2024 Cloud Security Trends and Predictions | FEATURE SEGMENT

SANS Institute · Advanced ·📄 Research Papers Explained ·2y ago

Key Takeaways

The video discusses 2024 cloud security trends and predictions, covering topics such as Kubernetes security, GraphQL, AI limitations, workload identity, and multicloud adoption, with a focus on the practical applications and challenges of these technologies.

Full Transcript

of course we'll talk about that when we get to our panel which let's do the keep answering the questions because I'm going to ask the panel the very same question when we bring them up right now I would like to introduce uh Brendan and Eric Brendon Eric how's it going uh what we're gonna do today first uh introduce yourself start off with uh we'll start off with Brandon introduce yourself and tell me what is the skill or thing you want to learn about in 2024 how's it going Sean thanks for having me uh my name is Brandon Evans I am an application developer who somehow became a security person over the past couple of years and I've been absolutely loving it my areas of focus are multicloud security and application security and I'm also in addition to being a consultant in those areas I'm the lead author alongside with Eric of SEC 510 public Cloud security AWS Azure and gcp where we teach you how to prevent a wide variety of types of attacks in the cloud using defense and depth mechanisms very cool welcome and I like that how I went I was applications and then I went into security and usually it's you found a problem right I mean because I was applications developer way back to when I remember my friend going hey there's this thing called SQL injection I was like that's so cool that's how I got it so right welcome so no one uh no one grew up thinking they were gonna be an application security architect when they grew up everybody said astronaut or something else we all found our ways here yeah actually that is very true that is very true all right Eric if you introduce yourself and tell us what kind of skills tool you're looking for to in 2024 yeah so I'll join the club here it's uh it's been a long time but I I started out in software development also doing web app development probably right as the OAS top 10 came out and eventually ended up on an absc team which evolved into doing a lot of Dev SEC Ops work and Cloud work so all the infrastructure is code things and automated pipelines and those sorts of topics are really what I've focus on day in and day out at my day job at Puma security so um that's the tool chain I work with on pretty much a regular basis I've been fairly kneee in kubernetes over the last six months or so I can thank uh Andrew Martin from control plane over in the UK for that uh we we started working on some kubernetes stuff several years go and it's just now starting to resurface in a lot of the work that I'm doing so I think a professional goal for me in 24 uh you know I work a lot with the authorship team on SEC 540 and as Brandon mentioned SEC 510 and SEC 549 which is cloud Enterprise security architecture but I think professionally I'm going to try to grab the kubernetes security specialist certification this year and see if there's any kind of nooks and crannies of that ecosystem that I have not to run into yet try to get some more hands-on experience with that very cool all right well welcome and I will I didn't answer the question myself about uh what I would be interested in I don't know I don't know if I can say for 2024 but I have been diving into uh graphql I'm I mean I'm kind of old so rest interfaces was where I've been running for so long and so so much of uh the tooling that we're interacting with is graphql and with Microsoft off graph API and those kind of things it just seems like graphql is going to be a bigger play so I have been starting my 20 uh my my January looking at those kind of things so as you we pop back up on the screen kind of the active poll you're still free to answer the questions I like that more Microsoft search uh AI was all over the place so I I'm guessing we're gonna be talking about AI today we ask some of the questions so thank you and thanks for joining me so uh let me ask uh Brandon uh what is a a trend in 2023 that surprised you uh and think about not just what you read about but what you talk to folks in your classes like what is something you saw happening in 2023 that kind of surprised you you weren't you weren't expecting well I was uh kind of happy to see that AI did not just show up and then disappear you know we've had a lot of different hype Cycles over the past couple of years there's been a lot of discussions about blockchain there's still conversations about blockchain but as a lot of people have seen a lot of that infrastructure fell apart in 2023 so I've seen a lot of people compare AI to blockchain in terms of its utility and that it's kind of a fad and I like to see that AI immediately proved that it had a lot of good use cases it already proved that it had a lot of good use cases but it proved that large language model specifically can be very useful although flawed and I'm glad that that has continued throughout the year I'm also happy to see that people are starting to understand the limitations of this tool not dismissing it completely but understanding that it has some significant limitations such as hallucinations and how we should not just trust everything it says but I'm glad that we're having a more mature conversation about this technology that's clearly here to stay versus other technologies