SlideShare a Scribd company logo
Mapping Data Flows Across
Apps, Microservices & APIs
Presented by:
Etan Lightstone, VP of Product Design
Agenda
• Mapping Data Flows is Getting Harder
• Common Leakage Scenarios
• Mapping Flows with Semantic Graphing
• Demo
• Q&A
2.5 quintillion bytes of data is created every day
Mapping Data Flows is Getting Harder
Faster releases
Less time to
understand code
Modular
architectures
More siloed
knowledge
Open source & 3rd
Party APIs
More complexity &
external leakage
GDPR & CA Privacy
Act 2018
More types of data
become critical
CRM
Logs
Data Flows & Leakage
Storage Buckets
Database
Customer
Microservice
A
Microservice
B
Microservice
C
Microservice
D
Code Repository
Virtual Machine (Java VM)
Web Framework (Spring Boot)
Open Source Dependencies
Your Application
Logic
Your Application Stack’s Code Property Graph
SemanticGraphing
Example information flow
Querying the graph for visibility & security issues
Semantic
Graph
Exit Points
Entry Points
Vulnerabilities
Dependencies
Custom code
Data Leaks
Security DNA
Demo
Free Data Leakage Assessment
• Discovery & classification of sensitive data
• Handling across microservices & exit points
• GDPR compliance readiness
• Discovery of known & unknown vulnerabilities
Sign-up here:
• https://go.shiftleft.io/data-leakage-assessment
Mapping Data Flows Across Apps, Microservices & APIs
Mapping Data Flows Across Apps, Microservices & APIs
Free Data Leakage Assessment
• Classification
• Handling
• GDPR
• Vulnerabilities
Sign-up:
• https://go.shiftleft.io/data-
leakage-assessment

More Related Content

PDF
Under the Hood of Totango's Award Winning Technology
PDF
Architecting Petabyte Scale AI Applications
PDF
[WSO2Con EU 2018] Kicking Your Enterprise Security Up a Notch With Adaptive A...
PDF
[WSO2Con EU 2018] A New Service Architecture for Effective Business Services
PDF
Workshop: Threat Intelligence - Part 1
PPTX
CSA Presentation - Software Defined Perimeter
PDF
IoT Dynatrace
PPT
Application Integration - Todd Swedeen, Evergreen Solutions
Under the Hood of Totango's Award Winning Technology
Architecting Petabyte Scale AI Applications
[WSO2Con EU 2018] Kicking Your Enterprise Security Up a Notch With Adaptive A...
[WSO2Con EU 2018] A New Service Architecture for Effective Business Services
Workshop: Threat Intelligence - Part 1
CSA Presentation - Software Defined Perimeter
IoT Dynatrace
Application Integration - Todd Swedeen, Evergreen Solutions

What's hot (10)

PDF
LeanIX introduction_pathfinder_v2
PDF
[WSO2Con EU 2018] Decentralized Data Architectures
PPTX
The Future of CASBs - A Cloud Security Force Awakens
PDF
End-to-End Security Analytics with the Elastic Stack
PPTX
Azure Refresh 2015 - KeyNote - DotNetLombardia
PDF
Keynote: Making search better, faster, easier
PPTX
apidays LIVE New York 2021 - Securing access to high performing API in a regu...
PPTX
AWS and Sumo Logic Webinar: Simplify Compliance with Proactive Machine Data A...
PDF
Elastic Stack: Using data for insight and action
PPTX
Digital Ethics and Privacy in a GDPR World
LeanIX introduction_pathfinder_v2
[WSO2Con EU 2018] Decentralized Data Architectures
The Future of CASBs - A Cloud Security Force Awakens
End-to-End Security Analytics with the Elastic Stack
Azure Refresh 2015 - KeyNote - DotNetLombardia
Keynote: Making search better, faster, easier
apidays LIVE New York 2021 - Securing access to high performing API in a regu...
AWS and Sumo Logic Webinar: Simplify Compliance with Proactive Machine Data A...
Elastic Stack: Using data for insight and action
Digital Ethics and Privacy in a GDPR World
Ad

Similar to Mapping Data Flows Across Apps, Microservices & APIs (20)

PDF
GraphSummit Europe 2024 - From Data Lakes to Knowledge Graphs (LSEG).pdf
PDF
2022 APIsecure_API Abuse - How data breaches now and in the future will use A...
PDF
Apidays Helsinki & North 2024 - Data, API’s and Banks, with AI on top by Serg...
PDF
Software Analytics with Jupyter, Pandas, jQAssistant, and Neo4j [Neo4j Online...
PDF
10 tips for enabling data discovery and governance in your organization
PDF
2018 12-10 apidays.io eric horesnyi streamdata.io event-driven ap is
PDF
October 2014 Webinar: Cybersecurity Threat Detection
PDF
Reduce API Security Risk by Leveraging Graph Analytics Webinar Slides
PPTX
100X Investigations - Graphistry / Microsoft BlueHat
PDF
Semantic Security : Authorization on the Web with Ontologies
PPTX
Crack the Domain with Event Storming By Vivek
PDF
Smart Data Webinar: Choosing the Right Data Management Architecture for Cogni...
PPTX
PPTX
Real time insights for better products, customer experience and resilient pla...
PDF
EVOLVING PATTERNS IN BIG DATA - NEIL AVERY
PPTX
Agile Mumbai 2022 - Balvinder Kaur & Sushant Joshi | Real-Time Insights and A...
PDF
APIdays Paris 2018 - Event-Driven APIs Eric Horesnyi, CEO, Streamdata.io
PDF
OpenDataSoft - Towards Cost-efficient Innovation with Data Open Platforms
PPTX
Finding Zero-Days Before The Attackers: A Fortune 500 Red Team Case Study
PDF
Describing the Organisation Data Landscape
GraphSummit Europe 2024 - From Data Lakes to Knowledge Graphs (LSEG).pdf
2022 APIsecure_API Abuse - How data breaches now and in the future will use A...
Apidays Helsinki & North 2024 - Data, API’s and Banks, with AI on top by Serg...
Software Analytics with Jupyter, Pandas, jQAssistant, and Neo4j [Neo4j Online...
10 tips for enabling data discovery and governance in your organization
2018 12-10 apidays.io eric horesnyi streamdata.io event-driven ap is
October 2014 Webinar: Cybersecurity Threat Detection
Reduce API Security Risk by Leveraging Graph Analytics Webinar Slides
100X Investigations - Graphistry / Microsoft BlueHat
Semantic Security : Authorization on the Web with Ontologies
Crack the Domain with Event Storming By Vivek
Smart Data Webinar: Choosing the Right Data Management Architecture for Cogni...
Real time insights for better products, customer experience and resilient pla...
EVOLVING PATTERNS IN BIG DATA - NEIL AVERY
Agile Mumbai 2022 - Balvinder Kaur & Sushant Joshi | Real-Time Insights and A...
APIdays Paris 2018 - Event-Driven APIs Eric Horesnyi, CEO, Streamdata.io
OpenDataSoft - Towards Cost-efficient Innovation with Data Open Platforms
Finding Zero-Days Before The Attackers: A Fortune 500 Red Team Case Study
Describing the Organisation Data Landscape
Ad

