ãŸããã
cloudpack æšæïŒå¯ïŒã§ãã
æ¬èšäºã¯AWS ã¢ã¯ã»ã¹ããŒæŒæŽ©ã«ã€ããŠæ¡å ãããŠããã ããŸãã
ïŒAWS ã¢ã¯ã»ã¹ããŒïŒ
ã¢ã¯ã»ã¹ããŒã¯ãIAM ãŠãŒã¶ãŒãŸã㯠AWS ã¢ã«ãŠã³ãã®ã«ãŒããŠãŒã¶ãŒ ã®é·æçãªèªèšŒæ å ±ã§ãã
ã»IAM ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã管çããã
ïŒAWS ã¢ã¯ã»ã¹ããŒ æŒæŽ©åé¡ïŒ
ã¢ã¯ã»ã¹ããŒãæŒæŽ©ããŠãããšAWSãã以äžã®ãããªä»¶åã®ã¢ã©ãŒãã¡ãŒã«ãéä»ãããŸãã
ç·æ¥æ§ã¯é«ãæ©æ¥ãªå¯Ÿå¿ãšå¯Ÿçã宿œããå¿
èŠããããŸãã
ã»Irregular Activity Detected for Your AWS Access Key for Account AWS Account
ã»Your AWS Access Key is Exposed for AWS Account
ã»Unexpected Activity Detected on your AWS Account AWS Account
ã»Your AWS account is compromised
ã¢ã¯ã»ã¹ããŒãæŒæŽ©ãããšæªæããè
ãAWSã¢ã«ãŠã³ãã«äŸµå
¥ããAWSãµãŒãã¹ãäžæ£äœ¿çšããŠå€é¡ã®è²»çšãæ¯æãããšã«ãªã£ãããæ©å¯æ
å ±ãçãŸãããªã©é倧ãªã»ãã¥ãªãã£ã€ã³ã·ãã³ããçºçããæãããããŸãã
å®éã«å€æ°ã®äºæ¡ãçºçããŠãããŸãã
è¿å¹Žãã¢ã¯ã»ã¹ããŒæŒæŽ©ãå¢å ããŠãããŸãã®ã§æ¬èšäºãã圹ã«ç«ã¡ãŸããšå¹žãã§ãã
âŸïžåå
ã¢ã¯ã»ã¹ããŒãæŒæŽ©ããåå ã§ããæ§ã
ãªèŠå ããããŸãã
以äžå
容ãå
šãŠã§ã¯ããããŸãããåèã«ãªããŸããã幞ãã§ãã
ããœãŒã¹ã³ãŒããšããŒãžã§ã³ç®¡çã·ã¹ãã ããã®æŒæŽ©ã
âå
¬éãªããžããªã«èª€ã£ãŠã³ãããããïŒçºçé »åºŠãé«ãã§ãïŒ
ã¢ã¯ã»ã¹ããŒãå«ããœãŒã¹ã³ãŒããGitHubã®ãããªå
¬éããŒãžã§ã³ç®¡çã·ã¹ãã ã«èª€ã£ãŠããã·ã¥ããŠããŸãã
ãã¡ãã¯æªæãããããã«ãã£ãŠåžžæã¹ãã£ã³ãããŠãããã¢ã¯ã»ã¹ããŒãããã·ã¥ãããŠããæ°ååã§æªçšãããã±ãŒã¹ãããããã§ãã
âèšå®ãã¡ã€ã«ããœãŒã¹ã³ãŒãã«ã¢ã¯ã»ã¹ããŒãçŽæ¥èšèŒããã
AMIãECSã®ã³ã³ããã€ã¡ãŒãžã«çŽæ¥ã¢ã¯ã»ã¹ããŒãèšèŒããŠããã
Terraformçã®ãµãŒãããŒãã£ããŒã«ã«çŽæ¥ã¢ã¯ã»ã¹ããŒãèšèŒããŠããã
äŸãäžæçã§ãã£ãŠããããå®è¡ããããšã§ãã°ãä¿åããããã®ãã°ãæŒæŽ©ã®å
