Skip to content
AppSec PodcastThe Application Security Podcast — home
44 min

Bill Wilder -- Running Azure Securely

with Bill Wilder

on Security Testing, Cloud and Infrastructure and Vulnerabilities and Exploits

Audio hosted by Buzzsprout. Nothing loads until you press play.

Bill Wilder joins Chris and Robert to talk about Running Azure Securely. You can find Bill on Twitter @codingoutloud

Mentioned in this episode

Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.

Transcript

6,416 words · assemblyai

0:00Chris RomeoHey folks, season 4, episode 25 of the AppSec Podcast. On this episode, we're joined by Bill Wilder, and Bill is an expert in all things cloud security and Azure. Bill takes us on a journey through all the different features, functionality, and services that exist in Azure to help you run your apps more securely in the cloud. We hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. Uh, this episode, we're talking about using Azure securely. We're joined by Bill Wilder. And Bill, we always start— the first question we ask people is, what is your security origin story? Our listeners are dying to know, how did you get into the world of security?

1:13Bill WilderHey, Chris. Hey, Robert. Yeah, it's good to be here. My security origin story, I guess I would trace back to my general interest over my career. I have a developer background and I've always been interested in, let's say, interesting technical challenges. And as you probably would both agree, a lot of these tend to be security-related. One of the interesting ones for me that was kind of formative was I joined a web startup back around the year 2000 in the boom days of web startups. It was called LifeFX. And we were trying to productize a technology that had come out of academia, MIT, and, uh, I think the University of Auckland in New Zealand was the other. And this technology was done by a bunch of PhDs, and it was really cool. It could animate the human face, a model of it. So we take some photos and videos, get a high-quality multi— like 3-dimensional model of, of the subject.

2:15Yeah.

2:16Bill WilderAnd once this was done, the technology allowed applying an audio track to it and have it— and then have the face animated so that it looked like the face was speaking what was in the audio track. So we were— it wasn't quite video quality, but that was the idea, is that it was very close to video, at least from the shoulders up. This is pretty impressive stuff, especially for the time. And we had some people that we hired, some models to make, we call them stand-ins, to make stand-ins. And we animated some pets and some other things. But we realized that if we were ever gonna get traction, it would be really helpful if we got well-known people to get on our platform. And we realized that nobody was gonna be willing to do this if they had to be worried about other people putting words in their face, words in their mouth, and having it sound like they were, you know, speaking something that they didn't really say. Of course, this is also a challenge today. Uh, the technology has moved along, but back then, uh, this was a, um, it was pretty hard to do this, and we were creating a weapon that could, you know, could potentially do that. So we had to solve this, and I took on the challenge. And to solve it, I basically went on a deep dive with Bruce Schneier's Applied Cryptography book, and I dug into lots of the cryptographic principles and the crypto tools like hashing and digital signatures and public-private asymmetric key pairs, and, and basically had a lot of fun building out a cryptographically secure, uh, digital rights management scheme to protect these assets. Uh, so that was my first, like, deep dive into something security-related. It was CRM and crypto. I'm sorry, it was DRM and crypto in that case. But I was kind of hooked, uh, because I do, you know, I like, uh, like I said, interesting problems. So I, I never stopped digging into the field from that point. And I guess, um, Basically, these security generally has been increasingly a part of my life, you know, as a percent of the time I spend in my day job over the years. As I mentioned, I have a developer background, so interspersed in there has been the usual developer stuff like learning about cross-site scripting and SQL injection and so forth. But as I Like 2011, I guess, I moved into cloud consulting. I was an early Azure adopter, and I was paying even more attention to security since I was helping companies and decision makers reason about security in the cloud. So I also kind of brought a different perspective to it. And, um, so anyway, that's continued to this day. As I, every year, my percent of time spent on security has increased probably to the point where instead of being— in the past, some years ago, I might have described myself as an architect who codes, where maybe I'm now more of a security professional who still does some architecture.

5:33Chris RomeoYeah, that's a very interesting path and journey and a little bit different than a lot of the other people that we actually hear from as far as the way they're getting to to security. So the topic is, for the rest of our time with you today, Bill, is gonna be using Azure securely. And so with Azure, I guess the first high-level question I'm gonna ask here is, can you even do cloud securely in this day and age? Is that even possible? Let's start at the macro level and work our way down.