that may be fading away in the near future if not have already faded away oh yeah I totally agree yeah it feels different because I think people are saying oh it's a tool so how can I best use this new tool that's you know it's not just a I don't know a thing where I don't know the the blockchain stuff is always been really interesting NFC was kind of like okay I don't know if I need these playing cards but uh there was you know some interesting things you could do with them but I think we're gonna see more and more with that AI all right Eric question to you what is the thing you saw in 2023 that surprised you most about Cloud you know that there's a lot of research with stolen credentials and the miter attack framework with longwave creds and ways to establish persistence in Cloud environments and what I would say is a trend that I liked in 23 was the huge push across the board from the public Cloud providers towards workload identity and updates to all the web interfaces to essentially steer you away from generating Long Live service account keys and access keys and things like that with large disclaimers on the screen saying hey you're about to maybe do something that's an anti- pattern maybe you don't want that access key that's going to live for three to four years and instead consider setting up you know open ID connect or a saml Federated identity connection you know into a cloud environment rather than using their native Off Systems so that was one thing in 23 that I loved the push forward there from the providers telling the rest of us this is how we should be doing it rather than relying on the the way that we've done it for many many years leading up to this point oh yeah and it took a while for some of the cloud providers to get better integration with like these single sign on services but for even for some of them I don't I it's still hard to do you know uh short-term credentials when they're going in and out of their Cloud environments they just haven't given really good tools for that and I'm hoping I hope we see them fix it because longterm or yeah long-term cries are just so dangerous and so hidden in some cases yeah you know GitHub actions I think was one of those catalysts there that you know they were one of the primary cicd systems that really paved that road and git lab 2 with their CI you know when both of them started publishing all the research on here's how to authenticate through oidc into AWS Azure and Google I think that was the real set of documentation that showed everybody the way to do it and to do it right so that that was awesome and it's still not still not super easy but it's better but I just set that up yeah yeah very very difficult very very difficult I mean we published a uh code snippet that shows you how to do this from one cloud provider to another and I'll post that in the chat in just a moment uh but just creating the Bare Bones example of lambdas that upload to the different Cloud providers automatically it was thousands of lines of both terraform and application code I tried updating the DK for Microsoft and it just broke everything and not to mention there's no current way of getting Azure resources using AWS credentials natively because AWS can't generate an open IDC uh connect token at all so there are some Integrations that are hard there are some that are impossible today and as a result Eric you could speak to this better than I can are we even really seeing a whole lot of adoption from the majority of organiz um I think workload wise that's very rare as you're describing a Lambda cross authenticating into like Azure storage or something like that I think it's becoming much more common place for cicd pipelines I think that is being pretty heavily adopted at this point rather than just handing them an access key to terraform to go build my infrastructure we're seeing more the open IE connect configs on that side I think that's a lot more common yeah I totally agree yeah yeah and I think it's it maybe because if you're going to do on a CSD pipeline you put a lot of focus on a single system you get it working whereas if you're doing like all these Federated Services each Dev team kind of has their own process unfortunately and they don't all match up and so I think it's that Federation of resources versus you know bringing it all together into a CSD pipeline yeah absolutely um I I'll say for from from my perspective so AI would be a one that I wouldn't I wouldn't say is a trend for 2023 in terms of security because I haven't seen J of AI being used too much right now it's kind of everyone's trying to figure it out and play with it uh you know being GitHub we're using gener of AI for code but I wouldn't I wouldn't count that for the security side I I will say I one thing I was surprised about I saw in my students in class is that at the beginning of the year when I would say hey what cloud are you all using they were all like AWS and then maybe some of the other ones and by the end of the year most people were doing Microsoft and then also AWS but they were all in Microsoft and I don't know why like it I don't know how that why that transition is happening but I can see and it wasn't just because they're moving from one to the other but they're adding to it so they're they're starting to go into that multicloud uh part of it is because uh you know the company bought another company that tends to be an acquisition-based multicloud uh but then there they're just trying to figure out how do I kind of interact with these different clouds