ã«ãªãå¯èœæ§ããããŸãã
ããŠãŒã¶ãŒç°å¢ã®ã»ãã¥ãªãã£äžåã
âããŒãã¬ãŒãã¹ãã€ãŠã§ã¢ãªã©ã®ãã«ãŠã§ã¢ã«ææããã
ãŠãŒã¶ãŒãäžå¯©ãªã¡ãŒã«ãWebãµã€ããžã¢ã¯ã»ã¹ããããšã«ããææããå¯èœæ§ããããŸãã
ãã£ãã·ã³ã°ãµã€ãã«ããIDãšãã¹ã¯ãŒããçªåãããAWSã¢ã«ãŠã³ãã«äŸµå
¥ãããã
âäžé©åãªç®¡ç
ã¢ã¯ã»ã¹ããŒã誰ã§ãèªã¿åããããã¹ããã¡ã€ã«ãä¿è·ãããŠããªãã¹ãã¬ããã·ãŒãã«ä¿åãããŠããã
ç°¡åã«æã¡åºãå¯èœãªç¶æ
ã«ããŠããã
ã¡ãŒã«ãã¢ããªãªã©ã§ã¢ã¯ã»ã¹ããŒãå
±æããŠããã
éè·è
ã¢ã«ãŠã³ããåé€ããŠãããæªçšãããã
ãAWS S3ãã±ããããã®æŒæŽ©ã
âS3ãã±ããã®ãããªãã¯èšå®ã®åé¡
âS3ãã±ããACL (Access Control List)ã®èšå®ããACL æå¹ããšãªã£ãŠãããé©åãªACLã§ãªãã
ãã¡ããæªæãããŠãŒã¶ãŒããããã«ãã£ãŠçãããŠããŸãã
AWS S3ãã±ããã®ãããªãã¯ã¢ã¯ã»ã¹èšå®ã誰ã§ãã¢ã¯ã»ã¹ã§ããç¶æ
ã§ãããã¢ã¯ã»ã¹ããŒãå«ãŸãããã°ãèšå®ãã¡ã€ã«ããããšæ
å ±ãæŒæŽ©ããå¯èœæ§ããããŸãã
以äžã®ãããªåå ãæããããŸãã
âŸïžèª¿æ»æ¹æ³
åé ã®AWSããã®éç¥å
ã«æŒæŽ©ããŠããIAMãŠãŒã¶ãŒãšã¢ã¯ã»ã¹ããŒãèšèŒãããŠããããšããããŸããïŒAWSã«äºæãã¬ã¢ã¯ãã£ããã£ãçãããŠããããªãå ŽåããããŸãïŒ
Githubãªã©ã§ãªã³ã©ã€ã³å
¬éãããŠããå Žåã¯ãã®URLãèšèŒãããŠããããšããããŸãã
ãã®ããã該åœIAMãŠãŒã¶ãŒãšã¢ã¯ã»ã¹ããŒãURLããã©ã®ããã«æŒæŽ©ããã調æ»ããŠãã ããã
ããããªãããªã³ã©ã€ã³å
¬éãããŠããªãå Žåã¯æŒæŽ©ããŠããIAMãŠãŒã¶ãŒãšã¢ã¯ã»ã¹ããŒã®ã¿ããããç¶æ
ã§ããïŒäºæãã¬ã¢ã¯ãã£ããã£ãçãããŠããå Žåã¯äžå¯©ãªãªãœãŒã¹ããªãã確èªããŠãã ããïŒ
ãã¡ãã®èª¿æ»ã¯æŒæŽ©ããIAMãŠãŒã¶ãŒã®çšéãå©çšè
ã«ç¢ºèªããŠã©ã®ãããªèšå®ïŒã¢ã¯ã»ã¹ããŒãã³ãŒãã«çŽæ¥å
¥åãããïŒãå
±æïŒèª°ãã«æž¡ãããïŒãä¿åæ¹æ³ïŒS3ã誰ã§ãé²èЧã§ãããã¡ã€ã«ã«ä¿åããŠããªããïŒãªã©ã確èªããŠããã ãããšã«ãªããŸãã
äžèšã®åå ãåèã«èª¿æ»ããŠãã ããã
âŸïžå¯Ÿå¿æ¹æ³
å®éã«ã¢ã¯ã»ã¹ããŒãæŒæŽ©ããŠAWSããéç¥ãéä»ããããšä»¥äžã®ãããªå¯Ÿå¿æ¹æ³ãèšèŒãããŠããŸãã
