Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Security Command Center × PagerDuty 自動アラート通知の取り組み
Search
Kyohei Mizumoto
August 04, 2022
Technology
790
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Security Command Center × PagerDuty 自動アラート通知の取り組み
3-shake SRE Tech Talk #4 の登壇資料です。
https://3-shake.connpass.com/event/253028/
Kyohei Mizumoto
August 04, 2022
More Decks by Kyohei Mizumoto
See All by Kyohei Mizumoto
ソフトウェアサプライチェーンの構造的リスクとコンテナ環境の保護
kyohmizu
5
1.1k
最新の脅威動向から考える、コンテナサプライチェーンのリスクと対策
kyohmizu
1
1.1k
コンテナセキュリティの最新事情 ~ 2026年版 ~
kyohmizu
9
4.3k
Black Hat USA 2025 Recap ~ クラウドセキュリティ編 ~
kyohmizu
0
1k
CTFのためのKubernetes入門
kyohmizu
3
1.3k
クラウドネイティブ環境の脅威モデリング
kyohmizu
3
860
コンテナサプライチェーンセキュリティ
kyohmizu
2
560
サイバーセキュリティの最新動向:脅威と対策
kyohmizu
1
470
コンテナセキュリティの基本と脅威への対策
kyohmizu
4
2.4k
Other Decks in Technology
See All in Technology
【ゲームメーカーズスクランブル2026】『Shadowverse: Worlds Beyond』UIとアニメーションで実現する最高のユーザー体験を叶えるプロトタイピング
cygames
PRO
0
140
Oracle Base Database Service 技術詳細
oracle4engineer
PRO
16
120k
技術的負債から考える、AI時代のエンジニアリング投資 — ビズリーチの技術的負債と向き合った経験から、変更し続けられるソフトウェアを考える/ technical-debt-con2026
visional_engineering_and_design
4
3.7k
データ界隈LT祭 第1回LT登壇
taromatsui_cccmkhd
2
1.5k
2026_devsumi_ozono.pdf
o3
3
580
AIを活用するために決めた "やらないこと" - 価値に注目する / Not betting on AI
soudai
PRO
3
590
CLIライブラリ開発を支える技術
htnabe
0
150
品質と信頼性を地続きにする
grimoh
2
950
Claude Codeを「使うほど育つ」AI秘書にするノウハウ
minorun365
PRO
33
31k
AIで社員の自主発信に広報目線を組み込む
_mossann_t
0
140
今話題のAI「Jev」って何? 宇宙最速で学ぶ会
minorun365
PRO
30
19k
Making AI Agents Safe and Fast- Jev, Obsidian, and the Meta-Harness
x5gtrn
PRO
0
120
Featured
See All Featured
The World Runs on Bad Software
bkeepers
PRO
72
12k
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2.2k
How to train your dragon (web standard)
notwaldorf
97
6.8k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
6.1k
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
1
610
Leadership Guide Workshop - DevTernity 2021
reverentgeek
1
370
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
23k
Code Review Best Practice
trishagee
74
20k
Thoughts on Productivity
jonyablonski
76
5.4k
Applied NLP in the Age of Generative AI
inesmontani
PRO
4
2.5k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
21
1.6k
Building a A Zero-Code AI SEO Workflow
portentint
PRO
0
730
Transcript
Security Command Center × PagerDuty 自動アラート通知の取り組み @kyohmizu
Copyrights©3-shake Inc. All Rights Reserved. 2 whoami 水元 恭平 (@kyohmizu)
株式会社スリーシェイク Sreake事業部 SRE/CSIRT - AWS, GCP, kubernetes - 脆弱性評価・セキュリティアラートの基盤構築と運用 - セキュリティ運用改善(IaC, 自動化ツール作成など) - IAM設計、脅威情報の収集、サイバー演習 etc… イベント - 3-shake SRE Tech Talk 運営 - CloudNative Days 実行委員(~2021)
Copyrights©3-shake Inc. All Rights Reserved. 3 モチベーション Security Command Center
(SCC) のアラートを自動通知する仕組みを作る! - AWS では SecurtyHub × PagerDuty の連携を行なっている - インテグレーション機能でサクッと解決 - 同じ仕組みを Google Cloud でも作りたい - …インテグレーションがない??? 思ったより大変だったので、実装する上で必要な設定やハマりポイントをご紹介します。
Copyrights©3-shake Inc. All Rights Reserved. 4 アーキテクチャ
Copyrights©3-shake Inc. All Rights Reserved. 5 実装の手順 1. PagerDuty 側の準備(今回はお話ししません)
a. Service 作成 b. インテグレーションに Custom Event Transformer を追加 c. Jira インテグレーションを追加 2. Security Command Center API の有効化 3. Pub/Sub トピックの作成 4. Cloud Functions のコード実装&デプロイ 5. SCC Notification Config の作成
