Upgrade to Pro — share decks privately, control downloads, hide ads and more …

20160825_AWS運用時に気をつけておくべきセキュリティのポイント(株式会社 ターン・...

Classmethod
August 29, 2016
3.7k

20160825_AWS運用時に気をつけておくべきセキュリティのポイント(株式会社 ターン・アンド・フロンティア)

Classmethod

August 29, 2016
Tweet

More Decks by Classmethod

Transcript

  1. ̏֊૚ͷϧʔτςʔϒϧ w QVCMJDOFUXPSL &-# /"5αʔό /"5(8  ౿Έ୆αʔό w QSPUFDUFEOFUXPSL

    8&#αʔό "11αʔό w QSJWBUFOFUXPSL %#αʔό 3%4 ૹ৴ઌ λʔήοτ  MPDBM ૹ৴ઌ λʔήοτ  MPDBM  OBU9999999 ૹ৴ઌ λʔήοτ  MPDBM  JHX9999999
  2. ໿෼ޙʹ߈ܸ͞ΕΔ TTIE<>%JEOPUSFDFJWFJEFOUJpDBUJPOTUSJOHGSPN TTIE<>"EESFTTNBQTUPXXXNBHVNBDPN CVUUIJTEPFT OPUNBQCBDLUPUIFBEESFTT1044*#-&#3&",*/"55&.15 TTIE<>*OWBMJEVTFSBGSPN TTIE<>JOQVU@VTFSBVUI@SFRVFTUJOWBMJEVTFSB<QSFBVUI> TTIE<>$POOFDUJPODMPTFECZ<QSFBVUI> TTIE<>"EESFTTNBQTUPXXXNBHVNBDPN CVUUIJTEPFTOPU

    NBQCBDLUPUIFBEESFTT1044*#-&#3&",*/"55&.15 TTIE<>*OWBMJEVTFSBKBZGSPN TTIE<>JOQVU@VTFSBVUI@SFRVFTUJOWBMJEVTFSBKBZ<QSFBVUI> TTIE<>$POOFDUJPODMPTFECZ<QSFBVUI> TTIE<>"EESFTTNBQTUPXXXNBHVNBDPN CVUUIJTEPFTOPU NBQCBDLUPUIFBEESFTT1044*#-&#3&",*/"55&.15 TTIE<>*OWBMJEVTFSBTLGSPN TTIE<>JOQVU@VTFSBVUI@SFRVFTUJOWBMJEVTFSBTL<QSFBVUI> TTIE<>$POOFDUJPODMPTFECZ<QSFBVUI>
  3. "EESFTTNBQTUPXXXNBHVNBDPN CVUUIJTEPFT OPUNBQCBDLUPUIFBEESFTT1044*#-&#3&",*/"55&.15 ߈ܸ͖ͯͨ͠*1ΞυϨεΛௐࠪᶄ w *1ΞυϨεͷ%/4Λ֬ೝ w ͷٯҾ͖ w XXXNBHVNBDPNͷਖ਼Ҿ͖

    JOBEESBSQB*/153XXXNBHVNBDPN XXXNBHVNBDPN*/$/".&NBHVNBDPN NBHVNBDPN*/"
  4. "EESFTTNBQTUPXXXNBHVNBDPN CVUUIJTEPFTOPU NBQCBDLUPUIFBEESFTT1044*#-&#3&",*/"55&.15 ߈ܸ͖ͯͨ͠*1ΞυϨεΛௐࠪᶄ w *1ΞυϨεͷ%/4Λ֬ೝ w ͷٯҾ͖ w XXXNBHVNBDPNͷਖ਼Ҿ͖

    JOBEESBSQB*/153XXXNBHVNBDPN XXXNBHVNBDPN*/$/".&NBHVNBDPN NBHVNBDPN*/"
  5. ΫϩεαΠτεΫϦϓςΟϯά w ςετ಺༰ ͱ͋ΔϒϩάʹίϝϯτͳͲΛ౤ߘ͢ΔαΠτΛ໛ٖ ίϝϯτ౤ߘ಺༰ͰTDSJQUΛຒΊࠐ·ΕͨΒͲ͏ͳΔͷ͔Λςετ w ղઆ 1045Ͱड͚औͬͨத਎Λਫ਼͍ࠪͯ͠ͳ͍ͨΊɺͦͷ··%#ʹίϝϯτͱ ͯ͠JOTFSUΛߦ͏ɻ ͦͷ݁ՌɺҎԼͷΑ͏ͳίϝϯτΛೖΕΒΕͨ৔߹ɺӾཡ࣌ʹKT͕࣮ߦ͞

    ΕΔɻ ʮTDSJQUBMFSU EPDVNFOUDPPLJF TDSJQUʯ ࣮ߦKTͷ෦෼ʹϩάΠϯηογϣϯΛଞαʔόʹQPTU͢ΔΑ͏ͳهࡌ͕͋ͬ ͨ৔߹ɺηογϣϯ͕߈ܸऀʹ࿙Εͯ͠·͍ɺηογϣϯΛྲྀ༻ͯ͠αΠ τΛ๚໰Ͱ͖ͯ͠·͏ɻ
  6. ·ͱΊ w ੬ऑੑͷରࡦ w ΍ΒΕͨ࣌ͷͨΊʹ-0(Λ֎෦΁సૹ ˠZVNTFDVSJUZVQEBUFͳͲύονͷద༻ ˠσϑΥϧτ44-҉߸Խ௨৴ ˠBXTMPHTͰखܰʹ҆ՁͰϩάΛ֎෦ʹసૹ ˠ"84Ͱ͸%FFQ4FDVSJUZ͕͓͢͢Ί w

    ωοτϫʔΫߏ੒Λ֊૚Ͱઃܭ ˠ"84͔ͩΒͦ͜खܰʹͰ͖ΔOFUXPSLߏஙɻ*1੍ݶˍTTI伴ೝূ ˠ1045σʔλ΍(&5ύϥϝʔλͷਫ਼ࠪ ˠJOTQFDUPSͳͲΛ࢖༻ͯ͠αʔόͷݱঢ়Λ೺Ѳ w ͓͢͢Ίରࡦ੡඼