Contents

27. AWS Security & Encryption

KMS, Encryption SDK, SSM Parameter Store

์ „์†ก์ค‘ ์•”ํ˜ธํ™” (SSL)

  • ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•˜๊ธฐ ์ „์— ์•”ํ˜ธํ™”. ์ˆ˜์‹  ํ›„ ๋ณตํ˜ธํ™”
  • SSL ์ธ์ฆ์„œ๋กœ ์•”ํ˜ธํ™” (HTTPS)
  • ์ „์†ก ์ค‘ ์•”ํ˜ธํ™”๋Š” MITM(man in the middle attack)์ด ๋ฐœ์ƒํ•˜์ง€ ์•Š๋„๋ก ๋ณด์žฅ

Server side encryption at rest

  • ๋ฐ์ดํ„ฐ๊ฐ€ ์„œ๋ฒ„์— ์ˆ˜์‹  ๋œ ํ›„ ์•”ํ˜ธํ™”
  • ๋ฐ์ดํ„ฐ๊ฐ€ ์„œ๋ฒ„์— ์ „์†ก ์ „ ๋ณตํ˜ธํ™”
  • ๋ฐ์ดํ„ฐ ํ‚ค๋ผ๊ณ  ๋ถˆ๋ฆฌ์šฐ๋Š” ํ‚ค ๋•๋ถ„์— ๋ฐ์ดํ„ฐ๋Š” ์•”ํ˜ธํ™” ๋œ ํ˜•ํƒœ๋กœ ์ €์žฅ
  • ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™” ํ‚ค๋Š” ์–ด๋”˜๊ฐ€์— ๊ด€๋ฆฌ๋˜์–ด์•ผ ํ•˜๋ฉฐ ์„œ๋ฒ„๋Š” ์ด์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.
/posts/images/aws/server-side-encryption.jpg

Client side encryption

  • ๋ฐ์ดํ„ฐ๊ฐ€ ํด๋ผ์ด์–ธํŠธ์— ์˜ํ•ด ์•”ํ˜ธํ™”๋˜๊ณ  ์„œ๋ฒ„๋Š” ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์—†์Œ
  • ๋ฐ์ดํ„ฐ๋Š” ์ˆ˜์‹  ํด๋ผ์ด์–ธํŠธ์— ์˜ํ•ด ๋ณตํ˜ธํ™”
  • ์„œ๋ฒ„๋Š” ๋ฐ์ดํ„ฐ์˜ ์•”ํ˜ธ๋ฅผ ๋ณตํ˜ธํ™” ํ•  ์ˆ˜ ์—†์Œ
  • Envelop Encryption ์•”ํ˜ธํ™”๋ฅผ ํ™œ์šฉ
/posts/images/aws/client-side-encryption.jpg

AWS KMS (Key Management Service)

  • KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ๋žŒ๊ณผ ๋Œ€์ƒ์„ ์‰ฝ๊ฒŒ ์ œ์–ด

  • ์ธ์ฆ์„์œ„ํ•œ IAM๊ณผ ์™„๋ฒฝํ•˜๊ฒŒ ํ†ตํ•ฉ๊ฐ€๋Šฅ

  • CLI / SDK ์‚ฌ์šฉ ๊ฐ€๋Šฅ

  • ๋‹ค์Œ์˜ ์„œ๋น„์Šค์™€ ์™„๋ฒฝํ•˜๊ฒŒ ํ†ตํ•ฉ:

    • Amazon EBS: ๋ณผ๋ฅจ ์•”ํ˜ธํ™”
    • Amazon S3 : Server side encryption of objects
    • Amazon Redshift: encryption of data
    • Amazon RDS: encryption of data
    • Amazon SSM: Parameter store
    • ๊ทธ์™ธ…

Customer Master Key (CMK) Types

๋Œ€์นญํ‚ค Symmetric (AES-256 Key)

  • ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”๊ฐ€ ๋™์ผ
  • AWS๋Š” KMS์™€ ํ†ตํ•ฉ๋œ Symmetric CMKs๋ฅผ ์‚ฌ์šฉ
  • envelope encryption์— ํ•„์š”
  • ์•”ํ˜ธํ™”๋˜์ง€ ์•Š์€ ํ‚ค์— ์•ก์„ธ์Šค ํ•  ์ˆ˜ ์—†์Œ - ์‚ฌ์šฉํ•˜๋ ค๋ฉด KMS API ํ˜ธ์ถœ ํ•„์š”

