SlideShare una empresa de Scribd logo
1 de 57
Descargar para leer sin conexión
Thursday, Apr 18, 2019
1. Intro & Activity Update
2. Community Open Mic
3. Andrew Brown, ExamPro: "Serverless
Security in AWS Cloud"
4. Mike Apted, AWS Canada: "Serverless,
Startups & AWS - The beginning of a
beautiful friendship"
5. Networking
1
ServerlessToronto.org Meetup Agenda
Manning Publications 2019 giveaways:
1. www.manning.com/books/serverless-applications-with-nodejs
2. www.manning.com/livevideo/production-ready-serverless
3. www.manning.com/livevideo/production-ready-serverless
4. www.manning.com/livevideo/serverless-applications-with-AWS
5. www.manning.com/livevideo/serverless-applications-with-AWS
6. www.manning.com/books/serverless-architectures-on-aws
7. www.manning.com/books/http2-in-action
8. www.manning.com/books/event-streams-in-action
9. www.manning.com/books/the-design-of-everyday-apis
10. www.manning.com/livevideo/graphql-in-motion
11. www.manning.com/books/voice-applications-for-alexa-and-google-assistant
12. www.manning.com/livevideo/machine-learning-for-mere-mortals
13. www.manning.com/books/classic-computer-science-problems-in-python
2
3
4
5
Community Open Mic
6
10 seconds of freedom
to pitch yourself, or
your company
Andrew Brown
April 18 2019
andrew@exampro.co
CEO of ExamPro
12 Year Full Stack Developer
4/10 AWS Certifications
Loves StarTrek DS9
The Fast Track to
Serverless Security on AWS
Full-Stack Powerleveling
Powerleveling The Fast Track to Security on AWS exampro.co
This Tech Talk Is Designed To Help You
Study For The Security Speciality AWS Certification
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Keeping our secrets a secret
Mitigating DDoS Attacks
Encrypting data at rest
Encrypting data in transit
Least permissive IAM policies
Securing AWS Lambda Functions
Protect against common exploits and attacks
Automated Security with ML services
KMS - Key Management Service
ACM - AWS Certification Manager
IAM - Identity and Access Management
Lambda
CloudFront, AWS Shield
Param Store, Secrets Manager
WAF - Web Application Firewall
Macie, Guard Duty
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Serverless Security Resources
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Serverless Security Resources
1. Injection
2. Broken Authentication and Session Management
3. Sensitive Data Exposure
4. XML External Entity
5. Broken Access Control
6. Security Misconfiguration
7. Cross-Site Scripting
8. Insecure deserialization
9. Using Components With Known Vulnerabilities
10. Insufficient Logging and Monitoring
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Serverless Security Resources
KMS - Key Management Service
checkbox secure and start encrypting
Multi-tenant HSM to create and control encryption keys
Hardware security module
$1 / per key
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Powerleveling The Fast Track to Security on AWS exampro.co
KMS integrates with many AWS services
Securing AWS Lambda Functions
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
lets you run code without provisioning or managing servers
Scan vulnerabilities in your 3rd party dependencies
Prevent event-data injection
Least permissive IAM policies
Keeping our secrets a secret
Lambda Protection from AWS Lambda Partners
Lambda Compliance
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Securing AWS Lambda Functions
Snyk
A developer-first solution that automates finding & fixing
vulnerabilities in your dependencies
Scan vulnerabilities in your 3rd party dependencies
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Securing AWS Lambda Functions
Prevent Event-Data Injection
“DELETE * FROM USERS”
File name
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Securing AWS Lambda Functions
Least Permissive IAM Policies
SSM Param Store
Powerleveling The Fast Track to Security on AWS exampro.co
Stores sensitive data such as passwords
Secrets Manager
$$$ - $0.40 /secret
● RDS Integration
● Multiple Key / Values in on Secret
● *Automated Key Rotation (via Lambda)
● Restore Accidentally deleted secrets
● Free!
● Versioned
● Rotate Keys with Cloudwatch + Lambda
Securing AWS Lambda Functions
Keeping Our Secrets a Secret
Powerleveling The Fast Track to Security on AWS exampro.co
● SOC 1
● SOC 2
● SOC 3
● PCI DSS
● HIPAA
Use AWS Artifact to gain access to these reports
on how AWS is compliant
Compliant with:
AWS Lambda Compliance
Macie
Both use machine learning to analyze logs
GaurdDuty
Powerleveling The Fast Track to Security on AWS exampro.co
DNS and Flow Logs CloudTrail Logs for S3
Powerleveling The Fast Track to Security on AWS exampro.co
Powerleveling The Fast Track to Security on AWS exampro.co
Macie
Powerleveling The Fast Track to Security on AWS exampro.co
Macie
Powerleveling The Fast Track to Security on AWS exampro.co
Macie
Powerleveling The Fast Track to Security on AWS exampro.co
WAF - Web Application Firewall
Powerleveling The Fast Track to Security on AWS exampro.co
Put a firewall in-front of your ALB or CloudFront
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
CloudFront (CDN) API Gateway Lambda
Default Throttled
10K requests per second (rpm)
WAF
WAF
ALB
Lambda
Two ways to protect Lambdas with WAF
Powerleveling The Fast Track to Security on AWS exampro.co
$5 per ACL
$1 per Rule
Powerleveling The Fast Track to Security on AWS exampro.co
WAF - Web Application Firewall
Powerleveling The Fast Track to Security on AWS exampro.co
Serverless Security AWS Whitepapers
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
AWS Lambda Security Partners
Serverless Security Platform
✓ Seamless integration into your CI/CD
✓ Checks over-permissive IAM roles
✓ Checks insecure storage of app secrets
✓ Scans known vulnerable 3rd party dependencies
✓ Serverless application firewall
★ Behavioural protection engine
✓ Security visibility via dashboard and notifications
AWS Lambda
Powerleveling The Fast Track to Serverless Security on AWS exampro.co
Questions?
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Mike Apted – Startup Solutions Architect
@mikeapted
AWS Canada
Serverless, Startups & AWS
The beginning of a beautiful friendship
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Zero upfront cost
With AWS’s infrastructure-on-demand,
startups can pay only for the resources
they use instead of investing in servers
upfront
Focus on core business value
Startups can focus on growing their
business rather than on infrastructure
Launch faster
