BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Deescalate the overly-permissive IAM\n   When: Sunda
 y\, Aug 14\, 11:50 - 12:30 PDT\n   Where: Flamingo - Sunset-Scenic Ballroo
 m (Cloud Village) - [1]Map\n\n   SpeakerBio:Jay Chen\n   Jay Chen is a sec
 urity researcher with Palo Alto Networks. He has\n   extensive research ex
 perience in cloud-native\, public clouds\, and edge\n   computing. His cur
 rent research focuses on investigating the\n   vulnerabilities\, design fl
 aws\, and adversary tactics in cloud-native\n   technologies. In the past\
 , he also researched Blockchain and mobile\n   cloud security. Jay has aut
 hored 20+ academic and industrial papers.\n\n   Description:\n   The princ
 iple of least privilege states that a subject should be given\n   only tho
 se privileges needed for it to complete its task. The concept\n   is not n
 ew\, but our recent research on 18\,000 production cloud\n   accounts acro
 ss AWS and Azure showed that 99% of the cloud identities\n   were overly-p
 ermissive. The majority of the identities only used less\n   than 10% of t
 heir granted permissions. While I investigated the issue\n   further\, one
  interesting pattern quickly surfaced\, many\n   overly-permissive permiss
 ions were granted by CSP-managed permission\n   policies. CSP-managed poli
 cies were granted 2.5 times more permissions\n   than customer-managed pol
 icies. These excessive permissions\n   unnecessarily increased the attack 
 surface and risks of the cloud\n   workloads. In particular\, many identit
 ies could abuse the granted\n   permissions to obtain admin privilege.\n\n
    These findings raised a few questions. Are we all doing something\n   t
 erribly wrong? Is the principle of least privilege a realistic and\n   nec
 essary goal in modern cloud environments? What can be done to\n   mitigate
  the problem? Knowing the problem and the risks\, I will then\n   introduc
 e an open-source tool IAM-Deescalate to shine a light on the\n   problem.\
 n\n   IAM-Deescalate can help identify and mitigate the privilege escalati
 on\n   risks in AWS. It models the relationship between every user and rol
 e\n   in an AWS account as a graph using PMapper. It then identifies the\n
    possible privilege escalation paths that allow non-admin principals to\
 n   reach admin principals. For each path\, IAM-Deescalate revokes a\n   m
 inimal set of permissions to break the path to remediate the risks.\n   At
  the time of writing\, IAM-Deescalate can remediate 24 out of the 31\n   p
 ublicly known privilege escalation techniques. On average\, it\n   remedia
 tes 75% of the privilege escalation vulnerabilities that\n   existing open
 -source tools can detect.\n\n   The audience will gain a new perspective o
 n IAM security and pick up a\n   new tool for their security toolbox.\n\n 
   '\n\n   1. https://defcon.outel.org/consolidated_page.html#FlamingoThird
 Floor\n\n\n
DTEND:20220814T193000Z
DTSTART:20220814T185000Z
LOCATION:CLV - Flamingo - Sunset-Scenic Ballroom  (Cloud Village)
SUMMARY:Deescalate the overly-permissive IAM
END:VEVENT
END:VCALENDAR
