Link
Embed
Share
Beginning
This slide
Copy link URL
Copy link URL
Copy iframe embed code
Copy iframe embed code
Copy javascript embed code
Copy javascript embed code
Share
Tweet
Share
Tweet
Slide 1
Slide 1 text
ηΩϡϦςΟ୲ऀ͔Βݟͨ re:Invent ͱ AWS Security Hub Hokuto Hoshi Head of Infrastructure, Cookpad Inc.
[email protected]
Slide 2
Slide 2 text
ే (΄͠ ΄͘ͱ) / @kani_b • ΫοΫύουגࣜձࣾ ΠϯϑϥετϥΫνϟʔ෦ ෦ ݉ ίʔϙϨʔτΤϯδχΞϦϯά෦ ݉ ࠪҕһձ ࠪิॿऀ • SRE, ηΩϡϦςΟΤϯδχΞ • AWS ೝఆ SA, DevOps ΤϯδχΞ (Professional) • AWS ར༻ྺ8͘Β͍
Slide 3
Slide 3 text
https://kanny.me/
Slide 4
Slide 4 text
ΠϯϑϥετϥΫνϟʔ෦ • શαʔϏε͕ར༻͢ΔΠϯϑϥڥͮ͘Γ • SRE (Site Reliability Engineering) άϧʔϓ • σʔλج൫άϧʔϓ • ηΩϡϦςΟάϧʔϓ
Slide 5
Slide 5 text
ηΩϡϦςΟάϧʔϓ • 3໊ • αʔϏεࣾγεςϜͳͲձࣾʹ͓͚Δ͋ΒΏΔใηΩϡϦ ςΟରࡦͦͷӡ༻ʹैࣄ • γεςϜͷઃܭߏஙɺ࣮ࡍͷӡ༻·Ͱߦ͏
Slide 6
Slide 6 text
Full-AWS since 2011 ~1,400 EC2 instances 200+ ECS Services Over 3 regions 15,000+ requests/sec
Slide 7
Slide 7 text
re:Invent ͱࣗ • 2013͔ΒຖࢀՃ • 2012·ֶͩੜόΠτͩͬͨ • 2017Ͱొஃ • ػցֶशϫʔΫϩʔυΛίϯςφͰ࣮ߦ͢Δ • ࠓͰ6ճ • ϥεϕΨε7ճ
Slide 8
Slide 8 text
ΫοΫύουͱ re:Invent • 2012͔Βຖෳ໊ࢀՃ • ΠϯϑϥܥͰͳ͘αʔϏε։ൃऀͷࢀՃऀΛ૿͍ͯ͠Δ • ࠓࢀՃऀͷ8ׂҎ্
Slide 9
Slide 9 text
ηΩϡϦςΟܥηογϣϯ, ϫʔΫγϣοϓ • ຖ͕ͩେྔ • ΑΓߴͳτϐοΫʹߦ͘΄Ͳ “ίʔυΛॻ͍ͯࣗͨͪͰ࡞͍ͬͯ͘” ͷ͕ଟ͍ • AWS ηΩϡϦςΟαʔϏεͷհ͚ͩͰͳ͘ AWS αʔϏεΛͬͯΑΓྑ͍ηΩϡϦςΟγ εςϜΛͭ͘Δ • ࣗͷҎ֎ͷϫʔΫγϣοϓͳͲʹग़͍ͯΔΤϯδχΞଟ͍ • ηΩϡϦςΟΤϯδχΞ͕ DynamoDB ઃܭͷϫʔΫγϣοϓʹग़͍ͯΔͳͲ • εϥΠυಈըެ։͞Ε͍ͯ·͢
Slide 10
Slide 10 text
Security Jam • AWS ্ͰηΩϡϦςΟରࡦΠϯγσϯτϨεϙϯεΛମݧͯ͠ ͍͘Πϕϯτ • ָͦ͠͏ͳͷʹຖճ GameDay ͱඃͬͯ͠·͍ ࢀՃͰ͖͍ͯͳ͍… (ಉ྅ᐌָ͔ͬͨ͘͠ͱͷ͜ͱ) • ຊͰΔ͔ GameDay ͱ࣌ؒΛͣΒ͍ͯͩ͘͠͞!!!