Startups can have new IT resources
available in just a few clicks, increasing
agility
Experiment often at lower risk
Being able to deprovision resources as needed
enables startups to experiment often and fail
fast if an idea doesn’t work
Enabling Lean Startups with AWS Cloud
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Amazon launched their cloud
storage and computing services
and auto-scaling capability in
2006
Source: https://bothsidesofthetable.com/why-has-seed-investing-declined-and-what-does-this-mean-for-the-future-6a9572357130
Massive technology shifts such as cloud computing made it
significantly cheaper to launch a startup:
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Operational responsibility models
On-Premises Cloud
Less More
Compute Virtual Machine
EC2 Elastic Beanstalk LambdaFargate
Databases MySQL MySQL on EC2
RDS MySQL RDS Aurora Aurora Serverless DynamoDB
Storage Storage
S3
Messaging ESBs
Amazon MQ Kinesis SQS / SNS
Analytics
Hadoop Hadoop on EC2 EMR Elasticsearch Service Athena
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Startups benefit from serverless:
No infrastructure provisioning,
no management
Automatic scaling
Pay for value Highly available and secure
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
AWS
Lambda
AWS
Fargate
Amazon
API Gateway
Amazon
SNS
Amazon
SQS
AWS
Step Functions
COMPUTE
DATA STORES
INTEGRATION
Amazon Aurora
Serverless
Amazon
S3
Amazon
DynamoDB
AWS
AppSync
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Global Startup Business Development team
At AWS, we have a team of exited founders, former investors and startup
mentors aligned to every VC and accelerator of note
Beyond technology
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
AWS Startup BD/SA:
Working with venture
capital and the startup
ecosystem
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Innovation hubs are designed to help, collectively
Type of Hub Stage Funding Round ~ Revenue Timing Support Provided
Growth Hub > Self- Sufficient > A/B > $5 million As Needed
•Connections to
Customers, Capital
and Talent
Scaleup Hub
PMF to Self-
Sufficient
Seed → A/B
$1 million →$5
million
As needed
•Peers
•Network
•Services
•Network
•Office Space
Accelerator
MVP to Product
Market Fit
Angel → Seed
$0 →
$1 million ARR
Cohort
(3-6 mo)
•Mentors
•Network
•Programs
•Peers
•Office Space
•Investment
Incubator 0 to MVP 0 → Angel $0 As needed
•Mentors/Coaches
•Guidance
•Network
•Service Providers
MaturityofVenture
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
We invest indirectly alongside venture funds and accelerators
We don’t
• Invest cash
• Take a capital position
We do
• Invest time
• Share knowledge/experience/wisdom
• Help navigate AWS resources and support
• Open doors internally and externally
• Remove obstacles
• Leverage our global footprint
• Champion startups across all of Amazon
• Take a long-term view
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
We focus on helping our startup customers grow
by wiring them into people, resources, opportunities across Amazon
Technical
• Architecture design/optimization reviews
• Best practices
• Subject matter experts
• Betas/previews
• Security/compliance
Go-to-market
• Co-marketing
• PoC funding
• Sales referrals
• Distribution
• Capital intros
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Amazon programs that help startups grow their business
*Eligibilities and limits apply
AWS Activate AWS Migrate
AWS Well-Architected
Review
AWS Connections
• AWS promotional credits
• AWS Business Support Plan
• Online training credits
• Office hours
• Credits that help offset cost
of migration (limited time)
• Technical migration support
• Free review by AWS Solution
Architects
• Ensures secure, high-
performing, resilient,
efficient infrastructure
• Introduction to enterprises
with a specified solution
need
AWS Partner Network AWS Marketplace Amazon Launchpad Alexa Fund
• Tiered funding benefits
• Technical training
• Sales and business
enablement
• Co-marketing
• Streamlined go-to-market
on AWS’s software
marketplace
• Integrated billing with AWS
• Dedicated launch and
marketing support for selling
physical product on
amazon.com
• Equity investment for voice
technology startups
• Development and marketing
support and benefits
…and more! Contact your AWS Startup Business Development Manager for details.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Assistance to grow
Benefits
• Equity investment
• Early access to SDK capabilities
• Hands-on development support
• Marketing support
• Placement at Amazon showcase events
Eligibility
• Product benefits from the Alexa Voice Service or delivers new
abilities to Alexa-enabled devices through the Alexa Skills Kit
• Contributes to the science behind voice technology
More information
• Alexa Fund website
Alexa Fund
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Assistance to grow
Benefits
• Mentorship and network from across Amazon and Techstars
networks
Eligibility
• Product benefits from the Alexa Voice Service or delivers new
abilities to Alexa-enabled devices through the Alexa Skills Kit
• Contributes to the science behind voice technology
More information
• Amazon Alexa Accelerator website
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Removing barriers to
adoption
Benefits
• Credits that help offset cost of migration (limited time)
• Technical support (partner funding, AWS Support Plan)
Eligibility
• Speak with an AWS startup BD manager for details
More information
• Featured startup migrations on AWS Startup Blog
Startup Migrate Program
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Support at the
earliest stages
Benefits
• AWS promotional credits
• Business Support Plan
• Online self-paced lab credits
• Office hours
• Startup Spotlight
Eligibility
• Startups in accelerators, incubators, early VC funds or other
startup organizations (ex. university programs, co-working
spaces, etc.)
More information
• AWS Activate website
TOP OBSTACLES
PROVISIONING SERVERS
PAYING FOR SERVER IDLE TIME
SCALING FOR USAGE
THE DOORR PLATFORM
SOLVED MULTIPLE PAIN POINTS
USING SERVERLESS ARCHITECTURE
WITHOUT SERVERLESS
DOOR’S GROWTH WOULDN’T BE SUSTAINABLE
DUE TO INFRASTRUCTURE COSTS.
RESULTS
NET MONTHLY COST
$280
TIME TO BUILD CORE PLATFORM
3 MONTHS
TRANSACTIONS PER MONTH
24 MILLION
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Thank you!
Mike Apted – Startup Solutions Architect
@mikeapted
AWS Canada

