Amazon Web Services (以ä¸AWS)ã®å©ç¨éå§æã«ããã¹ãè¨å®ä½æ¥ã解説ãã¾ããAWSã®å©ç¨éå§ã¨ã¯ãAWSã¢ã«ã¦ã³ãã®éè¨ãæå³ãã¾ãããããå®å ¨ã«å©ç¨ãããããAWSã¢ã«ã¦ã³ãéè¨ç´å¾ã«ããã¹ãè¨å®ãããã¤ãããã¾ãããã®é£è¼ã§ã¯ãã®è¨å®å 容ã説æãã¾ãã
AWS Organizationsã使ç¨ãããã¨ã§ãè¤æ°ã®ã¢ã«ã¦ã³ãã«èªåçã«ãããã£ãåæè¨å®ãè¡ããã¨ãå¯è½ã§ããããã®é£è¼ã§ã¯æ°è¦ã§1ã¢ã«ã¦ã³ãã使ããå ´åãåæã¨ãã¾ããè¤æ°ã¢ã«ã¦ã³ãã®å ´åããåºæ¬çãªèãæ¹ã¯åãã«ãªãã¾ãã
è¨å®ä½æ¥ã¯å ¨ï¼ï¼åããã使¥å 容ã®é£ãããå¿ è¦æ§ã«å¿ãã¦ä»¥ä¸ï¼ã¤ã«åé¡ãã¦ãã¾ãã å°ãªãã¨ãMUSTã®ä½æ¥ã«ã¤ãã¦ã¯å®æ½ããããã«ãã¾ãããã
- MUST ï¼ã¢ã«ã¦ã³ãéè¨å¾ã«å¿ ã宿½ãã¹ã使¥
- SHOULD ï¼è¨å®å å®¹ã®æ¤è¨ã¾ãã¯å©ç¨æ¹æ³ã決å®ã®ãããå¯è½ãªéã宿½ãã¹ã使¥
- BETTER ï¼AWSç¥èã®ããæ¹ãã»ãã¥ãªãã£è¦ä»¶ã®é«ãã¢ã«ã¦ã³ãã§å®æ½ãã¹ã使¥
éçºã»æ¤è¨¼ç¨éã®AWSã¢ã«ã¦ã³ãã®å ´åãããAWSã¢ã«ã¦ã³ããä¹ã£åããã¦ã大éã®ãªã½ã¼ã¹ã使ãããã䏿£å©ç¨ããããã¨ãã£ããªã¹ã¯ã¯åå¨ãããããå ¨ã¦ã®AWSã¢ã«ã¦ã³ãã§è¨å®ãããã¨ãéè¦ã§ãã
ã«ã¼ãã¦ã¼ã¶ã®ä¿è·
ã«ã¼ãã¦ã¼ã¶ã¨ã¯ãAWSã¢ã«ã¦ã³ã使æã«è¨å®ããã¡ã¼ã«ã¢ãã¬ã¹ã¨ãã¹ã¯ã¼ãã§ãã°ã¤ã³ã§ããã¦ã¼ã¶ã®ãã¨ãæãã¾ããå ¨ã¦ã®AWSãµã¼ãã¹ã¨ãªã½ã¼ã¹ã®æä½ãå¯è½ã§ãããæä½ããå人ãç¹å®ã§ãã¾ãããå¾è¿°ããIAMã¦ã¼ã¶ã¼ã使ããå¾ã¯ãåºæ¬çã«ä½¿ç¨ããªãããã«ããã¹ãã§ãã ã«ã¼ãã¦ã¼ã¶ãä¿è·ããããã«ä»¥ä¸ã®è¨å®ãè¡ãã¾ãã
使¥ï¼. ãã¹ã¯ã¼ãã®è¨å®ã[ MUST ]
ã¢ã«ã¦ã³ãè¨å®ãã¼ã¸ãããå¼·åãªãã¹ã¯ã¼ããã«ã¼ãã¦ã¼ã¶ã«è¨å®ãã¾ããå ·ä½çã«ã¯ã14æå以ä¸ã大æåã»å°æåã»æ°åã»ç¹æ®æåãå«ããã¢ã«ã¦ã³ãåãEã¡ã¼ã«ã¢ãã¬ã¹ã¨é¢é£æ§ã®å°ãªãæååã¨ãã¾ãã
â»è¿½è¨ï¼æè¿ã§ã¯ããé·ããã¹ã¯ã¼ããä¸è¬çãªããã8æåâ14æåã«è¨è¼å¤æ´ãã¾ããã
使¥ï¼. å¤è¦ç´ èªè¨¼ï¼MFAï¼ã®æå¹åã[ MUST ]
ã»ãã¥ãªãã£èªè¨¼æ å ±ã®ãã¼ã¸ãããã«ã¼ãã¦ã¼ã¶ã®MFAæå¹åãè¡ãã¾ããããã«ãããMFAããã¤ã¹ãæã£ã管çè ã®ã¿ãã«ã¼ãã¦ã¼ã¶ã§ãã°ã¤ã³å¯è½ã¨ãªãã¾ããMFAããã¤ã¹ã¯ç©çã¨ä»®æ³ã®2種é¡ããã¾ãããç©çããã¤ã¹ã®ç¨æãé£ããå ´åã¯ã¹ãã¼ããã©ã³ã¢ããªçã§è¨å®å¯è½ãªä»®æ³MFAããã¤ã¹ã使ç¨ãã¾ãã

