key.
So that brings me to the demo. I'm gonna share my screen and hopefully take you through a quick journey just to show you some of these things to give you a flavor. I've landed inside of, um, sig, uh, our sa sig secure our SaaS platform, by the way, you're welcome.
Fiero runs on AWS, um, and what you're seeing is kind of, and again, talking about being a platform, you're seeing various kind of insights at a high level in the home screen around things like runtime events. We talked about that as a key tenant watching our environment or perhaps vulnerabilities and how we're doing and what's our kind of level of, you know, uh, vulnerabilities that are out there and potentially exploitable or maybe not in use where we can worry less about them or even things like, um, posture related things. And I'll take, I'll take you through some of that as well.
And then we talked about user information and sort of understanding who's doing what, what permissions are out there, which ones are being, uh, unused and so on. And, and one of the places I I like to start is simply, you know, the, uh, our inventory screen and why would I start here? Well, a lot of times things move so quickly and, and, and by the way, AWS makes it easy for you to spin up new infrastructure and services in order to support applications that you're gonna wanna know that these are out there, whether that's something related to, uh, cloud native or containers, or maybe it's more of a classic service.
So what we've done at SIG is we interact with AWS, we, we, uh, tap agentlessly into APIs, into cloud trail logs and those kind of things in order to say, okay, show me in my environment what kind of resources are out there, right? And assuming that I am seeing it over time, I can start running posture policies against see how I'm doing. Frankly, in my demo environment, we're not doing very well, but we have a lot of ECS tasks, um, and I can keep going.
And there are other areas, for instance, where, um, I've actually also scanned the workload to understand things like what are the vulnerabilities that are there? And some of the posture, so vulnerabilities, some of the posture capabilities that are there. So, uh, it's good to know what's out in the environment.
One of the exciting, newest things is that I have, this contains AI package option. And again, this is specifically to say, Hey, I want to know if AI is making its way into my environment, sorry, I need to actually also collect, select all this, right? And then I can see, right?
Um, I've got AI packages and applications that are interacting with bedrock out in my, uh, EKS environment, right? And so why would I want this awareness? Well, because a lot of organizations are concerned about the use of AI in their environments, the data that it's being trained on and so on and so forth.
And so by being able to automatically discover and show you this, and even automatically start to apply policies against it, we can help you keep track of those things. And ultimately, whether we're talking about the idea of managing vulnerabilities, or we're talking about things like the posture and compliance, or even permissions, ultimately what we want to help deliver so that you can kind of rise up out of the noise is this idea of risk. Uh, and bubbling up the risks that are inside of your environment.
And the way that we're doing this, remember I used the word correlate, is we wanna be able to say, Hey, there is something going on here, and it is, uh, not just one alert that's firing, but sort of a, a stateful, um, risk here that has various things associated with it that are across the stack, whether it's, uh, a vulnerability configuration issue, and so on. So I can open this up and, um, take a look at this. And one of the things we do for you, and I'm, I'll expand this, is sort of draw this, um, attack path map.
And I know the word attack is, is quite scary, but what we can do is say, okay, what's going on here with the particular workload that needs my attention? Well, one, we see that it's facing the internet, so that's always helpful to know because that's, you know, a lot of times we're gonna wanna make sure like we have permissions and things locked down, which in our case here, we are identifying that part of this is there are some permission issues that need to be managed, right? And we will help you to view more about that and understand some of the things that we are seeing, like you're not actually following the best practice, right?
And if you're not following the best practice, then obviously it's going to leave you exposed and potentially let someone in. Similarly things like, oh, this is work, this is workloads running on EKS and is operating in a container. There may be critical CVEs or vulnerabilities associated with those things, and we want to ask the right teams to actually, uh, go to the latest update if possible, right?
And look, in my example, there is no fix available. So we're in a bit of a, uh, a quandary here, but this is why the combination of things is so important. If we are, uh, trying, if we have allowed a vulnerability to run a production, what else do we want?
Well, we want to be able to monitor and make sure that that vulnerability is not being, uh, manipulate it or exploit exploited, right? And then, so we're going, we're showing you all of the construct of how this all works together, but also showing you in real time what's, what's raw, right? And in this case, we're also doing live threat detection and we see a malicious binary that's been detected, right?
