Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
15分で始められる Tenable.io on AWS
Search
sakamaki
October 26, 2018
0
670
15分で始められる Tenable.io on AWS
AWS向けTenable.ioソリューション活用セミナー「15分で始められる Tenable.io on AWS」の登壇資料です。
sakamaki
October 26, 2018
Tweet
Share
More Decks by sakamaki
See All by sakamaki
AWS Well-Architected Frameworkの概要
sakamaki
0
1.4k
Featured
See All Featured
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
2.8k
It's Worth the Effort
3n
187
29k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
1
880
How STYLIGHT went responsive
nonsquared
100
6k
Marketing to machines
jonoalderson
1
4.5k
Bridging the Design Gap: How Collaborative Modelling removes blockers to flow between stakeholders and teams @FastFlow conf
baasie
0
420
Scaling GitHub
holman
464
140k
Odyssey Design
rkendrick25
PRO
0
450
Self-Hosted WebAssembly Runtime for Runtime-Neutral Checkpoint/Restore in Edge–Cloud Continuum
chikuwait
0
270
Bioeconomy Workshop: Dr. Julius Ecuru, Opportunities for a Bioeconomy in West Africa
akademiya2063
PRO
0
37
職位にかかわらず全員がリーダーシップを発揮するチーム作り / Building a team where everyone can demonstrate leadership regardless of position
madoxten
54
48k
