Patrick Kelley - Going Bananas for Cloud Security: AWS deployment with security_monkey - AppSecUSA15
Description:
Explore cloud security auditing and monitoring for AWS deployments using Netflix's open-source tool security_monkey in this AppSecUSA 2015 conference talk. Learn how security_monkey tracks changes across multiple AWS accounts and technologies, audits configurations for security implications, and helps understand interconnectivity between accounts. Discover best practices for cloud security, including eliminating IAM users, managing access keys, auditing security groups and S3 buckets, avoiding RFC-1918 IP ingress permissions, and expanding wildcard policies. Gain insights into how security_monkey enables Netflix's hands-off approach to security while maintaining robust auditing and monitoring capabilities for their AWS environment.
Going Bananas for Cloud Security - Auditing AWS Deployments with Security Monkey