for different purposes and so I think um you know I think that's the thing I was most surprised about in 2023 yeah that it's getting even more extensive we recently did the 2023 multicloud survey and I mean it's just almost every organization does a little bit in one cloud provider of each of the big three and in many cases the big six which is unbelievable I think this is maybe just going to the point of how much technology sprawl there is out there where people just can't standardize uh but also I think there's a lot of myths about what we can get out of multicloud like high availability and being able to negotiate our way out of having a very expensive bill by saying we're going to go from AWS to Azure not understanding the tremendous tremendous amount of operational cost involved with getting all that working so it's good for Eric and I because we teach the multicloud course here at Sans but maybe not so good for the industry because it makes it really hard for us to get a grapple around these Technologies both from a functionality perspective and a security perspective well let me uh let me ask the folks that are listening at home or at work or wherever you are what which clouds are you in and if you're in multiple clouds just pop them in the chat we'd like to be able to see because that's one of the first things I do in class is what clouds you're in so I'd be interested especially with such a an you know you people all over the world so let us know what cloud you're working in in the in the chats and we we'll we'll take a look at them I I know that like America's very much been AWS and in Europe it's a lot of azure and it's that kind of but I can see them going back and forth and it might be because you know so many companies are mult they're multi National you know they're working all over the places so I can that's probably why we're seeing a lot of that multicloud too I I'll say from uh you know you all given your perspective as uh for protecting but for the classes I teach which is on detection that multicloud is very difficult because now the two operators that have to analyze all this data now have logs that look completely different right and and different approaches and they're deployed differently and it's very frustrating for them and so uh you know I don't think we're going to ever see a you know single pane of glass stuff we've been talking about that I mean I was government we talked about that all the time never made it so there's no incentive to allow for a single pane of glass that will get rid of aws's number one asset which is their vendor lock in and their popularity although Microsoft's trying to do that from the defender side but yeah I mean there can be some level of unification it's never going to be that we have one API that you can use to interact with all three clouds because if I was AWS the first thing I would do is break that the first thing I would do is introduce some kind of important bug fix that actually just broke all those Integrations yeah absolutely absolutely and so look at it people her popping in you know there's a fair amount of AWS there's some Azure uh gcp I see a couple people saying like their own so they must be running something that they're building that is their own cloud environment uh which is you know all the work and cost uh but uh a couple people listing multiple ones so definitely we're seeing multicloud gcp couple gcps on here so yeah I saw the uh the finops response and I don't know if you all saw on the news it was either last week or the week before but Google Cloud announced that they would if you apply for this window you can get free egress charges to move all of your data out of Google Cloud if you decide to leave and as I look at 24 and what I think is coming and it's related to finops and you've also seen like d and hey posting research on costing and is it actually cheaper to be running some of this stuff on Prem I I do think customers are going to really start scrutinizing their Cloud bills and I think they're going to start doing some PR Deep dive cost analysis in which cloud provider is it going to be most cost effective for me to be running in and I think as far as system designs and trying to build things so it's not as a dependent on AWS or Azure or Google so we can attempt to minimize cost I think that's going to be a huge push and Google suspending those eress charges kind of shows the trending there on can we actually be able to be free of the lock in as as Brandon mentioned with AWS specifically and some of those ridiculous charges that live inside of those ecosystems like will we see egress charges go down will we see the natat Gateway finally free us from our $30 per availability Zone a month cost and you know it's some of those really silly things I could see starting to be loosened up a little bit on the costing side sounds like a free return policy is what I'm what I hear they try to do right yeah and it's think get smart from a sales perspective like here this is you can come in you can test our kubernetes clusters out you can use big query and and if you hate it you can leave for free you're not stuck here forever it's an interesting move there well I know doing a lot of uh a lot of creative things in that area I know we don't have a whole lot of time but I was late to the party to learn that Google and aramco partnered to bring a lot of data centers to Saudi Arabia and uh wow uh that's a very interesting play and uh will definitely help them yeah I think so I and I think you're gonna see large