â»ä»¥äžã¯åèã§ããå®éã®éç¥å
容ãšã¯ç°ãªããŸãã
ïŒ1ïŒ
ã¢ã¯ã»ã¹ããŒãæŒæŽ©ããŠãããšãããIAMãŠãŒã¶ãŒã«ãAWSCompromisedKeyQuarantineV2ãã®IAMããªã·ãŒãä»äžãããŠããããšã確èªããŠãã ããã
ããã¯AWSåŽãæ©èœãæå¶ããããã«ä»äžãããã®ã«ãªããŸãã
ãã®ããªã·ãŒã®åé€ã¯åºæ¬çã«éæšå¥šã§ããåé€ãããŸãå Žåã¯ä»¥äžã®åŸç¶å¯Ÿå¿åŸã«å©çšè
æ§ã®å€æã«ãŠãé¡ãèŽããŸãã
â»ããªã·ãŒåé€ã¯ç®¡çè
æš©éãæã€ãŠãŒã¶ãŒããããã¯ãiam:DetachUserPolicyãã®ã¢ã¯ã»ã¹æš©ãæã€ãŠãŒã¶ãŒã§å¯èœã§ãã
Description: Denies access to certain actions, applied by the AWS team in the event that an IAM user's credentials have been compromised or exposed publicly. Do NOT remove this policy. Instead, please follow the instructions specified in the support case created for you regarding this event. ïŒèš³ïŒ 説æ: IAM ãŠãŒã¶ãŒã®èªèšŒæ å ±ã䟵害ãããããŸãã¯å ¬éãããå Žåã« AWS ããŒã ã«ãã£ãŠé©çšããããç¹å®ã®ã¢ã¯ã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãæåŠããŸãã ãã®ããªã·ãŒã¯åé€ããªãã§ãã ããã 代ããã«ããã®ã€ãã³ãã«é¢ããŠäœæããããµããŒãã±ãŒã¹ã«èšèŒãããŠããæé ã«åŸã£ãŠãã ããã
ã»AWSCompromisedKeyQuarantineV2
ïŒ2ïŒ
ã¢ã¯ã»ã¹ããŒã眮ãæããŠãã ããã
ã¢ã¯ã»ã¹ããŒã眮ãæããå Žåã¯ã該åœã®ã¢ã¯ã»ã¹ããŒãåé€ããåã«2ã€ç®ã®æ°ããã¢ã¯ã»ã¹ããŒãäœæããŠãã ããã
ãããŠæ°ããã¢ã¯ã»ã¹ããŒã䜿çšããããã«èšå®å€æŽããŠãã ããã
ã³ã³ãœãŒã«ã¢ã¯ã·ã§ã³ãç¡å¹åããéžæããŠè©²åœã®ã¢ã¯ã»ã¹ããŒãåé€ããã«ç¡å¹åããŠãã ããã
ãããã¢ããªã±ãŒã·ã§ã³çã«åé¡ãããå Žåã¯æŒæŽ©ããŠãã該åœã¢ã¯ã»ã¹ããŒãåå©çšã§ããŸãã
æ°ããã¢ã¯ã»ã¹ããŒã䜿çšããŠåé¡ãªããã°æŒæŽ©ããŠãã該åœã¢ã¯ã»ã¹ããŒãåé€ããŠãã ããã
åé¡ã解決ããããã«ãæçµçã«è©²åœã¢ã¯ã»ã¹ããŒã®åé€ãå¿
èŠã«ãªããŸãã
ã»ã¢ã¯ã»ã¹ããŒãæŽæ°ãã