ã³ã¹ãã®å¯è¦å
AWSã®ãããªã¯ã©ã¦ãç°å¢ã§ã¯ãå©ç¨éã«å¿ãã¦æéãçºçããããããªã½ã¼ã¹ã®å餿¼ããè¨å®ãã¹çã«ããå©ç¨æã大ãããªã£ã¦ãã¾ãå¯è½æ§ãããã¾ãããã®ãããå©ç¨æï¼ã³ã¹ãï¼ã®ç¶æ³ã¯ããã«ç¢ºèªã§ããããã«å¯è¦åãã¦ãããæ³å®ä»¥ä¸ã®å©ç¨æã«ãªã£ãå ´åã¯æ¤ç¥ããä»çµã¿ãå¿ è¦ã¨ãªãã¾ããæä½é以ä¸ã®è¨å®ã宿½ãã¦ããã¾ãããã
使¥ï¼. IAMã¦ã¼ã¶ã¼ã®è«æ±æ å ±ã¢ã¯ã»ã¹è¨±å¯ã[ MUST ]
ããã©ã«ãç¶æ ã§ã¯ãIAMã¦ã¼ã¶ã¼ã¯è«æ±æ å ±ã®ãã¼ã¸ã¸ã¢ã¯ã»ã¹ãããã¨ãã§ãã¾ãããã«ã¼ãã¦ã¼ã¶ã¯åºæ¬ä½¿ç¨ããªãæ¹éã¨ãããããIAMã¦ã¼ã¶ã¼ããã®ãã¼ã¸ã確èªã§ããããã«ãã¢ã«ã¦ã³ãè¨å®ã®ãã¼ã¸ããè¨å®ãã¦ããå¿ è¦ãããã¾ããã¢ã¯ã»ã¹è¨±å¯ã®è¨å®ã¯ã«ã¼ãã¦ã¼ã¶ã®ã¿å¯è½ãªãããã¢ã«ã¦ã³ãéè¨ç´å¾ã«è¨å®ãã¾ããããã¢ã«ã¦ã³ãè¨å®ãã¼ã¸ã¯ãããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãã°ã¤ã³å¾ãå³ä¸ã®ã¢ã«ã¦ã³ãåï¼ã¢ã«ã¦ã³ããé ã«é¸æãããã¨ã§é·ç§»ãå¯è½ã§ãããã¼ã¸ä¸é¨ã«ããã IAM ã¦ã¼ã¶ã¼/ãã¼ã«ã«ããè«æ±æ å ±ã¸ã®ã¢ã¯ã»ã¹ããã¢ã¯ãã£ãåãããã¨ã§ãIAMã¦ã¼ã¶ã¼ãåç §å¯è½ã«ãªãã¾ãã

使¥ï¼. Cost Explorerã®æå¹åã[ SHOULD ]
Cost Explorerã¯ãAWSå©ç¨æãæå¥ãæ¥å¥ããµã¼ãã¹å¥ã§ç¢ºèªã§ãããã¼ã«ã§ãããã¡ããè«æ±æ å ±ã®ãã¼ã¸ããæå¹ã«ããå¿ è¦ããããããä¸è¨IAMã¦ã¼ã¶ã¼ã®ã¢ã¯ã»ã¹è¨±å¯è¨å®ã¨åããã¦å®æ½ãã¾ãããã