Más contenido relacionado

La actualidad más candente

Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Amazon Web Services
 
Getting Started on AWS - AWSome Day Houston 2018
Getting Started on AWS - AWSome Day Houston 2018Getting Started on AWS - AWSome Day Houston 2018
Getting Started on AWS - AWSome Day Houston 2018
Amazon Web Services
 
Best Practices to Mitigate from the Emerging Vectors of Network Attack
Best Practices to Mitigate from the Emerging Vectors of Network AttackBest Practices to Mitigate from the Emerging Vectors of Network Attack
Best Practices to Mitigate from the Emerging Vectors of Network Attack
Amazon Web Services
 

La actualidad más candente (20)

Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019
Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019 Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019
Leadership session: Aspirational security - SEP318-L - AWS re:Inforce 2019
 
How to secure your Active Directory deployment on AWS - FND306-R - AWS re:Inf...
How to secure your Active Directory deployment on AWS - FND306-R - AWS re:Inf...How to secure your Active Directory deployment on AWS - FND306-R - AWS re:Inf...
How to secure your Active Directory deployment on AWS - FND306-R - AWS re:Inf...
 
Architecting security and governance through policy guardrails in Amazon EKS ...
Architecting security and governance through policy guardrails in Amazon EKS ...Architecting security and governance through policy guardrails in Amazon EKS ...
Architecting security and governance through policy guardrails in Amazon EKS ...
 
Five New Security Automation Improvements You Can Make by Using Amazon CloudW...
Five New Security Automation Improvements You Can Make by Using Amazon CloudW...Five New Security Automation Improvements You Can Make by Using Amazon CloudW...
Five New Security Automation Improvements You Can Make by Using Amazon CloudW...
 
AWSome Day Moscow 2014
AWSome Day Moscow 2014AWSome Day Moscow 2014
AWSome Day Moscow 2014
 
Evolving perimeters with guardrails, not gates: Improving developer agility -...
Evolving perimeters with guardrails, not gates: Improving developer agility -...Evolving perimeters with guardrails, not gates: Improving developer agility -...
Evolving perimeters with guardrails, not gates: Improving developer agility -...
 
How to Use Positive and Negative Security Models and Virtual Patching Techniq...
How to Use Positive and Negative Security Models and Virtual Patching Techniq...How to Use Positive and Negative Security Models and Virtual Patching Techniq...
How to Use Positive and Negative Security Models and Virtual Patching Techniq...
 
GraphQL backend with AWS AppSync & AWS Lambda
GraphQL backend with AWS AppSync & AWS LambdaGraphQL backend with AWS AppSync & AWS Lambda
GraphQL backend with AWS AppSync & AWS Lambda
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
 
Getting Started on AWS - AWSome Day Houston 2018
Getting Started on AWS - AWSome Day Houston 2018Getting Started on AWS - AWSome Day Houston 2018
Getting Started on AWS - AWSome Day Houston 2018
 
Securing your block storage on AWS - GRC207 - AWS re:Inforce 2019
Securing your block storage on AWS - GRC207 - AWS re:Inforce 2019 Securing your block storage on AWS - GRC207 - AWS re:Inforce 2019
Securing your block storage on AWS - GRC207 - AWS re:Inforce 2019
 
클라우드 환경에서의 SIEMLESS 통합 보안 서비스, Alert Logic - 채현주 보안기술본부장, Openbase :: AWS Sum...
클라우드 환경에서의 SIEMLESS 통합 보안 서비스, Alert Logic - 채현주 보안기술본부장, Openbase :: AWS Sum...클라우드 환경에서의 SIEMLESS 통합 보안 서비스, Alert Logic - 채현주 보안기술본부장, Openbase :: AWS Sum...
클라우드 환경에서의 SIEMLESS 통합 보안 서비스, Alert Logic - 채현주 보안기술본부장, Openbase :: AWS Sum...
 
