《254715 - Security That Enables SecurityCon 2023 -Saurabh_Wadhwa.pptx》由会员分享,可在线阅读,更多相关《254715 - Security That Enables SecurityCon 2023 -Saurabh_Wadhwa.pptx(20页珍藏版)》请在三个皮匠报告上搜索。
1、Security That Enables:Breaking Down Security Silos in the DevOps EcosystemSr.Solutions EngineerSaurabh Wadhwa2AgendaIntroduction1Rise in attacks on CI/CD ecosystem 2Security gaps in traditional pipeline 3Breakdown of Dropbox breach4Enabling Dev and Security Teams5Rise in Attacks on CI/CD Ecosystem K
2、ey Challenges in the Dev EcosystemLack of integrated and automated security testing toolsLarge and fragmented attack surface Diverse and complicated technical stackReliance on automation leads to complacencyDev Laptop to Cloud Breaches Public keys stolenEmployee GitHub tokens stolenAuthenticated ses
3、sion keys stolenSecurity Gaps in CI/CD Pipeline Why Security Gaps Persist in the CI/CD EcosystemUnrealized potential for CI/CD adoptionSystem hinges on various dependencies and configurations Haste and need for fast-paced delivery cycles Git RepositoryDeveloperLaptop DevelopmentCI/CDControl PlaneDat
4、a PlaneCode DevelopmentCode PullNode 1Node 2Node 3CI/CD ToolRegistryContainerRuntimeContainerOrchestrationBuild and Test Registry ScanningSecuring Your CI/CD PipelinePre-productionPost-productionSecuring Your CI/CD Pipeline in Runtime Control PlaneData PlaneNode 1Node 2Node 3ContainerRuntimeContaine
5、rOrchestrationIsolated Control and Data PlanesTracking Attacker Movements(e.g.Container Escape)Git RepositoryDeveloperLaptop DevelopmentCI/CDCode DevelopmentCode PullCI/CD ToolBuild and Test RegistryRegistry ScanningSecuring Your CI/CD Pipeline in Pre-Production Isolated Developer Tools Security fro
6、m Laptop to Cloud Anatomy of the Dropbox BreachDropbox:Breakdown of Events OverviewDisclosedBreachTechniques used 1234Sophisticated,targeted attack on CI/CD ecosystemNovember 1st,2022 publicly disclosed 130 internal repos cloned Public and private code in the stolen reposPhishing emails,enumeration(