使¥ï¼. äºç®ããã³ã¢ã©ã¼ãã®è¨å®ã[ MUST ]
AWS Budgets(äºç®)ã®ç»é¢ããããããããæ³å®ããå©ç¨æã決ãã¦ãããäºç®ã¨ãã¦è¨å®ãå¯è½ã§ããå©ç¨æãäºç®é¡ã«éããå ´åããäºç®é¡ã®ä½%ã«ãªã£ããã¡ã¼ã«éç¥ãè¡ãã¨ãã£ãè¨å®ãå¯è½ã§ããæå³ããªãå©ç¨æã®å¢å ã«æ°ã¥ãããã«ãå¿ ãè¨å®ããããã«ãã¾ããããä»ã«ãCloud Watch ã¢ã©ã¼ã ã使ç¨ãã¦å©ç¨æå¢å ã®æ¤ç¥ãè¡ããã¨ãå¯è½ã§ããã©ã®æ¹æ³ã§ãè¯ãã®ã§ãå©ç¨æã®å¢å ã«æ°ã¥ãä»çµã¿ã¯å¿ ãç¨æãã¦ããããã«ãã¾ãããã

IAMã¦ã¼ã¶ã¼ã®ä½æ
å人ãç¹å®ã§ããæä½æ¨©éã®è¨å®ãå¯è½ãªIAMã¦ã¼ã¶ã¼ã使ãã¾ãã
使¥ï¼. 管çè IAMã¦ã¼ã¶ã¼ã®è¨å®ã[ MUST ]
ã¾ãã¯å ¨ã¦ã®æä½ãå¯è½ãªç®¡çè ç¨ã®IAMã¦ã¼ã¶ã¼ã使ãã¾ããã¦ã¼ã¶ã¼ãã¨ã«æ¨©éãä»ä¸ããã®ã¯æéã«ãªããããIAMã°ã«ã¼ãã使ãããã®ã°ã«ã¼ãã«å ¨ã¦ã®æä½ãå¯è½ãªIAMããªã·ã¼ãAdministratorAccessããä»ä¸ãã¾ãããã®å¾å¿ è¦ãªäººæ°åIAMã¦ã¼ã¶ã¼ã使ãããã®IAMã°ã«ã¼ãã«æå±ããã¾ãã
使¥ï¼. å©ç¨è IAMã¦ã¼ã¶ã¼ã®è¨å®ã[ SHOULD ]
ã¢ã«ã¦ã³ãã®å©ç¨ç¨éï¼ä¾ãã°VPCã¨EC2ã®ã¿ä½¿ç¨ãããªã©ï¼ã決ã¾ã£ã¦ããã°ãå©ç¨ç¨éã®æ¨©éã®ã¿ä»ä¸ããIAMã¦ã¼ã¶ã¼ã使ãã¾ããå ¨ã¦ã®å©ç¨è ã¸ç®¡çè æ¨©éãä»ä¸ããã®ã§ã¯ãªããå¿ è¦æä½éãªæ¨©éãä»ä¸ãããã¨ã大åã§ãã

使¥ï¼. ãã¹ã¯ã¼ãããªã·ã¼ã®è¨å®ã[ MUST ]
ãã¹ã¯ã¼ãããªã·ã¼ã夿´ãããã¨ã§ãIAMã¦ã¼ã¶ã¼ã«è¨å®ãããã¹ã¯ã¼ãã®ã«ã¼ã«ãè¨å®ã§ãã¾ãã æåæ°ãè¨å·ãå«ããªã©ãå®å ¨ãªæ¡ä»¶ãè¨å®ãã¦ããã¾ãã
夿´ã¯ãIAMï¼ã¢ã«ã¦ã³ãè¨å®ããå¯è½ã§ãã

ãµãã¼ããã©ã³
使¥ï¼. ãµãã¼ããã©ã³ã®æ¤è¨ã夿´ã[ SHOULD ]
AWSã«ã¯è¤æ°ã®ãµãã¼ããã©ã³ãç¨æããã¦ãã¾ããé害æãAWSå ã§äºæ ããã£ãå ´åã¯ãAWSã«è¿ éã«å¯¾å¿ãã¦ãããå¿ è¦ãã§ã¦ãã¾ããåºæ¬çã«æ¬çªç°å¢ã§ä½¿ç¨ããAWSã¢ã«ã¦ã³ãã¯ããã¸ãã¹ä»¥ä¸ã®ãµãã¼ããã©ã³ã«å å ¥ãã¦ãããã»ããè¯ãã§ãããã
ãµãã¼ããã©ã³ã®å¤æ´ã¯ãã«ã¼ãã¢ã«ã¦ã³ãã®ã¿å®è¡å¯è½ã§ãã
CloudTrail

