2020年8月14日に開催されたFin-JAWS 第14回 Fin人類育成計画の登壇資料
AWS認定セキュリティ - 専門知識の説明をしつつ、AWSのセキュリティサービスを使って、どのようにAWSアカウントのセキュリティを守っていくかの解説
"84ೝఆηΩϡϦςΟઐࣝ"84ͷαʔϏεΛָͬͯͯ͠ηΩϡϦςΟ্ʂʂ/3*ωοτίϜגࣜձࣾɹࠤʑ'JO+"84ୈճ'JOਓྨҭܭը#finjaws
View Slide
ࠤʑCMPHIUUQTCMPHUBLVSPTOFU5XJUUFS!ELGKࣗݾհ#finjaws
+BQBO"1/"NCBTTBEPSબग़͞Ε·ͨࣗ͠ݾհ#finjaws
ೝఆηΩϡϦςΟࢼݧͷରࡦຊ#finjawsཁཧ͔Β߈ུ͢Δʰ"84ೝఆηΩϡϦςΟઐࣝʱIUUQTBN[OUP1,4D("84ೝఆηΩϡϦςΟઐࣝͷษڧͷํͱ"84ͷηΩϡϦςΟͷΨΠυϒοΫͱͯࣥ͠චʢͨͭ͠Γʣ
ࠓ͢༰"84ͷηΩϡϦςΟͷߟ͑ํͱೝఆࢼݧ"84ʹ͓͚Δ̏ͭͷηΩϡϦςΟͷ࣠ηΩϡϦςΟΛҡ࣋͢ΔͨΊͷ"84αʔϏε#finjaws
ຊͷΰʔϧ"84ͷηΩϡϦςΟͬͯɺ͜͏͍͏͜ͱΔΜͩΑͱಉ྅ʹͤΔΑ͏ʹͳΔ㱺ਓʹઆ໌͢Δͷ͕ɺཧղͷૣಓʂʂ#finjaws*".ϕετϓϥΫςΟεʹ͍ͭͯϏσΦͰઆ໌͢Δ*".ͰͷηΩϡϦςΟͷϕετϓϥΫςΟεIUUQTEPDTBXTBNB[[email protected]*".MBUFTU6TFS(VJEFCFTUQSBDUJDFTIUNM
"84ͷηΩϡϦςΟͱೝఆࢼݧ
"84ೝఆηΩϡϦςΟɹઐࣝιϦϡʔγϣϯΞʔΩςΫτͱͷҧ͍#finjawsιϦϡʔγϣϯΞʔΩςΫτηΩϡϦςΟઐࣝͲͷΑ͏ʹ࡞Δͷ͔ʁͲͷΑ͏ʹ҆શΛ֬อ͢Δͷ͔ʁ
ࢼݧൣғͱ#finjaws߲൪ ׂ߹ ΠϯγσϯτରԠ ϩάͱࢹ ΠϯϑϥετϥΫνϟͷηΩϡϦςΟ *%͓ΑͼΞΫηεཧ σʔλอޢ ॏ߲
"84ͱηΩϡϦςΟ͍Ζ͍ΖΔ͜ͱ͕ଟͯ͘ɺ͍͜͠ͱࢥͬͨ͜ͱ͋Γ·ͤΜ͔શମ૾ΛѲ͢ΔͨΊʹɺͬ͘͟Γͱྨͯ͠Έ·͠ΐ͏#finjaws
ਓੜɺָͯ͠ͳΜ΅#finjaws
ڊਓͷݞͷ্ʹཱͭҰ͔Βશ෦ࣗͰߟ͑ΔͱେมϑϨʔϜϫʔΫʹͬͯɺ࠷খݶͷ࿑ྗͰ·ͣఆੴΛ֮͑ͯɺਅࣅΔ͜ͱ͔Β࢝ΊΔ#finjaws
/*45αΠόʔηΩϡϦςΟϑϨʔϜϫʔΫྨ ΧςΰϦʔಛఆʢ*EFOUJGZʣɾࢿ࢈ཧɾϏδωεڥɾΨόφϯεɾϦεΫΞηεϝϯτɺϦεΫΞηεϝϯτཧɾαϓϥΠνΣʔϯϦεΫϚωδϝϯτޚʢ1SPUFDUʣɾΞΫηε੍ޚɾҙ্͓ࣝΑͼτϨʔχϯάɾσʔληΩϡϦςΟɾใΛอޢ͢ΔͨΊͷϓϩηε͓Αͼखॱɾอकɾอޢٕज़ݕʢ%FUFDUʣɾҟৗͱΠϕϯτɾηΩϡϦςΟͷܧଓతͳϞχλϦϯάɾݕϓϩηεରԠʢ3FTQPOEʣɾରԠܭըͷ࡞ɾίϛϡχέʔγϣϯɾੳɾݮ෮چʢ3FDPWFSʣɾ෮چܭըͷ࡞ɾվળɾίϛχέʔγϣϯIPA CSFίΞhttps://www.ipa.go.jp/files/000071204.pdf