6:08Bill WilderRight. Well, of course. I mean, I believe that it can be done securely. In a lot of ways, well, I guess if you're asking if it can be done securely, you have to start with the fact that you have a lot of the same challenges that you have when you're not in the cloud. So I mentioned earlier SQL injection, cross-site scripting, you know, those work pretty well in the cloud too. So you're not, There's no magic in going to the cloud. Your app security issues are still going to be there. But the cloud, I would say, it doesn't magically make you secure, but it gives you more tools to make you secure. So, for example, even with, say, cross-site scripting and SQL injection, some of the tools you might have rapid access to in a cloud environment might be a web application firewall to to help protect or alert you of attempts to exploit unknown cross-site scripting or SQL injection attacks. And some of the things that the cloud helps you do better than you might've had traditional access to is access to a more complete toolset So the, the, uh, I can— I know Azure best, but this would apply to most clouds. Uh, you have firewalls and, uh, built into the, all the places you would expect them, you know, ready to be used. You have, uh, encryption able to be turned on in the places you would expect it. Multifactor authentication, uh, protection of, uh, keys and secrets in a hardware security module.

7:57Chris RomeoYeah.

7:58Bill WilderAll that kind of stuff is a contributor to the answer to your question, which is yes, it's entirely possible to create applications in the cloud that are secure. And in a lot of ways, it's easier than more traditional non-cloud approaches.

8:17Yeah.

8:18Chris RomeoWell, let's kind of walk through a number of different potential security challenges. that our listeners that are using cloud may be dealing with. And I know you're gonna talk to these specifically from an Azure perspective because that's your level of expertise. And so just so our listeners are aware, we're gonna really focus heavily on Azure right now, but hopefully you can apply some of these principles to other cloud platforms as well. So the first one, Bill, that I'm thinking about and I'm seeing here in a talk that you did before, internet-exposed Remote Desktop Protocol or SSH endpoints. And so tell us a little bit about the risk and then tell us what we have in our cloud security toolbox to be able to take care of this.

8:59Bill WilderSure. Just like in the on-prem world, if you have a machine in the cloud, you may want to remotely access it for management and diagnostic reasons, normal stuff. So in the cloud, you have You could put a firewall around it to protect it, and you could put— you can lock it into a network segment so that you can only reach it through maybe a path through your corporate networks. Let me give you an example. You can have an entire Azure deployment that is not visible to the public internet, but is visible from, say, your on-prem world or even just one laptop. You can do this through the magic of VNets and VPN tunnels. Azure has a couple of technologies that support this. Virtual networks, of course, there's a whole networking capability where you can segment your networks and so forth. You can borrow into a virtual network through a technology, like from a laptop through a technology called Azure Point-to-Site networking. You can have your local, a local, say, on-prem network accessible to an Azure cloud network through a similar technology called Site-to-Site. You can even connect those up with a private circuit that you can rent that isn't routable over the public internet. So you'd go to a third-party provider and rent a circuit that would go from, say, your data center to the Azure data center. Microsoft has a whole host of many, many third parties that support this around the world.

10:51Mm-hmm.

10:52Bill WilderThat's a technology called Azure ExpressRoute. So there's a bunch of network-level technologies that will allow you to manage these servers without even having to expose them to the public internet.

11:05Chris RomeoSo now when we talk about this firewall here that's being deployed as part of Azure in my architecture, what is that actually? Like, is it a virtual machine that is being attached to my architecture, or what's actually happening under the hood for this firewall?

11:23Bill WilderSo the host-based firewall that you're referring to is running on the host. It's running on Windows or Linux. So by default, the virtual machines that you spin up from images available in the galleries from Microsoft will have these protections available, ready to use. So they do a lot of emphasis on focusing on secure by default.

11:54Chris RomeoOkay. And so there's no— I'm thinking, I guess I'm thinking more of the classical network architecture that I would have on-prem where I'd have a firewall at the edge. So from an Azure perspective, there's no firewall at the edge of my virtual environment. It's really, it's all about using network or host-based firewalls to protect all of the hosts across the board with their own host-based firewall.

12:19Bill WilderOh no, no. I'm glad you brought that up, Chris. It's just defense in depth. So that's one layer. You can certainly put a gateway there. Azure has multiple technologies for fronting these, but we'll call it, you know, there's a general gateway technology that can also have a, like a mod_security-style hosted firewall on that other tier of the network fronting these machines. So that could protect many machines, but each individual machine can have its host-based firewall as well. Okay.