CloudTrailã«ã¯AWSä¸ã®æä½å±¥æ´ãä¿åããã¾ããããã©ã«ãã§ã¯ç¹ã«è¿½å 使¥ãä¸è¦ã§ã90æ¥éä¿åããCloudTrailã®ç»é¢ãã確èªãããã¨ãå¯è½ã§ãã
使¥ï¼ï¼. CloudTrail証跡æ å ±ã®ä½æã[ MUST ]
証跡æ å ±ã使ãS3ã«ä¿åãã¦ãããã¨ã§ãå ¨ã¦ã®æä½å±¥æ´ãæ®ãã¦ãããã¨ãå¯è½ã§ããæ¯è¼çç°¡åã«è¨å®ãã§ãããããå¿ ã宿½ããããã«ãã¾ãããã

ï¼åèï¼CloudTrailã®å©ç¨æé
CloudTrailèªä½ã®å©ç¨ã¯ç¡æã§ã証跡ï¼S3ä¿åï¼1ã¤ç®ã®æéã¯ç¡æã§ãã証跡ã¯è¤æ°ä½æå¯è½ã§ã2åç®ä»¥éã®è¨¼è·¡ã¯ããã¼ã¿ä¿ååã«å¯¾ãã¦æéãçºçãã¾ãã
AWS Config

使¥ï¼ï¼. Configã®æå¹åã[ MUST ]
AWS Configï¼ä»¥ä¸ãConfigï¼ãæå¹ã«ãããã¨ã§ãAWSãªã½ã¼ã¹ã®è¨å®å¤æ´å±¥æ´ãä¿åãããã¨ãã§ãã¾ããCloudTrailã§ã¯èª°ãã©ã®æä½ãè¡ã£ãã®ãã¨ããå±¥æ´ãä¿åãã¾ãããConfigã§ã¯å¯¾è±¡ã®AWSãªã½ã¼ã¹ããã¤ãã©ã®ããã«å¤æ´ãããã®ãã¨ãã観ç¹ã§å±¥æ´ãä¿åããã¾ãã

以ä¸ã®ä¾ã§ã¯ãã»ãã¥ãªãã£ã°ã«ã¼ãã®è¨å®å±¥æ´ã表示ãã¦ãã¾ãã

使¥ï¼ï¼. Config ã«ã¼ã«ã®è¨å®ã[ BETTER ]
Configãæå¹ã«ãããã¨ã§ãè¨å®å±¥æ´ãä¿åãããã¨ãã§ãã¾ãããããã«å ãConfigã®æ©è½ã§ããConfig ã«ã¼ã«ã使ç¨ãããã¨ã§ãAWSãªã½ã¼ã¹ãè¨å®ããã«ã¼ã«ã«æºæ ãã¦ããããã§ãã¯ãããã¨ãå¯è½ã§ããä¾ãã°ä»¥ä¸ã®ãããªã«ã¼ã«ãè¨å®ãã¦ãã§ãã¯ãè¡ããã¨ãã§ãã¾ãã
- CloudTrailãæå¹ã«ãªã£ã¦ããã
- S3ãã±ããããããªãã¯èªã¿æ¸ãå¯è½ã«ãªã£ã¦ããªãã
- Security Groupã§SSHãã¼ãï¼22ï¼ããããªãã¯å ¬éããã¦ããªãã
ã¾ããConfig ã«ã¼ã«ã¨åããã¦ä¿®å¾©ã¢ã¯ã·ã§ã³ãè¨å®ãããã¨ã§ãSNSéç¥ãèªå修復å¦çãå®è£ ãããã¨ãå¯è½ã§ããåºæ¬çã«ã¢ã«ã¦ã³ãéè¨æã¯Configãæå¹åããã ãã§OKã§ãããããå³ããéç¨ãå¿ è¦ãªAWSã¢ã«ã¦ã³ãããå®è£ ç¥èã®ããæ¹ã¯Config ã«ã¼ã«ã®éç¨ãåããã¦æ¤è¨ããããã«ãã¾ãããã
ï¼åèï¼Configã®å©ç¨æé
è¨é²ãããè¨å®é ç®1ä»¶ã«ã¤ã0.003USDçºçãã¾ããä¾ãã°æããã5000ä»¶ã®è¨å®å¤æ´ããã£ãå ´åã¯$15ã®æéãçºçãã¾ãã è¨å®å¤æ´ã¨ã¯å¥ã«Config ã«ã¼ã«ã1ä»¶ã®è©ä¾¡ããã0.001USDï¼ï½100,000 ä»¶ï¼çºçãã¾ããä¾ãã°1æéãã¨ã«è©ä¾¡ãè¡ãã«ã¼ã«ã1ä»¶ãã£ãå ´åã0.001USDÃ24æéÃ31æ¥ï¼0.744USDãæåä½ã§çºçãããã¨ã«ãªãã¾ãã
Amazon GuardDuty