More from DevOps.com (20)

PDF
Modernizing on IBM Z Made Easier With Open Source Software
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
PDF
Next Generation Vulnerability Assessment Using Datadog and Snyk
PPTX
Vulnerability Discovery in the Cloud
PDF
2021 Open Source Governance: Top Ten Trends and Predictions
PDF
A New Year’s Ransomware Resolution
PPTX
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
PDF
Don't Panic! Effective Incident Response
PDF
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
PDF
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
PDF
Monitoring Serverless Applications with Datadog
PDF
Deliver your App Anywhere … Publicly or Privately
PPTX
Securing medical apps in the age of covid final
PDF
How to Build a Healthy On-Call Culture
PPTX
The Evolving Role of the Developer in 2021
PDF
Service Mesh: Two Big Words But Do You Need It?
PPTX
Secure Data Sharing in OpenShift Environments
PPTX
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
PDF
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
Modernizing on IBM Z Made Easier With Open Source Software
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
Next Generation Vulnerability Assessment Using Datadog and Snyk
Vulnerability Discovery in the Cloud
2021 Open Source Governance: Top Ten Trends and Predictions
A New Year’s Ransomware Resolution
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
Don't Panic! Effective Incident Response
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
Monitoring Serverless Applications with Datadog
Deliver your App Anywhere … Publicly or Privately
Securing medical apps in the age of covid final
How to Build a Healthy On-Call Culture
The Evolving Role of the Developer in 2021
Service Mesh: Two Big Words But Do You Need It?
Secure Data Sharing in OpenShift Environments
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...

Recently uploaded (20)

PDF
A comparative analysis of optical character recognition models for extracting...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
A Presentation on Artificial Intelligence
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Machine learning based COVID-19 study performance prediction
PPT
Teaching material agriculture food technology
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Assigned Numbers - 2025 - Bluetooth® Document
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Cloud computing and distributed systems.
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
A comparative analysis of optical character recognition models for extracting...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
A Presentation on Artificial Intelligence
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Machine learning based COVID-19 study performance prediction
Teaching material agriculture food technology
NewMind AI Weekly Chronicles - August'25-Week II
The Rise and Fall of 3GPP – Time for a Sabbatical?
Assigned Numbers - 2025 - Bluetooth® Document
The AUB Centre for AI in Media Proposal.docx
Chapter 3 Spatial Domain Image Processing.pdf
Cloud computing and distributed systems.
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
20250228 LYD VKU AI Blended-Learning.pptx
MIND Revenue Release Quarter 2 2025 Press Release
Digital-Transformation-Roadmap-for-Companies.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

Mapping Data Flows Across Apps, Microservices & APIs

  • 1. Mapping Data Flows Across Apps, Microservices & APIs Presented by: Etan Lightstone, VP of Product Design
  • 2. Agenda • Mapping Data Flows is Getting Harder • Common Leakage Scenarios • Mapping Flows with Semantic Graphing • Demo • Q&A
  • 3. 2.5 quintillion bytes of data is created every day
  • 4. Mapping Data Flows is Getting Harder Faster releases Less time to understand code Modular architectures More siloed knowledge Open source & 3rd Party APIs More complexity & external leakage GDPR & CA Privacy Act 2018 More types of data become critical
  • 5. CRM Logs Data Flows & Leakage Storage Buckets Database Customer Microservice A Microservice B Microservice C Microservice D Code Repository
  • 6. Virtual Machine (Java VM) Web Framework (Spring Boot) Open Source Dependencies Your Application Logic Your Application Stack’s Code Property Graph SemanticGraphing
  • 8. Querying the graph for visibility & security issues Semantic Graph Exit Points Entry Points Vulnerabilities Dependencies Custom code Data Leaks Security DNA
  • 10. Free Data Leakage Assessment • Discovery & classification of sensitive data • Handling across microservices & exit points • GDPR compliance readiness • Discovery of known & unknown vulnerabilities Sign-up here: • https://go.shiftleft.io/data-leakage-assessment
  • 13. Free Data Leakage Assessment • Classification • Handling • GDPR • Vulnerabilities Sign-up: • https://go.shiftleft.io/data- leakage-assessment