security & sre: natural force multipliers...-- archilochus, greek poet. 2018 “what’s the...

23
SRE Bruno Connelly Security & SRE: Natural Force Multipliers SREcon18 Cory Scott CHIEF INFORMATION SECURITY OFFICER

Upload: others

Post on 05-Oct-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

SRE

Bruno Connelly

Security & SRE: Natural Force Multipliers

SREcon18

Cory ScottCHIEF INFORMATION SECURITY OFFICER

Page 2: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Why should Security and SRE be so closely aligned?

Page 3: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

LinkedIn’s Engineering Hierarchy of Needs

Magic

Site Up & Secure

Technology at Scale

Development at Scale

Solid APIs & Building Blocks

Page 4: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

"the fox knows many things, but the hedgehog knows one

big thing."

-- Archilochus, Greek Poet

Page 5: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can
Page 6: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

2018

Page 7: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“What’s the state of product development and infrastructure?”

??

??

MICROSERVICE ARCHITECTURE

SCALING TO MEET DEMANDS

3RD PARTY ADOPTION EXPLODING

DATACENTER TECH ACCESSIBLE

FOR EVERYONE

FAST RATE OF EVOLUTION

PRODUCT VISUALIZED IN AM, DEPLOYED IN PM

!!

!!

That seems….. great?

Page 8: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“How are we doing on defense?”

??

??

!!

!! COMPLIANCE

INITIATIVES?

MAGIC BOXES?

CUSTOMER ASSURANCE?

NETWORK ACCESS

CONTROL?

ENDPOINT SECURITY PRODUCTS SUCH AS

ANTI-VIRUS?

BOUNTIES?

What!?!

Page 9: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

...

Page 10: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Site Reliability Hierarchy of Needs

Product

Monitoring & Incident Response

Post-Mortem & Analysis

Testing & Release Procedures

Capacity Planning

SRE Hierarchy of Needs from Google SRE book

Page 11: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“Changes in production applications are happening at a greater rate than ever before. New product ideas can be visualized in the morning and implemented in code in the

afternoon.”

Page 12: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Innovation and Rate Of Change

Embrace the Error Budget• Self Healing & Auto Remediation• Reduction of Manual Process

Inject Engineering Discipline• Review when architecture changes reach a

certain complexity point.

“Trust but Verify” • Security to follow SRE “trust but verify”

approach towards engineering partners

Page 13: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“Testing in production is the new norm”

Page 14: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Establishing Safe & Reliable Test Environments

SRE SECURITY

Page 15: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“Microservice architectures are exploding to meet scalability requirements”

Page 16: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Microservice ArchitectureSECURITY CHALLENGES ARE SIMILAR TO SRE

● Authentication

● Authorization

● Access Control Logic

SRE Challenges Security Challenges

● Latency & Performance Impact

● Cascading Failure Scenarios

● Service Discovery

Page 17: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“Dependencies on third-party code and services can be collected faster than you

can inventory them.”

Page 18: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Visibility in Your Third-Party Services

Page 19: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

“Data center technologies can all be controlled with a single web application in

the hands of a devops intern.”

Page 20: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Production Access & Change Control

Configuration as code, leveraging source code control paradigms, are a huge boon to security.

Rollback ruthlessly.

● Start with a known-good state ● Asset management and change control discipline● Ensure visibility● Validate consistently and constantly

Page 21: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

TAKEAWAYS OR GIVEAWAYS (DEPENDING ON YOUR POSITION IN THE AUDIENCE)

Page 22: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Overall Lessons for Security

Human-in-the-loop is your last resort, not your first

option

2

All security solutions must be scalable and default-on,

just like SREs build it

3

Your data pipeline is your security lifeblood

1

Page 23: Security & SRE: Natural Force Multipliers...-- Archilochus, Greek Poet. 2018 “What’s the state of product development and infrastructure?” ... “Data center technologies can

Overall Lessons for SRE

Remove single points of security failure like you do

for availability

1

Assume that an attacker can be anywhere in your system

or flow

2

Capture and measure meaningful security

telemetry

3