Exploitation and automated detection of threats to modern cloud infrastructure

By Krishnaa Srinivasa , Maithri Nadig on 01 Jun 2022 @ Securityfest
πŸ“Ή Video πŸ”— Link
#cloud-security #aws #vulnerability-assessment
Focus Areas: Application Security , Cloud Security , Penetration Testing , Vulnerability Management

Presentation Material

Abstract

Cloud infrastructure security is an oft-neglected topic when businesses invest in securing their web apps. Ensuring that a once-secured environment remains secure is even more challenging. In this presentation, we demonstrate common types of attacks against cloud infrastructure, taking the example of AWS. We show how scarily easy it is to attack misconfigured services such as AWS Security Groups, databases, S3 buckets and Network ACLs. After our demonstration of the exploits, we discuss techniques for automated scanning of various AWS services and resources.

Presented at Security Fest 2022.