Optimizing Cloud Detection & Response With Security Chaos Engineering - Kennedy Torkura
This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #cloud #developer #softwaredeveloper Attend the next NDC conference near you: https://ndcconferences.com https://ndc-security.com/ Subscribe to our YouTube channel and learn every day: /@NDC Follow our Social Media! / ndcconferences / ndc_conferences / ndc_conferences Cloud Detection and Resposne (CDR) is an evolving approach to proactively defending cloud infrastructure against cyber-attacks. CDR takes a lot of approaches from traditional Threat Detection and Incident Response (TDIR) and applies these approaches to cloud-native infrastructure. This approach allows for optimized strategies specifically designed to fit the cloud-native threat landscape, given the limitations of traditional TDIR in cloud-native infrastructure. CDR strategies combine cloud threat detection and incident response by employing several techniques, including active monitoring, log analytics, threat intelligence, incident response, forensic analysis, and threat analysis. This is advantageous since security teams are enabled to be agile and more productive; hence CDRs are rapidly becoming essential tools for security teams focused on protecting cloud-native infrastructure, including detection engineers, cloud security engineers, cloud incident responders, and SOC teams. However, enabling efficient CDR strategies is challenging for several reasons, including cloud complexities, insufficient expertise, and cloud misconfiguration. These challenges often lead to blindspots; some cloud attacks are not detected, leading to successful compromises. Furthermore, the ephemerality of cloud resources requires continuous assessment, validation, and configuration of CDR to align with the evolving threat landscape. This level of security validation is challenging for most teams, and there are hardly solutions that can be easily leveraged. Security Chaos Engineering (SCE) is an evolving approach to cyber security that employs empirical evaluation of security controls to proactively gain evidence about their effectiveness via quick feedback loops. These feedback loops, a core of system thinking, allow for quick analysis and adaption of security systems to stay ahead of cyber attacks. SCE is aligned with cloud-native infrastructure, given its roots are chaos engineering, a discipline Netflix formulated as part of its digital transformation process over a decade ago. Consequently, SCE empowers cloud security teams to quickly and continuously evaluate CDR efficiently in a variety of ways. This talk provides practical steps and examples based on a hybrid CDR system consisting of AWS GuardDuty, AWS Detective, and Datadog Cloud SIEM. Security chaos engineering experiments are conducted using the Mitigant Cloud Immunity platform, which is the first of its kind. Using the examples, we are able to demonstrate how CDR systems can miss malicious patterns, including those defined in the MITRE ATT&CK library. The talk provides recommendations on how to remediate these blindspots to enhance CDR systems' efficiency.

Purple is the New Black: Modern Approaches to Application Security - Tanya Janca

SANS Webcast | Detection Engineering in the Cloud: A Defenders Wonderland

Dave Rensin: Chaos Engineering for People Systems - Chaos Conf 2019

Cybersecurity Architecture: Who Are You? Identity and Access Management

DuckDB, Apache Arrow, & the Future of Data Engineering w/ Rusty Conover | S2E3

Keynote: Rust is not about memory safety - Helge Penne - NDC TechTown 2025

Attacking AI - Jason Haddix - NDC Security 2026

NOPASSWD: Building a Passwordless Cloud Infrastructure - Kyle Kotowick - NDC London 2023

How I Learned to Stop Worrying and Build a Modern Detection & Response Program

Practical Magic: The Resilience Potion & Security Chaos Engineering • Kelly Shortridge • GOTO 2023

Firewall Fundamentals Explained | Network Security for Beginners

How hacking works - Espen Sande-Larsen - NDC TechTown 2023

Enterprise Chaos Engineering Certification Prep Session

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

Why Adam Savage Won't Trust USB Keys

Personal VPNs: Encryption Myths and Data Security Explained

Secure development with C++ - Lessons and techniques - Helge Penne - NDC TechTown 2023

AI Bubble: How AI's push towards IPOs became a death drive | Ed Zitron

Linux user namespaces: a blessing and a curse - Ignat Korchagin - NDC TechTown 2024

