Peter Bennink 3rd of July, 2018
Automated analysis of AWS infrastructures
Supervisor: Cedric van Bockhaven - MSc System & Network Engineering
Automated analysis of AWS infrastructures Supervisor: Cedric van - - PowerPoint PPT Presentation
Peter Bennink 3rd of July, 2018 MSc System & Network Engineering Automated analysis of AWS infrastructures Supervisor: Cedric van Bockhaven - Peter Bennink 3rd of July, 2018 Background ... a secure cloud services platform, offering
Peter Bennink 3rd of July, 2018
Supervisor: Cedric van Bockhaven - MSc System & Network Engineering
Peter Bennink 3rd of July, 2018
2
“... a secure cloud services platform, offering compute power, database storage, content delivery and other functionality …”
Peter Bennink 3rd of July, 2018
3
EC2 (Elastic Compute Cloud) RDS (Relational Database Service) S3 (Simple Storage Service)
Peter Bennink 3rd of July, 2018
4
VPC Security groups IAM
Peter Bennink 3rd of July, 2018
5
VPC Security groups IAM
Peter Bennink 3rd of July, 2018
6
IAM
Peter Bennink 3rd of July, 2018
7
IAM > Policies
Peter Bennink 3rd of July, 2018
8
Peter Bennink 3rd of July, 2018
9
Bloodhound Active Directory
Peter Bennink 3rd of July, 2018 Research question
10
Peter Bennink 3rd of July, 2018
11
1. Analysis 2. Development 3. Testing
Peter Bennink 3rd of July, 2018
12
1. Analysis 2. Development 3. Testing
Peter Bennink 3rd of July, 2018
13
IAM
Peter Bennink 3rd of July, 2018
14
IAM > Policies
Peter Bennink 3rd of July, 2018
15
IAM
Peter Bennink 3rd of July, 2018
16
Metadata server
Peter Bennink 3rd of July, 2018
17
Metadata crawler
Captures everything on the metadata server… … including security credentials
Peter Bennink 3rd of July, 2018
Permission bruteforcer
Checks what commands access keys can use
18
Infrastructure analyser
Uses access of key(s) to create mapping of infrastructure
Peter Bennink 3rd of July, 2018
19
Peter Bennink 3rd of July, 2018
20
Peter Bennink 3rd of July, 2018
21
access & escalating privilege
important than privilege in terms of enumeration
https://gitlab.com/PeterBennink/aws-infrastructure-analysis
Peter Bennink 3rd of July, 2018
22
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
23
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
24
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
25
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
26
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
27
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
28
Expandable in an infinite number of ways
Peter Bennink 3rd of July, 2018
29 https://gitlab.com/PeterBennink/aws-infrastructure-analysis