当前位置:首页 > 报告详情

Securing The Cloud- Taking Back The Attacker's Mindset.pdf

上传人: 张** 编号:162740 2024-05-01 22页 7.61MB

1、PRESENTED BYSecuring The Cloud:Taking Back The Attackers MindsetChris HoskingCloud Security Evangelist31234AgendaAI Within the Cloud Security ChallengeCloud Threat LandscapeAI to Secure the CloudTaking Back the Attackers Mindset4Antoine de Saint Exupry“The machine does not isolate man from the great

2、 problems of nature but plunges him more deeply into them.”5AI within the Cloud Security challengeInternal AI opportunities:People,Processes&TechnologyAI-fueled External Challenges:Evolving Cloud Threat Landscape&Motivated Threat Actors(APTs)6Cloud Threats On The RiseIncrease in#of cloud breaches:Ta

3、rgeting business critical applications in cloud&the increasing amount of data stored in public cloudIncrease in cloud attack sophistication:Novel techniques continue to be seen,across more threat actors,and in new combinations Increase in AI&automation in cloud attacks:Chat&WormGPT,&bots including c

4、rypto-miners,scrapers,phishing,credential harvesting&stuffing7PassGan&PCFG CrackersAI&ML powered password crackersMalGanFeed-forward neural networks designed to evade ML detection enginesDeepLockerIBM POC with deep neural network capabilities&stays hidden until hitting pre-defined contextPrevious Ex

5、amples of AI-Powered Attacks8Cloud Attacks:The Knock On The DoorFileless attacks running in memory steadily risingWipers&Ransomware now have Linux variantsContainer specific attacks(container escape,mounting filesystems)CryptojackingOS&App level vulnerabilities found via automated tooling&exploited

6、via automated toolingAI-Malware polymorphism Black Mamba recent example9Cloud Attacks:DevOps Pipeline ThreatsTargeted Supply Chain campaigns are being observed for the first timeUse of non-standard languages for threat actors to hide in open-source packagesCode Repositories are being targeted for cr

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本次演讲由Chris Hosking,Securing The Cloud: Taking Back The Attacker's Mindset,主要讨论了云计算安全面临的挑战,以及如何利用人工智能(AI)来防御这些威胁。 1. AI在云安全挑战中的角色:AI在内部(如人员、流程和技术)和外部(如不断演变的云威胁景观和有动机的威胁行为者)都提供了机遇和挑战。 2. 云威胁的上升:云泄露事件增多,攻击手段越来越复杂,AI和自动化在攻击中的应用也在增加。 3. AI驱动的攻击手段:例如,AI和ML驱动的密码破解工具,DeepLocker等利用深度学习技术的隐蔽攻击。 4. 云攻击的类型:文件less攻击,Wiper和Ransomware的Linux变体,针对特定容器和操作系统的攻击等。 5. 应对策略:需要区分正常活动和异常活动,利用AI在云运行时进行安全防护,如静态AI/ML和行为AI。 6. AI的安全用途:生成式AI可以用于代码检测、事件总结和交互支持等。 7. 验证攻击路径:确保时间和资源不被浪费在追逐AI的假象上,通过Offensive Security Engine和Verified Exploit Paths来模拟和捕捉攻击者的行为。 综上所述,随着云计算的普及,云安全面临着前所未有的挑战。利用AI进行防御是必要的,但同时需要确保AI的安全性和有效性。
探讨AI如何影响云安全,以及它面临的挑战是什么。 了解当前云威胁的形势以及如何利用AI来防御这些威胁。 探讨如何通过云原生安全策略和技术来预测和防范攻击。
客服
商务合作
小程序
服务号
折叠