companies financial companies maybe or governments that are like going to spend a lot more money on a on a couple Cloud providers to get that rolling better and driving you know security requirements or things that are going to be helpful for everybody and you know most of the companies and countries are kind of doing multic Cloud so they're kind of spreading out a little bit right I can of see that so well so uh let's take let's ask our next question so um let's was that all about Trends in 2023 yes you didn't even get to the second question I'm looking at my notes I'm like oh my gosh that was okay I foreshadowed all right so yeah so uh what are some things that you're going to see in 2020 for that are either good or bad that you're concerned about uh and that you think we need to be spending more time in and I'm going to hit Brandon with this when to start off all right gonna start off with some negativity so I'm gonna say something that I think a lot of people are feeling technology is getting worse I think objectively getting worse things that used to work just stopped working Google Maps broken all the time my browser giving glitches all the time on Facebook I have all these jumping around uh icons and elements right now I'm looking into the screen that I'm recording on and I just see a black screen no one else has the same issue as me oh my goodness there's a whole lot of issues I've had and if I get another error message from slack mobile telling me that I have failed to upload a file from my phone to a slack Channel I'm just going to throw the dang thing I mean it's we saw this problem 30 years ago with email attachments so why is this happening and why do I think this is going to continue to get worse in 2024 I have a couple of theories the first one is that technology is getting harder by a large margin it's getting harder there's this article I'm going to share with you in a moment which is called what it's like to be a developer in 2015 which was a very funny satirical article about how things had gotten so complicated from 2005 to 2015 15 and now we're in 2024 and things have just continued to go in that direction the second one is a lack of training we have a lot of developers who are joining the workforce without a computer science degree such as people coming from boot camps now I'm not trying to be an elitist or gatekeep in fact one of my proudest moments in my entire career was teaching a coding boot camp but the fact of the matter is folks with that lack of formal training need mentorship in order to make sure they don't introduce both functional bugs and security bugs and that brings me to my third reason which just really exacerbates that issue layoffs we saw over a quarter million layoffs in 2023 that we know of on layoffs.fyi and there's probably many many more and when you have people stressed to the maximum they can't provide the mentorship necessary to help those people get to the next level and make sure that they don't introduce security issues so we optt to put more and more work onto less and less people Outsource more and more things to Ai and I just see that this trend is very alarming with things breaking both in the virtual world and in the real world with the 737 max9 door that blew off a plane which delayed all of my travel plans and hopefully no one else here so we've got a lot of challenges in front of us just as a result of the workforce well all right so let me ask let me ask the audience this we you know had this question what is the things that you see that are both good and bad in 2024 uh let us know like kind of what you're seen predictions for for that also uh what software or Hardware did you have to fix over the break that was breaking all the time I know I I usually have to do computer Roundup around the house and fix stuff it sounds like your air the airplane doors are blowing off for for Brandon can't get home so um Eric let me ask you what is some Trends you see in 2024 either good or bad uh and that you're uh that you're looking forward to cloud cloud security operations you the AI thing came up a lot and I am excited for 24 to see security advances especially on the monitoring threat Intel side you know there's no reason that these Bots can't be trained to essentially start running our queries for us and looking for anomalies and alerts and and some of those really fun things that I think we can get to as an industry as we start to really leverage that technology to take care of some of that maybe level one kind of triage and Analysis so that's something I'm excited to see if we can get some advancements there Brandon as as you went through your whole Shield about technology being broken it it reminded me about uh Kelsey high tower probably almost 10 years ago at one point tweeted you know he's knee deep in kubernetes and all things microservices at that point and he tweeted are we going to look back in 10 years and realize that this whole microservices thing was a horrible idea and as you went through all of these different things that are broken all I can picture in the back of my mind is just all these little containers crashing left to right and then a cluster spinning them back up and trying to get it back to full capacity so you know as we expanded all of that complexity are we finally starting to see some of the downsides of of going this distributed out versus having the big mono app that consistently just ran and handled all the requests maybe will that be a trend in 2 24 I highly doubt it because that's just the way that things