And again, we can dive in and this is done carob SIGs runtime, uh, security or cloud detection and response, which is built on, and I'll show you in a second, which is built on open source Falco, which you see here, hopefully, um, that these are, are rules that are observing at a fine grain level in your environments. Whether that's data source is something like sys calls via Linux, EVPF, whether it is a cloud trail log, whether there are other things that we've plumbed in like Okta logs or GitHub logs, right? To be able to say, Hey, this thing is happening.
We've got it from this data source, we're telling you within seconds and now what you need to, uh, actually, um, jump into action. Now, the cool thing about jumping into action was something we just launched, um, recently, is we can actually say, I wanna investigate this particular issue. And what's great about this is I can actually get information not just about the issue and not just about where it happened, where is important, but also where, for instance, are the user, uh, users that might have been behind some of these things, right?
So if I click, I can see, oh, well, uh, this is happening in Council Bluffs, United States, right? And we can start to, to dive in and get more details so that we can investigate right what's going on and really understand what's going on. And, and, um, this is key for various reasons, one of which is, lemme go to my events overview, one of which is that we really want to be able to get a handle on what's taking place where, right?
Here's another great example. CloudTrail deleted. Yeah, that's not best practice, is it?
Yep. No, it's not. We want to have those cloud trails activated and understand where they are.
And so in this instance, we see that there's a user user called GitHub ci, and this thing is taking place, right? And in a way, if this is, if there are logins happening across all these different locations, we probably have an issue here where this is not necessarily the way the world should be working, and we probably have a security issue. So you can continue to dive in, understand what is the content of the event, who's doing it, where is it?
And we also have various tags so that you can understand, look, if I need to be ISO 27 0 0 1 compliant, and this is triggering, I'm at risk, right? So all of these things work together to get you to the bottom of the issue and help you address the threat in particular. Um, alright, and so we've walked through a bit of the overview.
Um, now that we understand what's happening in real time and runtime, one of the last things I wanna show you that's pretty cool, and I'm gonna double back a little bit, but when we're watching at runtime and we're looking at where are the vulnerabilities that I have, one of the things here is I can say, okay, um, here I've found some vulnerabilities in and around this particular workload, right? One of the things I can do is say, well dial in for me, oh, wow, three, 3,408. Well, I only care about the, the medium and high ones, right?
Or maybe it's just high and above. Let's do that instead. So I'm gonna be able to go and narrow that down.
I still have too many, right? 564. And one of the things that becomes interesting is, is it exploitable?
Now I'm down to a reasonable number. Uh, is there even a fix available? Now, here's the magic, right?
Where Cy will say, well, is it, is this particularly, uh, this vulnerable package even being used, right? And now I'm down to 10. And so adding the insight that we get, we have the all information, we have the profile of what's happening at runtime, and we marry those things to try and help teams know where to work first in order to make what we're, uh, what we do in a day, in a day out basis, address real risk versus just spinning our wheels, fixing cvs that may not matter.
So I wanted to show that because it's sort of a result of all the things that we've brought together and what we call runtime insights, the ability to spot in use issues and problems, um, versus the ones that aren't used, which means the exposure is, is, uh, not at the same level. And so bringing all that together is really what our platform is all about. And we do a lot as you see here around AWS and, you know, sort of a, a, uh, broad cloud spec.
So we're gonna pause here, but before we go to q and a one, thank you for watching, um, and spending time with us today. We have a few questions we will answer. Um, we are available on AWS marketplace.
It's a great place to go see what kind of security solutions are available to augment your AWS environment. com. There is an asset there, and I think, um, you, you, uh, should be able to get it right here in the interface, but do visit that page to get a little more details on, on.
So our recommendation, so five steps to securing right? Infrastructure and workload, frankly. And so, uh, just some things to help move you along if you're here to learn more about, uh, recommended best practice.
Well, I wanna thank you both. This has been a very enlightening session, and thank you for your flexibility and grace, and at this time I'm going to end the webinar. Have a great rest of your day, everyone.
Thank you everyone. Thank you. Thanks everyone.