Slide 11
Slide 11 text
Expo • ηΩϡϦςΟͷϓϩόΠμʑ૿Ճ͍ͯ͠Δ • ࠓίϯςφηΩϡϦςΟ͕ଟ͔ͬͨҹ • SIEM, ΠϕϯτϚωδϝϯτͳͲ
Slide 12
Slide 12 text
ࠓͷൃද • ͍Ζ͍Ζ͋Γ·ͨ͠Ͷ • ML, IoT, Robot ͳͲ͋Γͭͭݎ࣮ͳྖҬʹେྔϦϦʔε
Slide 13
Slide 13 text
ൃද (ηΩϡϦςΟ) https://aws.amazon.com/jp/new/reinvent/
Slide 14
Slide 14 text
ηΩϡϦςΟͷൃදগͳ͘ͳ͍ʁʁʁ • ηΩϡϦςΟΛλʔήοτʹͨ͠ͷ͔֬ʹগͳ͍ • ͕ɺηΩϡϦςΟγεςϜͷߏஙͳͲʹ͑Δͷͨ͘͞Μ • “ηΩϡϦςΟ” λά͕͍ͭͨαʔϏε͚͕ͩ AWS ηΩϡϦςΟͰͳ͍
Slide 15
Slide 15 text
https://speakerdeck.com/mizutani/security-log-search
Slide 16
Slide 16 text
ηΩϡϦςΟγεςϜʹ͑Δ or ͑ͦ͏ͳ ϦϦʔεͱײΛհ (ݸਓͷݟղͰ͢)
Slide 17
Slide 17 text
CloudWatch Logs Insights • CW Logs ͷϩάʹର͠ߜΓࠐΈूܭɺੳ͕Մೳʹ • JSON ͳͲʹରԠͰ͖Δ • ৽όοΫΤϯυʹΑΔരݕࡧ • େྔͷϩάσʔλʹରͯ͠ഒҎ্͍ (࣮ࡍʹͬͯ·͢) • γεςϜϩάΞΫηεϩάͳͲͷετϨʔδͱͯ͠༗ྗީิʹ • ͨͩ͠Ձ֨ཁ֬ೝ
Slide 18
Slide 18 text
S3 Object Lock • S3 Object ΛҰఆ or ແظݶͰ্ॻ͖/আͰ͖ͳ͘ͳΔػೳ • ࠷ڧͷϞʔυͰ root account Ͱ͢Βআෆೳʹ • MFA Delete ʹΘΔબࢶʹͳΔ • ֤छॏཁϩάͷอ࣋ʹར༻Մೳ • ޡരʹҙ
Slide 19
Slide 19 text
S3 Glacier ͷػೳڧԽ • ໊শมߋͱಉ࣌ʹ৭ʑग़ͨ • S3 Glacier ετϨʔδΫϥεͷૹ • ΫϩεϦʔδϣϯϨϓϦέʔγϣϯͷ Glacier ରԠ • ෮ݩ௨ɺ෮ݩΞοϓ • S3 Glacier Deep Archive • ͔͞Έ͕ͪͳηΩϡϦςΟؔ࿈ϩάͷظόοΫΞοϓʹ͑Δ • ΫοΫύουͰ Lifecycle Ͱ Glacier ૹΓʹ͍ͯ͠·͢
Slide 20
Slide 20 text
S3 Intelligent Tiering • S3 Standard ͱ Standard-IA (ස) ΛࣗಈͰߦ͖དྷͰ͖Δ • Athena ͳͲΛϩάݕࡧʹ͍ͬͯΔέʔεͰศར • ϑϧεΩϟϯ͢Δͱҙຯ͕ͳ͘ͳΔͷͰϢʔεέʔεઃܭ͕େࣄ
Slide 21
Slide 21 text
KMS Custom Key Store • KMS ͷΩʔετΞͱͯ͠ CloudHSM ͕͑ΔΑ͏ʹ • ߟ͑ΒΕΔ༻్ • Ͳ͏ͯ͠ΩʔετΞΛ͢Δඞཁ͕͋Δ • KMS Λ௨ͯ͠Ͱͳ͘ CloudHSM ଆ͔Β伴ͷࠪΛ͍ͨ͠ • զʑʹར༻༻్͕ͳ͍Ͱ͢…
