AWS Security Meetup (07/23/2020)

1. AWS New WAF โ€“ ์ƒˆ๋กœ์›Œ์ง„ AWS WAF ์˜ ์ฃผ์š” ๊ธฐ๋Šฅ์— ๋Œ€ํ•ด ์•Œ๋ ค๋“œ๋ฆฝ๋‹ˆ๋‹ค

๋ฐœํ‘œ์ž: ์กฐ์ด์ • ๋‹˜(AWS Solutions Architect)

AWS WAF (Web Application Firewall) ๋ž€?

  • AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources.

  • AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define.

AWS WAF Class vs. WAF

์ƒˆ๋กœ์šด API

  • "wafv2" ๋ผ๋Š” ๊ณ ์œ ํ•œ namespace

  • "waf" ๋‚˜ "waf-regional" ์ด ์—†์–ด์ง€๊ณ , ๋‹จ์ผ API๋กœ ์‚ฌ์šฉ

์ƒˆ๋กœ์šด Rule ์ž‘์„ฑ ๋ฐฉ๋ฒ•

  • ๊ฐ Tool type์— ๋”ฐ๋ฅธ ๊ฐœ๋ณ„ API ์—†์Œ

  • JSON format ์˜ Document-based rule ์ž‘์„ฑ

  • JSON ํŒŒ์ผ๋กœ ๋ชจ๋“  rule์„ ๊ตฌ์„ฑํ•˜๊ณ  ๊ฐ„ํŽธํ•˜๊ฒŒ UpdateWebACL API ๋ฅผ call ํ•ด์„œ ๋ฐ˜์˜

์ƒˆ๋กœ์šด ๋ฃฐ์…‹ ์šฉ๋Ÿ‰: WAF Capacity Unit (WCU)

  • ๋” ์ด์ƒ WebACL ๋‹น 10๊ฐœ ๋ฃฐ๋กœ ์ œํ•œ๋˜์ง€ ์•Š์Œ

  • ๋‹ค์–‘ํ•œ ์„œ๋น„์Šค ์ œํ•œ ์†Œ๋ฉธ

    • ex) ํ•„ํ„ฐ ๊ฐœ์ˆ˜ ์ œํ•œ

์ƒˆ๋กœ์šด ์ฝ˜์†” ๊ฒฝํ—˜

  • ๊ฐ„ํŽธํ•ด์ง€๊ณ  ์ง๊ด€์ ์œผ๋กœ ๋ณ€ํ™”

์ƒˆ๋กœ์šด ํƒ์ง€ ๋Šฅ๋ ฅ

  • QR ๋กœ์ง, ๋‹ค์ค‘ ๋ณ€ํ˜•

Built-In ๊ฝŒ๋ฆฌํ˜• ๋ฃฐ์…‹: AWS Managed Rules

  • AWS ๊ฐ€ ๊ด€๋ฆฌํ•˜๊ณ  ์œ ์ง€ํ•˜๋Š” ๋ฃฐ์…‹

  • Amazon ๋‚ด๋ถ€์—์„œ ์Šต๋“ํ•œ ๋ณด์•ˆ ์ง€์‹๊ณผ ์œ„ํ˜‘ ํƒ์ง€ ๋ฐ˜์˜

  • OWASP Top 10 ๋ฐ anti-bot IP reputation list ํฌํ•จ

Workshop URL

: https://go.aws/2xx2XT9

  • 1์‹œ๊ฐ„ ๋ฐ˜ ์ •๋„ ๊ฑธ๋ฆฐ๋‹ค๊ณ  ํ•จ! ํ•ด๋ด์•ผ์ง•

2. AWS New Macie/Detective โ€“ ์ƒˆ๋กœ์›Œ์ง„ Macie ์„œ๋น„์Šค์™€ ์‹ ๊ทœ ๋ณด์•ˆ ์„œ๋น„์Šค์ธ Detective ์˜ ์ฃผ์š” ๊ธฐ๋Šฅ์— ๋Œ€ํ•ด ์•Œ๋ ค๋“œ๋ฆฝ๋‹ˆ๋‹ค

๋ฐœํ‘œ์ž: ์‹ ์€์ˆ˜ ๋‹˜(AWS Security Specialist Solutions Architect)

์šฐ๋ฆฌ Macie๊ฐ€ ์ด๋ ‡๊ฒŒ ๋‹ฌ๋ผ์กŒ์–ด์š”

1. Amazon Macie - ์™„์ „ํ•˜๊ฒŒ ์ƒˆ๋กœ์šด ์„œ๋น„์Šค (Upgrade ์ˆ˜์ค€์ด ์•„๋‹˜!)

  • ๊ธฐ์กด Macie ์„œ๋น„์Šค์˜ ์ด๋ฆ„ ๋ณ€๊ฒฝ - Macie Classic

  • Macie Classic์„ ์‚ฌ์šฉํ•˜๋Š” ๊ณ ๊ฐ๋„ ์ƒˆ๋กœ์›Œ์ง„ Macie๋ฅผ ๋™์‹œ์— ์‚ฌ์šฉ ๊ฐ€๋Šฅ

2. ์ง€๋‚œ 2๋…„๊ฐ„์˜ ๊ณ ๊ฐ ์š”๊ตฌ ์‚ฌํ•ญ์„ ๋ฐ˜์˜ํ•˜์—ฌ ๊ฐœ์„ 

  • AWS์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” ๋ฐ์ดํ„ฐ์˜ ๊ฐ์‹œ์™€ ๋ฏผ๊ฐ ์ •๋ณด ํƒ์ง€์— ์ตœ์ ํ™”

3. Macie Clasic ๊ณ ๊ฐ๋„ ์ƒˆ๋กœ์›Œ์ง„ Macie ์‚ฌ์šฉ์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ ์•„๋ž˜์™€ ๊ฐ™์€ ์ €๋ž“์— ๋”ฐ๋ผ ์ „ํ™˜ ๊ฐ€๋Šฅ

  • ๊ธฐ์กด์˜ ๋ถ„๋ฅ˜ ๊ฒฐ๊ณผ๋ฅผ ๋‚ด๋ณด๋‚ด๊ธฐ

  • Macie Classic ๋น„ํ™œ์„ฑํ™”

Macie vs Macie Classic

์ฃผ์š” ๋ณ€ํ™”

image-20200723200808822
  • ์ด์ƒํ–‰์œ„ ํƒ์ง€ ๋ฐ S3์— ๋Œ€ํ•œ CloudTrail ๋กœ๊ทธ ๋ถ„์„์€ GuardDuty๋กœ ์ด๊ด€

+

๋А๋‚€์ 

AWS๊ฐ€ ์ œ๊ณตํ•˜๋Š” ์„œ๋น„์Šค๋Š” ์ •๋ง ๋‹ค์–‘ํ•˜๋‹ค๋Š” ๊ฒƒ์„ ๋‹ค์‹œ ํ•œ๋ฒˆ ๋А๊ผˆ๋‹ค...!

์จ๋ด์•ผ ํ•  ์ œํ’ˆ, ์จ๋ณด๊ณ  ์‹ถ์€ ์ œํ’ˆ์ด ๋„ˆ๋ฌด ๋งŽ๋‹ค! ๊ฐˆ ๊ธธ์ด ๋ฉ€๋“œ์•„!!

Last updated

Was this helpful?