Crafting Experiences
bethany
0
25
Transcript
!1 AWSࣄۀຊ෦ίϯαϧςΟϯά෦ ࡔר Ұٛ 2018/10/25 Ͱ࢝ΊΒΕΔ5FOBCMFJPPO"84
εϥΠυޙͰೖख͢Δ͜ͱ͕ग़དྷ·͢ͷͰ ൃදதͷ༰ΛϝϞ͢Δඞཁ͋Γ·ͤΜɻ ࣸਅࡱӨΛ͢Δ߹ ϑϥογϡɾγϟολʔԻ͕ग़ͳ͍Α͏ʹྀ͍ͩ͘͝͞ Attention
ࣗݾհ ܦྺ 4JFSͰΠϯϑϥΤϯδχΞ ݄ೖࣾ ࠷ۙ͞Θ͍ͬͯΔ"84αʔϏε -BNCEBɺ4UFQ'VODUJPOT ࡔרҰٛ "84ࣄۀຊ෦ίϯαϧςΟϯά෦
ຊͷηογϣϯͰ͍͑ͨ͜ͱ !4 5FOBCMFJPΛར༻͢Ε ੬ऑੑஅ͕؆୯ʹߦ͑Δ
ࠓ͢͜ͱɾ͞ͳ͍͜ͱ
ࠓ͢͜ͱʢAgendaʣ !6 "84Ͱ5FOBCMFJPΛར༻͢ΔϝϦοτ εΩϟφΠϯελϯεͷߏஙखॱ εΩϟϯ࣮ࢪʗݕग़ͨ͠ڴҖΛੋਖ਼ εΩϟϯͷ࣮ࢪύλʔϯ ·ͱΊ
ࠓ͞ͳ͍͜ͱ !7 8FC"QQMJDBUJPOTʢΣϒΞϓϦஅʣ $POUBJOFS4FDVSJUZʢίϯςφஅʣ
AWSͰTenable.ioΛར༻ ͢ΔϝϦοτ
ಥવͰ͕͢.. !9 "84্Ͱ੬ऑੑஅͨ͠ ࣄ͋Γ·͔͢ʁ
੬ऑੑஅʹ͚ͨਃ !10 εΩϟϯରͷ*1ΞυϨεʗ*% ςετͰ༻͢ΔଳҬ෯ ϐʔΫ࣌ͷϦΫΤετ εΩϟϯΛ࣮ࢪ͢Δ։࢝࣌ࠁ εΩϟϯΛ࣮ࢪ͢Δऴྃ࣌ࠁ ɾ ɾ ɾ
"84Ͱͷېࢭߦҝͱ۠ผ͢ΔͨΊʹɺࣄલʹঝೝ͕ඞཁ
(ݸਓతʹ)ਃͰਏ͍ͱ͜Ζ !11 ਃϑΥʔϜ͕ӳޠ ࠷ͷਃ ΞλοΫͱ۠ผ͢ΔͨΊʹਃ߲͕ଟ͍ʢવ͚ͩͲʣ ࣄલਃ͕ඞཁͰঝೝ·ͰӦۀཁ͢Δ ٸͳεέδϡʔϧͷมߋʹରԠͮ͠Β͍
ࢥͬͨࣄ͋Γ·ͤΜ͔ʁ !12 खܰʹ੬ऑੑஅ͕͍ͨ͠
5FOBCMFJP
ࣄલঝೝ͞ΕͨεΩϟφΠϝʔδ !14 "84.BSLFUQMBDFʹొ͞Ε͍ͯΔɺ εΩϟφΠϝʔδʢ/FTTVT4DBOOFSʣΛ ར༻͢Δ͜ͱͰɺ"84ͷਃෆཁͰε Ωϟϯʢ੬ऑੑஅʣ͕Մೳ
ࣄલঝೝ͞ΕͨεΩϟφΠϝʔδ !15 "84ࣄલঝೝࡁΈ
AWSͰTenable.ioΛར༻͢ΔϝϦοτ !16 ࣄલঝೝ͞ΕͨεΩϟφʢ"84POMZʣ "1*ίωΫλʢ"84POMZʣ ΞηοτΛࢹ͠৽͍͠ͷՃɺ ݹ͍ͷআɺΞηοτΛಈతʹཧ ࠪεΩϟϯ͕Մೳ ϕετϓϥΫςΟε$*4ʹରͯ͠ͷϕϯνϚʔΫ
εΩϟφΠϯελϯεߏங
ࠓճͷߏஙൣғ !18 εΩϟϯ࡞ εΩϟφΠϯελϯεߏங
εΩϟϯͷͳ͕Ε !19 5FOBCMFJPΑΓεΩϟϯ࣮ߦ εΩϟφʹεΩϟϯ໋ྩ λʔήοταʔόεΩϟϯ։࢝ εΩϟϯ݁ՌΞοϓϩʔυ அ݁Ռ֬ೝ
εΩϟϯͷͳ͕Ε !20
5FOBCMFJPίϯιʔϧ ϦϯΫΩʔऔಘ