Slide 22
Slide 22 text
AWS Control Tower • લͷൃදͰઆ໌͕͋ͬͨͷͰجຊઆ໌লུ • େྔΞΧϯτΛཧ͢ΔڥԼͰ͔ͳΓศརͦ͏ • ΧδϡΞϧʹ AWS ΞΧϯτΛ࡞Γ͘͢ͳΔ
Slide 23
Slide 23 text
AWS Security Hub • લͷൃදͰઆ໌͕͋ͬͨͷͰجຊઆ໌লུ • ͏গ͠۷ΓԼ͛ͯɺͲͷΑ͏ʹ׆༻͍͔ͨ͠Λ͠·͢
Slide 24
Slide 24 text
ηΩϡϦςΟγεςϜͷجຊํ • ༷ʑͳιϑτΣΞαʔϏεΛηϯαʔͱͯ͠͏ • ηϯαʔ͔ΒͷϩάΞϥʔτΛूͯ͠ཧ͢Δ • ͦΕͧΕͷཧίϯιʔϧʹϩάΠϯͯ͠…ͱ͍͏ͷ ΘΕͳ͍γεςϜΛੜΉ͚ͩͳͷͰΊΔ • ຊʹඞཁͳஅʹूதͰ͖ΔΈΛͭ͘Δ (ࣗಈԽ)
Slide 25
Slide 25 text
ΞʔΩςΫνϟ֓ཁ ύʔτ͚ ϩάϑΝΠϧઃஔͷ ΠϕϯτΛݕग़ Lambda Lambda Lambda Kinesis Stream S3 S3 Athena ϧʔϧΛ༻͍ͨ Ξϥʔτͷݕ Ξϥʔτͷൃใ ϩάͷม EC2 Elasticsearch Service ߴͰΠϯλϥΫςΟϒͳ ظతϩάͷݕࡧ ظؒʹΘͨΔ ϩάͷݕࡧ GHE PagerDuty Slack Ξϥʔτͷൃใɾཧ Ξϥʔτͷௐࠪ EC2 instances ͦͷଞϓϩμΫτ Kinesis Stream Kinesis Stream ϩάऩूύʔτ ϩάॲཧύʔτ Ξϥʔτॲཧύʔτ CloudWatch Logs/ Event, GuardDuty, CloudTrail
Slide 26
Slide 26 text
֓ཁ • ༷ʑͳϑΥʔϚοτͷϩάΞϥʔτΛ S3 ʹऩू • AWS αʔϏεͱͯ͠ GuardDuty ͳͲΛར༻ • ऩूͨ͠ϩάɾΞϥʔτΛਖ਼نԽͯ͠ Graylog / S3 ʹೖ • Ωϟονͨ͠Ξϥʔτਖ਼نԽͯ͠ GitHub (Enterprise) ʹىථ • ՄೳͳݶΓͷॳظௐࠪΛࣗಈͰߦ͏ • PagerDuty, Slack ͷൃใߦ͏
Slide 27
Slide 27 text
͞Βʹվળ͍ͨ͠ϙΠϯτ • Ξϥʔτͷਖ਼نԽ͕ͪΐͬͱେม (ࣗͨͪͰ࡞Δ) • ΞϥʔτࣗମͷूܭɺՄࢹԽ • ࣗಈԽΛߋʹਐΊΔ • ௐࠪɺରԠ • ظతͳੳ
Slide 28
Slide 28 text
Ξϥʔτਖ਼نԽ • ରԠ͍ͯ͠ΔαʔϏεͰ͋Εਖ਼نԽෆཁ • ଞγεςϜʹΞϥʔτΛॻ͖ࠐΈ͍ͨ߹ Security Hub ΛڬΉ͜ͱͰ ॲཧΛڞ௨ԽͰ͖Δ • Ξϥʔτʹ͍ͭͯ “ͱΓ͋͑ͣ Security Hub ʹಥͬࠐΉ” ͜ͱ͕ Ͱ͖ΔΑ͏ʹͳΔ • ࠓޙ৽نʹηΩϡϦςΟαʔϏε͕ग़͖ͯͯૉૣ͘౷߹Ͱ͖Δ
Slide 29
Slide 29 text