๋น„๋Œ€์นญํ‚ค Asymmetric (RSA & ECC Key pairs)

  • SSL ์ž‘๋™ ์›๋ฆฌ
  • ์•”ํ˜ธํ™” ์‹œ public key ๋ณตํ˜ธํ™” ์‹œ private key ์‚ฌ์šฉ
  • ์•”ํ˜ธํ™”/๋ณตํ˜ธํ™” ๋ฐ Sing/Verify ์ž‘์—…์— ์‚ฌ์šฉ
  • public key๋ฅผ ๋‹ค์šด๋กœ๋“œํ•  ์ˆ˜ ์žˆ์ง€๋งŒ private key์—๋Š” ์•ก์„ธ์Šค ํ•  ์ˆ˜ ์—†์Œ
  • ์‚ฌ์šฉ ์‚ฌ๋ก€
    • KMS API๋ฅผ ํ˜ธ์ถœํ•  ์ˆ˜ ์—†๋Š” ์‚ฌ์šฉ์ž์— ์˜ํ•œ AWS ์™ธ๋ถ€ ์•”ํ˜ธํ™”

KMS ๋Œ€์นญํ‚ค

  • KMS Symmetric Key ํ‚ค ์ •์ฑ…
    • ์ƒ์„ฑ์ •์ฑ…
    • Rotation policies - ํ‚ค ๊ต์ฒด ์ •์ฑ…
    • ํ™œ์„ฑํ™” ๋ฐ ๋น„ํ™œ์„ฑํ™”
  • CloudTrail์„ ์‚ฌ์šฉํ•˜์—ฌ ํ‚ค ์‚ฌ์šฉ์„ ๊ฐ์‚ฌ
  • Customer Master Keys(CMS) ์œ ํ˜•
    1. AWS Managed Service Default CMK: free
    2. User Keys created in KMS: $1 / month
    3. User Keys imported (must be 256-bit symmetric key): $1 / month
    • Call KMS API ($0.03 / 10000 calls)

AWS KMS 101

  • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒจ์Šค์›Œ๋“œ
  • ์™ธ๋ถ€ ์„œ๋น„์Šค์˜ ์ž๊ฒฉ์ฆ๋ช…
  • SSL ์ธ์ฆ์„œ์˜ private key
Tip
KMS๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๊ฑฐ๋‚˜ ๋ณตํ˜ธํ™”ํ•˜๋Š” ํ‚ค๋ฅผ ๋ณผ ์ˆ˜ ์—†๊ธฐ ๋•Œ๋ฌธ์— AWS์˜ ์ „์ฒด ๋ณด์•ˆ์ด ๊ฐ€๋Šฅ
  • Secret ๋ฐ์ดํ„ฐ๋Š” ํ”Œ๋ ˆ์ธํ…์ŠคํŠธ๋กœ ํŠนํžˆ ์ฝ”๋“œ๋กœ ์ €์žฅํ•˜์ง€ ์•Š๋Š”๋‹ค.
  • KMS ์š”์ฒญ๋‹น 4KB์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๋Š”๋ฐ ํšจ์œจ - ๋ฐ์ดํ„ฐ๊ฐ€ 4KB ํฐ ๊ฒฝ์šฐ envelop encryption ์‚ฌ์šฉ
๋‹ค๋ฅธ ์‚ฌ์šฉ์ž์—๊ฒŒ KMS ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋ ค๋ฉด
  • ํ‚ค ์ •์ฑ…์ด ์‚ฌ์šฉ์ž๋ฅผ ํ—ˆ์šฉํ•˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.
  • IAM ์ •์ฑ…์ด API๋ฅผ ํ˜ธ์ถœ์„ ํ—ˆ์šฉํ•˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.

