Aaron Rinehart -- Chaos Engineering and #AppSec episode artwork

EPISODE · Oct 9, 2018 · 36 MIN

Aaron Rinehart -- Chaos Engineering and #AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you know a security control will work when the system around it fails? Aaron Rinehart introduces chaos engineering as a way to test assumptions about complex systems before an unexpected incident exposes them. He explains its relationship to good engineering, Netflix’s Chaos Monkey, and site reliability engineering, then brings the discussion into application security. Chris and Robert explore ChaoSlingr, the difference between testing a failure condition and introducing a vulnerability, and how experiments can reveal gaps in detection or response. Aaron also discusses a SOC-less model that connects security signals with the people best placed to act. Books and foundational resources round out an introduction to learning from controlled experiments and building confidence in how systems actually behave.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Aaron Rinehart:→ Aaron Rinehart on LinkedInMentioned in this episode:→ Principles of Chaos Engineering→ Chaos Monkey→ ChaoSlingr→ Release It! Second Edition→ Google SRE booksFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Chaos engineering and AppSec with Aaron Rinehart03:31 Security as a reflection of good engineering06:52 What chaos engineering means09:57 How Chaos Monkey works12:30 Principles and the wider movement14:13 The relationship with site reliability engineering15:56 Examples of complex-system failures20:28 Applying chaos engineering to security21:13 Introducing ChaoSlingr24:50 Testing failure conditions rather than adding flaws25:58 Resources for learning more29:17 Release It and resilience lessons31:33 The SOC-less model at Netflix35:04 Aaron’s writing and further reading

Episode metadata supplied by the publisher feed · Published Oct 9, 2018

Embed this episode

How do you know a security control will work when the system around it fails? Aaron Rinehart introduces chaos engineering as a way to test assumptions about complex systems before an unexpected incident exposes them. He explains its relationship to good engineering, Netflix’s Chaos Monkey, and site reliability engineering, then brings the discussion into application security. Chris and Robert explore ChaoSlingr, the difference between testing a failure condition and introducing a vulnerabilit...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Aaron Rinehart -- Chaos Engineering and #AppSec

0:00 36:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 9, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!