snyk.io
Securing Serverless - By Breaking In
Guy Podjarny, Snyk @guypod
Securing Serverless - By Breaking In Guy Podjarny, Snyk @guypod - - PowerPoint PPT Presentation
Securing Serverless - By Breaking In Guy Podjarny, Snyk @guypod snyk.io About Me Guy Podjarny, @guypod on Twitter CEO & Co-founder at Snyk History: Cyber Security part of Israel Defense Forces First Web App Firewall
snyk.io
Guy Podjarny, Snyk @guypod
snyk.io
snyk.io
https://www.youtube.com/watch?v=CiyUD_rI8D8 https://www.infoq.com/articles/serverless-security
snyk.io
snyk.io
snyk.io
snyk.io
snyk.io
19 Lines of Code 2 Direct dependencies 19 dependencies (incl. indirect) 191,155 Lines of Code
snyk.io
snyk.io
Just not app dependencies
snyk.io
snyk.io
snyk.io
snyk.io
snyk.io
Not all your services elastically scale
snyk.io
snyk.io
snyk.io
Just use it!
snyk.io
snyk.io
snyk.io
AWS Security Policy
Policy 3 Policy 2 Policy 1
snyk.io
snyk.io
snyk.io
That needs to be secured
Perimeter Perimeter Perimeter Perimeter Perimeter
snyk.io
snyk.io
snyk.io
Reducing impact substantially, but not eliminating it
snyk.io
snyk.io
Vulnerabilities in your code Vulnerable App Dependencies Permissions Securing Data at rest Vulnerable OS Dependencies Denial of Service Long-lived Compromised Servers Third Party Services Attack Surface Security Monitoring
snyk.io
Thank You! Guy Podjarny, Snyk @guypod
More to come: Microservices Panel, Mon, 5:25pm Serverless AMA, Wed, 2:55pm