Tenable.ioʗLinking Keyऔಘ !22 ʮ4DBOTʯΛΫϦοΫ
Tenable.ioʗLinking Keyऔಘ !23 ʮ4DBOOFSTʯΛΫϦοΫ
Tenable.ioʗLinking Keyऔಘ !24 ϦϯΫΩʔΛ߇͑Δ
"84Ϛωδϝϯτίϯιʔϧ *".ϩʔϧ࡞
AWSʗIAMϩʔϧ࡞ !26 ϩʔϧΛ༻͢ΔαʔϏεʮ&$ʯ
AWSʗIAMϩʔϧ࡞ !27 "NB[PO&$3FBE0OMZ"DDFTTݖݶΛ༩
AWSʗIAMϩʔϧ࡞ !28 ҙͷϩʔϧ໊
AWSʗIAMϩʔϧ࡞ !29
"84Ϛωδϝϯτίϯιʔϧ εΩϟφΠϯελϯε࡞
!31 AWSʗεΩϟφΠϯελϯε࡞ "84.BSLFUQMBDFΑΓʮ5FOBCMFʯͰݕࡧ
!32 AWSʗεΩϟφΠϯελϯε࡞ ιϑτΣΞྉۚෆཁ
!33 AWSʗεΩϟφΠϯελϯε࡞ ΠϯελϯελΠϓɺUNFEJVNɺUMBSHFɺNϑΝϛϦʔ ύϑΥʔϚϯεΛॏࢹ͢Δ߹NMBSHFҎ্͕ਪ
!34 AWSʗεΩϟφΠϯελϯε࡞ ࡞ͨ͠*".ϩʔϧΛࢦఆ
!35 \ OBNF"84@4DBOOFS LFZFCEEB999999999 JBN@SPMF5FOBCMF3PMF ^ AWSʗεΩϟφΠϯελϯε࡞ +40/ܗࣜͰϢʔβʔσʔλʢςΩετʣΛೖྗ
!36 AWSʗεΩϟφΠϯελϯε࡞ OBNF 5FOBCMFJP্ʹදࣔ͞ΕΔεΩϟφ໊ LFZ औಘͨ͠ϦϯΫΩʔ JBN@SPMF εΩϟφΠϯελϯεʹ༩ͨ͠*".ϩʔϧ
!37 AWSʗεΩϟφΠϯελϯε࡞ ετϨʔδαΠζɺ(J#Ҏ্Λࢦఆ
!38 AWSʗεΩϟφΠϯελϯε࡞ ҙͷλάΛ༩
!39 AWSʗεΩϟφΠϯελϯε࡞ ΠϯόϯυτϥϑΟοΫͳ͠ ʢεΩϟφΠϯελϯεϩάΠϯߦΘͳ͍ʣ
!40 AWSʗεΩϟφΠϯελϯε࡞ ࢦఆͨ͠Λ֬ೝͯ͠ΠϯελϯεΛ࡞
!41 AWSʗεΩϟφΠϯελϯε࡞ ΩʔϖΞෆཁ
!42 AWSʗεΩϟφΠϯελϯε࡞ εΩϟφΠϯελϯε࡞ྃʂʂ
5FOBCMFJPίϯιʔϧ εΩϟϯ࡞
!44 Tenable.ioʗεΩϟϯ࡞ εΩϟφ Πϯελϯε ͕ೝࣝ͞Εͨ͜ͱΛ֬ೝ
Tenable.ioʗεΩϟϯ࡞ !45 ʮ/FX4DBOʯΛΫϦοΫ
!46 Tenable.ioʗεΩϟϯ࡞ εΩϟϯςϯϓϨʔτΛબ
!47 Tenable.ioʗεΩϟϯ࡞
!48 AWSʗεΩϟφΠϯελϯε࡞ /BNF ࡞͢ΔεΩϟϯ໊ 'PMEFS εΩϟϯ݁Ռͷ֨ೲϑΥϧμ 4DBOOFS εΩϟϯ࣌ʹར༻͢ΔεΩϟφ
!49 Tenable.ioʗεΩϟϯ࡞ λʔήοταʔόʢεΩϟϯରʣΛબ
