ã¯ããã«
GuardDutyã¯ã¿ãªãã䜿ãããŠããããšããšæããŸãã
æ¬èšäºã§ã¯GuardDutyåºæ¬æ©èœã§ã¯ãªããåProtectionæ©èœã«ã€ããŠèª¿æ»ããæ©äŒããããŸããã®ã§ãã£ããã§ãã®ã§èšäºãšããŠæ®ããããšæããŸãã
ã»ãã¥ãªãã£ãåäžããã¿ããã ãã©å
·äœçã«ãªã«ãã§ããã®ããšãã£ãäºã説æããŸãã
ã©ããå°ã調æ»ããã°åããããšã§ããã²ãšã€ã«ãŸãšããèšäºãããã°ããçè§£ãé²ããšèãå·çããŸããã
ããããGuardDutyãšã¯
AWS CloudTrail 管çã€ãã³ããAWS CloudTrail ã€ãã³ããã°ã(Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ããã®) VPC ãããŒãã°ãDNS ãã°ããªã©ã® åºç€ããŒã¿ãœãŒã¹ ãåæããŠåŠçããã»ãã¥ãªãã£ã¢ãã¿ãªã³ã°ãµãŒãã¹ã§ãã
ãŸããKubernetes ç£æ»ãã°ãRDS ãã°ã€ã³ã¢ã¯ãã£ããã£ãS3 ãã°ãEBS ããªã¥ãŒã ãã©ã³ã¿ã€ã ã¢ãã¿ãªã³ã°ãLambda ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãã°ãªã©ã®æ©èœãåŠçããŸãã
Amazon GuardDuty ãŠãŒã¶ãŒã¬ã€ãã®èª¬æãããããããã®ã§ãã®ãŸãŸåŒçšããŸãã
åŒçšïŒAmazon GuardDuty ãŠãŒã¶ãŒã¬ã€ã
ïŒhttps://docs.aws.amazon.com/ja_jp/guardduty/latest/ug/what-is-guardduty.htmlïŒ
æ¬èšäºã§èª¬æããéšå
äžè¿°ãããŠããå
ã®åŸåéšåã«ã€ããŠãæ¬èšäºã®å¯Ÿè±¡ãšãªããŸãã
å
·äœçã«ã¯ä»¥äžãµãŒãã¹ã®ããšã«ã€ããŠèšèŒãããŠãããŸãã
| é çª | ãµãŒãã¹åç§° |
|---|---|
| 1 | GuardDuty Malware Protection |
| 2 | GuardDuty EKS Protection |
| 3 | GuardDuty S3 Protection |
| 4 | GuardDuty RDS Protection |
| 5 | GuardDuty Lambda Protection |
å°å ¥
ãŸãèªèããŠããã ãããã®ã¯ãããããçºèŠççµ±å¶ã«åœ¹ç«ã€ãã®ãšãªããŸãã
ã€ãŸãäºåŸçã«è
åšæ€åºãè¡ãã©ã察å¿ããŠããã®ããèããæã®è
åšæ€åºéšåã«åœ¹ç«ãŠãããšãã§ããŸãã
äºé²ççµ±å¶ãšããŠä»çµã¿ã¥ãããæ€èšãããå Žåã«ã¯ãã¢ã¯ã»ã¹çµè·¯ãæå°éã«çµããäžå¿
èŠãªæš©éãäžããªããªã©ãšãã£ãåºæ¬çãªã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯ã«æºæ ãã€ã€ãããã§ãè¶³ããªããšå€æããå Žåã«ã¯ãµãŒãããŒãã£è£œã®ãœãããŠã§ã¢å°å
¥ã§æ€èšããŠããå¿
èŠããããŸãã