12:56Chris RomeoOkay, and so now when we're talking about those gateways, is that a virtual machine that's running separate from my— is it just another virtual machine that gets spun up, or what is that? I guess I'm trying to get to the essence of what is that gateway that exists in my virtual environment that Microsoft's providing to me through Azure.

13:18Bill WilderYeah, it may well be a virtual machine, but the point, but I don't know for sure because it's an abstraction that Microsoft manages. Like many things in the cloud, uh, the, the, like, you don't know or, and shouldn't care how Microsoft deploys them.

13:35Chris RomeoYep.

13:36Bill WilderUh, because they, they, uh, own and operate and their ops team handles it. You get to do some configuration and, uh, you know, so forth. You know which, uh, holes to punch in it, you know, which ports to let in and what IPs to let in and out, that kind of thing. And you can test it, right?

13:51Chris RomeoI mean, you can test it to verify that the, you know, that they're providing it in such a way. But I guess, I guess the takeaway I'm getting from you here is it doesn't really matter because they're providing it as a service. It doesn't matter how they're delivering it as long as it works, which it does.

14:07Bill WilderYes. In summary, I would agree with that.

14:11Chris RomeoOkay, let's move on to the next one here where you were talking about Virtual machines missing security patches. So I think everybody, almost all of our listeners have heard us talk about security patches a lot of times from the third-party software perspective. But what does Azure do for us as far as automatic updates and container-based stuff and kind of getting out of that patch grind that everybody seems to be in?

14:38Bill WilderThere's been a trend in the last a few years of moving towards, um, one of the, one of the trends that you hear, a buzzword, is serverless computing.

14:50Yep.

14:51Bill WilderAnd Azure has a version of that called Azure Functions and others as well, but the probably the most prominent is Azure Functions. Amazon has Lambdas. Google has also something called Functions, I believe. And I bring that up because The abstraction is so high that all you're handing them is some code snippets. So, some modules that, maybe some classes that are compiled, or some Python code, or some JavaScript code, and you don't know about the machine. So, when you go to the full serverless extreme, there is no machine that you even get to manage.

15:34Chris RomeoOkay.

15:34Bill WilderYou may need to manage your library path. If you're using an outdated Python library, I don't know that Microsoft will completely protect you from that because you're deploying that library. But if you're talking about the operating system itself, then Microsoft is doing the patches. They're doing the Linux patches and the Windows patches. and the SQL database patches and the firewall patches and all that. So, they're handling that. And then as you go down the abstraction, as you decrease your abstraction from serverless to platform as a service to infrastructure as a service, you have more responsibility for patching.

16:23Chris RomeoOkay.

16:26Bill WilderFor example, with a Windows virtual machine, you can choose when you want it to be patched. And again, the defaults are pretty secure by default where out of the box, it will automatically run Windows Update for you at a reasonable cadence to keep you up to date.

16:48Chris RomeoYeah, back to that whole secure by default. as a great principle to apply across any technology stack. What about containers? We talked about serverless, we talked about Windows servers that are running as virtual machines. What about containers? Is there anything in the Azure universe that provides a Docker-like capability, or is that something Microsoft has just left out of their stack?

17:18Bill WilderYeah, Microsoft is pretty all in on the container game. And in fact, they have a service called AKS, the Azure Kubernetes Service. So the container management or orchestration platform that they've sided with is Kubernetes, and they have a whole stack around that. And part of their solution for making secure images available for Kubernetes is through the Azure Container Registry. So the typical way that you would manage containers in your own world is you would have a base container that you would get from somewhere, like it might be a Linux-based image or it might be a Windows Server-based image, and then you would layer your own you would layer on top of that with maybe one that's company-specific, and then for each application that you deploy, there might be an application layer on that. So it's a stack of container images, kind of a nesting. And the primary one that you get from the Azure Container Registry is, you know, that you get from Microsoft. They'll be patching that all the time.

18:32Yeah.

18:32Bill WilderSo that's a solid way to solve that problem.