Amazon GuardDuty(以ä¸ãGuardDuty)ã¯ãAWSä¸ã®æªæã®ããæä½ã䏿£ãªåä½ãæ¤ç¥ãããµã¼ãã¹ã§ããä¾ãã°ä»¥ä¸ã®ãããªæ å ±ãæ¤ç¥ããã¾ãã
- ã«ã¼ãã¦ã¼ã¶ã®ä½¿ç¨
- IAMã¦ã¼ã¶ã¼ã®ä¸æ£å©ç¨(大éã®æä½å®è¡ãªã©)
- EC2ã®ä¸æ£éä¿¡
ã¤ã³ãããã¨ãªãæ å ±ã¯CloudTrailãVPC Flow LogsãDNS Logsã®ï¼ã¤ã§ãããããä¸è¨ã®ãããªä¸æ£ã夿ãã¦æ¤ç¥ãè¡ãã¾ãã
使¥ï¼ï¼. GuardDuty æå¹åã[ MUST ]
GuardDutyã®ãµã¼ãã¹ç»é¢ãããæå¹åããã®ã¿ã§ä½¿ç¨å¯è½ãªãããã¢ã«ã¦ã³ãéè¨å¾ãããã«è¨å®ããããã«ãã¾ãããã

ã©ã®ããã«æ¤ç¥ããããè¦ããå ´åã¯ããµã³ãã«ã¤ãã³ãã®çºè¡ãå¯è½ã§ãã

使¥ï¼ï¼. GuardDuty éç¥è¨å®ã[ SHOULD ]
æå¹åã«ãããã¨ã§ãAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã®ç»é¢ããæ¤ç¥çµæã確èªã§ããããã«ãªãã¾ãããããã ãã§ã¯ãªã¢ã«ã¿ã¤ã ã«æ¤ç¥ãã§ãã¾ãããä½è£ã®ããæ¹ã¯ãEventBridgeã¨SNSã使ç¨ãã¦ã管çè ã«ã¡ã¼ã«çã§éç¥ãè¡ãè¨å®ãåããã¦è¡ãã¾ãããã
EventBridgeã®ãµã¼ãã¹ç»é¢ããã«ã¼ã«ï¼ã«ã¼ã«ã使ã鏿ããã¤ãã³ãã½ã¼ã¹ã«GuardDutyãGuardDuty Findingã鏿ããã°ãå³å´ã®ã¿ã¼ã²ããã«æ¤ç¥çµæã渡ããã¨ãã§ãã¾ããã¿ã¼ã²ããã«ã¡ã¼ã«éç¥ãè¨å®ããSNSã鏿ãããã¨ã§ãã¡ã¼ã«éç¥ãå¯è½ã§ããï¼SNSãããã¯ã¯äºåã«ä½æããå¿ è¦ãããã¾ããï¼
å¾è¿°ããSecurty Hubã§GuardDutyã®éç¥ãåããã¦è¡ãå ´åã¯ããã®è¨å®ã¯ä¸è¦ã§ãã

ï¼åèï¼GuardDutyã®å©ç¨æé
CloudTrailï¼S3 ãã¼ã¿ã¤ãã³ããå«ãï¼ãVPC Flow LogsãDNS Logsã®å©ç¨éã«å¿ãã¦å©ç¨æéãçºçãã¾ãã å©ç¨ç¶æ³ã«ããç°ãªããã䏿¦ã«ã¯è¨ãã¾ããããå¤§è¦æ¨¡ãªãµã¼ãã¹ãå ¬éãã¦ããªãéãã¯ã$10以ä¸ã«ãªãã¨èãã¦è¯ãã§ãããã
â»2022å¹´1æã«Amazon Elastic Kubernetes Serviceï¼EKSï¼ã対象ã¨ãªãããã¡ããæéã®å¯¾è±¡ã¨ãªã£ã¦ãã¾ãã
About AWS GuardDuty EKS Protection - Amazon GuardDuty
IAM Access Analyzer