"848FMM"SDIJUFDUFEϑϨʔϜϫʔΫப ઃܭݪଇӡ༻্ͷ༏लੑɾӡ༻Λίʔυͱͯ͠ӡ༻ɾఆظతʹɺখنͳɺݩʹ͢͜ͱ͕Ͱ͖ΔมߋΛద༻͢Δɾӡ༻खॱΛఆظతʹվળ͢ΔɾোΛ༧͢Δɾ͋ΒΏΔӡ༻্ͷো͔ΒֶͿηΩϡϦςΟɾڧݻͳೝূج൫ͷ࣮ɾτϨαϏϦςΟʔͷ࣮ݱɾશϨΠϠʔͷηΩϡϦςΟͷద༻ɾηΩϡϦςΟͷϕετϓϥΫςΟεͷࣗಈԽɾૹத͓ΑͼอதͷσʔλอޢɾσʔλʹਓͷखΛೖΕͳ͍ɾηΩϡϦςΟΠϕϯτͷඋ͑৴པੑɾো͔Βࣗಈతʹ෮چ͢Δɾ෮چखॱΛςετ͢Δɾਫฏํʹεέʔϧͯ͠ू߹తͳϫʔΫϩʔυͷՄ༻ੑΛߴΊΔɾΩϟύγςΟʔΛײʹཔΒͳ͍ɾࣗಈԽͰมߋΛཧ͢ΔύϑΥʔϚϯεޮɾߴͳςΫϊϩδʔΛ୭Ͱ͑ΔΑ͏ʹ͢Δɾ͢Ͱάϩʔόϧʹల։͢ΔɾαʔόʔϨεΞʔΩςΫνϟΛ༷͢ΔɾΑΓසൟʹ࣮ݧ͢ΔɾϝΧχΧϧγϯύγʔΛߟྀ͢Δίετ࠷దԽɾΫϥυͷࡒཧͷӡ༻ɾফඅϞσϧΛಋೖ͢ΔɾશମతͳޮΛଌఆ͢Δɾඅ༻Λੳ͠ɺؼ݁ͤ͞ΔAWS Well-Architented ϑϨʔϜϫʔΫhttps://aws.amazon.com/jp/architecture/well-architected/
ϑϨʔϜϫʔΫʹԊͬͯઃܭ͞Ε͍ͯΔ͔Λߟ͑Δ
ϑϨʔϜϫʔΫʹͯΊͯΈΔͱʁLambdaSystems Manager AutomationCloudFormationOrganizations SCPIAMSNSConfigCloudWatchInspectorMacieGuardDutyShieldFirewall ManagerWAFVPC༧ ޚ ݕ ରԠ ෮چ௨ࣗಈԽLambdaCloudWatchௐࠪCloudWatchCloudTrail౷߹Security Hub#finjaws
ΞʔΩςΫνϟʔผʹݟͯΈΔͱShieldWAFCloudFrontELB߈ܸରࡦ ରϦιʔεNACLSecurityGroupωοτϫʔΫޚ ରϦιʔεELB EC2RDSKMSσʔλอޢ ରϦιʔεEC2RDSS3%%P4߈ܸΞϓϦέʔγϣϯ߈ܸෆਖ਼ωοτϫʔΫΞΫηεෆਖ਼ɹσʔλΞΫηεInspectorSystemsManagerαʔόʔཧSecurity Hub CloudTrail CloudWatchGuardDuty Config VPCFlow logsՄࢹԽɾϞχλϦϯά௨௨SNS௨ӡ༻୲ࢹɾશϨΠϠʔͷηΩϡϦςΟͷద༻ɾτϨαϏϦςΟʔͷ࣮ݱ