18:35Chris RomeoYeah, okay, cool. Yeah, I didn't even know that. I didn't even know Microsoft's story about containers, so that's very helpful to understand kind of what they're doing there. So let's keep moving down the list and let's look at the web app vulnerability risk. And so what is Azure providing for us as far as ways that we can test or better protect our web apps?

18:56Bill WilderSo Microsoft provides I mentioned some of the gateway technologies, and those can include an optional web application firewall. So that's a common tool folks use to help as a defense in depth with possible undetected, like, SQL injection or cross-site scripting vulnerabilities that might be in there, you know, in your web application. You also can— you're free to, within certain boundaries, you're free to pen test and vulnerability scan your own applications. So that's, um, I mean, so there's no, like, not a limitation on that. So just like you would test your application if it wasn't in the cloud, you, you still want to be able to pen test it in the cloud.

19:43Yeah.

19:43Bill WilderAnd, you know, do your regular vulnerability scans. The limits there are that they ask you not to, uh, penetration test their services.

19:53Yeah.

19:53Bill WilderFocus on your apps and not do DDoS. But beyond that, they have a pretty clear set of rules there, but that's the gist of it.

20:02Chris RomeoOkay. So they're not providing you with any— do they provide scanning tools? If you don't have a scanning tool, say you're a startup and you want to do a DAST dynamic style scan, do they have something in their arsenal where I just click a button and I can run their scanner, or is this something I got to do with my own outside tools?

20:22Bill WilderSo you can attach a DAST to what used to be called Visual Studio Code. Um, what am I trying to say here? Uh, for— you can, you can with their blip blip blip. All right, brain rewinding. So for, for a DAST tool, they do provide you the hooks to, uh, to hook that into your build and deployment pipeline. What they used to call VisualStudio.com has been rebranded to Azure DevOps, and that has all the hooks in it for you to run static code analysis, dynamic code analysis, whatever you need to keep your bits secure.

21:06Chris RomeoYeah. Now, are they just providing tools from other vendors like opening and allowing different companies to offer their tool in that Azure DevOps pipeline process? Because I don't think there's a Microsoft static tool or a Microsoft DAST. I don't think there is.

21:23Bill WilderI don't know. Microsoft Visual Studio has some code quality analysis available. It has some security features, but it isn't as complete as SonarQube or— trying to think of the other ones. What's the one out in Waltham, Robert? I'm sorry, which data center or the— No, the security tool vendor. I can't think of— they're one of the most common DAST analysis vendors. Their name is escaping me. Um, are you Veracode, or is that— that's in Berlin? Veracode. Yeah. Oh, Berlin. Yeah, yeah, yeah. So, uh, so Microsoft, you know, out of the box, they don't have, um— out of the box, they, they, they have the hooks, and they have a rich ecosystem of third parties that you can hook into, uh, SonarQube or Veracode, or HP has a product and so forth.

22:31Okay.

22:31Bill WilderAnd that's a good— that's a good point though to mention that, um, They've done a great job of enabling the third-party ecosystem, either through hooks like this or directly within the cloud itself. So if you weren't happy with, say, Microsoft's WAF gateway product and you were at the Juniper shop or Cisco or something, you could— or Barracuda— you could opt to use their tools and they're available for you right within the Azure portal itself.

23:03Chris RomeoAfter the break, Bill talks about the risk of weak admin credentials and how Azure deals with this. The Application Security Podcast operates with support from Security Journey. A Security Belt Program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com. Visit www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Bill dives back in to explaining the ways Azure deals with weak admin credentials.

23:45Bill WilderSo first, it's worth mentioning this list comes from a Mark Russinovich talk from a few years ago, and I've updated his answers. to account for more recent Azure advancements that weren't there maybe in 2015 when he wrote this.

24:01Chris RomeoOkay.

24:02Bill WilderSo the weak admin's credential was a risk leading to tenant breach, and the 2 primary mitigations listed here are the multifactor authentication, and that's definitely at the Azure Active Directory level.

24:21Chris RomeoOkay.

24:21Bill WilderSo this isn't just delegating to your on-prem AD. It could, they could be integrated, but this is the data, I'm sorry, the identity provider for all of Azure is Azure Active Directory. So if you log into an Azure portal, you're logging in with Azure Active Directory, regardless of whether it's integrated with your on-prem. If you're logging into Intune or into Office 365 or other kind of cloud products, those are all managed through the single Azure Active Directory provider. So they've really hyperinvested in an enterprise-class identity system. And it has baked into it multifactor authentication.