GuardDuty Malware Protectionãšã¯
Malware Protection ã¯ãAmazon Elastic Compute Cloud (Amazon EC2) ã€ã³ã¹ã¿ã³ã¹ããã³ã³ã³ããã¯ãŒã¯ããŒãã«ã¢ã¿ããããã Amazon Elastic Block Store (Amazon EBS) ããªã¥ãŒã ãã¹ãã£ã³ããããšã§ããã«ãŠã§ã¢ã®æœåšçãªååšãæ€åºããããšã«åœ¹ç«ã¡ãŸãã
ãŸããã«ãŠã§ã¢å¯Ÿçã«ãããçºèŠççµ±å¶ãšããŠå¹æçãªãµãŒãã¹ãšãªããŸãã
察象ãµãŒãã¹ã¯ãEC2ãšECSãšãªããŸããECSã«ãããŠFagateã¯å¯Ÿè±¡å€ãšãªããŸãã
ãããããããŒãžããµãŒãã¹ã§ããFargateå®è¡ç°å¢ã¯AWS責任ç¯å²ãšãªããŸãã®ã§ãŠãŒã¶ãŒåŽã§ã©ãããã§ãããã®ã§ããããŸããã
â»ããŒã¿éšåã«æªæã®ããããã°ã©ã ãã¡ã€ã«ããªããã©ããã¯ãŠãŒã¶ãŒè²¬ä»»ã§ç®¡çæ€èšããå¿
èŠãããŸã
ãŸãã¹ãã£ã³å®è¡ã«ã€ããŠã¯äºã€ã®ã¿ã€ãããéžæã§ããŸãã
1. GuardDuty å®è¡åãã«ãŠã§ã¢ã¹ãã£ã³
GuardDuty ã Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ãŸãã¯ã³ã³ããã¯ãŒã¯ããŒãã«ãã«ãŠã§ã¢ã®æœåšçãªååšãç€ºãæ€åºçµæãçæãããã³ã«ãGuardDuty ã圱é¿ãåããå¯èœæ§ã®ãããªãœãŒã¹ã«ã¢ã¿ããããã Amazon EBS ããªã¥ãŒã ã«ãšãŒãžã§ã³ãã¬ã¹ãã«ãŠã§ã¢ã¹ãã£ã³ãèªåçã«éå§
2. ãªã³ããã³ãã®ãã«ãŠã§ã¢ã¹ãã£ã³
Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ãŸãã¯ã³ã³ããã¯ãŒã¯ããŒãã«é¢é£ä»ãããã Amazon ãªãœãŒã¹ããŒã (ARN) ãæå®ããããšã§ããªã³ããã³ãã®ãã«ãŠã§ã¢ã¹ãã£ã³ãéå§
åè
ã¯ãŸãã«ãã«ãŠã§ã¢ã£ãœããµããŸããæ€ç¥ããæã«ã察象EBSããªã¥ãŒã ãã¹ãã£ã³ããåããšãªããŸãã
ç°¡åã«å°å
¥ã§ããã®ã§å©çšããå Žåã¯ã»ãŒã»ãŒãã¡ãããšæããŸãã
åŸè
ã¯ãªã³ããã³ãã¹ãã£ã³ç¶ç¶çå®è¡ã®ä»çµã¿ãã€ãããã°äºé²ççµ±å¶ã«åœ¹ç«ã€ãšæãããŸãã
æåŸã«æ¬¡åã¹ãã£ã³ã¿ã€ãã³ã°ãŸã§ã®ã€ã³ã¿ãŒãã«ã«ã¯æ°ãã€ããŸãããã
1. GuardDuty å®è¡åãã«ãŠã§ã¢ã¹ãã£ã³
èªåãã«ãŠã§ã¢ã¹ãã£ã³ã 24 æéã« 1 åéå§
2. ãªã³ããã³ãã®ãã«ãŠã§ã¢ã¹ãã£ã³
ååã®ã¹ãã£ã³ã®éå§æå»ãã 1 æéåŸã«ãåããªãœãŒã¹ã«ãªã³ããã³ãã®ãã«ãŠã§ã¢ã¹ãã£ã³ãéå§ã§ãã
GuardDuty EKS Protectionãšã¯