γεςϜͷϨΠϠʔผʹͯΊΔͱ#finjawsϚωδϝϯτίϯιʔϧ71$Ծઐ༗ྖҬ&$04ྖҬϩʔΧϧσΟεΫ3%4σʔλϕʔε4ετϨʔδ$MPVE8BUDIࢹ%JSFDU$POOFDU/8ηΩϡϦςΟͷରԠྫʢޚʣݕͷରԠྫ(VBSE%VUZ$POUSPM5PXFS4FDVSJUZ)VC'JSFXBMM.BOBHFS.BDJF5SVTUFE"EWJTPSɾ"84ΞΧϯτɿར༻੍ݶɾ*".Ϣʔβɿૢ࡞ݖݶͱଓݩ੍ݶɹར༻ՄೳϦιʔεʹର͢ΔΞΫηείϯτϩʔϧɺଟཁૉೝূͷಋೖɾຊ൪ڥɺ։ൃڥͱ͍ͬͨڥ୯ҐͰ71$ͷɾαϒωοτ୯ҐͰͷ௨৴੍ޚɺϧʔςΟϯάઃఆɾ71$ϑϩʔϩάͷऔಘɾ4FDVSJUZ(SPVQʹΑΔαʔόؒ௨৴੍ޚɾ4ZTUFNT.BOBHFSΛར༻ͯ͠ͷɺαʔόঢ়ଶͷѲͱҰׅύονͯɾαʔόͷϩάΠϯཧͷΈͱɺϩάूͷΈͷಋೖɾ҉߸ԽΦϓγϣϯʹΑΔσΟεΫશମͷ҉߸Խ$MPVE5SBJMʹΑΔ"84ૢ࡞ཤྺτϥϑΟοΫϩά֤छΞϓϦέʔγϣϯϩά04ϩάΠϯཤྺ%#ࠪϩά"84αʔϏε֤छʹΑΔϩάɾΞϥʔτݕࠪ͢Δ͖ϩάɾઐ༻ઢʢ%9ʣ71/Λར༻ͨ͠ܦ࿏҆શͷ֬อɾ5SBOTJU(BUFXBZΛར༻ͨ͠71$ɾܦ࿏ͷཧɾܦ࿏ͷԽʹΑΔࣄۀܧଓੑͷ֬อɾDBMSͷػೳʹΑΔςʔϒϧશମʢදྖҬʣͷ҉߸ԽɾDBʹର͢ΔΞΫηεݖݶͷཧɾ҉߸ԽΦϓγϣϯʹΑΔετϨʔδશମͷ҉߸ԽɾΫϥΠΞϯταΠυ҉߸ԽΩʔʹΑΓσʔλΛอޢɾCloudWatchʹΑΔAWSͷࢹͱɺӡ༻ࢹιϑτΣΞΛར༻ͨ͠αʔϏεɺΞϓϦέʔγϣϯࢹͷซ༻*OTQFDUPS"84ͷར༻ঢ়گͷࠪ"84ΞΧϯτͷઃఆͱΨόφϯεηΩϡϦςΟʔΞϥʔτͷूͱݕɾରԠ"84ͷෆਖ਼ར༻ͷݕ04ɺΞϓϦͷηΩϡϦςΟධՁ'JSFXBMMͷҰݩཧͱݕɾରԠ4ͷػີใͷݕग़ɺྨɺอޢ0SHBOJ[BUJPOT
༧త౷੍ͱൃݟత౷੍ #finjawsηΩϡϦςΟͷϕετϓϥΫςΟεͷҰͭ0SHBOJ[BUJPO6OJUAutomationAWS Systems ManagerAWS ConfigRuleઃఆෆඋΛݕम෮ࢦࣔ༧త౷੍ൃݟత౷੍SCPAWS OrganizationsSCPΛར༻ͯ͠ΞΧϯτશମʹېࢭࣄ߲ͷઃఆAWSΞΧϯτIAM UserྫʣSPPUϢʔβʔͷΞΫηεΩʔͷ࡞Λېࢭ͢Δྫʣ*".Ϣʔβʔͷ.'"͕༗ޮʹͳ͍ͬͯΔ͔νΣοΫ͢ΔҰ࣌తʹIAMϢʔβʔͷແޮԽ
͜ͷลΛҙࣝ͠ͳ͕ΒઃఆΛࣗͰΔͱഒཧղ͕ਐΉ
͏গ͠ղΓ͘͢͢ΔͨΊʹ"84্ͷγεςϜΛղ