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APACModule 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
 
Achieving security goals with AWS CloudHSM - SDD333 - AWS re:Inforce 2019
Achieving security goals with AWS CloudHSM - SDD333 - AWS re:Inforce 2019 Achieving security goals with AWS CloudHSM - SDD333 - AWS re:Inforce 2019
Achieving security goals with AWS CloudHSM - SDD333 - AWS re:Inforce 2019
 
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
 
How GoDaddy protects ecommerce and domains with AWS KMS and encryption - SDD4...
How GoDaddy protects ecommerce and domains with AWS KMS and encryption - SDD4...How GoDaddy protects ecommerce and domains with AWS KMS and encryption - SDD4...
How GoDaddy protects ecommerce and domains with AWS KMS and encryption - SDD4...
 
Hands-on with AWS Security Hub - FND213-R - AWS re:Inforce 2019
 Hands-on with AWS Security Hub - FND213-R - AWS re:Inforce 2019  Hands-on with AWS Security Hub - FND213-R - AWS re:Inforce 2019
Hands-on with AWS Security Hub - FND213-R - AWS re:Inforce 2019
 
Best Practices to Mitigate from the Emerging Vectors of Network Attack
Best Practices to Mitigate from the Emerging Vectors of Network AttackBest Practices to Mitigate from the Emerging Vectors of Network Attack
Best Practices to Mitigate from the Emerging Vectors of Network Attack
 
Encrypting everything with AWS - SEP402 - AWS re:Inforce 2019
Encrypting everything with AWS - SEP402 - AWS re:Inforce 2019 Encrypting everything with AWS - SEP402 - AWS re:Inforce 2019
Encrypting everything with AWS - SEP402 - AWS re:Inforce 2019
 
Big Data Analytics, Machine Learning e Inteligência Artificial
Big Data Analytics, Machine Learning e Inteligência ArtificialBig Data Analytics, Machine Learning e Inteligência Artificial
Big Data Analytics, Machine Learning e Inteligência Artificial
 

Similar a Serverless is not Cloudless - Serverless Security in AWS & AWS funds for Startups

Similar a Serverless is not Cloudless - Serverless Security in AWS & AWS funds for Startups (20)

DevConZM - Modern Applications Development in the Cloud
DevConZM - Modern Applications Development in the CloudDevConZM - Modern Applications Development in the Cloud
DevConZM - Modern Applications Development in the Cloud
 
AWS PROTECTED Certification - Lunch & Learn
  AWS PROTECTED Certification - Lunch & Learn  AWS PROTECTED Certification - Lunch & Learn
AWS PROTECTED Certification - Lunch & Learn
 
AWSome Day Bethesda - February 2019
AWSome Day Bethesda - February 2019AWSome Day Bethesda - February 2019
AWSome Day Bethesda - February 2019
 
India cloudsummit Bangalore - Advanced Container Use-cases on AWS Container S...
India cloudsummit Bangalore - Advanced Container Use-cases on AWS Container S...India cloudsummit Bangalore - Advanced Container Use-cases on AWS Container S...
India cloudsummit Bangalore - Advanced Container Use-cases on AWS Container S...
 
AWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 FebreroAWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 Febrero
 
AWSome Day, Milan | 5 Marzo 2015 - Contenuto Tecnico (Danilo Poccia - AWS Sol...
AWSome Day, Milan | 5 Marzo 2015 - Contenuto Tecnico (Danilo Poccia - AWS Sol...AWSome Day, Milan | 5 Marzo 2015 - Contenuto Tecnico (Danilo Poccia - AWS Sol...
AWSome Day, Milan | 5 Marzo 2015 - Contenuto Tecnico (Danilo Poccia - AWS Sol...
 
AWS Security By Design
AWS Security By DesignAWS Security By Design
AWS Security By Design
 
Proteggere applicazioni e dati nel cloud AWS
Proteggere applicazioni e dati nel cloud AWSProteggere applicazioni e dati nel cloud AWS
Proteggere applicazioni e dati nel cloud AWS
 
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
 
AWSome Day 2019 - New Jersey
AWSome Day 2019 - New JerseyAWSome Day 2019 - New Jersey
AWSome Day 2019 - New Jersey
 
Immersion Day - Well Architected Workshop - June 2019
Immersion Day - Well Architected Workshop - June 2019Immersion Day - Well Architected Workshop - June 2019
Immersion Day - Well Architected Workshop - June 2019
 
Implementing your landing zone - FND210 - AWS re:Inforce 2019
Implementing your landing zone - FND210 - AWS re:Inforce 2019 Implementing your landing zone - FND210 - AWS re:Inforce 2019
Implementing your landing zone - FND210 - AWS re:Inforce 2019
 
Introduction to the AWS Cloud - AWSome Day 2019 - Charlotte
Introduction to the AWS Cloud - AWSome Day 2019 - CharlotteIntroduction to the AWS Cloud - AWSome Day 2019 - Charlotte
Introduction to the AWS Cloud - AWSome Day 2019 - Charlotte
 
Introduction to the AWS Cloud - AWSome Day 2019 - Vancouver
Introduction to the AWS Cloud - AWSome Day 2019 - VancouverIntroduction to the AWS Cloud - AWSome Day 2019 - Vancouver
Introduction to the AWS Cloud - AWSome Day 2019 - Vancouver
 
Favorire l'innovazione passando da applicazioni monolitiche ad architetture m...
Favorire l'innovazione passando da applicazioni monolitiche ad architetture m...Favorire l'innovazione passando da applicazioni monolitiche ad architetture m...
Favorire l'innovazione passando da applicazioni monolitiche ad architetture m...
 