EKS Protection ã¯ãè åšæ€åºã®ç¯å²ãæäŸããAWS ç°å¢å ã® Amazon EKS ã¯ã©ã¹ã¿ãŒãä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
EKS Protection ã«ã¯ãEKS ç£æ»ãã°ã®ã¢ãã¿ãªã³ã°ãš EKS Runtime Monitoring ãå«ãŸããŸãã
ãã¡ããEKS ç£æ»ãã°ãšEKS Runtime Monitoringããçãããã¢ã¯ãã£ããã£ããã£ãå Žåã«æ€ç¥ããæ©èœã§ãã
ç¹ã«EKS Runtime MonitoringããœãŒã¹ãšããå Žåã«ã¯GuardDuty ã»ãã¥ãªãã£ãšãŒãžã§ã³ããšãåŒã°ããæ°ãã EKS ã¢ããªã³ aws-guardduty-agent ãå¿
èŠãšãªããŸãã
ããã«ããEKS ã¯ã©ã¹ã¿ãŒã®ã©ã³ã¿ã€ã åäœãåæããããšã§ãã»ãã¥ãªãã£è
åšãæ€åºããã®ã«åœ¹ç«ã¡ãŸãã
ãŸãšãããš
ç£æ»ãã°ã¯ããŠãŒã¶ãŒãKubernetes API ã䜿çšããã¢ããªã±ãŒã·ã§ã³ãã³ã³ãããŒã«ãã¬ãŒã³ããã®ã¢ã¯ãã£ããã£ãªã©
Runtime Monitoringã¯ããã¡ã€ã«ã¢ã¯ã»ã¹ãããã»ã¹å®è¡ããããã¯ãŒã¯æ¥ç¶ãªã©ãåã
ã® EKS ã¯ãŒã¯ããŒãã©ã³ã¿ã€ã
ã©ã®éšåã®åãã«ã€ããŠè
åšæ€åºããã®ãã®éãããããŸãã®ã§ãèŠä»¶ãšç
§ããåãããŠå©çšããŸãããã
GuardDuty S3 Protectionãšã¯
S3 Protection 㯠S3 ãã±ããå ã®ããŒã¿ã®æœåšçãªã»ãã¥ãªãã£ãªã¹ã¯ãç¹å®ããããã«ããªããžã§ã¯ãã¬ãã«ã® API ãªãã¬ãŒã·ã§ã³ã Amazon GuardDuty ãã¢ãã¿ãªã³ã°ããæ©èœãæå¹ã«ããŸãã
CloudTrail 管çã€ãã³ããšCloudTrail S3 ããŒã¿ã€ãã³ããããŒã¿ãœãŒã¹ã«ããŠäŸãã°ãæªæã®ãããã±ããå ¬éèšå®ãè åšã®ããIPã¢ãã¬ã¹ãããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ããã£ãå Žåã«æ€ç¥ããããšãã§ããŸãã
ãã¡ããæ¬æ©èœã®å©çšã«ã¯ãCloudTrail S3 ããŒã¿ã€ãã³ããæå¹åããå¿
èŠããããŸãã
ããã©ã«ãã§ã¯æå¹ãšãªã£ãŠãããŸããã®ã§ã泚æãã ããã
GuardDuty RDS Protectionãšã¯
RDS Protection ã¯ãRDS ãã°ã€ã³ã¢ã¯ãã£ããã£ãåæããŠãããã¡ã€ãªã³ã°ããAmazon Aurora ããŒã¿ããŒã¹ (Amazon Aurora MySQL äºæãšãã£ã·ã§ã³ããã³ Aurora PostgreSQL äºæãšãã£ã·ã§ã³) ãžã®æœåšçãªã¢ã¯ã»ã¹è åšããªããã©ããã調ã¹ãŸãããã®æ©èœã«ãããæœåšçã«çããããã°ã€ã³åäœãç¹å®ã§ããŸãã
æœåšçã«çããããã°ã€ã³è©Šè¡ãŸãã¯ç°åžžãªãã°ã€ã³è©Šè¡ããã£ãå Žåã«æ€ç¥ããããšãã§ããŸãã
