29
Securing Cloud and Mobile Pragma&c Enterprise Security Architecture Prabath Siriwardena (@prabath) WSO2 Director, Security Architecture

WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

  • Upload
    wso2

  • View
    376

  • Download
    0

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Securing  Cloud  and  Mobile  Pragma&c  Enterprise  Security  

Architecture  

Prabath  Siriwardena  (@prabath)    WSO2  

Director,  Security  Architecture  

Page 2: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Within  the  first  decade  of  the  21st  century  –  internet  worldwide  increased  from  350  million  

to  more  than  2  billion.    

Page 3: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Mobile  phone  subscribers  increased  from    

750  million  to  5  billion  Today  it’s  around  6  billion  

 

Page 4: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Only  30%  of  mobile  users,  password  protect  their  mobile  devices  

     

Page 5: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Many  SaaS  providers  ignore  mulJfactor  authenJcaJon  for  mobile  applicaJons  

     

Page 6: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

113  cell  phones  are  lost  or  stolen  every  minute  in  the  U.S  and  $7  million  worth  of  

smartphones  are  lost  daily        

 

Page 7: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

62%  of  mobile  workers    currently  use  their  personal  smartphones  for  

work  

Page 8: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

hAp://www.websense.com/assets/reports/websense-­‐2013-­‐threat-­‐report.pdf  

Page 9: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Mobile  Device  Management  systems  need  to  be  an  integral  part  of  the  corporate    

IdenJty  Management      

 

Page 10: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Cloud  service  providers  are    becoming  mobile  friendly  with  REST/JSON  APIs  

     

 

Page 11: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

OAuth  2.0  dominates  Mobile  and  API  security        

 

Page 12: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Avoid  using  Resource  Owner  Password  OAuth  grant  type  

     

 

Page 13: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Mobile  applicaJons  secured  with  OAuth  can  be  vulnerable  to  phishing  

     

 

Page 14: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Your  Facebook  or  TwiYer  account  credenJals  can  be  quite  easily  phished  through  your  

mobile  phone  -­‐  than  from  a  laptop  computer  

Page 15: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

The  need  to  bake-­‐in  client  key  and  the  secret  key  into  the  mobile  app  itself  is  an  issue  yet  to  

solve  

Page 16: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

 OAuth  has  given  a  beYer  failover  capability  to  mobile  applicaJons  in  case  of  an  aYack  

Page 17: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

It  takes  an  average  of  20  seconds  for  a  user  to  log  into  a  resource  

Page 18: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Single  Sign  On  increases  user  producJvity  

Page 19: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Browser  based  Single  Sign  On  

Na&ve  App   Na&ve  Web  Browser  

Authoriza&on  Server  (IdP)  

Mobile  Device  

Page 20: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture
Page 21: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

NaJve  Single  Sign  On  

Na&ve  App   Na&ve  IdP  App  

Mobile  Device  

Page 22: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture
Page 23: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

OpenID  FoundaJon  is  working  on  standardizing  NaJve  Single  Sign  On  based  on    

OpenID  Connect  

Page 24: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Federated  Single  Sign  On  

Na&ve  App   Na&ve  Web  Browser  

Authoriza&on  Server  (IdP)  

Mobile  Device  

SAML2  IdP  

SAML2  IdP  

Page 25: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Federated  Single  Sign  On  with  heterogeneous  AuthorizaJon  Servers    

Page 26: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Secured  /  ConfidenJal  data  channels  

Page 27: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

TLS,  JSON  Web  EncrypJon  (JWE)  

Page 28: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Managed  Cloud  APIs  

Mobile  App   API  Gateway  

Cloud  API  

Page 29: WSO2Con US 2013 - Securing Cloud and Mobile: Pragmatic Enterprise Security Architecture

Thank  You