Lock it Down: How to Secure your AWS Account and your Organization's Accounts
Lock it Down: How to Secure your AWS Account and your Organization's AccountsLock it Down: How to Secure your AWS Account and your Organization's Accounts
Lock it Down: How to Secure your AWS Account and your Organization's Accounts
 
Cloud Migration Insights Forum, Sydney
Cloud Migration Insights Forum, SydneyCloud Migration Insights Forum, Sydney
Cloud Migration Insights Forum, Sydney
 
Meetup Sécurité - AWS - Recap Reinforce 2019
Meetup Sécurité - AWS - Recap Reinforce 2019Meetup Sécurité - AWS - Recap Reinforce 2019
Meetup Sécurité - AWS - Recap Reinforce 2019
 
Cloud Migration Insights Forum, Perth
Cloud Migration Insights Forum, PerthCloud Migration Insights Forum, Perth
Cloud Migration Insights Forum, Perth
 
Introduction to the AWS Cloud - AWSome Day 2019 - Denver
Introduction to the AWS Cloud - AWSome Day 2019 - Denver Introduction to the AWS Cloud - AWSome Day 2019 - Denver
Introduction to the AWS Cloud - AWSome Day 2019 - Denver
 

Más de Daniel Zivkovic

Opinionated re:Invent recap with AWS Heroes & Builders
Opinionated re:Invent recap with AWS Heroes & BuildersOpinionated re:Invent recap with AWS Heroes & Builders
Opinionated re:Invent recap with AWS Heroes & Builders
Daniel Zivkovic
 
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML EngineersIntro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Daniel Zivkovic
 
This is my Architecture to prevent Cloud Bill Shock
This is my Architecture to prevent Cloud Bill ShockThis is my Architecture to prevent Cloud Bill Shock
This is my Architecture to prevent Cloud Bill Shock
Daniel Zivkovic
 
Azure for AWS & GCP Pros: Which Azure services to use?
Azure for AWS & GCP Pros: Which Azure services to use?Azure for AWS & GCP Pros: Which Azure services to use?
Azure for AWS & GCP Pros: Which Azure services to use?
Daniel Zivkovic
 
Serverless Evolution during 3 years of Serverless Toronto
Serverless Evolution during 3 years of Serverless TorontoServerless Evolution during 3 years of Serverless Toronto
Serverless Evolution during 3 years of Serverless Toronto
Daniel Zivkovic
 

Más de Daniel Zivkovic (20)

All in AI: LLM Landscape & RAG in 2024 with Mark Ryan (Google) & Jerry Liu (L...
All in AI: LLM Landscape & RAG in 2024 with Mark Ryan (Google) & Jerry Liu (L...All in AI: LLM Landscape & RAG in 2024 with Mark Ryan (Google) & Jerry Liu (L...
All in AI: LLM Landscape & RAG in 2024 with Mark Ryan (Google) & Jerry Liu (L...
 
Canadian Experts Discuss Modern Data Stacks and Cloud Computing for 5 Years o...
Canadian Experts Discuss Modern Data Stacks and Cloud Computing for 5 Years o...Canadian Experts Discuss Modern Data Stacks and Cloud Computing for 5 Years o...
Canadian Experts Discuss Modern Data Stacks and Cloud Computing for 5 Years o...
 
Opinionated re:Invent recap with AWS Heroes & Builders
Opinionated re:Invent recap with AWS Heroes & BuildersOpinionated re:Invent recap with AWS Heroes & Builders
Opinionated re:Invent recap with AWS Heroes & Builders
 
Google Cloud Next '22 Recap: Serverless & Data edition
Google Cloud Next '22 Recap: Serverless & Data editionGoogle Cloud Next '22 Recap: Serverless & Data edition
Google Cloud Next '22 Recap: Serverless & Data edition
 
Conversational Document Processing AI with Rui Costa
Conversational Document Processing AI with Rui CostaConversational Document Processing AI with Rui Costa
Conversational Document Processing AI with Rui Costa
 
How to build unified Batch & Streaming Pipelines with Apache Beam and Dataflow
How to build unified Batch & Streaming Pipelines with Apache Beam and DataflowHow to build unified Batch & Streaming Pipelines with Apache Beam and Dataflow
How to build unified Batch & Streaming Pipelines with Apache Beam and Dataflow
 
Gojko's 5 rules for super responsive Serverless applications
Gojko's 5 rules for super responsive Serverless applicationsGojko's 5 rules for super responsive Serverless applications
Gojko's 5 rules for super responsive Serverless applications
 
Retail Analytics and BI with Looker, BigQuery, GCP & Leigha Jarett
Retail Analytics and BI with Looker, BigQuery, GCP & Leigha JarettRetail Analytics and BI with Looker, BigQuery, GCP & Leigha Jarett
Retail Analytics and BI with Looker, BigQuery, GCP & Leigha Jarett
 
What's new in Serverless at AWS?
What's new in Serverless at AWS?What's new in Serverless at AWS?
What's new in Serverless at AWS?
 