Amazon Security Finding Format • ηΩϡϦςΟΞϥʔτʹٻΊΒΕͦ͏ͳ߲Ұ௨ΓΧόʔ • EC2 Πϯελϯε ͳͲ AWS ݻ༗ͷϑΟʔϧυ༻ҙ • ࠓͷஈ֊Ͱ AWS ϦιʔεΛओʹఆ͍ͯ͠ΔΑ͏ʹݟ͑Δ • ͏ͪΐͬͱ৭ʑͳϦιʔεʹରͯ͑͠Δͱ͏Ε͍͠… • ৄࡉ Security Hub ͷυΩϡϝϯτΛࢀর
Slide 30
Slide 30 text
ूܭɺՄࢹԽ • Insights Ͱ͋ΔఔՄೳ • Findings ΛϑΟϧλͨ݁͠Ռ (Group by ͳͲՄೳ) • άϥϑΧελϜͰ͖ͨΒخ͍͚͠Ͳɻɻ • ظతʹոͦ͠͏ͳϦιʔεΛݟ͚ͭΔͷʹ༗ޮ
Slide 31
Slide 31 text
ࣗಈԽ • CW Events ʹΠϕϯτΛૹ৴Ͱ͖Δ • Finding, Insights, Standards • Lambda function Step Function ΛݺͿ͜ͱ͕Ͱ͖Δ • ϩάऩूͱඥ͚, Ϩϐϡςʔγϣϯௐࠪ, ݕମௐࠪ, ΠϯελϯεͷίϚϯυൃߦͳͲͳΜͰ͋Γ
Slide 32
Slide 32 text
ͦͷଞͷྑ͍ػೳ • ϚϧνΞΧϯτରԠ • Control Tower Ͱ৽ن࡞࣌ʹશηΩϡϦςΟαʔϏε༗ޮԽ + Security Hub ͷૹ৴͕Ͱ͖ΔΑ͏ʹͳΔͱ͏Ε͍͠ • ηΩϡϦςΟඪ४ͷνΣοΫ • ࣮ମ Config Rules ͷू߹ମ (ݱࡏ CIS AWS foundation benchmark ͷΈ) • ͜ΕΧελϜ͕࡞ΕΔͱྑ͍
Slide 33
Slide 33 text
ͦͷଞ͜͏ͳͬͯ͘ΕΔͱخ͍͠ • Findings ͦͷͷͷΞοϓσʔτ (ଐੑͷՃͳͲ) • ࣗಈԽʹΑΔௐࠪ݁ՌͳͲΛՃ͓͖͍ͯͨ͠ (ݱঢ়ςΩετͷΈ) • Πϕϯτཧπʔϧͱͷ࿈ܞ • ͋Δ͍ Security Hub ͕ࣗཧπʔϧʹͳΔ • ୲ऀɺௐࠪঢ়گɺݟղɺetc • AWS WAF ࿈ܞ • Ξϥʔτ͕͔ͳΓଟ͘ͳΔͣͳͷͰɺͦͷ··දࣔͯ͠΄͘͠ͳ͍͕…
Slide 34
Slide 34 text
·ͱΊ
Slide 35
Slide 35 text
ࠓճͷൃදʹ͍ͭͯ • ͙͢ʹ͑Δͷଟ͘ྑ͔ͬͨͱࢥ͏ • ηΩϡϦςΟʹϑΥʔΧεͨ͠ͷଟ͘ͳ͍͕ɺ ηΩϡϦςΟʹ׆͔͢͜ͱ͕Ͱ͖ΔαʔϏεػೳ͕ग़͍ͯΔ • Control Tower, Security Hub ੵۃతʹར༻͍ͨ͠
Slide 36
Slide 36 text
͜Ε͔Βͷ AWS ηΩϡϦςΟ • (طʹͦ͏ͳ͍ͬͯΔ͕) ಛఆͷαʔϏειϑτΣΞΛ ͏͚ͩͰͳ͘ɺ͍ࢹͰηΩϡϦςΟγεςϜΛઃܭ࣮ͯ͢͠Δ • AWS ͕ఏڙ͍ͯ͠ΔύʔπʹΑͬͯ࡞Γ͍͢ڥ͋Δ • ͦ͏͍ͬͨͷ͕ఏڙ͞Ε͍ͯΔͱࢥ͏͠ɺ͍ͯͬͯ͠΄͍͠
Slide 37
Slide 37 text
PR
Slide 38
Slide 38 text
࣍ੈͷηΩϡϦςΟڥΛҰॹʹͭ͘Δ ΤϯδχΞΛืू͍ͯ͠·͢ https://cookpad.jobs/
Slide 39
Slide 39 text
Fin.