Copying Snapshots across regions

  • KMS ํ‚ค๋Š” ํŠน์ • ๋ฆฌ์ „์— ๋ฐ”์ธ๋”ฉ ๋œ๋‹ค.
    • ๋ฆฌ์ „ A์—์„œ KMS๋ฅผ ์ƒ์„ฑํ•˜๋ฉด ๋ฆฌ์ „ B๋กœ ์ „์†ก ๋ถˆ๊ฐ€๋Šฅ
  1. KMS๋กœ ์•”ํ˜ธํ™”๋œ EBS ๋ณผ๋ฅจ
  2. ๋™์ผํ•œ ํ‚ค๋กœ ์•”ํ˜ธํ™” ๋œ EBS ์Šค๋ƒ…์ƒท ์ƒ์„ฑ
  3. ๋‹ค๋ฅธ ๋ฆฌ์ „์— KMS ํ‚ค๋กœ ์žฌ ์•”ํ˜ธํ™”
  4. ์ƒˆ๋กœ์šด ๋ฆฌ์ „์— ์ƒˆ๋กœ์šด ํ‚ค๋กœ ์•”ํ˜ธํ™” ๋œ ์Šค๋ƒ…์ƒท์ƒ์„ฑ
  5. ํ•ด๋‹น ์Šค๋ƒ…์ƒท์œผ๋กœ ๋ณผ๋ฅจ์„ ์žฌ์ƒ์„ฑ

KMS ํ‚ค ์ •์ฑ…

  • KMS ํ‚ค์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ์ œ์–ด๋Š” S3 Bucket ์ •์ฑ…๊ณผ ๋น„์Šท
  • ์ฐจ์ด์  : ์‚ฌ์šฉ์ž ์—†์ด ์•ก์„ธ์Šค ์ œ์–ด ๋ถˆ๊ฐ€
๊ธฐ๋ณธ KMS ํ‚ค ์ •์ฑ… Custom KMS ํ‚ค ์ •์ฑ…
- ํŠน์ • ํ‚ค ์ •์ฑ…์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์œผ๋ฉด ๊ธฐ๋ณธ์œผ๋กœ ์ƒ์„ฑ - KMS ํ‚ค์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์šฉ์ž ๋ฐ role ์ •์˜
- ๋ฃจํŠธ ์‚ฌ์šฉ์ž = ์ „์ฒด AWS ๊ณ„์ •์— ๋Œ€ํ•œ ์ „์ฒด ์น˜ ์•ก์„ธ์Šค ๊ถŒํ•œ - ํ‚ค๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์šฉ์ž ์ •์˜
- KMS ํ‚ค์— ๋Œ€ํ•œ IAM ์ •์ฑ…์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ ๋ถ€์—ฌ - KMS ํ‚ค์˜ ๊ณ„์ •๊ฐ„ ์•ก์„ธ์Šค์— ์œ ์šฉ

Copying Snapshots across accounts

  1. ์‚ฌ์šฉ์ž์˜ CMK๋กœ ์•”ํ˜ธํ™” ๋œ ์Šค๋ƒ…์ƒท ์ƒ์„ฑ
  2. KMS ํ‚ค ์ •์ฑ…์„ ์ฒจ๋ถ€ํ•˜์—ฌ ๊ณ„์ •๊ฐ„ ๊ณ„์ • ์•ก์„ธ์Šค ๊ถŒํ•œ ๋ถ€์—ฌ
  3. ์•”ํ˜ธํ™” ๋œ ์Šค๋ƒ…์ƒท ๊ณต์œ 
  4. ์Šค๋ƒ…์ƒท ๋ณต์‚ฌ๋ณธ ์ƒ์„ฑ ๊ณ„์ •์˜ KMS ํ‚ค๋กœ ์•”ํ˜ธํ™”
  5. ์Šค๋ƒ…์ƒท ๋ณผ๋ฅจ ์ƒ์„ฑ

KMS Automatic Key Rotation

  • Customer-managed(CMK)์—์„œ๋งŒ (not AWS managed CMK)
  • ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ 1 ๋…„๋งˆ๋‹ค ํ‚ค๊ฐ€ rotation
  • ์ด์ „ ๋ฐ์ดํ„ฐ๋“ค์ด ๋ณตํ˜ธํ™” ๋  ์ˆ˜ ์žˆ๋„๋ก ์ด์ „ํ‚ค์˜ ์ƒํƒœ๋Š” ํ™œ์„ฑํ™”
  • ์ƒˆ ํ‚ค์˜ CMK ID๋Š” ๋™์ผํ•˜๋‹ค. (Backing Key๋งŒ ๋ณ€๊ฒฝ)

