Slide 1

Slide 1 text

The History of tsundere GuardDuty who can do or do not detect and me who keep attacking 攻撃し続けた僕と検知したりしなかったりする ツンデレの君(GuardDuty)の歴史 #jawsug #jawspankration2021 #jawspankration Usuda Keisuke / うすだけいすけ 1

Slide 2

Slide 2 text

2 Who am I? / ⾃⼰紹介 Usuda Keisuke / ⾅⽥佳祐 ・Classmethod, Inc. AWS BU Consulting Div. Senior Solution Architect Security Team Leader AWS Authorized Instructor ・Security-JAWS Member ・My favorite AWS Service: Amazon GuardDuty

Slide 3

Slide 3 text

3 Story It was a sudden encounter. 出会いは突然だった

Slide 4

Slide 4 text

4 In re:Invent 2017

Slide 5

Slide 5 text

5 Introduction / 概要 What a wonderful feature! I fell in love with her at first sight. 素敵なセキュリティ機能 僕は彼⼥を⾒てひと⽬で恋 に落ちた

Slide 6

Slide 6 text

6 However, She (GuardDuty) is Tsundere! しかし彼⼥はツンデレだった

Slide 7

Slide 7 text

7 About Tsundere? / ツンデレとは Tsundere is a Japanese term for a character development process that depicts a character with a personality who is initially cold, stern, stoic, harsh, temperamental, hotheaded (and sometimes even hostile) before gradually showing a warmer, friendlier side over time. The word is derived from the terms tsun tsun (ツンツン) ('to turn away in disgust or anger') and dere dere (デレデレ) ('to become affectionate'). (by Wikipedia)

Slide 8

Slide 8 text

8 About Tsundere? / ツンデレとは Originally found in Japanese bishōjo games, the word is now part of the otaku moe phenomenon, reaching into other media such as maid cafés, anime, manga, novels, and mass media. The term was made popular in the visual novel Kimi ga Nozomu Eien(Rumbling Hearts). (by Wikipedia)

Slide 9

Slide 9 text

9 At the time of release / リリース当時 When I first met her, she was very aggressive. (Tsun Tsun) A lot of Alerts! (´・ω・`) 最初はとにかく攻撃的(ツンツン) アラート沢⼭出してくる(´・ω・`)

Slide 10

Slide 10 text

10 Jealous / モテモテな彼⼥ On the other hand, she was severely attacked by various countries. She was being pampered. その頃の彼⼥は⾊んな国からの攻撃を 検知していました

Slide 11

Slide 11 text

11 Update in May, 2018 / 2018年5⽉のアップデート Automatic archiving was possible. She became “Dere Dere” (affectionate). ⾃動アーカイブが出来るようになった アラートがなくなり、デレた

Slide 12

Slide 12 text

12 In re:Invent 2018 I attended the event secretly without telling her. But she immediately detected that I was in Las Vegas by “UnauthorizedAccess”. 僕は彼⼥に内緒でre:Inventに⾏った しかし彼⼥は僕がラスベガスにいること をUnauthorizedAccessで検知した

Slide 13

Slide 13 text

13 She was also Yandere! 彼⼥はヤンデレでもあったのです

Slide 14

Slide 14 text

14 Evidence / エビデンス

Slide 15

Slide 15 text

15 Meanwhile… / ⼀⽅その頃

Slide 16

Slide 16 text

16 Update in May, 2019 / 2019年5⽉のアップデート She was then able to detect privilege escalation. It was slightly unstable, but it was a good feature. IAMの権限昇格を検知できるように 僕の攻撃に対して少し不器⽤だけどちゃ んと検知してくれた

Slide 17

Slide 17 text

17 Detect Privilege Escalation / 権限昇格の検知 When an attack fails, she was detected “Persistence” instead of “Privilege Escalation ”↓ ↓ ↓ ↑ ↑ ↑ When an attack succeeds, she correctly detected “Privilege Escalation ”.

Slide 18

Slide 18 text

18 Update in Feb, 2020 / 2020年2⽉のアップデート She began to detect more advanced attacks. She was then able to detect DNS rebinding. DNS Rebindingを検知できるように ⾮常に⾼度なテクニックを検知しました

Slide 19

Slide 19 text

19 UnauthorizedAccess:EC2/MetaDataDNSRebind

Slide 20

Slide 20 text

20 Update in Apr, 2020 / 2020年4⽉のアップデート AWS Chatbot was GA. Notification to Slack became very neat and clean. AWS Chatbotが正式リリース GuardDutyの通知がリッチに

Slide 21

Slide 21 text

21 In Jun, 2020 / 2020年6⽉ I wrote a script for her. It was a script to easily generate privilege escalation. 私は簡単にGuardDutyをテストするため 権限昇格を発⽣させるスクリプトを書き ました

Slide 22

Slide 22 text

22 I feel close to her.

Slide 23

Slide 23 text

23 Happiness never lasts.

Slide 24

Slide 24 text

24 Archived Finding Types. 18 Types

Slide 25

Slide 25 text

25 Can I complete her route? She hasn't completely been “Dere Dere” (affectionate) to me yet. Can I complete her route and will be happy ending? まだまだデレデレまでは遠い 彼⼥のルートを攻略してハッピーエンド になる⽇は来るのか︖

Slide 26

Slide 26 text

26 To Be Continued.