Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Improving the Security of Software Defined Infrastructures - AppSec EU 2017

OWASP Foundation via YouTube

Overview

Explore the security challenges and best practices for Software Defined Infrastructures (SDI) in this 26-minute conference talk from AppSec EU 2017. Delve into the advantages and potential vulnerabilities of configuration management tools like Puppet and Chef. Learn about the attack surface and threats in SDI deployments, and discover techniques for identifying vulnerabilities through source code analysis. Gain insights from real-world security reviews and understand how to remediate common security issues. Cover topics including insufficiently protected interfaces, insecure handling of secrets, encryption of configuration values, logging configuration changes, credential management, untrusted code, and implementing a robust security lifecycle. Benefit from practical examples and lessons learned to improve the security of your SDI implementations.

Syllabus

Introduction
About Theodoor
Explanation
Software Defined Infrastructure
SPI Architecture
Advantages of SPI
SPI as an attack factor
Insufficiently protected interfaces
Insecure handling of secrets
Encrypt Configuration Values
Logging Configuration Changes
Credentials
Untrusted Code
Security Lifecycle
Examples

Taught by

OWASP Foundation

Reviews

Start your review of Improving the Security of Software Defined Infrastructures - AppSec EU 2017

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.