KMS Manual Key Rotation

  • 90์ผ, 180์ผ ๋“ฑ ์›ํ•˜๋Š” ๊ฐ„๊ฒฉ์œผ๋กœ rotate ํ•  ๊ฒฝ์šฐ
  • ์ƒˆ ํ‚ค์˜ CMK ID๊ฐ€ ๋‹ค๋ฅด๋‹ค
  • ์ด์ „ ๋ฐ์ดํ„ฐ๋“ค์ด ๋ณตํ˜ธํ™” ๋  ์ˆ˜ ์žˆ๋„๋ก ์ด์ „ํ‚ค์˜ ์ƒํƒœ๋Š” ํ™œ์„ฑํ™”
  • UpdateAlias API๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณ„์นญ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹๋‹ค.
  • ์ž๋™ ํ‚ค ๋กœํ…Œ์ด์…˜ CMK(๋น„๋Œ€์นญ CMK ๊ฐ™์€)์— ์ ํ•ฉํ•˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ์ข‹์€ ๋Œ€์•ˆ

SSM Parameter Store

  • ๊ตฌ์„ฑ ๋ฐ ๊ธฐ๋ฐ€ ๋ฐ์ดํ„ฐ๋ฅผ ์œ„ํ•œ ์•ˆ์ „ํ•œ ์Šคํ† ๋ฆฌ์ง€
  • KMS๋ฅผ ์‚ฌ์šฉํ•œ ์›ํ™œํ•œ ์•”ํ˜ธํ™”(์˜ต์…˜)
  • Serverless, ํ™•์žฅ์„ฑ, ๋‚ด๊ตฌ์„ฑ, ์†์‰ฌ์šด SDK
  • ๋ฒ„์ „ ํŠธ๋ž˜ํ‚น
  • path & IAM์„ ์‚ฌ์šฉํ•œ ๊ตฌ์„ฑ ๊ด€๋ฆฌ
  • CloudWatch ์ด๋ฒคํŠธ ์•Œ๋ฆผ
  • CloudFormation๊ณผ ํ†ตํ•ฉ

SSM Parameter Store Hierarchy

/posts/images/aws/ssm-hierarchy.jpg

Parameters Policies (for advanced parameters)

  • ์•”ํ˜ธ๊ฐ™์€ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๊ฐ•์ œ๋กœ ์—…๋ฐ์ดํŠธํ•˜๊ฑฐ๋‚˜ ์‚ญ์ œํ•˜๊ธฐ ์œ„ํ•ด ๋งŒ๋ฃŒ์ผ์— TTL์„ ์ ์šฉ
  • ํ•œ๋ฒˆ์— ์—ฌ๋Ÿฌ ์ •์ฑ…์„ ํ• ๋‹น ๊ฐ€๋Šฅ
ํŒŒ๋ผ๋ฏธํ„ฐ ์ •์ฑ…

Expiration(ํŒŒ๋ผ๋ฏธํ„ฐ ์‚ญ์ œ)

1
2
3
4
5
6
7
{
    "Type": "Expiration",
    "Version" : "1.0",
    "Attributes": {
        "Timestamp" : "2020-12-02T21:34:33.000Z"
    }
}

๋งŒ๋ฃŒ ์•Œ๋ฆผ(CloudWatch Events)

1
2
3
4
5
6
7
{
    "Type": "Expiration",
    "Version" : "1.0",
    "Attributes": {
        "Timestamp" : "2020-12-02T21:34:33.000Z"
    }
}

NoChangeNotification(CloudWatch Events)

1
2
3
4
5
6
7
8
{
    "Type": "NoChangeNotification",
    "Version" : "1.0",
    "Attributes": {
        "After": "20",
        "Unit": "Days"
    }
}

AWS Secret Manager

  • ๊ธฐ๋ฐ€ ์ €์žฅ์„ ์œ„ํ•œ ์ƒˆ๋กœ์šด ์„œ๋น„์Šค
  • X ์ผ๋งˆ๋‹ค ๊ฐ•์ œ๋กœ ๊ธฐ๋ฐ€์„ ๋กœํ…Œ์ด์…˜ ํ•˜๋Š” ๊ธฐ๋Šฅ
  • Amazon RDS (MySQL, PostgreSQL, Aurora) ํ†ตํ•ฉ
  • KMS์„ ์‚ฌ์šฉํ•œ ์•”ํ˜ธํ™”
  • ๋Œ€๋ถ€๋ถ„์˜ RDS ํ†ตํ•ฉ์„ ์œ„ํ•จ