are working right now but it'll be interesting to see if that ever turns around yeah I I'll have to say on the microservices uh but I'm I'm not an expert because I don't build production code that uses microservices but I have built move code from server based into uh or client server into to microservices and I love the capabilities I got out of it because I was able to you know have things be able to elastically build up and down because we moved it on Prim into Cloud uh but it was more complicated to build and manage and it's a little bit more hidden and so like if a little thing goes wrong it's hard to see until everything goes wrong you know it so I think uh I I would love to see microservices but with better uh orchestration and management that's a little bit more builtin um I've not done in Microsoft but like in AWS you're kind of up to your own to implement your own things and it's a little bit too much up to your own you know I I think I would love to see a little more tooling to help people doing that and I think that in general people mention all these benefits and there are objective benefits to microservices there are benefits to going multicloud there's all these benefits and then whenever you mention a draw back they say oh you just got to figure that out that's your job to figure out not our not our problem we're just going to go 100% with the benefits and this lack of cost benefit analysis is really frustrating you know I don't think it's a question of yes microservices no microservices yes serverless no serverless yes multicloud no multicloud the question is how much when does it make sense and everyone refuses to answer that question because they want to do the next big thing to make their company look great and the next big thing to Pat out their resume yeah I think I've seen the term macr Services which is just a bunch of microservices on a VM and it's like oh you got to name it that why just you know well I will say people uh people been chatting and giving comments and they feel very similar to Brandon there's Michael's like software is garbage you know there's H folks talk folks mentioning that uh we've gotten used to other people being the beta testers uh the customer being the beta testers I can definitely seeing that someone suggested using ring central over slack but I hope that was a joke um I think it was there was a smiley face there so thanks for those answers so you know as you're as you're coming and listening let us know what you think uh is like a big prediction or something you're going to be looking at for 2024 in the chat we'd love to be able to see that um I think I think a number of people are feeling you though Brandon about that quality of software and I I I think Eric you're right it's probably about how we approach the software how the we're Distributing that stuff too much and it's just too hard for human to go and figure out what that code looks like and what's wrong with it and where the problem is I would agree with that um so some people have suggested and that they're looking forward to uh improvements in blockchain which I'm not a blockchain person so I don't I don't have a good handle on what those were but those blockchain experts they're really figuring out new ways of being able to take data and kind of get other people to be able to grab and make and use it securely so uh I'm I'm looking to see what those are going to be in the future I'll go further for blockchain specifically we talk about benefits and drawbacks I think it's been less about why do blockchain and more about why not do blockchain and now we're learning all of the many reasons why not to do blockchain so if the member of the audience has an example of how blockchain solves a problem that existing technology does not solve better please let me know because I really don't want to write off all this technology without really exhausting it but it's been so many years and I have not heard one example I you had someone Jason just posted up that uh Brandon loves yeah Jason's heard before I think there's a sarcasm in that in that chat message um you a couple people have mentioned uh Ai and so I will say my prediction for TR 24 is people starting to figure out how to use AI generative AI I'm talking about I feel like our old school AI of machine learning which was like analyzing large amounts of data and trying to come up with you know this is normal versus not normal I think it would have worked better it would work better if our environments weren't just so wacky like you know just from our perspective when we do like log collection analysis and stuff like that every team kind of just works a little bit different and that it makes that kind of machine learning really difficult to do I think with generative AI I'm excited about being able to use generative AI to better ask questions about the data that is stored inside of a data store that we don't really know too well and so you know seen Promises of being able to analyze you know bunch of a security data and then being able to ask the question which of my virtual machines are running too hot and I can ask that question and see the results and the query that they use to go and get that and then it maybe 80% correct and that would be great and then you can tune it a little bit I I don't think AI is going to fix all the problems but I think it's going to be another tool to help us make sense of kind of all these different data and these different stores and I don't have to learn a new I don't have to become an expert a new