使¥ï¼ï¼. ã¢ãã©ã¤ã¶ã¼ã®ä½æã[ MUST ]
IAM Access Analyzerã¯IAMã®ç»é¢ããã¢ãã©ã¤ã¶ã¼ã使ãããã¨ã§ãAWSã¢ã«ã¦ã³ãå¤ã¨å ±æãã¦ããIAMãã¼ã«ãS3ãã±ãããªã©ã®AWSãªã½ã¼ã¹ãä¸è¦§ã§ç¢ºèªãããã¨ãã§ãã¾ãããã«ãã¢ã«ã¦ã³ããä¸è¬çãªã£ã¦ããä¸ã§ãAWSã¢ã«ã¦ã³ãéã®é£æºãå¤ããªã£ã¦ãã¾ãããæå³ããªãå¤é¨ã¸ã®è¨±å¯ã¯ã»ãã¥ãªãã£ãªã¹ã¯ã¨ãªãããã宿çã«ç¶æ³ã確èªãã¦ããå¿ è¦ãããã¾ãã
ãªã¼ã¸ã§ã³åä½ã§ã®è¨å®ãå¿ è¦ãªãããå©ç¨ãããªã¼ã¸ã§ã³å ¨ã¦ã§è¨å®ããå¿ è¦ãããã¾ãã


ï¼åèï¼IAM Access Analyzerã®å©ç¨æé
IAM Access Analyzerã®å©ç¨æéã¯ç¡æã§ããæéãæ°ã«ãããæ¹ãç©æ¥µçã«ã¢ãã©ã¤ã¶ã¼ã使ãã¾ãããã
AWS Security Hub

AWS Security Hubï¼ä»¥ä¸ãSecurity Hubï¼ã¯ãAWSã¢ã«ã¦ã³ãå ã®ã»ãã¥ãªãã£ç¶æ³ãã³ã³ãã©ã¤ã¢ã³ã¹ã®æºæ ç¶æ³ã1ç®æã§ç¢ºèªã§ãããµã¼ãã¹ã§ãã以ä¸2種é¡ã®æ¤åºãå¯è½ã§ãã
- CIS AWS Foundations BenchmarkãPCI DSSã¨ãã£ãåºæºã«ãããã£ãã³ã³ãã©ã¤ã¢ã³ã¹ãã§ãã¯
- GuardDutyãMacieãInspectorãFirewall ManagerãIAM Access Analyzerã¨ãã£ãå種AWSã®ã»ãã¥ãªãã£ãµã¼ãã¹ã3rd Partyã®ã»ãã¥ãªãã£ãµã¼ãã¹ã®æ¤åºãã¢ã©ã¼ãã®ä¸å 管ç
æ¤åºãããµã¼ãã¹ã«GuardDutyãIAM Access Analyzerãå«ã¾ãã¾ãããSecurity Hubãæå¹ã«ãããã¨ã§ããããèªåçã«æå¹åããã訳ã§ã¯ãªããããåå¥ã«æå¹åããå¿ è¦ãããã¾ãã
使¥ï¼ï¼. Security Hub æå¹åã[ MUST ]
Security Hubã®ãµã¼ãã¹ç»é¢ã§æå¹åããã®ã¿ã§ä½¿ç¨ãå¯è½ã§ãã