25:13Okay.

25:14Bill WilderYou can apply password policies, you know, complexity and password rolling and so forth. And they even have other features like privileged identity management and advanced policies. So for example, if you're logging in with legitimate credentials, but you're, 10,000 miles away from where you were an hour ago, and that location 10,000 miles away is an unusual location for you to log in from, you can also have a policy that says, I want to ensure that there's an extra challenge. So maybe even if you didn't have multifactor authentication enabled, it could cause it to challenge you in that case, or it could just decline to allow you to log in.

26:06Chris RomeoOkay.

26:07Bill WilderDepending on the policies you set.

26:09Chris RomeoYeah, so this is some good stuff there. So the next one is this unrestricted SQL endpoints. And so when I think about kind of classic architectures of, you know, 3-layer kind of systems, you know, with a couple of layers of firewalls in between, I don't feel like there's a lot— I don't feel like that database firewall layer is still as prevalent as it used to be. So what's the real advantage of the Azure SQL Database Firewall?

26:40Bill WilderWell, like any other firewall, it will allow you to limit who has network-based access to your database. Actually, that's not quite right. Let me rephrase that. Like other firewalls, it will allow you to whitelist who is able to access your database based on their source IP address.

27:06Chris RomeoOkay.

27:07Bill WilderSo if you have, uh, maybe if you have a firewall— I'm sorry, maybe if you have a SQL database that needs to be accessed by many developers, uh, you might have a pretty liberal firewall policy.

27:23Chris RomeoOkay.

27:23Bill WilderAnd that's, you know, I think pretty common. Uh, it might even be wide open. But if you have data that you're trying to protect, you probably know the applications from which it's being accessed, and you can whitelist those IP addresses. Or if you have, you know, an ops team that always comes in from certain IP addresses, you can, for troubleshooting, say, you can whitelist those, that kind of stuff. You can also put it on, you can also take it off the network entirely and make it so that it can only be accessed accessed from certain— so it isn't even visible on the public internet.

27:58Chris RomeoOkay. Now, is this an Azure SQL Database Firewall that actually speaks SQL? Is it doing layer 7 SQL firewalling as well, or is this just like a network-based firewall that happens to sit near the SQL databases?

28:13Bill WilderYeah, it's the second one. It's a layer 3, layer 4 firewall. firewall that will— I think it knows protocols and IP addresses.

28:24Chris RomeoOkay, great. So the next one was talking about in the slide from your talk that you got from Mark, you talked about storage key disclosure. I want to go a step further and just talk about secrets in general at this point, because there's obviously a risk in any cloud, there's a risk almost anywhere that if you have secrets, people are going to try to get them. And if you store them poorly, they're potentially going to be found. What does Azure give us from a— I'm familiar with Amazon's Key Management Services and being able to have that cloud-based secure storage of the most important secrets that my architecture needs to operate. What's the Azure answer on secret protection?

29:05Bill WilderIt's interesting. The answer used to be, that Microsoft offered a hardware security module, which is the kind of industrial-strength protection that a bank or a— I'm trying to think— like a certificate provider or other highly secure operations would buy. And they cost many tens of thousands of dollars.

29:39Yeah.

29:40Bill WilderMicrosoft and other big cloud vendors like Amazon make them available almost for free. They cost something, but it's a trivial amount of money. So we have access to some of the most effective secret management storage systems that are available commercially at ridiculously discounted prices.

30:03Chris RomeoYeah. And just for our listeners that might not know what a hardware security module is, Can you give us a sentence or two just to help kind of solidify with them what is an HSM?

30:15Bill WilderYes. In the context of Azure, an HSM, in the particular case of Azure, the HSM is something called Azure Key Vault. And Azure Key Vault has a couple of interesting properties that make it a, you know, a great place to store your secrets. One is that to access secrets from Azure Key Vault, one needs to authenticate to the Key Vault itself. And further, and this is one of the defining characteristics of HSMs generally, hardware security modules generally, is you could put secrets in Azure Key Vault that you yourself can't take out.

30:53Chris RomeoMm-hmm.