programming language to get started with asking those questions that's kind of what I'm I'm excited about yeah I'm with you on that I mean how long is it going to be until you know you're in a log analytics workspace or Sentinel and I can say show me all of the IP addresses that have made a request from this service principal in the last hour and I don't have to know kql and I don't have to understand the structure of that table or any of the columns and it's just going to say here you go Eric here's all the data that you asked for and gen generatively you know if there's an anomaly in there how interesting will it be when one of those IP addresses is an anomaly and it can then ask you hey Eric would you like to disable this service principle and I can just say yeah sure and and I think that's really where the the expansion is going to be is you know can our analysts just be talking with a generative AI bot instead of having to do a lot of that work themselves I agree and I think it's important to recognize that you still need to have that human element today you still need that context currently robots don't know the difference between good and bad they don't know what your business case is so similarly to how I've always been frustrated with static analysis tools which are able to find bugs but not the most important bugs that matter to your industry or any issues related to business logic flaws similarly AI is only going to be able to find issues if you drive it in the directions that make sense in the context of your business because one transaction in one environment may be perfectly legitimate and not in another one so don't get rid of all the humans we still need the humans please keep them around yeah it's another tool it's just I feel like it's another tool it's a a good tool maybe if we use it properly but I think it's another tool so someone asked this question in the chat what tools are considered top choices for security monitoring for 2024 so I'll ask each of you what is a tool that you're looking at either getting you're going to use more or you think it's going to get better in 2024 we start with Eric oh this is a tough one for security monitoring you know we've done a lot of work with uh you know the traditional kind of like the Sim Solutions the sore Solutions the spunks the U security onion Stacks Etc and I think it kind of circles back to my cost comment earlier where to use those especially from a multicloud context you're just getting hammered with egress charges to pull all that data out so I think the the solution and it's not a great solution this is me redesigning or rearchitecturing rearching a monitoring stack to avoid costing but I think the notion of a security data Lake per cloud is really catching on where if I'm in Google I've got BQ and maybe a little bit of Chronicle happening but I'm going to keep that siloed there and then Azure I'm going to probably in log analytics and Sentinel and in AWS you're probably in the the new like cloud trail data lake is service and a lot of that conversation goes down to can I use those tools to get the fine grain things that I need and then maybe you've got a very fine grain set of events that I'm then maybe G to push out of the cloud into that Central monitoring stack if you've got an actual event and a run book set up for it that's probably the only reason for that event to be leaving and going to the central Splunk instance for example that maybe running on Prem so I think that is a loaded question it's hard to just pick one anymore because of all the cost associated with it so you almost need to be an expert in a lot of different so sounds like better better integrating between these different things yeah I could definitely see that Brandon how about you we're at time and you could answer this question way better than me so I'm gonna kick it back to you all right I will say uh for security monitoring I would say probably the big thing I would thinking at is being able to show like your resources what is the activity and the posture at the same time in a way that makes sense what's going on I see too many tool saying here's a buch of alerts and then you have to go somewhere else to say is this thing even healthy or not so being able to combine those two together I could see and there's some tools out there now they're doing a better job of that and so I could definitely see that happening so um I want to say thank you to my panel because we are at about time thank you so much and thank you for those who have joined online and asked questions and engag I really do appreciate it Eric and Brandon have a great day and hopefully I'll see you at a at a Sans class sometime soon sounds good take care thanks for having us all right thank you

Original Description

In this week’s Wait Just an Infosec, SANS Certified Instructor and cloud security champion, Shaun McCullough, joins us to discuss his 2024 cloud security trends and predictions. Shaun and guests Brandon Evans, Eric Johnson, and Moses Frost will address cloud security trends and predictions through the lens of their vast experience with and knowledge of cloud attack techniques, monitoring, and threat detection. -- SANS is the most trusted and by far the largest source for information security training and security certification in the world. It also develops, maintains, and makes available at no cost, the largest collection of research documents about various aspects of information security, and it operates the Internet's early warning system - the Internet Storm Center.