!50 Tenable.ioʗεΩϟϯ࡞ $SFEFOUJBMTઃఆ
!51 Tenable.ioʗεΩϟϯ࡞ &$ͷೝূใΛೖྗ
!52 Tenable.ioʗεΩϟϯ࡞ &$εΩϟφΛར༻ͨ͠ɺεΩϟϯ͕
εΩϟϯ࣮ࢪʗ ݕग़ͨ͠ڴҖΛੋਖ਼
!54 λʔήοταʔόઃఆ εΩϟφΠϯελϯε͔ΒͷΞΫηεΛڐՄ ඞཁͳϓϩτίϧ5$1ɺ6%1ɺ*$.1
!55 εΩϟϯ࣮ࢪ ֘εΩϟϯͷʮ-BVODIʯͰεΩϟϯ։࢝
εΩϟϯ࣮ࢪ !56 ͰεΩϟϯ͕ྃ
εΩϟϯ݁Ռ֬ೝ
!58 εΩϟϯ݁Ռ֬ೝ "TTFUT ݕग़͞ΕͨڴҖͷ݅ɺ04ͷஅରͷใΛදࣔ 7VMOFSBCJMJUJFT $744 ڞ௨੬ऑੑධՁγεςϜ ͷʹج͖ͮϨϕϧ͚͞ΕͨڴҖΛදࣔ
$SJUJDBMɿɺ)JHIɿະຬɺ.FEJVNɿະຬɺ-PXɿະຬ 3FNFEJBUJPOT ݕग़͞ΕͨڴҖʹର͢Δੋਖ਼ํ๏ΛҰཡදࣔ )JTUPSZ εΩϟϯཤྺΛදࣔ
εΩϟϯ݁Ռ֬ೝʗAssets !59
εΩϟϯ݁Ռ֬ೝʗVulnerabilities !60
εΩϟϯ݁Ռ֬ೝʗRemediations !61
εΩϟϯ݁Ռ֬ೝʗHistory !62
ݕग़ͨ͠ڴҖΛੋਖ਼
ݕग़ͨ͠ڴҖΛੋਖ਼ !64 "NB[PO-JOVY".*DVSM "-"4 Λ֬ೝ
!65 ݕग़ͨ͠ڴҖΛੋਖ਼
!66 DVSMʹ͓͚ΔόοϑΝΤϥʔͷ੬ऑੑ ݕग़ͨ͠ڴҖΛੋਖ਼
!67 ੋਖ਼ํ๏ɺؔ࿈߲දࣔ ݕग़ͨ͠ڴҖΛੋਖ਼
!68 TVEPZVNVQEBUFDVSM ಡΈࠐΜͩϓϥάΠϯQSJPSJUJFT VQEBUFNPUE VQHSBEFIFMQFS BN[ONBJOcL# BN[OVQEBUFTcL# ґଘੑͷղܾΛ͍ͯ͠·͢ τϥϯβΫγϣϯͷ֬ೝΛ࣮ߦ͍ͯ͠·͢ɻ ʢলུʣ
ྃ͠·ͨ͠ ڴҖΛݕग़ͨ͠λʔήοταʔόͰίϚϯυ࣮ߦ ݕग़ͨ͠ڴҖΛੋਖ਼
!69 ࠶εΩϟϯͰڴҖͷ݅ݮগΛ֬ೝ ݕग़ͨ͠ڴҖΛੋਖ਼
!70 3FNFEJBUJPOTͷ"DUJPOΛ࣮ࢪͯ͠ੋਖ਼͕Մೳ ݕग़ͨ͠ڴҖΛੋਖ਼
!71 3FNFEJBUJPOTͷ"DUJPOΛ࣮ߦ͍ͯ͘͠ͱɽɽ TVEPZVNVQEBUFLFSOFM ಡΈࠐΜͩϓϥάΠϯQSJPSJUJFT VQEBUFNPUE VQHSBEFIFMQFS BN[ONBJOcL# BN[OVQEBUFTcL# ґଘੑͷղܾΛ͍ͯ͠·͢ τϥϯβΫγϣϯͷ֬ೝΛ࣮ߦ͍ͯ͠·͢ɻ
ɾ ɾ ݕग़ͨ͠ڴҖΛੋਖ਼
!72 ੬ऑੑ͕ݮ͍ͬͯ͘ʂʂ ݕग़ͨ͠ڴҖΛੋਖ਼
