Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Deep Securityのホットデータを活用する ~AWS WAFの場合~
Search
fnifni
March 17, 2016
Technology
1k
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Deep Securityのホットデータを活用する ~AWS WAFの場合~
Deep Security User Night #2 の登壇資料です。
fnifni
March 17, 2016
More Decks by fnifni
See All by fnifni
Azure Sentinel ~ 導入から2ヶ月間の運用の肌感 ~
fnifni21
2
910
踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08
fnifni21
0
2.7k
Deep Securityの運用TIPS
fnifni21
1
600
Other Decks in Technology
See All in Technology
LayerXにおけるセキュリティ管理の現在地と次の一手
tosho
0
190
なぜ Platform Engineering の土台に Kubernetes を選ぶのか
r4ynode
2
640
AIエージェントが名古屋の猛暑からあなたを守る
happysamurai294
0
120
AIネイティブな開発のサプライチェーンリスク対策 〜激動の開発現場でリスクに立ち向かう〜【ZennFes】
cscengineer
PRO
2
130
攻撃者視点で考えるDetection Engineering
cryptopeg
3
1.8k
Claude Codeとのおしゃべりでセマンティックモデルの定義からダッシュボード作成まで完成させる
nic_sugiyama
0
110
脆弱性対応、どこで線を引くか
rymiyamoto
1
390
Bedrock AgentCore RuntimeでAuth0 Changelog調査AIをアップグレードした話
t5u8a5a
1
160
20260619 私の日常業務での生成 AI 活用
masaruogura
1
210
【NRUG vol.18】なぜ多くのオブザーバビリティ導入は失敗するのか
nrug_member
0
130
"何を作るか"を任される エンジニアは、どう育つのか
yutaokafuji
1
680
2026TECHFRESH畢業分享會 - Lightning Talk - 打造精準高效的 MCP 設計模式與測試實務
line_developers_tw
PRO
0
1.1k
Featured
See All Featured
<Decoding/> the Language of Devs - We Love SEO 2024
nikkihalliwell
1
240
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Deep Space Network (abreviated)
tonyrice
0
170
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
390
Product Roadmaps are Hard
iamctodd
PRO
55
12k
WCS-LA-2024
lcolladotor
0
630
Being A Developer After 40
akosma
91
590k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
The Director’s Chair: Orchestrating AI for Truly Effective Learning
tmiket
1
190
Winning Ecommerce Organic Search in an AI Era - #searchnstuff2025
aleyda
1
2k
Navigating Weather and Climate Data
rabernat
0
220
VelocityConf: Rendering Performance Case Studies
addyosmani
333
25k
Transcript
The Three Points Protect your Web from cyber attack in
Paris of terrorist attacks
Deep Securityͷϗοτσʔλ Λ׆༻͢Δ AWS WAFͷ߹
Who ami I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
Security Engineer at cloudpack http://qiita.com/fnifni
and more ? • ࠷ۙɺ͝ԑ͕͋ͬͯɺ ӡ༻ͰഓͬͨϊϋʢͭΒΈʣΛجʹ ηΩϡϦςΟͷϕʔεϥΠϯ্ͷීٴ׆ಈ R&DΒͬͯ·͢ɻ
and more ? • ͋Μͳ͜ͱ
and more ? • ͦΜͳ͜ͱɻ
Attention ! • ຊ͓͢Δ༰ɺॾൠͷࣄʹΑΓ 2016/3/12(ۚ)·ͰSNSެ։ɺͭͿ͖Λ ͝ԕྀ͍ͩ͘͞ɻ • ຊ͓͢Δ༰PoC (֓೦࣮ূ) ͷ݁ՌΛ
ؚΈ·͢ɻαʔϏεϨϕϧͰ࣮͢Δʹɺ τϨϯυϚΠΫϩ༷ʹΑΔػೳվमΛཁ͠·͢ɻ
Points • Dynamically • Linkage • Operation (Tuning)
Points • Dynamically • Linkage • Operation (Tuning)
2015.11.13
https://ja.wikipedia.org/wiki/%E3%83%91%E3%83%AA%E5%90%8C%E6%99%82%E5%A4%9A %E7%99%BA%E3%83%86%E3%83%AD%E4%BA%8B%E4%BB%B6
ຊͱύϦͷ࣌ࠩ JST -8
CASE #1
2015/11/12 23:26:29(JST)
None
͜ͷ࣌ “ύϦ͔Βͷ߈ܸͳΜͩ” ”͍͠ͳ” ͘Β͍ʹࢥ͍ͬͯ·ͨ͠
55,247
Painful • ະͷ߈ܸͷΛؚΉՄೳੑΛߟྀͯ͠ɺ ਵ࣌NACLʹొʢӡ༻ෛՙߴ͍ʣ • IPίϩίϩସΘͬͯΠλνͬ͜͝ʢ40ۙ͘ʣ • ”195.154.0.0/16”ͱొ͔͕ͨͬͨ͠ɺ ͕ඍົͩͬͨʢ࠷ऴతʹొͨ͠ʣ
reActive͡ΌπϥΠ
Points • Dynamically • Linkage • Operation (Tuning)
CASE #2
ผͷڥʹͯ NACLͰͷःஅޙݕܧଓ
None
None
Painful • લͷૹ৴ݩIPΞυϨε͕CloudFrontͳͷͰɺ x-fowerded-forʹه͞ΕͨIPΛNACLʹొ͠ ͯःஅ͕Ͱ͖ͳ͍ɻ • ࣌AWS WAF͕ग़͔ͨΓͰɺ ςετແ͠Ͱͷຊ൪ೖϋʔυϧ͕ߴ͔ͬͨɻ
IP੍ޚΛ͔ʹ CloudFront·Ͱ͍࣋ͬͯ͘ ඞཁ͕͋ͬͨ
ͦΜͳ͜ͱ͋ͬͨޙͷ 2015.11.27
https://github.com/deep-security/aws-waf
੩తใ (IP List)Λ AWS WAFొ͢Δͷ ͚ͩͲɺ͑ΔΜ͡ΌͶʁ
ΑΖ͍͠ ͳΒ࣮ͩ
PoC (֓೦࣮ূ)
None
How to 1 (SIEM) IUUQpMFTUSFOENJDSPDPNKQVDNPEVMFUNET TQ%FFQ@4FDVSJUZ@@41@"ENJO@(VJEF@+1QEG
How to 2 ( totalization )
How to 3 ( push to DSM )
How to 4 ( DSM to AWS WAF ) http://qiita.com/fnifni/items/8ae2b49d5fe6af3d08fe
DEMO
Future Request • Deep Security • Output XFF in SIEM
(syslog) • ip_list_to_set.py • Comment character (#) ← 3.4 fixed !! • Line of only a line feed code ← 3.10 fixed !!
Points • Dynamically • Linkage • Operation (Tuning)
νϡʔχϯάͷϙΠϯτ • ਪઃఆͷݕࡧ • ରԠࡁΈͷ੬ऑੑͷϧʔϧ֎͢ʢݕϕʔεʣ • ݕΛΔʢͲΜͳ௨৴Λݕ͢Δ͔ʣ • αʔϏεͰ༻͍ͯ͠Δ௨৴͔൱͔ •
URI, POST, XML, SQL, CSS, HTML, SSL…
γεςϜੜ͖ ߈ܸੜ͖ νϡʔχϯάӡ༻ͷҰ෦
ηΩϡϦςΟ ӡ༻໋͕ʂ
Thank you !