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from SANS Institute · SANS Institute · 0 of 60

← Previous Next →
1 SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS FOR610: Reverse Engineering Malware: Malware Analysis Tools & Techniques
SANS Institute
2 SANS Institute Cybersecurity Training Customer Stories
SANS Institute Cybersecurity Training Customer Stories
SANS Institute
3 SANS Institute UK Cyber Academy
SANS Institute UK Cyber Academy
SANS Institute
4 SANS Institute UK Cyber Academy
SANS Institute UK Cyber Academy
SANS Institute
5 CISSP® Prep Exam, MGT414, by SANS Institute
CISSP® Prep Exam, MGT414, by SANS Institute
SANS Institute
6 SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute's Rob Lee Discusses The OPM.GOV Hack on CNN
SANS Institute
7 Information Security Training from SANS Institute - Student Testimonials
Information Security Training from SANS Institute - Student Testimonials
SANS Institute
8 SANS NetWars
SANS NetWars
SANS Institute
9 SANS DFIR NetWars
SANS DFIR NetWars
SANS Institute
10 Hack The Drone - SANS Cyber Academy UK
Hack The Drone - SANS Cyber Academy UK
SANS Institute
11 SANS VetSuccess Immersion Academy
SANS VetSuccess Immersion Academy
SANS Institute
12 SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Cybersecurity Training, Certifications & Placement for Veterans
SANS Institute
13 The 2015 SANS Holiday Hack Challenge
The 2015 SANS Holiday Hack Challenge
SANS Institute
14 SANS VetSuccess Academy: Hands-on Skills
SANS VetSuccess Academy: Hands-on Skills
SANS Institute
15 SANS VetSuccess Academy Overview
SANS VetSuccess Academy Overview
SANS Institute
16 SANS ICS Security Summit & Training 2017
SANS ICS Security Summit & Training 2017
SANS Institute
17 Exploring the Unknown Industrial Control System Threat Landscape – SANS ICS Security Summit 2017
Exploring the Unknown Industrial Control System Threat Landscape – SANS ICS Security Summit 2017
SANS Institute
18 WannaCry recap, patches, and analysis
WannaCry recap, patches, and analysis
SANS Institute
19 If We’re Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
If We’re Doing So Well at Cyber Security, Why Are We Still Doing So Poorly?
SANS Institute
20 Graduation Day - SANS HM Gov Cyber Retraining Academy
Graduation Day - SANS HM Gov Cyber Retraining Academy
SANS Institute
21 Incentivizing ICS Security: The Case for Cyber Insurance – SANS ICS Security Summit 2017
Incentivizing ICS Security: The Case for Cyber Insurance – SANS ICS Security Summit 2017
SANS Institute
22 SANS Data Breach Summit & Training 2017
SANS Data Breach Summit & Training 2017
SANS Institute
23 SANS Secure DevOps Summit & Training 2017
SANS Secure DevOps Summit & Training 2017
SANS Institute
24 How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
How Threats Are Slipping In the Back Door - SANS ICS Security Summit 2017
SANS Institute
25 SANS Webcast – Continuous Opportunity: DevOps & Security
SANS Webcast – Continuous Opportunity: DevOps & Security
SANS Institute
26 SANS Cybersecurity Programs for the Department of Defense
SANS Cybersecurity Programs for the Department of Defense
SANS Institute
27 SANS Pen Test HackFest Summit & Training 2017
SANS Pen Test HackFest Summit & Training 2017
SANS Institute
28 SANS SIEM & Tactical Analytics Summit & Training
SANS SIEM & Tactical Analytics Summit & Training
SANS Institute
29 If We’re Doing So Well, Why Are We Still Doing So Poorly? – SANS ICS Security Summit 2017
If We’re Doing So Well, Why Are We Still Doing So Poorly? – SANS ICS Security Summit 2017
SANS Institute
30 SANS Institute
SANS Institute
SANS Institute
31 ICS515: ICS Active Defense and Incident Response
ICS515: ICS Active Defense and Incident Response
SANS Institute
32 SANS Institute
SANS Institute
SANS Institute
33 Introducing the NEW SANS Pen Test Poster
Introducing the NEW SANS Pen Test Poster
SANS Institute
34 SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute - An Inside Look at the Newly Updated ICS515 Course
SANS Institute
35 SANS ICS Security Training, Munich, Germany
SANS ICS Security Training, Munich, Germany
SANS Institute
36 SANS Automotive Summit Webcast
SANS Automotive Summit Webcast
SANS Institute
37 Privesc Playground - SANS Pen Test HackFest Summit 2017
Privesc Playground - SANS Pen Test HackFest Summit 2017
SANS Institute
