AWS Security Meetup (07/23/2020)

1. AWS New WAF – μƒˆλ‘œμ›Œμ§„ AWS WAF 의 μ£Όμš” κΈ°λŠ₯에 λŒ€ν•΄ μ•Œλ €λ“œλ¦½λ‹ˆλ‹€

λ°œν‘œμž: 쑰이정 λ‹˜(AWS Solutions Architect)

AWS WAF (Web Application Firewall) λž€?

  • AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources.

  • AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define.

AWS WAF Class vs. WAF

μƒˆλ‘œμš΄ API

  • "wafv2" λΌλŠ” κ³ μœ ν•œ namespace

  • "waf" λ‚˜ "waf-regional" 이 없어지고, 단일 API둜 μ‚¬μš©

μƒˆλ‘œμš΄ Rule μž‘μ„± 방법

  • 각 Tool type에 λ”°λ₯Έ κ°œλ³„ API μ—†μŒ

  • JSON format 의 Document-based rule μž‘μ„±

  • JSON 파일둜 λͺ¨λ“  rule을 κ΅¬μ„±ν•˜κ³  κ°„νŽΈν•˜κ²Œ UpdateWebACL API λ₯Ό call ν•΄μ„œ 반영

μƒˆλ‘œμš΄ λ£°μ…‹ μš©λŸ‰: WAF Capacity Unit (WCU)

  • 더 이상 WebACL λ‹Ή 10개 룰둜 μ œν•œλ˜μ§€ μ•ŠμŒ

  • λ‹€μ–‘ν•œ μ„œλΉ„μŠ€ μ œν•œ μ†Œλ©Έ

    • ex) ν•„ν„° 개수 μ œν•œ

μƒˆλ‘œμš΄ μ½˜μ†” κ²½ν—˜

  • κ°„νŽΈν•΄μ§€κ³  μ§κ΄€μ μœΌλ‘œ λ³€ν™”

μƒˆλ‘œμš΄ 탐지 λŠ₯λ ₯

  • QR 둜직, 닀쀑 λ³€ν˜•

Built-In κ½Œλ¦¬ν˜• λ£°μ…‹: AWS Managed Rules

  • AWS κ°€ κ΄€λ¦¬ν•˜κ³  μœ μ§€ν•˜λŠ” λ£°μ…‹

  • Amazon λ‚΄λΆ€μ—μ„œ μŠ΅λ“ν•œ λ³΄μ•ˆ 지식과 μœ„ν˜‘ 탐지 반영

  • OWASP Top 10 및 anti-bot IP reputation list 포함

Workshop URL

: https://go.aws/2xx2XT9

  • 1μ‹œκ°„ 반 정도 κ±Έλ¦°λ‹€κ³  함! 해봐야징

2. AWS New Macie/Detective – μƒˆλ‘œμ›Œμ§„ Macie μ„œλΉ„μŠ€μ™€ μ‹ κ·œ λ³΄μ•ˆ μ„œλΉ„μŠ€μΈ Detective 의 μ£Όμš” κΈ°λŠ₯에 λŒ€ν•΄ μ•Œλ €λ“œλ¦½λ‹ˆλ‹€

λ°œν‘œμž: μ‹ μ€μˆ˜ λ‹˜(AWS Security Specialist Solutions Architect)

우리 Macieκ°€ μ΄λ ‡κ²Œ λ‹¬λΌμ‘Œμ–΄μš”

1. Amazon Macie - μ™„μ „ν•˜κ²Œ μƒˆλ‘œμš΄ μ„œλΉ„μŠ€ (Upgrade μˆ˜μ€€μ΄ μ•„λ‹˜!)

  • κΈ°μ‘΄ Macie μ„œλΉ„μŠ€μ˜ 이름 λ³€κ²½ - Macie Classic

  • Macie Classic을 μ‚¬μš©ν•˜λŠ” 고객도 μƒˆλ‘œμ›Œμ§„ Macieλ₯Ό λ™μ‹œμ— μ‚¬μš© κ°€λŠ₯

2. μ§€λ‚œ 2λ…„κ°„μ˜ 고객 μš”κ΅¬ 사항을 λ°˜μ˜ν•˜μ—¬ κ°œμ„ 

  • AWS에 μ €μž₯λ˜μ–΄ μžˆλŠ” λ°μ΄ν„°μ˜ κ°μ‹œμ™€ 민감 정보 탐지에 μ΅œμ ν™”

3. Macie Clasic 고객도 μƒˆλ‘œμ›Œμ§„ Macie μ‚¬μš©μ΄ κ°€λŠ₯ν•˜λ©° μ•„λž˜μ™€ 같은 μ €λž“μ— 따라 μ „ν™˜ κ°€λŠ₯

  • 기쑴의 λΆ„λ₯˜ κ²°κ³Όλ₯Ό 내보내기

  • Macie Classic λΉ„ν™œμ„±ν™”

Macie vs Macie Classic

μ£Όμš” λ³€ν™”

  • μ΄μƒν–‰μœ„ 탐지 및 S3에 λŒ€ν•œ CloudTrail 둜그 뢄석은 GuardDuty둜 이관

+

λŠλ‚€μ 

AWSκ°€ μ œκ³΅ν•˜λŠ” μ„œλΉ„μŠ€λŠ” 정말 λ‹€μ–‘ν•˜λ‹€λŠ” 것을 λ‹€μ‹œ ν•œλ²ˆ λŠκΌˆλ‹€...!

써봐야 ν•  μ œν’ˆ, 써보고 싢은 μ œν’ˆμ΄ λ„ˆλ¬΄ λ§Žλ‹€! 갈 길이 λ©€λ“œμ•„!!

Last updated