"84ͱηΩϡϦςΟ"84ͷηΩϡϦςΟ̏ͭͷ࣠Ͱߟ͑Δᶃ"84ʹߏஙͨ͠ωοτϫʔΫͱαʔόʔͷηΩϡϦςΟᶄ"84ૢ࡞ʹؔ͢Δݖݶʢ*".ʣᶅηΩϡϦςΟΛҡ࣋ཧ͢ΔͨΊͷ"84αʔϏεAWS ManagementConsoleRoleVPCAWS CloudSubnetInternet gatewayAmazon Simple StorageService (S3)VPN gatewayEndpointsUserૢ࡞ݖݶInstance Instance InstanceAWS LambdaRoleᶄᶃAWS Command LineInterfaceAWS Config AWS Systems ManagerAWS Service Catalog AWS Trusted Advisor AWS CloudTrailᶅηΩϡϦςΟΛҡ࣋ཧ͢ΔαʔϏε#finjaws
ᶃ"84ʹߏஙͨ͠ωοτϫʔΫͱαʔόʔͷηΩϡϦςΟڞ༗Ϟσϧͷͷ෦ઃܭͷߟ͑ํΦϯϓϨͱେ͖͘ҧΘͳ͍͕ɺઃఆͷํ"84ͷྲّྀʹै͏ඞཁ͕͋ΔIUUQTBXTBNB[PODPNKQDPNQMJBODFTIBSFESFTQPOTJCJMJUZNPEFM#finjaws
ᶄ"84ͷૢ࡞ʹؔ͢Δݖݶʢ*".ʣ"84ͷηΩϡϦςΟͷத֩ͷҰͭͲΜͳʹωοτϫʔΫαʔόʔͷηΩϡϦςΟΛڧݻʹ͍ͯͯ͠ɺ"84Λૢ࡞͞ΕΔͱ͕݀։͚ΒΕΔ"84ͷബ͍ຊɹ*".ͷϚχΞοΫͳIUUQTCPPUIQNKBJUFNT#finjaws
ᶅηΩϡϦςΟΛҡ࣋ཧ͢ΔɹͨΊͷ"84αʔϏε"84ಠࣗͷ෦ར༻͠ͳͯ͘γεςϜΛηΩϡΞͳঢ়ଶΛҡ࣋Ͱ͖Δ͕ɺ্ख͘׆༻͢ΔͱࣗྗͰΔΑΓഒָʹͳΔ"84ͷബ͍ຊᶘΞΧϯτηΩϡϦςΟͷϕʔγοΫηΦϦʔIUUQTCPPUIQNKBJUFNT#finjaws
ηΩϡϦςΟΛҡ࣋͢ΔͨΊͷ"84αʔϏε
ΨόφϯεͷҝͷΨʔυϨʔϧηΩϡϦςΟҰઃఆ͓ͯ͠ऴ͍Ͱͳ͍ɻڥશମʹܧଓతͳΨόφϯεΛఏڙ͢Δҝͷϧʔϧ͕ඞཁɻ"84ͦΕΛαϙʔτ͢ΔαʔϏεΛఏڙ͍ͯ͠Δᶃ༧ɹʜɹ*".4$1Ͱېࢭࣄ߲ͷૢ࡞ࣄ߲Λग़དྷͳ͘͢Δ͜ͱᶄݕɹʜɹېࢭࣄ߲ͷૢ࡞͕͞ΕͨΒؾ͕͚Δঢ়ଶʹ͢Δ͜ͱΨʔυϨʔϧؔॴ#finjaws
$MPVE5SBJMAWS ManagementConsoleUserAWS Command LineInterfaceAWS CloudTrailAmazon Simple StorageService (S3)Amazon CloudWatch"84Ϧιʔεͷૢ࡞ཤྺΛهɾ௨ᶃϚωδϝϯτίϯιʔϧͱ"1*ͷૢ࡞ཤྺΛ4ʹอଘᶄ$MPVE8BUDI-PHTΛར༻ͯ͠4/4ܦ༝Ͱ௨ՄೳAWSϦιʔε#finjaws
$POpHఆˍΠϕϯτൃੜ࣌ʹ"84ͷঢ়ଶΛهᶃ"84ͷঢ়ଶΛه͠ཧ͢ΔαʔϏεᶄ$POpH3VMFTΛར༻͢Δ͜ͱʹΑΓɺ͋Δ͖ঢ়ଶ͔Β֎Εͨ͜ͱΛݕ͢Δ͜ͱ͕Ͱ͖ΔAWS ConfigUserAWSϦιʔεͷߏมߋߏཧɾهͷอଘมߋޙͷߏͷධՁʢConfig RulesʣAmazon SimpleNotification Service#finjaws