38 Introduction to Reverse Engineering for Penetration Testers – SANS Pen Test HackFest Summit 2017
Introduction to Reverse Engineering for Penetration Testers – SANS Pen Test HackFest Summit 2017
SANS Institute
39 Honey, Please Don’t Burn Down Your Office: Fun with Smart Home Automation
Honey, Please Don’t Burn Down Your Office: Fun with Smart Home Automation
SANS Institute
40 SANS Security Operations Summit & Training 2018
SANS Security Operations Summit & Training 2018
SANS Institute
41 Sh*t Happens!  (But You Still Need to Drink the Water) – SANS ICS Summit 2018
Sh*t Happens! (But You Still Need to Drink the Water) – SANS ICS Summit 2018
SANS Institute
42 ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape – SANS ICS Summit 2018
ICS Threat Intelligence: Moving from the Unknowns to a Defended Landscape – SANS ICS Summit 2018
SANS Institute
43 You’re Probably Not Red Teaming (And Usually I’m Not, Either) – SANS ICS Summit 2018
You’re Probably Not Red Teaming (And Usually I’m Not, Either) – SANS ICS Summit 2018
SANS Institute
44 A Sneak Peak at the New ICS410
A Sneak Peak at the New ICS410
SANS Institute
45 Jumping Air Gaps – SANS ICS Summit 2018
Jumping Air Gaps – SANS ICS Summit 2018
SANS Institute
46 Introduction to Linux
Introduction to Linux
SANS Institute
47 Introduction to Malware Analysis
Introduction to Malware Analysis
SANS Institute
48 You’re Probably Not Red Teaming (And Usually I’m Not, Either) Webcast by Deviant Ollam
You’re Probably Not Red Teaming (And Usually I’m Not, Either) Webcast by Deviant Ollam
SANS Institute
49 Hacking your SOEL: SOC Automation and Orchestration – SANS Security Operations Summit 2018
Hacking your SOEL: SOC Automation and Orchestration – SANS Security Operations Summit 2018
SANS Institute
50 Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
Hunting for Post-Exploitation Stage Attacks with Elastic Stack and the MITRE ATT&CK Framework
SANS Institute
51 Apples and Oranges?:  A CompariSIEM – SANS Security Operations Summit 2018
Apples and Oranges?: A CompariSIEM – SANS Security Operations Summit 2018
SANS Institute
52 SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Webcast - Perimeter Security and Why it is Obsolete
SANS Institute
53 SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Webcast - Trust No One: Introducing SEC530: Defensible Security Architecture
SANS Institute
54 The Science of Security: The Psychological Impacts of Security Awareness Programs
The Science of Security: The Psychological Impacts of Security Awareness Programs
SANS Institute
55 How I Pulled Off an Edgy Security Campaign – SANS Security Awareness Summit 2018
How I Pulled Off an Edgy Security Campaign – SANS Security Awareness Summit 2018
SANS Institute
56 Practical Advice for Submitting to Speak at a Cybersecurity Conference
Practical Advice for Submitting to Speak at a Cybersecurity Conference
SANS Institute
57 SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Webcast - Consuming OSINT: Watching You Eat, Drink, and Sleep
SANS Institute
58 SANS Webcast - Zero Trust Architecture
SANS Webcast - Zero Trust Architecture
SANS Institute
59 SANS STX Cyber Range
SANS STX Cyber Range
SANS Institute
60 Part 1 – SANS Institute and Tenable talk about cloud security
Part 1 – SANS Institute and Tenable talk about cloud security
SANS Institute

The video provides an overview of 2024 cloud security trends and predictions, covering topics such as Kubernetes security, GraphQL, AI limitations, and multicloud adoption. It discusses the practical applications and challenges of these technologies and provides insights into the future of cloud security.

Key Takeaways
  1. Investigate Kubernetes security best practices
  2. Evaluate AI limitations and potential applications
  3. Assess multicloud adoption and its challenges
  4. Apply retrieval augmented generation and fine-tune AI models
  5. Utilize vector stores for security data and optimize security monitoring
  6. Evaluate security data analysis tools and assess AI-driven security effectiveness
💡 The video highlights the importance of understanding AI limitations and potential applications in cloud security, as well as the need for effective security monitoring and data analysis.

Related Reads

Up next
Welcome to the Next Temperamental Era
Charles Schwab
Watch →