使¥ï¼ï¼. Security Hub éç¥è¨å®ã[ BETTER ]
GuardDutyåæ§ããªã¢ã«ã¿ã¤ã æ¤ç¥ãè¡ãå ´åã¯EventBridgeã«ããæ¤ç¥è¨å®ãè¡ãã¾ãããã ããSecurity Hubã®çµæãå ¨ã¦éç¥ããã¨ãéç¥éãå¤ããªããããå¿ è¦ã«å¿ãã¦ä»¥ä¸ã®ããã«éç¥ããçµæãéå®çã«ãã¾ãã
ä¾1ï¼çµæã®éè¦åº¦ãHIGHãMEDIUMã®ã¿éç¥ãã
EventBridgeã®ãµã¼ãã¹ç»é¢ããã«ã¼ã«ï¼ã«ã¼ã«ã使ã鏿ããã¤ãã³ããã¿ã¼ã³ãç·¨éãã以ä¸ã®éãå ¥åãã¾ããdetail.findings.Severity.LabelãJSONã§æå®ãããã¨ã§ãæå®ããéè¦åº¦ã®ã¿ã®éç¥ãå¯è½ã§ãã
{ "source": [ "aws.securityhub" ], "detail-type": [ "Security Hub Findings - Imported" ], "detail": { "findings": { "Severity": { "Label": [ "CRITICAL", "HIGH", "MEDIUM" ] } } } }
ä¾2ï¼GuardDutyã®çµæã®ã¿éç¥ãã
ã¤ãã³ããã¿ã¼ã³ã以ä¸ã®éãå ¥åãã¾ãã
{ "source": [ "aws.securityhub" ], "detail-type": [ "Security Hub Findings - Imported" ], "detail": { "findings": { "ProductFields": { "aws/securityhub/ProductName": [ "GuardDuty" ] } } } }
æåã¯ãªã¢ã«ã¿ã¤ã éç¥ãéå®çã«ãã¦ããã¦ãèªåã®AWSã¢ã«ã¦ã³ãã®æ¤ç¥ç¶æ³ã宿çã«ç¢ºèªããªããããªã¢ã«ã¿ã¤ã éç¥ãã¹ãçµæãæ´çãã¦ããããã«ãã¾ãããã
ï¼åèï¼Security Hubã®å©ç¨æé
ã³ã³ãã©ã¤ã¢ã³ã¹ãã§ãã¯ã®ä»¶æ°ã¨ãå種ãµã¼ãã¹ã®æ¤åºçµæã®ä»¶æ°ã®ä»¶æ°ã«å¿ãã¦æéãçºçãã¾ãã æ¤åºçµæã¯1ä¸ä»¶ã¾ã§ã¯ç¡æã®ãããå¤§è¦æ¨¡ãªå©ç¨ãç¡ãéãã¯ç¡æã¨èãã¦è¯ãã§ããããã³ã³ãã©ã¤ã¢ã³ã¹ãã§ãã¯ã¯1ãã§ãã¯ããã0.0010USDãçºçãã¾ããå°ãã§ãæéãæ°ã«ãªãæ¹ã¯ã³ã³ãã©ã¤ã¢ã³ã¹ãã§ãã¯ãç¡å¹åãããã¨ãå¯è½ã§ãã
Amazon Detective

Amazon Detectiveï¼ä»¥ä¸ãDetectiveï¼ã¯ãVPC Flow LogsãCloudTrailãGuardDuty ãªã©ã®ä»ã®AWSãµã¼ãã¹ã®æ å ±ãã¤ã³ãããã«ãæ½å¨çãªã»ãã¥ãªãã£åé¡ãä¸ä¿¡ãªã¢ã¯ãã£ããã£ãåæã調æ»ã§ãããµã¼ãã¹ã§ãã
GuardDutyã¯çºçããã»ãã¥ãªãã£ã¤ãã³ããæ¤ç¥ãããããçºçããã¤ãã³ããã¼ã¹ã§ã®èª¿æ»ãè¡ããã¨ã«ãªãã¾ãããDetectiveã§ã¯éå»ã®ãã°ãã¤ãã³ãæ å ±ãã¨ãã£ãæç³»åã®è¦³ç¹ãå«ã¿ãã°ã©ãçã§è¦è¦åãããã¨ãå¯è½ã§ããGuardDutyã¨ã¯ç®çãç°ãªãããã両æ¹å ±ã«æå¹ã«ãããã¨ã大åã§ãã
使¥ï¼ï¼. Detective æå¹åã[ SHOULD ]
Detectiveã®ãµã¼ãã¹ç»é¢ã§æå¹åããã®ã¿ã§ä½¿ç¨ãå¯è½ã§ãã


以ä¸ã®ç»é¢ã¯ããIAMã¦ã¼ã¶ã¼1ã¤ã対象ã¨ããåæç»é¢ã§ããæåã失æã®API Callæ°ï¼ã©ãã ãæä½ãè¡ã£ãã®ãï¼ãã°ã©ãã¨ãã¦è¡¨ç¤ºããã¦ãã¾ãã

ã°ã©ãã®ä¸ãããFailed callsãå¤ãã°ã©ãé¨åãã¯ãªãã¯ããã¨ããã®æé帯ã«é¢ããæ å ±ãåããã¦è¡¨ç¤ºããã¾ããå¼ã°ããAPIã®å 容ï¼å¤±ææ°ãæåæ°å«ãï¼ãå®è¡å IPã¢ãã¬ã¹ã使ç¨ãããã¢ã¯ã»ã¹ãã¼æ å ±ã確èªãããã¨ãã§ãã¾ãã