ïŒ3ïŒ
Cloud Trailãã°ã§äžèŠãªã¢ã¯ãã£ããã£ããªãã確èªããŠãã ããã
æªæããè
ãå¥éIAMãŠãŒã¶ãŒãäœæããŠããªãããé¢é£ãããã¹ã¯ãŒãïŒãã°ã€ã³ãããã¡ã€ã«ïŒãã¢ã¯ã»ã¹ããŒãããŒã«ãäžæçãªã»ãã¥ãªãã£èªèšŒæ
å ±ãªã©ã¢ã«ãŠã³ãã«äžèŠãªã¢ã¯ãã£ããã£ããªãã確èªããŠãã ããã
ééã£ãŠå¿
èŠãªã¢ã«ãŠã³ãæ
å ±ãåé€ããªãããã«ååã«æ³šæããŠãã ããã
ïŒ4ïŒ
AWSã¢ã«ãŠã³ãã«äžèŠãªAWSå©çšããªãã確èªããŠãã ããã
åãµãŒãã¹ããŒãžã確èªããŠEC2ã€ã³ã¹ã¿ã³ã¹ãLambda颿°ãEC2ã¹ãããå
¥æãªã©äžèŠãªå©çšããªãã確èªããŠãã ããã
ãè«æ±ãšã³ã¹ã管çãã§ã確èªã§ããŸãã
äžèŠãªAWSå©çšã¯ã©ã®ãªãŒãžã§ã³ã§è¡ãããŠãããããããŸãããå¿
ãå
šãªãŒãžã§ã³ã確èªãã ããã
ïŒ5ïŒ
äžèšïŒ1ïŒ~ïŒ4ïŒãŸã§ã確èªã宿œãããAWSéç¥ã«å¯ŸããŠå¯Ÿå¿ããå
容ãèšèŒããŠè¿ä¿¡ããŠãã ããã
ã»å
šãŠã®ã¢ã¯ã»ã¹ããŒãããŒããŒã·ã§ã³ããæš
ã»äžæ£ã«èµ·åããããªãœãŒã¹ã®ç¢ºèªãšåé€ããæš
[åè]
AWS ã¢ã«ãŠã³ãã®äžæ£ãªã¢ã¯ãã£ããã£ã«æ°ä»ããå Žåãã©ãããã°ããã§ãã?
âŸïžå¯Ÿç
ïŒå¯Ÿç1ïŒ
ã¢ã¯ã»ã¹ããŒãæŒæŽ©ããªãããã«äºã察çã宿œããŠãã ããã
äžèšAWSããã¥ã¡ã³ãã«IAMå©çšã®ãã¹ããã©ã¯ãã£ã¹ãã¢ã¯ã»ã¹ããŒã®ä»£ããã«äžæçãªèªèšŒæ
å ±ãå©çšãããªã©ããæ€èšãã ããã
ã»IAM ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã管çãã
ã»IAMã«ãããã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
ã»IAM ã®äžæçãªã»ãã¥ãªãã£èªèšŒæ
å ±
ã¢ã«ãŠã³ãã«Webåãã®ãªãœãŒã¹ãŸãã¯APIããæã¡ã®å Žåã¯ãæ¢ç¥ã®äŸµå®³ã¿ã€ãããã¯ãŒã¯ããŒããä¿è·ã§ããAWS WAFã®ãå©çšããæ€èšãã ããã
ã»AWS WAFãšãã®ã³ã³ããŒãã³ãã®èšå®
ãŸããAWSãã鲿¢çãšããŠä»¥äžã®ãããªæ¡å ãããããŸãã
ïŒå¯Ÿç2ïŒ
æå³ããªãè«æ±ãã¢ãã¿ãªã³ã°ããããã以äžèšèŒã®ãã¡å°ãªããšã2ã€ã®ãµãŒãã¹ã«ã€ããŠæå¹åãæšå¥šãããŠããŸãã
ïŒAWS BudgetsïŒ
ã»AWS Budgets ã§ã³ã¹ãã管çãã
ïŒAWS CloudTrailïŒ
ã»AWS CloudTrail ãšã¯äœã§ãã?
