AWS身份威胁建模:从联合身份验证到资源访问.pdf

编号:1013120 PDF 51页 456.41KB 下载积分:VIP专享
下载报告请您先登录!

AWS身份威胁建模:从联合身份验证到资源访问.pdf

1、 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.S E C 3 3 5Threat modeling for AWS identity:From federation to resource accessMeg Peddada(She/Her)Senior Partner SAAWSAlex Waddell(He/Him)Senior Security Specialist

2、SAAWS 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Answer these four questionsHow to threat model 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.What are we working on?What can go wrong?What are we going to do about it?Did we do a good enough job?Answer thes

3、e four questionsHow to threat model 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Threat framework example:STRIDESpoofingTamperingRepudiationInformation disclosureDenial of serviceElevation of privilege 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Threat st

4、atementA threat source with pre-requisites,can threat action,which leads to threat impact,resulting in goal of impacted assets.2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Tooling at AWSThreat ComposerA simple open source and free to download threat modeling tool to help humans

5、 to reduce time-to-value when threat modelinghttps:/awslabs.github.io/threat-composer/2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.Scenario:User managing applicationResourcesAWS Identity and Access Management(IAM)Web browser/CLIUserAuthn/AuthZAWS CloudAWS VPCAWS accountIdentity

6、 ProviderAWS IAM Identity Center 2025,Amazon Web Services,Inc.or its affiliates.All rights reserved.AWS IAM Identity CenterData StoreData Flow&Trust Boundaries2User accesses the data storeData store validates credentialsExternal Identity Provider1IdP Group&User sync(SCIM)4User retrieves data from th

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(AWS身份威胁建模:从联合身份验证到资源访问.pdf)为本站 (明日何其多) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