
Spooky Scary Lambda Attacks | Cloud Security Webcast
Source: YouTube · SANS Cloud Security · published Nov 25, 2024 · 44:37
Lambda is a powerful tool for AWS development, but it requires careful attention to security and testing to mitigate inherent risks 0:08.
Key Takeaways:
• The speaker emphasizes a love for using Lambda in workflows despite its associated challenges 0:27.
• Developers often overlook security implications when initially building Lambda functions 0:46.
• Proper testing and validation are critical to ensure Lambda functions work correctly in production 0:41.
Understanding these pitfalls is essential for building secure and reliable serverless applications.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, good morning or afternoon whenever you are. Uh, thank you for joining us on this talk about Lambda. Uh, my name is Shan McCulla. I'm excited to be here uh, chatting with you. I I I kind of picked this one because uh, even though I I I get paid to do security work, I really love software development and the times where I've had to build workflows uh, and was able to use Lambda, I just I loved it. I just thought it was a great tool and a great way to use it inside of my AWS development ecosystem. Uh, but there's problems with it and concerns and things that I need to kind of uh figure out and make sure works properly and is tested and and all that kind of stuff that we normally would do development. But then there are security implications and a lot of times we don't think about t…