2013 AWS Worldwide Public Sector Summit
Washington, D.C.
Next Generation Privileged Identity Management
Who We Are
•
Security software company providing Next
Generation Privileged Identity Management
solutions
•
Global Fortune 1000 and Government
Our Customers Include
Commercial
• Top 5 Global Bank
• Top 3 Telecommunications Company • Fortune 10 Financial Services Company • Top 5 Global Retailer
• Multiple Global Stock Exchanges • Fortune 200 Food Products Company • Top 3 Online Broker
• Top 3 Smart Phone Provider • Top 3 Food and Drug Retailer
The Problem We Solve
•
Protect Enterprises from Privileged User Risks
•
Reduced Complexity of Audit and Compliance Controls
– PCI/DSS, HIPAA/HITECH, NERC CIP, FISMA, GLBA, SOX
•
Privilege Usage Gateway to Manage Access Across Traditional, Virtualized,
Cloud, and Hybrid Environments
Deploy Privileged Account Management for
IaaS and Private Cloud
Administrators of private cloud and IaaS environments gain more concentrated power — and the risk that goes with it — ………..additional controls should be put in place around the
privileged accounts within these environments and employ privileged account management products to aid in placing finer-grained controls around the additional operations that these environments provide.
Compliance and Audit
•
Controls, Directives, Policy, Frameworks….
– HSPD-12, CAP Goals (PIV, Cont. Monitoring, TIC) – NIST SP-800-53(r4) (Insider Threat, Cloud)
•
Audit Findings (POAM)
– Shared accounts (“who was root”)
– Shared credentials (email / sticky note) – Weak / default passwords
DoD 8520.03- Identity Authentication
for Information Systems
•
Credential Strength “E”
all administrative access
•
Hardware token PKI
technology
•
Identity proofing
•
Identity vetting
•
Credential registration
Who Are Privileged Users?
On Premise Employees/Partners • Systems Admins • Network Admins • DB Admins • Application Admins Partners Systems/NW/DB/Application Admins Employees Systems/NW/DB/A pplication Admins Public Cloud Apps AppsUnauthorized User Hacker (Malware/APT)
Migration to the New Enterprise
Figure 2. The Virtualization Road Map Through Private Cloud Computing
Source: Gartner (February 2012) • Consolidation
• Capital expense
• Capital expense elimination • Increased
flexibility (up and down)
• Flexibility and speed • Operational expense automation • Less downtime • Self-serve agility • Standardization • IT as a business • Usage metering STAGE 1: Server Virtualization STAGE 5: Public Cloud STAGE 2: Distributed Virtualization STAGE 3: Private Cloud STAGE 4: Hybrid Cloud
• Costs for peak loads
NIST 800-125
“Guide to Security for Full Virtualization Technology”Restrict and protect administrator access to the virtualization solution
•“The security of the entire virtual infrastructure relies on the security of the virtualization
management system”
•“…start guest OSs, create new guest OS images, and perform other administrative actions.
Because of the security implications of these actions, access to the virtualization management system should be restricted to authorized administrators only.”
•“Secure each management interface, whether locally or remotely accessible.”
•“For remote administration, the confidentiality of communications should be protected, such as
NIST Cloud Security Architecture
Privilege Management Infrastructure
Identity Management Authentication Services
Authorization Services Privilege Usage Management Domain Unique Identifier Identity Provisioning Federated IDM Attribute Provisioning Policy Enforcement Policy Management Resource or Data Management Policy Definition Privileged Data Management XACML Role Management Obligation Out of the Box (OTB)
SAML Token Risk Based Authenticati on Multifactor OTP Smart Card Password Management Network Authentication Middleware Authentication OTB Keystroke/Sessio n Logging Privilege Usage Gateway Password Vaulting Resource Protection Biometrics Single Sign On WS Security Identity
Identity Integration Enterprise-Class Core
Hardware Appliance OVF Virtual Appliance AWS AMI
Unified Policy Management
Control and Audit All Privileged Access
• Vault Credentials
• Centralized Authentication • Federated Identity
• Privileged Single Sign-on
• Role-Based Access Control • Prevent Leapfrogging • Monitor & Record Sessions • Full Attribution
Introducing Xsuite
®Next Generation Privileged Identity Management
Traditional Data Center
Mainframe, Windows, Linux, Unix, Networking
New Enterprise
Virtualized Data Center
VMware Console
SaaS Applications
Office 365 Console Public Cloud - IaaS
High Level Xsuite Architecture
- Security, Compliance, and Audit…simplified
Xs ui te Se c urity A dm in
Keystroke and Session Recording Alerting, Logging, and Resource
Protection
Web Interface
Password and Key Vaulting and FIPS 140-2 Encryption
Federated Privileged Identity Service
API Proxy
Security Policy Engine (Authorization Services)
Session Applets
Third Party Log and SIEM Platform
Third Party Encryption, Identity Providers, and X.509 Services Directory Services (LDAP, AD FS, AD) Target Cloud, Application or Host Platform Authentication Service
Privileged Identity and Authentication Management
HSM Crypto Support
Credential Safe Session
Logs Policies
Attribute Identity for Shared Accounts (e.g., Root/Admin)
Control Access to Target Systems Prevent Leapfrogging
Monitor Sessions & Prevent Unauthorized Commands Record Sessions
Positively Authenticate Users
Before: ID: abc123 PW: password After: ID: abc123 PW:x8km&eie10$z*!B
Vault & Manage Credentials
Xsuite for AWS
Security Across AWS Regions, Management Console, and APIs
Xceedium Announces Privileged User Protection for AWS
Cloud Management APIs
AWS Management API Security
•
Shared credentials are
typical
•
Difficult to attribute
privileged API activities to
unique users
•
No log files of what
happened
AWS APIs
(Compute/Networking, Storage/Content Delivery, App Services, Database)
Xsuite for AWS API Proxy
• Single point of access control, monitoring, and audit - all activity with AWS Management Console and REST APIs • Role-based API access control for programmatic and manual
AWS API Access • Separation of duties
• Full, real-time bi-directional audit trail of all API calls
• Attribute AWS API activity to a specific user – no need to add users to AWS Identity and Access Management (IAM)
• Uses alternative credentials valid only with the Xsuite AWS API Proxy – no direct access to AWS APIs
• Vault and manage the credentials used by scripts to access AWS APIs and eliminate the practice of sharing these
important keys
Public Cloud/ Gov. Cloud/ VPC
Core Xsuite Capabilities
•
Comprehensive Protection for Management Consoles, APIs and Guest
Systems:
– Role Based Privileged Access Control
– Password and Access Key Vaulting & Management – Application-to-Application Password Vaulting
– Privileged User Single Sign-On
– Full Audit Trail and Session Recording – Full Identity Attribution for Shared Accounts – Auto-discovery and Provisioning
What Sets Xceedium Apart?
•
Next Generation Privileged Identity Management
•
Xsuite is the Only Platform With:
– A comprehensive set of well integrated controls enforced across hybrid cloud environments – Single policy enforcement point across hybrid-cloud environments
– Unified policy management
– Protection for both management consoles and guest systems
– Integration with VMware, Amazon Web Services and Microsoft Office 365 – Control and Auditing of AWS management API calls
– Specifically architected for dynamic, elastic cloud environments – Choice of appliance form factor: hardware, OVF or AMI