!73 7VMOFSBCJMJUJFTͷ4PMVUJPOɺ3FNFEJBUJPOTͷ"DUJPOΛߦ͏͜ͱͰɺ ڴҖΛੋਖ਼͢Δ͜ͱͰ͖·͕͢ɺΞϓϦέʔγϣϯͷಈ࡞Λอূ͢ ΔͷͰ͋Γ·ͤΜɻύοέʔδΞοϓσʔτͷରԠʹ͍ͭͯɺ ࣄલʹόοΫΞοϓΛऔಘ͢Δɺڥʹ͋ΘͤͯରԠ͍ͯͩ͘͠͞ɻ ݕग़ͨ͠ڴҖΛੋਖ਼
εΩϟϯ࣮ࢪύλʔϯ
εΩϟϯ࣮ࢪύλʔϯ !75 /FTTVT4DBOOFSΛߏங͢Δύλʔϯ /FTTVT"HFOUΛར༻͢Δύλʔϯ 5FOBCMFJP֎෦εΩϟφΛར༻͢Δύλʔϯ
/FTTVT"HFOUΛ ར༻͢Δύλʔϯ
Nessus Agentߏਤ !77 /FTTVT"HFOUΠϯετʔϧ
Nessus AgentΛར༻͢Δύλʔϯ !78 ϝϦοτ "HFOU͕ࣗใΛऔಘ͢ΔͷͰɺεΩϟφར༻࣌ ʹൺͯ71$ͷ/8ͷӨڹখ͘ɺੳߴ ೝূใ͕ෆཁ Ϣʔεέʔε ϞόΠϧϫʔΧʔ͕ଟ͍ϗετ ηΩϡϦςΟϙϦγʔతʹωοτϫʔΫܦ༝Ͱೝূ
ใ͕༻Ͱ͖ͳ͍߹
!79 ฐࣾϒϩάͰ͝հ͍ͯ͠·͢ Nessus AgentΛར༻͢Δύλʔϯ
5FOBCMFJP֎෦εΩϟφΛ ར༻͢Δύλʔϯ
Tenable.io֎෦εΩϟφΛར༻͢Δύλʔϯ !81 ֎෦εΩϟφΛར༻
!82 ϝϦοτ σϓϩΠෆཁʢ5FOBCMFJPʹඪ४Ͱؚ·Ε͍ͯΔʣ ະͷ"TTFUTΛಛఆͰ͖Δ Ϣʔεέʔε ڴҖͷΫΠοΫੳ ϙϦγʔతʹλʔήοταʔόͷมߋ͕Ͱ͖ͳ͍߹ ҙ "84ͷਃ͕ඞཁ Tenable.io֎෦εΩϟφΛར༻͢Δύλʔϯ
!83 ฐࣾϒϩάͰ͝հ͍ͯ͠·͢ Tenable.io֎෦εΩϟφΛར༻͢Δύλʔϯ
·ͱΊ
·ͱΊ !85 ࣄલঝೝ͞ΕͨεΩϟφΛར༻͢Εɺ ؆୯ʹ੬ऑੑஅ͕ߦ͑Δ εΩϟφΠϯελϯεͷߏங௨ৗͷ&$ ߏஙͱಉ͡खॱ εΩϟϯ࣮ࢪͷύλʔϯʹΑͬͯɺ"84 ਃ͕ඞཁͳ߹͋Δ
ؔ࿈ࢿྉ !86 5FOBCMFJPGPS"NB[PO8FC4FSWJDFT IUUQTEPDTUFOBCMFDPNPUIFS5FOBCMFJP"84*OUFHSBUJPO(VJEFQEG /FTTVT"HFOUΛར༻ͨ͠੬ऑੑஅ IUUQTEFWDMBTTNFUIPEKQDMPVEBXTUFOBCMFJPOFTTVTBHFOUCBTJDOFUXPSLTDBO
5FOBCMFJPͷ#BTJD/FUXPSL4DBOΛ࣮ࢪͯ͠Έͨ IUUQTEFWDMBTTNFUIPEKQDMPVEBXTUFOBCMFJPWVMOFSBCJMJUZNBOBHFNFOU CBTJDOFUXPSLTDBO ੬ऑੑஅ͕Ͱ͖Δ5FOBCMFJPΛ"84Ͱར༻͢Δͱ͖ͷߏΠ ϝʔδʹ͍ͭͯ·ͱΊͯΈͨ IUUQTEFWDMBTTNFUIPEKQDMPVEBXTUFOBCMF@BSDIJUFDU@PO@BXT
!87