ãŸãRDS Protection æ©èœãæå¹ã«ãããšãGuardDuty ã¯çŽã¡ã«ã¢ã«ãŠã³ãã«ãã Aurora ããŒã¿ããŒã¹ã® RDS ãã°ã€ã³ã¢ã¯ãã£ããã£ã®ã¢ãã¿ãªã³ã°ãéå§ããŸãã
ãªã®ã§ãã®æ©èœã®ä»ã«æå¹ã«ããªããã°ãªããªããã®ã¯ãããŸããã®ã§å°å
¥ã¯ãšãŠãç°¡åã§ãã
泚æç¹ãšããŠã¯ãéåžžã®åäœãããŒã¹ã©ã€ã³ã«ããããã®åŠç¿æéãå¿
èŠãšãªããŸãã
æé·ã§ 2 é±éçšåºŠãé¢é£ããç°åžžãã°ã€ã³ãæ€åºãããªãããšããããŸãã
GuardDuty Lambda Protectionãšã¯
Lambda Protection ã¯ãAWS ç°å¢å ã§ AWS Lambda 颿°ãåŒã³åºããããšãã«æœåšçãªã»ãã¥ãªãã£è åšãç¹å®ããã®ã«åœ¹ç«ã¡ãŸããLambda Protection ãæå¹ã«ãããšãGuardDuty 㯠Lambda ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãã°ã®ã¢ãã¿ãªã³ã°ãéå§ããŸããããã«ã¯ VPC ãããã¯ãŒã¯ã䜿çšããªããã°ãå«ããã¢ã«ãŠã³ãã®ãã¹ãŠã® LambdaVPC Flow Logs 颿°ããéå§ãããLambda 颿°ãåŒã³åºããããšãã«çæãããŸããGuardDuty ã Lambda 颿°ã«æœåšçã«æªæã®ããã³ãŒããååšããããšã瀺ãçããããããã¯ãŒã¯ãã©ãã£ãã¯ãç¹å®ããå ŽåãGuardDuty ã¯æ€åºçµæãçæããŸãã
æªæã®ããã³ãŒããååšããããšã瀺ãçããããããã¯ãŒã¯ãã©ãã£ãã¯ãç¹å®ããå Žåã«æ€ç¥ããããšãã§ããŸãã
ãŸãLambda Protection ãæå¹ã«ãããšãGuardDuty 㯠Lambda ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ãã°ã®ã¢ãã¿ãªã³ã°ãéå§ããŸãã
ãªã®ã§ãã®æ©èœã®ä»ã«æå¹ã«ããªããã°ãªããªããã®ã¯ãããŸããã®ã§å°å
¥ã¯ãšãŠãç°¡åã§ãã
ãã®ä»æ©èœãšåæ§ã§ãããæªæã®ããã³ãŒããã®ãã®ã®è åšæ€åºãã§ããèš³ã§ãªãããããã¯ãŒã¯ã¢ã¯ãã£ããã£ãšããæ¯ãèãã«å¯ŸããŠè åšæ€åºããããã®ã«ãªããŸãã
ãŸãšã
以äžã§GuardDutyåProtectionæ©èœã«ã€ããŠã®ç解床ãããããŸããã§ããããã
ç§ã®å Žåã調æ»åã¯ã»ãã¥ãªãã£é¢é£ã®ãµãŒãã¹ãšããããšã§äºé²çãªæ©èœãåããã®ããšå
å
¥èгããã£ãŠãããŸããã
ããã調æ»ãããäžã§ã䟵害ããã£ãå Žåã®æ€ç¥ãã§ãããµãŒãã¹ã§ãããšããããšãçè§£ããŸããã
ãããã®ãµãŒãã¹ãããŸã䜿ãã€ã€ãã¯ãŒã¯ããŒãèªäœã¯AWS Well-Architectedçãå©çšãã»ãã¥ãªãã£ã®ãã¹ãã©ãéµå®ããå¿
èŠããããªãšæ¹ããŠèªèããŸããã
以äžãæåŸãŸã§ã芧ããã ãããããšãããããŸããã