(VBSE%VUZڴҖͷݕग़ᶃηΩϡϦςΟ؍͔ΒͷڴҖϦεΫΛݕग़ᶄϩάσʔλʢ71$'MPX-PHT $MPVE5SBJM&WFOU-PHT %/4-PHTʣΛੳᶅڴҖΛ"*ʹΑΓΠϯςϦδΣϯεʹݕग़ѱҙͷ͋ΔεΩϟϯΠϯελϯεͷڴҖΞΧϯτͷڴҖAmazon GuardDutyFlow logsEvent LogsDNS LogsϩάڴҖͷஅAmazon SimpleNotification ServiceAmazon CloudWatchEvents௨#finjaws
4FDVSJUZ)VChttps://aws.amazon.com/jp/security-hub/ηΩϡϦςΟΞϥʔτΛҰݩཧᶃ(VBSE%VUZ .BDJF *OTQFDUPSͷΞϥʔτΛ౷߹ͯ͠ཧᶄ֤छϩάΛݩʹίϯϓϥΠΞϯενΣοΫᶅαʔυύʔςΟπʔϧͱͷ࿈ܞɾෳ"84ΞΧϯτͷ౷߹Մೳ#finjaws
5SVTUFE"EWJTPS"84ͷར༻ঢ়گΛධՁᶃ̑ͭͷ؍ʢίετ࠷దԽɾύϑΥʔϚϯεɾηΩϡϦςΟɾϑΥʔϧττϨϥϯεɾαʔϏε੍ݶʣͰධՁᶄσϑΥϧτͰద༻͞Ε͍ͯΔͷͰɺҰݟͯΈΔ͜ͱᶅ௨ʢ&ϝʔϧͷΈʣՄೳ#finjaws
$POUSPM5PXFShttps://aws.amazon.com/jp/controltower/ෳΞΧϯτͷηΩϡϦςΟઃఆͱࢹᶃ"84ͷϕετϓϥΫςΟεΛΓࠐΜͩઃఆͰɺ"84ΞΧϯτͷߏஙᶄΞΧϯτͷϙϦγʔΛܧଓతʹཧͱՄࢹԽᶅطଘͷΞΧϯτΛ$POUSPM5PXFSʹొ͢Δͷා͍#finjaws
ϕετϓϥΫςΟεᶃదͳݖݶཧ͕࠷ॏཁʢ*".ͱ4$1ʣᶄ"84ͷαʔϏεΛͬͯݕͷػೳΛΓࠐΉᶅߏஙςϯϓϨʔτԽɻϚϧνΞΧϯτͰ͋Εɺ$MPVE'PSNBUJPO4UBDL4FUT0SHBOJ[BUJPOT͕ਆ#finjaws$MPVE'PSNBUJPO4UBDL4FUT0SHBOJ[BUJPOTͷνϡʔτϦΞϧIUUQTCPPUIQNKBJUFNT
ͪΐͬͱએ#finjawsࣗͰ͖ΔΑ͏ʹͳΔ·Ͱɺͯ͠Β͏ͷ͋Γʂʁ/3*ωοτίϜɹ"84ΞΧϯτɹηΩϡϦςΟରࡦࢧԉαʔϏεIUUQTXXXOSJOFUDPNQSPEVDUTBXTBDDPVOUTFD
ηΩϡϦςΟ"*ͷྖҬʹ#finjaws߈ܸଆɺ࣌ؒ΄΅શࣗಈͰ߈ܸޚଆʢ͋ͳͨʣɺͦΕΛਓྗͰकΕ·͔͢ʁAWS Cloud͋ͳͨͷγεςϜޚଆɺࣗಈతͳޚ͕ඞ༻ݸʑͷஅ"*ʹͤͳ͍ͱແཧͳྖҬʹ࣌ؒλʔήοτΛ୳ͯ͠߈ܸ
·ͱΊ
ࠓͨ͠ςʔϚ"84ͷηΩϡϦςΟͷߟ͑ํͱೝఆࢼݧ"84ʹ͓͚Δ̏ͭͷηΩϡϦςΟͷ࣠ηΩϡϦςΟΛҡ࣋͢ΔͨΊͷ"84αʔϏε#finjaws