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML EngineersIntro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
Intro to Vertex AI, unified MLOps platform for Data Scientists & ML Engineers
 
Empowering Developers to be Healthcare Heroes
Empowering Developers to be Healthcare HeroesEmpowering Developers to be Healthcare Heroes
Empowering Developers to be Healthcare Heroes
 
Get started with Dialogflow & Contact Center AI on Google Cloud
Get started with Dialogflow & Contact Center AI on Google CloudGet started with Dialogflow & Contact Center AI on Google Cloud
Get started with Dialogflow & Contact Center AI on Google Cloud
 
Building a Data Cloud to enable Analytics & AI-Driven Innovation - Lak Lakshm...
Building a Data Cloud to enable Analytics & AI-Driven Innovation - Lak Lakshm...Building a Data Cloud to enable Analytics & AI-Driven Innovation - Lak Lakshm...
Building a Data Cloud to enable Analytics & AI-Driven Innovation - Lak Lakshm...
 
Smart Cities of Italy: Integrating the Cyber World with the IoT
Smart Cities of Italy: Integrating the Cyber World with the IoTSmart Cities of Italy: Integrating the Cyber World with the IoT
Smart Cities of Italy: Integrating the Cyber World with the IoT
 
Running Business Analytics for a Serverless Insurance Company - Joe Emison & ...
Running Business Analytics for a Serverless Insurance Company - Joe Emison & ...Running Business Analytics for a Serverless Insurance Company - Joe Emison & ...
Running Business Analytics for a Serverless Insurance Company - Joe Emison & ...
 
This is my Architecture to prevent Cloud Bill Shock
This is my Architecture to prevent Cloud Bill ShockThis is my Architecture to prevent Cloud Bill Shock
This is my Architecture to prevent Cloud Bill Shock
 
Lunch & Learn BigQuery & Firebase from other Google Cloud customers
Lunch & Learn BigQuery & Firebase from other Google Cloud customersLunch & Learn BigQuery & Firebase from other Google Cloud customers
Lunch & Learn BigQuery & Firebase from other Google Cloud customers
 
Azure for AWS & GCP Pros: Which Azure services to use?
Azure for AWS & GCP Pros: Which Azure services to use?Azure for AWS & GCP Pros: Which Azure services to use?
Azure for AWS & GCP Pros: Which Azure services to use?
 
Serverless Evolution during 3 years of Serverless Toronto
Serverless Evolution during 3 years of Serverless TorontoServerless Evolution during 3 years of Serverless Toronto
Serverless Evolution during 3 years of Serverless Toronto
 
Simpler, faster, cheaper Enterprise Apps using only Spring Boot on GCP
Simpler, faster, cheaper Enterprise Apps using only Spring Boot on GCPSimpler, faster, cheaper Enterprise Apps using only Spring Boot on GCP
Simpler, faster, cheaper Enterprise Apps using only Spring Boot on GCP
 

Último

Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
masabamasaba
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
masabamasaba
 

Último (20)

Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
Abortion Pills In Pretoria ](+27832195400*)[ 🏥 Women's Abortion Clinic In Pre...
 
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
%in Bahrain+277-882-255-28 abortion pills for sale in Bahrain
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
Artyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptxArtyushina_Guest lecture_YorkU CS May 2024.pptx
Artyushina_Guest lecture_YorkU CS May 2024.pptx
 
%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto%in Soweto+277-882-255-28 abortion pills for sale in soweto
%in Soweto+277-882-255-28 abortion pills for sale in soweto
 
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
 
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
%+27788225528 love spells in new york Psychic Readings, Attraction spells,Bri...
 
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
 
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
 
WSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - Keynote
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
 
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
WSO2CON 2024 - WSO2's Digital Transformation Journey with Choreo: A Platforml...
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 

Serverless is not Cloudless - Serverless Security in AWS & AWS funds for Startups