ãããã£ãæ å ±ãããæé帯ãå®è¡éãå®è¡å 容ã¨ãã£ã観ç¹ã§ç°¡åã«åæãããã¨ãã§ãã¾ãã ä»åã¯IAMã¦ã¼ã¶ã¼ãä¾ã«ç´¹ä»ãã¾ããããä»ã«ãEC2ãAWSã¢ã«ã¦ã³ããIPã¢ãã¬ã¹ãã¦ã¼ã¶ã¼ã¨ã¼ã¸ã§ã³ããGuardDutyã®æ¤ç¥ã¤ãã³ãããã¼ã¹ã¨ããåæãå¯è½ã§ããã©ã®å°åããå®è¡ããã¦ãããã¨ãã£ã観ç¹ã§ç¢ºèªãå¯è½ã§ããã¤ãã³ãæ¤ç¥å¾ã®èª¿æ»ã«æ´»ç¨ãã¾ãããã
ï¼åèï¼Detectiveã®å©ç¨æé
GuardDutyã¨åæ§ã«åå¾ããæ å ±éã«ããå¤åãã¾ããGuardDutyãããæéã¯é«ãã«è¨å®ããã¦ãããããGuardDutyã®2ï½3åã«ç¨åº¦ã«ãªãã¨èãããã¾ãã30æ¥éã®ç¡æãã©ã¤ã¢ã«æéãããã¾ãã®ã§ãã¾ãã¯å©ç¨ãã¦ã¿ã¦ç¶æ³ãè¦ãã¨è¯ãã§ãããã
æºæ æ³ã®å¤æ´
使¥ï¼ï¼. AWS Artifactã«ããæºæ æ³ã®å¤æ´ã[ SHOULD ]
AWS ã¢ã«ã¦ã³ãéè¨æãæºæ æ³ã¯ç±³å½ã¯ã·ã³ãã³å·æ³ã¨ãªã£ã¦ãã¾ãããæºæ æ³ãæ¥æ¬æ³ã«å¤æ´ã§ãã¾ãã æ³çãªæç¶ãããã©ãã«çºçæã®ãã¨ãèããã¨ãæ¥æ¬ã§å©ç¨ããå ´åã¯æ¥æ¬ã«å¤ãã¦ãããã»ããè¯ãã§ãããããæ¥æ¬æ³ã«æºæ ãããã¨ãã¨ããã客æ§ã®è¦ä»¶ãããå ´åãããã¾ãã
夿´ã¯AWS Artifactã®ç»é¢ããå¯è½ã§ãå¥ç´ï¼ãæ¥æ¬æºæ æ³ã«é¢ããï½ããã¯ãªãã¯ããå¥ç´ããã¦ã³ãã¼ããã¦å 容確èªãã¾ãã確èªå¾ãå¥ç´ãå諾ãããã¨ã§æºæ æ³ã夿´ããã¾ãã

ã¾ã¨ã
ãããã§ããã§ããããããããªãã®ä½æ¥éããã£ããã¨æãã¾ãã AWSã¢ã«ã¦ã³ãéè¨ã®é½åº¦ããããã®ä½æ¥ãæåã§å®æ½ããã®ã¯æéãããããããCloudFormationãTerraformã¨ãã£ããµã¼ãã¹ã使ç¨ãã¦ãã³ãã¬ã¼ãåãè¡ããè¨å®ãèªååãããã¨ãåããã¦æ¤è¨ãã¾ãããã
ã¾ããOrganizationsã使ããç°å¢ã§ããã°ãControl Towerã䏿¬è¨å®æ©è½ã使ç¨ãã¦èªåè¨å®ãããã¨ãå¯è½ã§ãã
ãããã£ãã»ãã¥ãªãã£ç³»ã®ãµã¼ãã¹ã¯ãæ¥ã ã¢ãããã¼ããè¡ããããããææ°æ å ±ããã£ããã¢ãããã¦ãè¨å®ãã使¥å å®¹ãæ´æ°ãã¦ãããã¨ã大åã§ãã
AWSã®ã»ãã¥ãªãã£æ¯æ´ããã£ã¦ãã¾ãã®ã§ãä½ãããã°ãç¸è«ãã ããï¼
