security as a service

21
SaaS - Security as a Service SaaS - Security as a Service ------ ------ bullshit bingo … or just a future glimpse bullshit bingo … or just a future glimpse by Vitor Domingos http://vitordomingos.com

Upload: vitor-domingos

Post on 04-Dec-2014

1.456 views

Category:

Technology


1 download

DESCRIPTION

my latest talk on security as a service, on a local IT & Security group

TRANSCRIPT

Page 1: Security As A Service

SaaS - Security as a ServiceSaaS - Security as a Service------------

bullshit bingo … or just a future glimpsebullshit bingo … or just a future glimpse

by Vitor Domingoshttp://vitordomingos.com

Page 2: Security As A Service
Page 3: Security As A Service
Page 4: Security As A Service
Page 5: Security As A Service
Page 6: Security As A Service

Security HistorySecurity History

1.0 – Computer1.0 – Computer

2.0 – Network2.0 – Network

3.0 – Information3.0 – Information

4.0 – Your digital you4.0 – Your digital you

Page 7: Security As A Service

Security Menace HistorySecurity Menace History

1.0 – Virus, Stealing Information

2.0 – Worms, Trojans, Virus

3.0 – DDoS, Trojans, Identity Theft

4.0 – FarmVille, Mafia Wars, Data Theft

Page 8: Security As A Service

Firewall HistoryFirewall History

1 Gen – Packet1 Gen – Packet

2 Gen – Application Layer2 Gen – Application Layer

3 Gen – Stateful3 Gen – Stateful

4 Gen – Semantic4 Gen – Semantic

5 Gen – Personal 5 Gen – Personal

Page 9: Security As A Service

security is about information

Page 10: Security As A Service

security is about informationnow securing

Page 11: Security As A Service

divide and conquer no longer applies

Page 12: Security As A Service
Page 13: Security As A Service

Security as a ServiceSecurity as a Service

- nothing new; more explicit- nothing new; more explicit

- managed security, rented security- managed security, rented security

- outsourcing security infrastructure > cloud- outsourcing security infrastructure > cloud

- auth management- auth management

- secure API's- secure API's

- ongoing tasks (patch, scan, log, defend)- ongoing tasks (patch, scan, log, defend)

Page 14: Security As A Service
Page 15: Security As A Service

SaaS Meh'sSaaS Meh's

- it's the web baby- it's the web baby

- secure web gateways- secure web gateways

- cloud security provider- cloud security provider

- managed security 2.0- managed security 2.0

- trust- trust

- bandwidth- bandwidth

Page 16: Security As A Service
Page 17: Security As A Service

it could workit could work

- not with marketing bullshit- not with marketing bullshit

- XSS, data injection, data leak- XSS, data injection, data leak

- auth, weak password validation- auth, weak password validation

- worm, trojan, bruteforce, DDoS- worm, trojan, bruteforce, DDoS

- secure not the browser, but the pipe- secure not the browser, but the pipe

- social firewall ?- social firewall ?

Page 18: Security As A Service
Page 19: Security As A Service
Page 20: Security As A Service
Page 21: Security As A Service

Vitor Domingos - [email protected] Vitor Domingos - [email protected]