30:54Bill WilderAnd that may seem useless, but if you consider asymmetric cryptography as one of your scenarios, it's pretty powerful. So an ops team can put a certificate into Azure Key Vault, or you can ask Azure Key Vault to generate them itself. That's also quite reasonable. And then you can ask it to decrypt something on your behalf. You never get the private key out of the Key Vault to do the decryption outside of Key Vault itself, but you can ask it to decrypt a particular key. So there's no risk of losing the decryption key. This is an asymmetric cryptography scenario here. And you can further, you can ask it to sign something, digitally sign something for non-repudiation or purposes where a digital signature might be relevant.

31:50Mm-hmm.

31:51Bill WilderAll those can be done without ever exposing the private key itself. You don't need the private key to do encryption or validation of a digital signature, so those don't need to be done within the Key Vault itself. Those can be done with the public key. Bill, that brings up an interesting thing that I caught on your description there with the ops team doing something. I was thinking about from a developer perspective also, And what the developer needs to think about in terms of architecture and building out solutions that are going to work with, for example, Azure or any other cloud environment. I mean, they have to really think about these things, right, in order to build new applications that are not hosted on-prem but instead hosted in the cloud. Yeah, that's a totally fair point. It's a different flow. if you're submitting a secret to be just decrypted from somewhere else than it is if you're doing it inline, 'cause you can't programmatically grab the key and do all the encryption. So yeah, there are some cases where your system design would be a little bit different, but there are many cases where it's just simpler. So let me give you another example where it goes beyond just the use of the hardware security module, you know, Azure Key Vault, where Azure Active Directory is also involved. So I mentioned before that you need to authenticate to Azure Key Vault in order to access, you know, secrets within it or to use the secrets within it that are— that it won't give you to, like, exercise the use of private key to sign something or to decrypt a value. When you're authenticating to Azure Key Vault, you're using Azure Active Directory. Azure Active Directory can also be used with a higher-level abstraction called Managed Identities. When you're interacting with a service like Azure SQL Database, which you can think of as a managed version of It's a little different than that, but for conversation purposes, let's say it's that. Since Microsoft is managing Azure SQL Database and Microsoft is managing Azure Key Vault and it knows your application is in the cloud and it can identify your application as a known entity because you've registered with Azure Active Directory, directory, you can ask Microsoft to handle the authentication of your application with Azure SQL Database. The bottom line there is you never see a database credential either.

34:43Hmm.

34:44Bill WilderInstead of saying, how do we get the database connection string? how do we store and manage that? How do we get it into our app? You can let Microsoft worry about that, and you're not managing it at all. There isn't a username that has to flow into your application and password especially that has to flow into your application.

35:12Chris RomeoYeah, that's really neat. That seems like a very innovative way to approach what is what I've always thought of as perhaps one of the hardest problems in development security. How do you get the secrets in at the right time?

35:25Bill WilderAgree. Yeah, it is innovative. It is powerful. They're basically trying to reduce the number of times we actually need credentials in your hand. And this is, like you said, innovative is a good word for it.

35:41Chris RomeoYeah, very cool. So the last one on the list, we always know There's one thing in security that always ends up on the last entry on any list, and that is in regards to monitoring and logging. And so what has Azure given us from a security and log management perspective?

36:00Bill WilderIt's interesting that you phrase it as the last thing. I think this slide was definitely made before the most recent OWASP Top 10 was released, and I think insufficient monitoring is also the last one on that new OF Top 10 list. So that's— the stars are aligning there. So what does Azure give you in terms of solving for the insufficient monitoring problem? There's a really long answer, so I'll touch on a few points. So one is, from a strictly security point of view, Azure has Let me back up for a second. Azure has dozens and dozens of services. I mentioned some of them already, like Azure Key Vault, Azure SQL Database, Azure Active Directory, and virtual machines, many more. They also have a service called Azure Security Center, which is a service that exists just to help you manage the security of other services. And Azure Security Center is a kind of a centerpiece to the security story that you may want to, you know, make your— Azure Security Center is what you would probably make the centerpiece of your story of how you would secure your Azure deployments. Azure Security Center is growing every week, it seems, there's a new feature in it. But many of the features, let's see, how do I want to say this? Azure Security Center is, you might think of it as divided into 2 major parts. One is there is a free part that is applied to all your resources, which is static analysis. If you have a SQL database or a Blob Storage account, that doesn't have transparent data encryption enabled so that data is always encrypted at rest, it will scan for that and let you know that you might want to turn that on.

