A Live Demo of a Cloud Misconfiguration Breach.

Amazon Web Services - Bay Area
Amazon Web Services - Bay Area
Public group

Intuit Building 6

2750 Coast Avenue · Mountain View, CA

How to find us

This is the only single story building next to the waterfall

Location image of event venue


Schedule and Agenda:

6:00 - 6:30 : Arrive and Network!
6:30 - 6:40 : Announcements and sponsors recognition
6:40 - 7:40 : A Live Demo of a Cloud Misconfiguration Breach
7:40 - 8:00 : More networking

Speaker: Josh Stella
Josh Stella is co-founder and CTO of Fugue, the company delivering autonomous cloud infrastructure security and compliance. Previously, Josh was a Principal Solutions Architect at Amazon Web Services (AWS), where he supported customers in the area of national security. Prior to Fugue, Josh served as CTO for a technology startup and in numerous other IT leadership and technical roles over the past 25 years.

Presentation: Cloud misconfiguration is now the leading cause of cloud-based data breaches, typically due to a lack of secure cloud architecture practices. Because cloud infrastructure is 100% software, cloud security is a software engineering problem, not a traditional security analysis problem. In order to prevent data breaches in the cloud, we must address it with secure software architecture right from the start.

In this talk, Josh Stella will run a live simulation of an advanced cloud misconfiguration exploits to show a number of ways common cloud architectural anti-patterns create opportunities for hackers to gain entry to cloud environments, move laterally using tools like IAM services, and ultimately discover and breach data. Many of the misconfigurations exploited won’t be flagged by compliance scans and often aren’t considered risky by security teams.

Attendees will learn
* how common cloud architectural practices can lead to misconfiguration
* how hackers exploit those misconfigurations to breach sensitive data
alternative cloud architectural approaches can prevent them
* Actionable information to improve their cloud security posture

A quick survey: I'm thinking about organizing a one day Code Camp style conference in the Bay Area (free for attendees.) If you would be interested in attending that, please let me know which topics you would be interested in. https://docs.google.com/forms/d/e/1FAIpQLSfO1HYWtfD2iyYKwifsdJiHud2LRm0giZlAGfDUI3jRBfZghQ/viewform?usp=sf_link . The topics will be approved by the community and the talks will all be centered around code.

Presence Sponsor: Fugue - https://www.fugue.co/

Food and Space Sponsor: Intuit
Intuit is hiring. Intuit is a great place to work. https://careers.intuit.com/

Want to be a speaker?
If you have an educational DevOps or AWS related topic, please fill out this form (https://goo.gl/forms/mE1f5wJEnyUt3PeR2)

Want to be a Sponsor?
Interested in promoting your company and brand. Sponsor our meetup. It's quick, easy, and profitable! (http://www.meetup.com/awsgurus/pages/20874992/Sponsor_the_AWS_Bay_Area_Meetup/)