ïŒAWS Trusted AdvisorïŒ
ã»Trusted Advisorã®æšå¥šäºé
ã䜿ãå§ãã
ïŒAWS Cost Anomaly DetectionïŒã³ã¹ãç°åžžæ€åºïŒïŒ
ã»AWS ã³ã¹ãç°åžžæ€åº
â»åŒç€Ÿè«æ±ä»£è¡ãµãŒãã¹ããå©çšãããŠããããŸãã客æ§ã«ãããŠã¯AWS Cost Anomaly DetectionïŒã³ã¹ãç°åžžæ€åºïŒã¯ãå©çšããã ããŸããã
ïŒå¯Ÿç3ïŒ
ã»ãã¥ãªãã£ã匷åããããã以äžèšèŒã®ãã¡å°ãªããšã1ã€ã®ãµãŒãã¹ã«ã€ããŠæå¹åãæšå¥šãããŠããŸãã
ïŒMFAïŒ
ã»AWS IAMã«ãããå€èŠçŽ èªèšŒ
ïŒAWS Security HubïŒ
ã»AWS ã»ãã¥ãªãã£ãããšã¯äœã§ãã?
ïŒAmazon GuardDutyïŒ
ã»GuardDutyã䜿ãå§ãã
âŸïžãããããåãåãã
ïŒã©ã®ããã«èª¿æ»ãããè¯ããããããªãïŒ
èª¿æ»æ¹æ³ã«ã€ããŠåãåããããããŸãããå
·äœçãªèª¿æ»æ¹æ³ã«ã€ããŠã¯ã©ã®ãããªçµè·¯ã§æŒæŽ©ãããAWSã«åãåãããŠãAWSåŽã§ãããããªãããåçããã ããŸããã
ãã®ãããäºãã¢ã¯ã»ã¹ããŒãæŒæŽ©ããªãããã«å¯Ÿçã宿œããŠãã ããã
äœåããäºæ¿ã®çšãããããé¡ãèŽããŸãã
ïŒAWSã®æ€ç¥ã·ã¹ãã ã«ã€ããŠïŒ
ãã¡ãã«ã€ããŠãåãåããããããŸãã
ããããªããAWSã«åãåããããŠãæ©å¯æ
å ±ã®ããåçããã ããŸããã
ãã¡ããå
¬è¡šãããšãã®ã·ã¹ãã ãåé¿ãããæªçšãããæãããããããšã®ããšã§ãã®ã§äºããäºæ¿ã®çšãããããé¡ãèŽããŸãã
以äžã«ãªããŸãã
åèã«ãªããŸããã幞ãã§ãã
ããšãã
AWS ã¢ã¯ã»ã¹ããŒæŒæŽ©ã§ããããã¡ããšé£åããã®ãAWS äžæ£äœ¿çšã§ãã
AWSã¢ã«ãŠã³ããä¹ã£åãããããããã«æ°ã¥ãããªãããã«æ®æ®µäœ¿çšããŠãããªãŒãžã§ã³ãšã¯å¥ã§ã€ã³ã¹ã¿ã³ã¹ããµãŒãã¹ã䜿çšããè¡çºãçºçããŠããŸãã
æ°çŸäžåèŠæš¡ã®è¢«å®³ãåºãŠããŸãã
ãŸãAWS äžæ£äœ¿çšãããŠããããŸããšAWSã¢ã«ãŠã³ãèªäœã忢ãããããšãããããŸãã®ã§ååãæ³šæãã ããã
éçšãã»ãã¥ãªãã£ã«ãäžå®ãããããŸãããåŒç€Ÿéçšã»ä¿å®ãµãŒãã¹ããæ€èšããã ããŸããšå¹žãã§ãã
AWSéçšã»ä¿å®ãµãŒãã¹