CloudHSM

  • KMS๋Š” AWS์—์„œ ์•”ํ˜ธํ™”๋ฅผ ์œ„ํ•œ ์†Œํ”„ํŠธ์›จ์–ด ๊ด€๋ฆฌ
  • CloudHSM => AWS์—์„œ ์•”ํ˜ธํ™” ํ•˜๋“œ์›จ์–ด ํ”„๋กœ๋น„์ €๋‹
  • ์ „์šฉ ํ•˜๋“œ์›จ์–ด (HSM = Hardware Security Module)
  • AWS๊ฐ€ ์•„๋‹Œ ์ž์‹ ์˜ ์•”ํ˜ธํ™” ํ‚ค๋ฅผ ์ „์ฒด์ ์œผ๋กœ ๊ด€๋ฆฌํ•ด์•ผ ํ•œ๋‹ค.
  • HSM๋Š” ๋ณ€์กฐ ๋ฐฉ์ง€, FIPS 140-2 ๋ ˆ๋ฒจ 3 ์ค€์ˆ˜
  • ๋Œ€์นญ ๋ฐ ๋น„๋Œ€์นญ ์•”ํ˜ธํ™” (SSL/TLS ํ‚ค)๋ชจ๋‘ ์ง€์›
  • ํ”„๋ฆฌํ‹ฐ์–ด ์•„๋‹˜
  • CloudHSM Client Software๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•จ
  • Redshift๋Š” ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ์•”ํ˜ธํ™”์™€ ํ‚ค ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•ด CloudHSM๋ฅผ ์ง€์›
  • SSE-C ์•”ํ˜ธํ™”์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜๊ธฐ ์ข‹์€ ์˜ต์…˜

CLoudHSM Diagram

  • IAM Permissions
    • CRUD an HSM Cluster
  • CloudHSM software
    • Manage the Keys
    • Manage the Users

CLoudHSM - High Availability

  • CloudHSM ํด๋Ÿฌ์Šคํ„ฐ๋Š” Multi AZ(HA) ๋ถ„์‚ฐ๋œ๋‹ค.
  • ๋›ฐ์–ด๋‚œ ๊ฐ€์šฉ์„ฑ ๋ฐ ๋‚ด๊ตฌ์„ฑ์„ ๊ฐ–๋Š”๋‹ค.

CloudHSM vs. KMS

๊ธฐ๋Šฅ AWS KMS AWS CloudHSM
Tenancy Multi-Tenant Single-Tenant
Standard FIPS 140-2 Level 2 FIPS 140-2 Level 3
Master Keys ยท AWS Owned CMK
ยท AWS Manged CMK
ยท Customer Managed CMK
Customer Managed CMK
Key Types ยท Symmetric
ยท Asymmetric
ยท Digital Signing
ยท Symmetric
ยท Asymmetric
ยท Digital Signing & Hashing
Key Accessibility ์—ฌ๋Ÿฌ AWS ๋ฆฌ์ ผ์—์„œ ์•ก์„ธ์Šค ๊ฐ€๋Šฅ ยท VPC์—์„œ ๋ฐฐํฌ ๋ฐ ๊ด€๋ฆฌ
ยท VPC ๊ฐ„์— ๊ณต์œ  ๊ฐ€๋Šฅ(VPC ํ”ผ์–ด๋ง)
Cryptographic Acceleration None ยท SSL/TLS Acceleration
โ€ข Oracle TDE Acceleration
Access & Authentication AWS IAM ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ๊ถŒํ•œ์„ ๊ด€๋ฆฌ
High Availability AWS Managed Service ์„œ๋กœ ๋‹ค๋ฅธ AZ์— ์—ฌ๋Ÿฌ HSM ์ถ”๊ฐ€
Audit Capability ยท CloudTrail
ยท CloudWatch
โ€ข CloudWatch
โ€ข CloudTrail
โ€ข MFA support
Free Tier Yes No

AWS Shield

AWS Shield Standard

  • ๋ฌด๋ฃŒ ์„œ๋น„์Šค
  • SYN/UDP Floods, Reflection, ๋„คํŠธ์›Œํฌ Layer3/Layer4 ๊ณต๊ฒฉ๊ณผ ๊ฐ™์€ ๊ธฐํƒ€ ๊ณต๊ฒฉ์œผ๋กœ ๋ถ€ํ„ฐ ๋ณดํ˜ธ ์ œ๊ณต

AWS Shield Advanced

  • ์„ ํƒ์ ์ธ DDoS ์™„ํ™” ์„œ๋น„์Šค ($3,000 per month per organization)
  • Amazon EC2, Elastic Load Balancing(ELB), Amazon CloudFront, AWS Global Accelerator ๋ฐ Route 53์— ๋Œ€ํ•œ ๋ณด๋‹ค ์ •๊ตํ•œ ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธ
  • AWS DDoS ๋Œ€์‘ํŒ€(DRP) ์—ฐ์ค‘๋ฌดํœด ์•ก์„ธ์Šค
  • DDoS๋กœ ์ธํ•ด ์‚ฌ์šฉ๋Ÿ‰์ด ๊ธ‰์ฆํ•˜๋Š” ๋™์•ˆ ๋” ๋†’์€ ์ˆ˜์ˆ˜๋ฃŒ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธ

