SlideShare a Scribd company logo
Vulnerability Testing in the Cloud
by dint of DevSecOps
Owen Byrne
Cisco dCloud
obyrne@cisco.com
https://www.linkedin.com/in/owen-byrne/
@owbyrne
devopsdays Galway 2017
Our journey begins..
Enabled by some great OpenSource tools…
Cloud ‘Authorisation to Operate’ (CATO)
Conundrum
Security? Not my job!
• CD model means deployed code is constantly changing
• Security Tools vary in:
• Skill level to operate (developer friendly, automation possible?)
• Coverage (gaps & detection – false positives/negatives)
• Varied output formats (JSON, XML, Unstructured,
But…Security Testing is Hard
OpenSource: https://norad.gitlab.io/
License: Apache 2
8
Enabling DevSecOps
• Ability to plug in new, home-grown
tests & 3rd party tools quickly
• Docker images containing
preconfigured tools to scan for a
specific type of vulnerability
Containerised Security Tests
How Norad Works
Cust omer Cl oud
NORAD
Cisco Confidential
Centralised Results
Pipeline Integration
Python (boto) AWS CLIAWS Console Powershell
Tools
Cloud Module
Cloudformation
BUT…many other ways to create Infra…
AutoScaling
“You can think of CloudWatch Events as the central nervous system
for your AWS environment. It is wired in to every nook and cranny of the
supported services, and becomes aware of operational changes as they
happen. Then, driven by your rules, it activates functions
and sends messages (activating muscles, if you will) to respond to the
environment, making changes, capturing state information, or taking
corrective action.”
AWS CloudWatch Events
“AWS Lambda is a compute service that lets you run
code without provisioning or managing servers”
“…use AWS Lambda to run your code in response to
events”
AWS Lambda
Stitching Things Together
Continuous Compliance
with Lambda
Based on: https://github.com/awslabs/aws-security-
benchmark
Config Check Rule evaluated every 24hours
When SecOps show up to the meeting
http://devopsreactions.tumblr.com/post/142837211682/when-secops-shows-up-to-the-meeting
Thank You!

More Related Content

PDF
Practical Approaches to Container Security
PDF
The Future of Security and Productivity in Our Newly Remote World
PDF
Play 2 Java Framework with TDD
PDF
Docker container security
PPTX
DEVNET-1169 CI/CT/CD on a Micro Services Applications using Docker, Salt & Ni...
PDF
Faster safer and 100 user centric application at equifax with docker
PPTX
Docker crash course
PPTX
Continuous Security Testing with Devops - OWASP EU 2014
Practical Approaches to Container Security
The Future of Security and Productivity in Our Newly Remote World
Play 2 Java Framework with TDD
Docker container security
DEVNET-1169 CI/CT/CD on a Micro Services Applications using Docker, Salt & Ni...
Faster safer and 100 user centric application at equifax with docker
Docker crash course
Continuous Security Testing with Devops - OWASP EU 2014

What's hot (20)

PDF
Infrastructure as Code with Ansible
PPTX
Pulumi iac on gcp
PDF
Building Top-Notch Androids SDKs
PPTX
DevSecCon Tel Aviv 2018 - Integrated Security Testing by Morgan Roman
PPTX
Test Automation Workshop with BDD Approach
PDF
5 patterns for success for application transformation
PDF
Hacking into your containers, and how to stop it!
PDF
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
PDF
Secure Substrate: Least Privilege Container Deployment
PPT
Jenkins Overview
PDF
DockerCon EU 2015: Official Repos and Project Nautilus
PDF
All Things Open 2017: How to Treat a Network as a Container
PDF
Build & Deploy Multi-Container Applications to AWS
PDF
ScriptRock Overview
PPTX
Introduction to Containers & Diving a little deeper into the benefits of Con...
PDF
Javantura v4 - Test-driven documentation with Spring REST Docs - Danijel Mitar
PDF
Docker Security - Secure Container Deployment on Linux
PPTX
Onnx and onnx runtime
PDF
From Zero to Hero: Continuous Container Security in 4 Simple Steps
PDF
DockerCon SF 2015: Docker at Lyft
Infrastructure as Code with Ansible
Pulumi iac on gcp
Building Top-Notch Androids SDKs
DevSecCon Tel Aviv 2018 - Integrated Security Testing by Morgan Roman
Test Automation Workshop with BDD Approach
5 patterns for success for application transformation
Hacking into your containers, and how to stop it!
Know What’s in Your Containers! Manage and Secure all Open Source that Compos...
Secure Substrate: Least Privilege Container Deployment
Jenkins Overview
DockerCon EU 2015: Official Repos and Project Nautilus
All Things Open 2017: How to Treat a Network as a Container
Build & Deploy Multi-Container Applications to AWS
ScriptRock Overview
Introduction to Containers & Diving a little deeper into the benefits of Con...
Javantura v4 - Test-driven documentation with Spring REST Docs - Danijel Mitar
Docker Security - Secure Container Deployment on Linux
Onnx and onnx runtime
From Zero to Hero: Continuous Container Security in 4 Simple Steps
DockerCon SF 2015: Docker at Lyft
Ad

Similar to Vulnerability Testing in the Cloud by dint of DevSecOps (8)

PDF
DevSecOps - Background, Status and Future Challenges
PDF
Forecast 2012 Panel: Cloud Security Christofer Hoff
PPTX
Security as Code
PDF
What is exactly anti fragile in dev ops - v3
PDF
The Impact of DevSecOps on Cloud Security.pdf
PPTX
In the Cloud, nobody can hear you scream: AWS Cloud Security for DevOps
PDF
The Emergent Cloud Security Toolchain for CI/CD
PDF
DevOps Days Tel Aviv 2013: What exactly is anti-fragile in DevOps? - Asher St...
DevSecOps - Background, Status and Future Challenges
Forecast 2012 Panel: Cloud Security Christofer Hoff
Security as Code
What is exactly anti fragile in dev ops - v3
The Impact of DevSecOps on Cloud Security.pdf
In the Cloud, nobody can hear you scream: AWS Cloud Security for DevOps
The Emergent Cloud Security Toolchain for CI/CD
DevOps Days Tel Aviv 2013: What exactly is anti-fragile in DevOps? - Asher St...
Ad

Recently uploaded (20)

PPTX
MYSQL Presentation for SQL database connectivity
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPT
Teaching material agriculture food technology
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
KodekX | Application Modernization Development
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
MYSQL Presentation for SQL database connectivity
Mobile App Security Testing_ A Comprehensive Guide.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Machine learning based COVID-19 study performance prediction
Reach Out and Touch Someone: Haptics and Empathic Computing
Teaching material agriculture food technology
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Review of recent advances in non-invasive hemoglobin estimation
Per capita expenditure prediction using model stacking based on satellite ima...
The AUB Centre for AI in Media Proposal.docx
KodekX | Application Modernization Development
The Rise and Fall of 3GPP – Time for a Sabbatical?
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Chapter 3 Spatial Domain Image Processing.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Network Security Unit 5.pdf for BCA BBA.
Diabetes mellitus diagnosis method based random forest with bat algorithm
20250228 LYD VKU AI Blended-Learning.pptx

Vulnerability Testing in the Cloud by dint of DevSecOps

Editor's Notes

  • #16: https://aws.amazon.com/blogs/aws/new-cloudwatch-events-track-and-respond-to-changes-to-your-aws-resources/
  • #17: http://docs.aws.amazon.com/lambda/latest/dg/welcome.html