Copyrights©3-shake Inc. All Rights Reserved. 6 Cloud Functions コード実装 def
scc_to_pd(event, context): webhook_url = os.getenv('WEBHOOK_URL', None) attributes = base64.b64decode(event["data"]).decode("utf-8") headers = { "Content-Type": "application/json; charset=UTF-8" } data = { "Data": json.loads(attributes), } req = urllib.request.Request(webhook_url, data=json.dumps(data).encode("utf-8"), method="POST", headers=headers) try: res = urllib.request.urlopen(req, timeout=5) except Exception as e: print(e) SCC findings の内容を丸ごと送信 - SCC は組織権限がないと参照できないため、対応担当者が見れないケースもある - PagerDuty や Jira チケット管理により権限問題を解消
Copyrights©3-shake Inc. All Rights Reserved. 7 ハマりポイント① Terraform 実装について -
Notification Config は自身のユーザで terraform apply しても失敗する - サービス アカウントの権限借用 (service account impersonation) が必要 - SA のアクセストークンを設定したプロバイダを用意する - https://cloud.google.com/blog/topics/developers-practitioners/using-google-cloud-service-account-imperso nation-your-terraform-code - Pub/Sub, CloudFunctions 等のリソースは通常のプロバイダを使用
Copyrights©3-shake Inc. All Rights Reserved. 8 ハマりポイント① provider "google" {
alias = "impersonation" scopes = [ "https://www.googleapis.com/auth/cloud-platform", "https://www.googleapis.com/auth/userinfo.email", ] } provider "google" { alias = "scc-creator" project = var.project_id access_token = data.google_service_account_access_token.scc_creator.access_token } data "google_service_account_access_token" "scc_creator" { provider = google.impersonation target_service_account = google_service_account.scc_creator.email scopes = ["userinfo-email", "cloud-platform"] lifetime = "1200s" } resource "google_scc_notification_config" "notify_to_pubsub" { provider = google.scc-creator … }
Copyrights©3-shake Inc. All Rights Reserved. 9 ハマりポイント② VPC Service Controls
への対応 - VPC Service Controls を有効化していたため Notification Config の作成に失敗 - 事前に VPC Service Controls の Ingress/Egress 設定を追加する必要がある - ドキュメントの手順通りに行えば OK - https://cloud.google.com/security-command-center/docs/how-to-notifications#grant-perimeter-access - (VPC Service Controls つらい)
Copyrights©3-shake Inc. All Rights Reserved. 10 運用上の課題 アラートのチューニングについて - SCC
の Mute設定 - 個別設定 or Config 作成。設定がやや複雑なのと条件付き - Mute しても通知が来る? - CloudFunctions のコード修正 - コードの複雑化や停止のリスク。都度デプロイの必要あり - PagerDuty のカスタムルール アラート調査のコスト高 - セキュリティ担当者による対応の限界 - 一次対応者をサービス担当者へ振り分ける - チケットの可読性向上の必要性
Copyrights©3-shake Inc. All Rights Reserved. 11 Security Command Center の機能
https://cloud.google.com/security-command-center/pricing 通知設定 https://htayyar.medium.com/pagerduty-google-cloud-security-command-center-6ad92debb026 https://cloud.google.com/security-command-center/docs/how-to-notifications https://cloud.google.com/security-command-center/docs/how-to-api-manage-notifications terraform 関連 https://github.com/hashicorp/terraform-provider-google/issues/10534 https://cloud.google.com/iam/docs/impersonating-service-accounts https://cloud.google.com/blog/topics/developers-practitioners/using-google-cloud-service-account-impersonation-your-terraform-code https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/scc_notification_config 参考