Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
5min GuardDuty Extended Threat Detection EKS
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
takakuni
June 30, 2025
Technology
400
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
5min GuardDuty Extended Threat Detection EKS
takakuni
June 30, 2025
More Decks by takakuni
See All by takakuni
ECS Express Mode
takakuni
0
40
AWS WAF Anti-DDoS Protection in 5 Minutes!
takakuni
0
660
AWS Backup Air-Gapped Vaults with Multi-Party Approval Explained in 5 Minutes!
takakuni
0
340
OpenAI models overview 202505
takakuni
0
470
[Sample] Validate hyperlink for Amazon Bedrock Data Automation
takakuni
0
330
Classmethod AI Talks #13
takakuni
0
460
About Extended Threat Detection in Amazon GuardDuty
takakuni
0
440
SageMaker Hyperpod 101 #regrowth_sapporo
takakuni
1
460
What is Amazon Bedrock knowledge base with an Amazon Kendra GenAI index?
takakuni
0
820
Other Decks in Technology
See All in Technology
『三匹の子ぶた』から学ぶネットワークセキュリティの昔と今 / Network Security: Then and Now Through the Lens of The Three Little Pigs
nttcom
1
6.1k
AI-DLC実践録_フルサイクル開発への挑戦
miyuc
0
110
社内の7割が使うデータ基盤を、 データチーム2人で回すためにやったこと
koh_yoshi
4
1.4k
会社紹介資料 / Sansan Company Profile
sansan33
PRO
24
430k
生成 AI の基礎 〜 サンプル実装で学ぶ基本原理
enakai00
7
4.4k
【CEDEC2026】『ウマ娘 プリティーダービー』 英語版のキャラクターの方言や口調をローカライズするための創造的アプローチ
cygames
PRO
2
990
認知負荷をGemini で溶かす — GKE 基盤「Orbit」における AI エージェントの実践
sansantech
PRO
1
300
同じWAFが、攻撃の“形”は弾く── 正当な“形”の不正は通す
kuroneko13
0
200
【Google Cloud Next Tokyo'26】Gemini Enterprise と Oracle AI Database で実現する、業務データ活用を実現する AI エージェント実装
shisyu_gaku
0
250
Software Supply Chain Attackからクラウド環境を守るためにできること
lhazy
2
260
【CEDEC2026】次世代デジタルカードゲームのサーバー設計と運用 〜『Shadowverse: Worlds Beyond』の舞台裏~
cygames
PRO
1
1.3k
制約理論(ToC)入門 2026版
recruitengineers
PRO
8
2.3k
Featured
See All Featured
Tell your own story through comics
letsgokoyo
1
1k
Building the Perfect Custom Keyboard
takai
2
840
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
520
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
133
19k
Are puppies a ranking factor?
jonoalderson
1
3.8k
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
230
The Curse of the Amulet
leimatthew05
2
14k
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
Mind Mapping
helmedeiros
PRO
1
310
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
1
2.3k
We Are The Robots
honzajavorek
0
300
Transcript
5分でわかる!GuardDuty 拡張脅威検出 EKS 編
2 • 部署 ◦ クラウド事業本部コンサルティング部 • 名前(ニックネーム) ◦ たかくに •
ロール ◦ ソリューションアーキテクト ⾃⼰紹介
re:Inforce 2025 どうでしたか?
GuardDuty でしたね。
Extended Threat Detection の話をします。
Extended Threat Detection とは
拡張脅威検出 です!
拡張脅威検出とは
拡張された脅威を検出する機能!
10 今までの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types
11 これからの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types 10. GuardDuty attack sequence finding types(NEW !)
• 複数の脅威が連なった状態を検出 • 普段の検出タイプに加え、弱いシグナルも評価対象 ◦ 弱いシグナル:普段の検出タイプでは表⽰されな い API アクティビティ •
MITRE ATT&CK のステップ別に重要度を表⽰ 12 GuardDuty attack sequence finding types
• Attack sequence ◦ 複数のイベント(シグナル)の相関関係 • Findings ◦ GuardDuty が発⾒した脅威(≒シグナル)
• Signals ◦ GuardDuty が観察した API アクティビティ 13 単語のおさらい
14 図にすると
ここからアップデートの紹介です
• AttackSequence:IAM/CompromisedCredentials ◦ IAM が侵害されている可能性が⾼い場合に検出 • AttackSequence:S3/CompromisedData ◦ S3 が漏洩している可能性が⾼い場合に検出
• AttackSequence:EKS/CompromisedCluster(NEW) ◦ Amazon EKS クラスター内で⼀連の疑わしいアクショ ンがあった場合に検出される 16 GuardDuty attack sequence finding types
17 複数の脅威が連なった状態を検出
18 MITRE ATT&CK のステップ別に重要度を表⽰
• EKS audit log events • AWS CloudTrail data events
for S3 • AWS CloudTrail management events • VPC Flow Logs • Route53 Resolver DNS query logs • Amazon EKS malware detection for Amazon EC2 • Runtime Monitoring for Amazon EKS 19 参照するソース
20 ログを有効化しておく必要があるのか...? https://aws.amazon.com/jp/guardduty/faqs/
以下のどちらかを有効にしておくこと • EKS Protection • EKS Runtime Monitoring 最⼤限活⽤したい場合は、どちらも有効が推奨 21
前提条件
• 拡張脅威検出は⼀連の脅威を連なった形で検出する脅威タイプ ◦ 今回新たに EKS クラスターの脅威タイプが加わった • 複数のデータソースから脅威を検出 ◦ ⼀部のデータソースはユーザー側の設定がなくとも、
GuardDuty 側で独⽴して収集してくれる • EKS Protection または Runtime Monitoring for Amazon EKS のど ちらも有効化して最⼤限機能を活かしましょう! 22 まとめ
None