Hands On Workshop: Cloud VM Deployment and Hardening

Опубликовано: 02 Октябрь 2024
на канале: SANS Cloud Security
487
14

Securing a cloud environment can be challenging and time consuming, especially if you don't know where to start. This 2-hr hands-on workshop will scrutinize a common cloud service: Virtual Machines, and focus on the secure implementation of that service. We'll discuss Operating Systems (and why it matters from a cloud perspective), as well as security groups, remote access, system and network hardening as well as how mature organizations handle deployments. While discussing these topics will be enlightening and entertaining, deploying our own infrastructure will be a blast! Join this 2-hour workshop to learn how experts solve for the security concerns surrounding virtual machines in a cloud environment.

LEARNING OBJECTIVES:
Learn about how to deploy and harden an EC2 instance
Understand the attack surface an exposed instance creates
Apply your knowledge to implement stronger security controls on an AWS endpoint

PREREQUISITE KNOWLEDGE:
Familiarity with cloud computing and networking/system administration

SYSTEM REQUIREMENTS:
An AWS cloud account with root access or the ability to deploy virtual machines
SSH client software.
Web Browser and SSH client (no VM is required) already installed and ready to use.

This workshop supports both SANS SEC388: Introduction to Cloud Computing https://www.sans.org/cyber-security-c... and Security and SANS SEC488: Cloud Security Essentials https://www.sans.org/cyber-security-c...

About the Creator/Instructor
When it comes to cyber security, Serge is among the best possible instructors to learn from due to his experience, accomplishments, and, quite frankly, his personality. Duplicate badges to walk right through security and access a "secure" facility – did that. Dumpster diving for sensitive information outside of a financial institution – to him, that was “lots of fun.” Create an enterprise-wide, measurably successful security program for a billion-dollar company – one of his many accomplishments. All of them, in scope of the engagements. He’s an instructor for SEC488: Cloud Security Essentials, author of SEC388: Introduction to Cloud Computing & Security, a published author, President of the Denver Open Web Application Security Project (OWASP) chapter, founder and CEO of the cyber security consulting firm, SpyderSec, he’s discovered multiple 0-days, written OSINT tools for the community, and is a polished presenter who speaks regularly at national conferences. Truly, an expert in the field. Learn more about Serge at https://www.sans.org/profiles/serge-b...


SANS Cloud Security focuses the deep resources of SANS on the growing threats to The Cloud by providing training, GIAC certification, research, and community initiatives to help security professionals build, deploy and manage secure cloud infrastructure, platforms, and applications.

SANS Cloud Security Curriculum: www.sans.org/cloud-security
GIAC Cloud Security Certifications: https://www.giac.org/focus-areas/clou...
LinkedIn:   / sanscloudsec  
Discord: www.sansurl.com/cloud-discord
Twitter: @SANSCloudSec