Making Life Simpler for DevOps with Security Practices
May 04, 2016

Anirban Banerjee
Onion ID

The next breach inside enterprises is expected to come from within. Many articles have been written about Insider Threats, the origination points, motivation, detection, DLP and more. I have talked to many an enterprise to understand the strategies and policies that are employed to manage this threat.

Privilege Management is a new age term, born from the crucible of Role Based Access Control (RBAC). Privilege Management refers to the ability of any enterprise to successfully manage, detect and mitigate any possibility of employee account misuse. The definition is quite terse and a bit wishful. In reality most organizations have very poor privilege management practices employed for their resources. In this blog, I will discuss why that is the case, what are some good strategies to launch effective privilege management in your organization and some of the gotchas that you can avoid.

The Many Faces of DevOps

Lets accept a fact: DevOps plays a multitude of roles inside most organizations. It is no longer: “Let's make sure our DNS stays up all the time.” It is: “Let's make sure our DNS stays up all the time and that we are DDoS resistant.”

Feel free to tag on a couple of more statements dealing with enhancing the security of the previously mentioned DNS system. The point is that DevOps is evolving at a breakneck speed and more enterprises are putting jobs on a DevOps person's plate than they can reasonably take off it.

The Pain Point

One of the constant thorns in the side is security. As if it's not hard enough to keep things running at web scale. It's great to read articles on hacker news about how you can use nodejs to power millions of requests a second without breaking a sweat. In reality though things are far from rosy. It's a lot of hard work, long nights, group huddles that get things to work, and, work with a good degree of reliability.

In this blog, I am going to talk about how a lot of DevOps teams are managing security practices and what can be done to reduce the amount of time spent on each aspect yet up the amount of security that you can actually eek out of the system.

Why Existing Tools Don't Alleviate the Pain

Using configuration management systems ensures that DevOps does not spend time on making sure the base OS images, packages and software on servers that make up a cluster are uniform and adhere to a common set of security guidelines.

Even though the tools mentioned above are very effective in providing network visibility they do not help DevOps when the proverbial (expletive deleted) hits the fan from a compliance perspective.

Consider the case where an employee account is misused to perform some actions that are not in compliance with a company's policies. In this case, using configuration management systems helps only to the effect that you can find out if someone accessed an account, when and possibly which server were affected. However if the employee is smart enough and tries to cover their tracks by wiping history, logs etc. it's a rabbit hole that DevOps and security teams have to now jump into.

This is a case of misalignment of expectations from a DevOps group. Unfortunately this happens more often than not because DevOps handles the heartbeat of any product and so is called in time and again to help with various teams like security.

Simple Fixes

To make life simpler for DevOps here are some high level tool category suggestions that will save time and headaches when push comes to shove:

1. Install and use a SSH key rotation system: This will help in keeping compliance reviews short and prevent attackers from causing massive damage.

2. Install and use a SSH session recording system: This helps in making sure that if ever a request comes in to analyze whether someone performed a specific action, DevOps does not have to spend a ton of time investigating issues.

3. Use an inventory management system for all your infrastructure: Something akin to security monkey for AWS. This helps you keep tabs on what you really see in the configuration management system is actually what is on your cloud IaaS account or not.

4. Use a blacklist of commands: Mistakes happen often in life and people often make costly mistakes. Don't let someone type rm -rf* on your production cluster by mistake.

I discussed the high level rationale for why a DevOps job is not easy. I followed that up with some concrete product areas that will help make life simpler and less hectic for everyone.

Dr. Anirban Banerjee is CEO of Onion ID.

Share this

Industry News

April 25, 2024

JFrog announced a new machine learning (ML) lifecycle integration between JFrog Artifactory and MLflow, an open source software platform originally developed by Databricks.

April 25, 2024

Copado announced the general availability of Test Copilot, the AI-powered test creation assistant.

April 25, 2024

SmartBear has added no-code test automation powered by GenAI to its Zephyr Scale, the solution that delivers scalable, performant test management inside Jira.

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.