46
Azure Security Overview Maxime Coquerel - MVP Azure

Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

  • Upload
    others

  • View
    17

  • Download
    2

Embed Size (px)

Citation preview

Page 1: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Overview

Maxime Coquerel - MVP Azure

Page 2: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Disclamer

“Tous les posts de cette présentation ne reflètent que mon opinion et non celle de mes employeurs et clients.“

Page 3: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Remerciements

Merci à l’équipe OWASP Québec ainsi qu’au Cégep Sainte Foy!

Page 4: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

# Speaker

Maxime Coquerel

Cloud Architect

Email : [email protected]

Blog : zigmax.net (Since 2012)

Github : https://github.com/zigmax

Twitter : @zig_max

Open Source Contributor (Kubernetes / OpenStack).

Page 5: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Session Agenda / Goal● Introduction

● Compliance & Gouvernance

● Gestion des identités

● Chiffrement et voûte de mots de passe

● Infrastructure

● Azure Security Center

● Investigation

● Conclusion

Page 6: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway
Page 7: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Data Breach

Page 8: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Data Breach - Facebook

Page 9: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Data Breach - Government of India/Aadhaar

Page 10: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway
Page 11: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Compliance & Gouvernance

Page 12: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway
Page 13: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Microsoft Trust Center

https://www.microsoft.com/en-us/trustcenter/default.aspx

Page 14: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Policy

https://github.com/Azure/azure-policy | Source: Microsoft Ignite - BRK3085

Page 15: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Policy

Page 16: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Policy - Demo

Page 17: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Gestion des identités

Page 18: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure AD

Page 19: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure B2C

Source : Microsoft Ignite 2018 - BRK3240

Page 20: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure B2C - Example Subway

Source : Microsoft Ignite 2018 - BRK3240

Page 21: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Chiffrement & Voûte de mots de passe

Page 22: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Disk Encryption● Need Azure Key Vault / Azure AAD / ● Based on Windows : BitLocker / Linux : DM-CRYPT

Howto : Azure Disk Encryption http://zigmax.net/azure-chiffrer-une-machine-virtuelle-azure-disk-encryption/

Official Documentation : https://docs.microsoft.com/en-us/azure/security/azure-security-disk-encryption

Page 23: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Key Vault

Example : https://github.com/zigmax/azureqc17-security/tree/master/AzureKeyVault_Demo

Page 24: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Infrastructure

Page 25: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Network and Application Security Group (NSG)

Network Security Groups

● Protects your workloads with distributed ACLs

● Simplified configuration with augmented security rules

● Enforced at every host, applied on multiple subnets

Application Security Groups

● Micro-segmentation for dynamic workloads

● Named monikers for groups of VMs● Removes management of IP addresses

Source Microsoft Ignite 2018 - BRK4029

Page 26: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway
Page 27: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Firewall

Cloud native stateful Firewall as a Service● Built-in High Availability and Auto Scale● Network and Application traffic filtering● Centralized policy across VNets and

Subscriptions

Complete VNET protection● Filter Outbound, Inbound, Spoke-Spoke

& Hybrid Connections traffic (VPN and ExpressRoute)

Centralized logging● Archive logs to a storage account,

stream events to your Event Hub, or send them to Log Analytics or SIEM

Page 28: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Web Application Firewall (WAF)

Page 29: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure WAF

Page 30: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure DDOS

Source : Microsoft Ignite 2018 - BRK4029

Page 31: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure DDOS Standard Protection

● Protection for your virtual network resources● Automatic mitigation for 60+ network layer

attacks● Adaptive tuning via application traffic profiling

and machine learning algorithms● Real time monitoring and alerting in Azure

Monitor● Integration with WAF for application layer

protection

Page 32: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center

Page 33: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center

● Integrated threat intelligence

● Behavioral analytics

● Anomaly detection

Page 34: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center

Page 35: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center

Page 36: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center

Page 37: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center - Alert

Page 38: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Security Center - Demo

Page 39: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Investigation

Page 40: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure Monitor

Page 41: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Forensic investigation (Logs)

Page 42: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Azure SIEM (IBM QRadar + Splunk)

Howto Azure with IBM QRadar: http://zigmax.net/azure-siem-ibm-qradar/

Page 43: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Conclusion

> Compliance …. Azure Policy

> Identity Management … Azure Active Directory

> No flat networks … Network Security Group

> Manage secrets … Azure Key Vault

> Firewall / WAF …. Azure Firewall / Azure WAF

> Threat Analytics - Azure Security Center

> Have fun :) !

Page 44: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Books

Page 45: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Technical Ressources

Microsoft Learn - https://docs.microsoft.com/fr-fr/learn/

Microsoft Virtual Academy (FR) - https://stanislas.io/2016/04/26/41/

Microsoft Technical Community Content https://github.com/Microsoft/TechnicalCommunityContent

Azure Security Blog - https://azure.microsoft.com/en-us/blog/topics/security/

Maxime Blog - http://zigmax.net

Microsoft Ignite 2018 - https://myignite.techcommunity.microsoft.com/

Page 46: Azure Security Overview - zigmax.netzigmax.net/wp-content/uploads/2018/10/Azure-Security-OWASP.pdf · Azure B2C Source : Microsoft Ignite 2018 - BRK3240. Azure B2C - Example Subway

Questions / Talks