Penetration Testing in the Cloud presented at SourceBoston 2015

by Dan Lambright,

Summary : This talk discusses challenges associated with ensuring your infrastructure is secure in the cloud. Cloud providers are very careful with letting customers run penetration tests because they can be misunderstood for real attacks, but such tests are needed to confirm data is safe. This talk discusses the conditions and limits of permissions obtainable, and explores methods of doing targeted tests in ways that will not affect others using multi-tenant hardware. A promising approach is to have a docker instance play the role of the hacker, and use an instance's internal network interface to carry out attacks.