  • 1. Thursday, Apr 18, 2019 1. Intro & Activity Update 2. Community Open Mic 3. Andrew Brown, ExamPro: "Serverless Security in AWS Cloud" 4. Mike Apted, AWS Canada: "Serverless, Startups & AWS - The beginning of a beautiful friendship" 5. Networking 1 ServerlessToronto.org Meetup Agenda
  • 2. Manning Publications 2019 giveaways: 1. www.manning.com/books/serverless-applications-with-nodejs 2. www.manning.com/livevideo/production-ready-serverless 3. www.manning.com/livevideo/production-ready-serverless 4. www.manning.com/livevideo/serverless-applications-with-AWS 5. www.manning.com/livevideo/serverless-applications-with-AWS 6. www.manning.com/books/serverless-architectures-on-aws 7. www.manning.com/books/http2-in-action 8. www.manning.com/books/event-streams-in-action 9. www.manning.com/books/the-design-of-everyday-apis 10. www.manning.com/livevideo/graphql-in-motion 11. www.manning.com/books/voice-applications-for-alexa-and-google-assistant 12. www.manning.com/livevideo/machine-learning-for-mere-mortals 13. www.manning.com/books/classic-computer-science-problems-in-python 2
  • 3. 3
  • 4. 4
  • 5. 5
  • 6. Community Open Mic 6 10 seconds of freedom to pitch yourself, or your company
  • 7. Andrew Brown April 18 2019 andrew@exampro.co CEO of ExamPro 12 Year Full Stack Developer 4/10 AWS Certifications Loves StarTrek DS9
  • 8. The Fast Track to Serverless Security on AWS Full-Stack Powerleveling
  • 9. Powerleveling The Fast Track to Security on AWS exampro.co This Tech Talk Is Designed To Help You Study For The Security Speciality AWS Certification
  • 10. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Keeping our secrets a secret Mitigating DDoS Attacks Encrypting data at rest Encrypting data in transit Least permissive IAM policies Securing AWS Lambda Functions Protect against common exploits and attacks Automated Security with ML services KMS - Key Management Service ACM - AWS Certification Manager IAM - Identity and Access Management Lambda CloudFront, AWS Shield Param Store, Secrets Manager WAF - Web Application Firewall Macie, Guard Duty
  • 11. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Serverless Security Resources
  • 12. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Serverless Security Resources 1. Injection 2. Broken Authentication and Session Management 3. Sensitive Data Exposure 4. XML External Entity 5. Broken Access Control 6. Security Misconfiguration 7. Cross-Site Scripting 8. Insecure deserialization 9. Using Components With Known Vulnerabilities 10. Insufficient Logging and Monitoring
  • 13. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Serverless Security Resources
  • 14. KMS - Key Management Service checkbox secure and start encrypting Multi-tenant HSM to create and control encryption keys Hardware security module $1 / per key Powerleveling The Fast Track to Serverless Security on AWS exampro.co
  • 15. Powerleveling The Fast Track to Security on AWS exampro.co KMS integrates with many AWS services
  • 16. Securing AWS Lambda Functions Powerleveling The Fast Track to Serverless Security on AWS exampro.co lets you run code without provisioning or managing servers Scan vulnerabilities in your 3rd party dependencies Prevent event-data injection Least permissive IAM policies Keeping our secrets a secret Lambda Protection from AWS Lambda Partners Lambda Compliance
  • 17. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Securing AWS Lambda Functions Snyk A developer-first solution that automates finding & fixing vulnerabilities in your dependencies Scan vulnerabilities in your 3rd party dependencies
  • 18. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Securing AWS Lambda Functions Prevent Event-Data Injection “DELETE * FROM USERS” File name
  • 19. Powerleveling The Fast Track to Serverless Security on AWS exampro.co Securing AWS Lambda Functions Least Permissive IAM Policies
  • 20. SSM Param Store Powerleveling The Fast Track to Security on AWS exampro.co Stores sensitive data such as passwords Secrets Manager $$$ - $0.40 /secret ● RDS Integration ● Multiple Key / Values in on Secret ● *Automated Key Rotation (via Lambda) ● Restore Accidentally deleted secrets ● Free! ● Versioned ● Rotate Keys with Cloudwatch + Lambda Securing AWS Lambda Functions Keeping Our Secrets a Secret
  • 21. Powerleveling The Fast Track to Security on AWS exampro.co ● SOC 1 ● SOC 2 ● SOC 3 ● PCI DSS ● HIPAA Use AWS Artifact to gain access to these reports on how AWS is compliant Compliant with: AWS Lambda Compliance
  • 22. Macie Both use machine learning to analyze logs GaurdDuty Powerleveling The Fast Track to Security on AWS exampro.co DNS and Flow Logs CloudTrail Logs for S3
  • 23. Powerleveling The Fast Track to Security on AWS exampro.co
  • 24. Powerleveling The Fast Track to Security on AWS exampro.co
  • 25. Macie Powerleveling The Fast Track to Security on AWS exampro.co
  • 26. Macie Powerleveling The Fast Track to Security on AWS exampro.co
  • 27. Macie Powerleveling The Fast Track to Security on AWS exampro.co
  • 28. WAF - Web Application Firewall Powerleveling The Fast Track to Security on AWS exampro.co Put a firewall in-front of your ALB or CloudFront
  • 29. Powerleveling The Fast Track to Serverless Security on AWS exampro.co CloudFront (CDN) API Gateway Lambda Default Throttled 10K requests per second (rpm) WAF WAF ALB Lambda Two ways to protect Lambdas with WAF
  • 30. Powerleveling The Fast Track to Security on AWS exampro.co $5 per ACL $1 per Rule
  • 31. Powerleveling The Fast Track to Security on AWS exampro.co
  • 32. WAF - Web Application Firewall Powerleveling The Fast Track to Security on AWS exampro.co
  • 33. Serverless Security AWS Whitepapers Powerleveling The Fast Track to Serverless Security on AWS exampro.co
  • 34. Powerleveling The Fast Track to Serverless Security on AWS exampro.co AWS Lambda Security Partners
  • 35. Serverless Security Platform ✓ Seamless integration into your CI/CD ✓ Checks over-permissive IAM roles ✓ Checks insecure storage of app secrets ✓ Scans known vulnerable 3rd party dependencies ✓ Serverless application firewall ★ Behavioural protection engine ✓ Security visibility via dashboard and notifications AWS Lambda
  • 36. Powerleveling The Fast Track to Serverless Security on AWS exampro.co
  • 38. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Mike Apted – Startup Solutions Architect @mikeapted AWS Canada Serverless, Startups & AWS The beginning of a beautiful friendship