38:06Mm-hmm.

38:06Bill WilderIf you don't have the latest patches on your virtual machines, it would let you know because you might want to do something about it. If you don't have a firewall, it might tell you to, you know, it would suggest to turn on the firewall. If you do have a firewall but it's wide open, like I mentioned, might be a common scenario for a dev environment, it would tell you that there's a firewall, but it's pretty wide open. You might want to lock it down. If you don't want to lock it down, you can tell it to ignore that particular recommendation for that particular resource. But the idea is that it's kind of like static code analysis, except on your infrastructure, where it's telling you all the things that don't seem to be configured optimally from a security point of view.

38:47Hmm.

38:47Bill WilderYou might want to put a WAF in here. You might want to You know, et cetera. There are so many of them. And then there's a dynamic aspect where Microsoft's machine learning and their operations and their threat intel, all that come into play, which will tell you about things that are happening, you know, activities that are happening that might be security sensitive. This is a paid service. This is Azure Security Center Standard. And that would tell you something such as my resources are being attacked. And this is the cloud, so this is common, especially if you have some, like in development, you have some open endpoints. It will tell you that somebody tried to brute force through RDP your virtual machine, or it would, if there was suspicious activity in, SQL database, it would tell you maybe that there were some query patterns that look like they could be SQL injection, that they could be SQL injection. You might want to investigate. It can tell you if you're communicating with a suspicious IP address and So if you had, say, a machine that was compromised, I'm pretty confident that their threat intel and their machine learning and such are able to identify those as potentially breached. Well, sorry, I'm kind of butchering this segment. I'll leave it there.

40:40Chris RomeoOkay. And so, yeah, so it sounds like Security Center is really the central point for all the things that we've been talking about here already. And I probably should ask that question first, but that's okay. It was building to the crescendo at the end where Security Center is the answer to a lot of the things that we're doing. here. So I know we've gone through a lot of different stuff here, a lot of different technologies and capabilities that Azure has. Bill, what would you recommend for our listeners who are thinking, okay, this is great, now I have a broad understanding of the pieces that Azure has for security? Where would you recommend people go next if they want to dive deeper into learning about these different things?

41:26Bill WilderSo to dive deeper and learn about these topics, Microsoft has tons of great educational resources. There's docs. Actually, I don't actually know the— let me take another swing at that and I'll say, I'll give you some offline. We can put them in the show notes. Is that a fair answer?

41:53Chris RomeoYes, sir.

41:54Bill WilderYeah. So Microsoft has invested a lot and they have tons of great technology resources for you to learn about all facets of Azure, all these services. And I'll share that offline and you can include that in the show notes.

42:08Chris RomeoOkay.

42:09Bill WilderThere's stuff available on Microsoft website. There are some interesting podcasts. There's like an Azure Friday that often has security topics. There are conferences, one in the Boston area. Actually, shit, I'm sorry. I'm not, I don't wanna, I know you're probably pressed for time here. No, no, no. Let me give this one more swing.

42:32Chris RomeoYeah, please.

42:33Bill WilderI'll just start from the top so it makes editing easier. So to dig in here more and learn more, so to dig in and learn more about Azure and security in Azure, there are tons of free resources available from Microsoft. They're available on their website and through podcasts and so forth. I'll send some links over that you can include in the show notes.

42:54Chris RomeoOkay.

42:55Bill WilderIf you're a conference kind of person, their annual conferences like Ignite have great content as well, and those are typically available as downloadable videos after the conferences.

43:07Chris RomeoThat's a Microsoft conference, Ignite is?

43:10Bill WilderThat's right.

43:11Okay.

43:11Bill WilderAnd if you're in the Boston area, Boston Azure is the user group I've been running since 2009. We frequently host events that are focused on security in Azure.

43:23Chris RomeoCool. Well, Bill, thanks for taking the time today and sharing all of your knowledge about all these things Azure. And I know I definitely learned a lot just from asking questions here. And so I know our listeners are going to take away a lot from this. So thank you for your time and we look forward to hearing more in the future about where Azure's going.

43:42Bill WilderThanks, it was great talking to you, Chris and Robert. Have a good one.

43:46Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Kartenberg. You can find us on Twitter @AppSecPodcast or on the web At www.appsecpodcast.org.

More like this