  • 39. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Zero upfront cost With AWS’s infrastructure-on-demand, startups can pay only for the resources they use instead of investing in servers upfront Focus on core business value Startups can focus on growing their business rather than on infrastructure Launch faster Startups can have new IT resources available in just a few clicks, increasing agility Experiment often at lower risk Being able to deprovision resources as needed enables startups to experiment often and fail fast if an idea doesn’t work Enabling Lean Startups with AWS Cloud
  • 40. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Amazon launched their cloud storage and computing services and auto-scaling capability in 2006 Source: https://bothsidesofthetable.com/why-has-seed-investing-declined-and-what-does-this-mean-for-the-future-6a9572357130 Massive technology shifts such as cloud computing made it significantly cheaper to launch a startup:
  • 41. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Operational responsibility models On-Premises Cloud Less More Compute Virtual Machine EC2 Elastic Beanstalk LambdaFargate Databases MySQL MySQL on EC2 RDS MySQL RDS Aurora Aurora Serverless DynamoDB Storage Storage S3 Messaging ESBs Amazon MQ Kinesis SQS / SNS Analytics Hadoop Hadoop on EC2 EMR Elasticsearch Service Athena
  • 42. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Startups benefit from serverless: No infrastructure provisioning, no management Automatic scaling Pay for value Highly available and secure
  • 43. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark AWS Lambda AWS Fargate Amazon API Gateway Amazon SNS Amazon SQS AWS Step Functions COMPUTE DATA STORES INTEGRATION Amazon Aurora Serverless Amazon S3 Amazon DynamoDB AWS AppSync
  • 44. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Global Startup Business Development team At AWS, we have a team of exited founders, former investors and startup mentors aligned to every VC and accelerator of note Beyond technology
  • 45. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark AWS Startup BD/SA: Working with venture capital and the startup ecosystem
  • 46. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Innovation hubs are designed to help, collectively Type of Hub Stage Funding Round ~ Revenue Timing Support Provided Growth Hub > Self- Sufficient > A/B > $5 million As Needed •Connections to Customers, Capital and Talent Scaleup Hub PMF to Self- Sufficient Seed → A/B $1 million →$5 million As needed •Peers •Network •Services •Network •Office Space Accelerator MVP to Product Market Fit Angel → Seed $0 → $1 million ARR Cohort (3-6 mo) •Mentors •Network •Programs •Peers •Office Space •Investment Incubator 0 to MVP 0 → Angel $0 As needed •Mentors/Coaches •Guidance •Network •Service Providers MaturityofVenture
  • 47. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
  • 48. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark We invest indirectly alongside venture funds and accelerators We don’t • Invest cash • Take a capital position We do • Invest time • Share knowledge/experience/wisdom • Help navigate AWS resources and support • Open doors internally and externally • Remove obstacles • Leverage our global footprint • Champion startups across all of Amazon • Take a long-term view
  • 49. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark We focus on helping our startup customers grow by wiring them into people, resources, opportunities across Amazon Technical • Architecture design/optimization reviews • Best practices • Subject matter experts • Betas/previews • Security/compliance Go-to-market • Co-marketing • PoC funding • Sales referrals • Distribution • Capital intros
  • 50. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Amazon programs that help startups grow their business *Eligibilities and limits apply AWS Activate AWS Migrate AWS Well-Architected Review AWS Connections • AWS promotional credits • AWS Business Support Plan • Online training credits • Office hours • Credits that help offset cost of migration (limited time) • Technical migration support • Free review by AWS Solution Architects • Ensures secure, high- performing, resilient, efficient infrastructure • Introduction to enterprises with a specified solution need AWS Partner Network AWS Marketplace Amazon Launchpad Alexa Fund • Tiered funding benefits • Technical training • Sales and business enablement • Co-marketing • Streamlined go-to-market on AWS’s software marketplace • Integrated billing with AWS • Dedicated launch and marketing support for selling physical product on amazon.com • Equity investment for voice technology startups • Development and marketing support and benefits …and more! Contact your AWS Startup Business Development Manager for details.
  • 51. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Assistance to grow Benefits • Equity investment • Early access to SDK capabilities • Hands-on development support • Marketing support • Placement at Amazon showcase events Eligibility • Product benefits from the Alexa Voice Service or delivers new abilities to Alexa-enabled devices through the Alexa Skills Kit • Contributes to the science behind voice technology More information • Alexa Fund website Alexa Fund
  • 52. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Assistance to grow Benefits • Mentorship and network from across Amazon and Techstars networks Eligibility • Product benefits from the Alexa Voice Service or delivers new abilities to Alexa-enabled devices through the Alexa Skills Kit • Contributes to the science behind voice technology More information • Amazon Alexa Accelerator website
  • 53. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Removing barriers to adoption Benefits • Credits that help offset cost of migration (limited time) • Technical support (partner funding, AWS Support Plan) Eligibility • Speak with an AWS startup BD manager for details More information • Featured startup migrations on AWS Startup Blog Startup Migrate Program
  • 54. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Support at the earliest stages Benefits • AWS promotional credits • Business Support Plan • Online self-paced lab credits • Office hours • Startup Spotlight Eligibility • Startups in accelerators, incubators, early VC funds or other startup organizations (ex. university programs, co-working spaces, etc.) More information • AWS Activate website
  • 55. TOP OBSTACLES PROVISIONING SERVERS PAYING FOR SERVER IDLE TIME SCALING FOR USAGE THE DOORR PLATFORM SOLVED MULTIPLE PAIN POINTS USING SERVERLESS ARCHITECTURE
  • 56. WITHOUT SERVERLESS DOOR’S GROWTH WOULDN’T BE SUSTAINABLE DUE TO INFRASTRUCTURE COSTS. RESULTS NET MONTHLY COST $280 TIME TO BUILD CORE PLATFORM 3 MONTHS TRANSACTIONS PER MONTH 24 MILLION
  • 57. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Thank you! Mike Apted – Startup Solutions Architect @mikeapted AWS Canada