AWS WAF - Web Application Firewall

  • ์ผ๋ฐ˜์ ์ธ ์›น ์•…์šฉ์œผ๋กœ ๋ถ€ํ„ฐ ์›น ์‘์šฉ ๊ณ„์ธต ๋ณดํ˜ธ (Layer 7)
  • Layer 7 is HTTP (vs Layer 4 is TCP)
  • Deploy on Application Load Balancer, API Gateway, CloudFront

Define Web ACL (Web Access Control List)

  • ๊ทœ์น™์—๋Š” IP address, HTTP headers, HTTP body, URI strings ํฌํ•จํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ์ผ๋ฐ˜์ ์ธ ๊ณต๊ฒฉ์œผ๋กœ ๋ถ€ํ„ฐ ๋ณดํ˜ธ
    • SQL injection
    • Cross-Site Scripting (XSS)
  • ํฌ๊ธฐ ์ œ์•ฝ, ์ง€๋ฆฌ์  ์ผ์น˜(๋ธ”๋ก ๊ตญ๊ฐ€)
  • DDoS ๋ณดํ˜ธ๋ฅผ ์œ„ํ•œ ์†๋„๊ธฐ๋ฐ˜ ๊ทœ์น™ (์ด๋ฒคํŠธ ๋ฐœ์ƒ ํšŸ์ˆ˜ ๊ณ„์‚ฐ)

AWS Firewall Manager

  • AWS ์กฐ์ง์˜ ๋ชจ๋“  ๊ณ„์ • ๊ทœ์น™์„ ๊ด€๋ฆฌ
  • ๊ณตํ†ต ๋ณด์•ˆ ๊ทœ์น™ ์ง‘ํ•ฉ
  • WAF ๊ทœ์น™ : (Application Load Balancer, API Gateways, CloudFront)
  • AWS Shield Advanced (ALB, CLB, Elastic IP, CloudFront)
  • VPC์˜ EC2 ๋ฐ ENI ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ Security Group

Amazon GuardDuty

  • AWS ๊ณ„์ • ๋ณดํ˜ธ๋ฅผ ์œ„ํ•œ ์ง€๋Šฅํ˜• ์œ„ํ˜‘ ๊ฒ€์ƒ‰
  • ๋จธ๋‹ ๋Ÿฌ์‹  ์•Œ๊ณ ๋ฆฌ์ฆ˜, ์ด์ƒ ์ง•ํ›„ ๊ฐ์ง€, 3rd party ๋ฐ์ดํ„ฐ ์ด์šฉ
  • ํด๋ฆญ ํ•œ ๋ฒˆ์œผ๋กœ ํ™œ์„ฑํ™” (30์ผ ํ‰๊ฐ€ํŒ), ์†Œํ”„์œผ์›จ์„œ ์„ค์น˜ ๋ถˆํ•„์š”
  • ์ž…๋ ฅ์—๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฐ์ดํ„ฐ๊ฐ€ ํฌํ•จ
    • CloudTrail Events Logs : ๋น„์ •์ƒ์ ์ธ API ํ˜ธ์ถœ, ๋ฌด๋‹จ ๋ฐฐํฌ
      • CloudTrail Management Events : VPC ์„œ๋ธŒ๋„ท ์ƒ์„ฑ, create trail ๋“ฑ
      • CloudTrail S3 Data Events : GetObject, ListObject, DeleteObject ๋“ฑ
    • VPC Flow : ๋น„์ •์ƒ์ ์ธ ๋‚ด๋ถ€ ํŠธ๋ž˜ํ”ฝ, ๋น„์ •์ƒ์ ์ธ IP ์ฃผ์†Œ
    • DNS Log : DNS ์ฟผ๋ฆฌ ๋‚ด ์•”ํ˜ธํ™”๋œ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•˜๋Š” EC2 ์ธ์Šคํ„ด์Šค์˜ ์†์ƒ
    • Kubernetes Audit Log : ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ™œ๋™๊ณผ EKS ํด๋Ÿฌ์Šคํ„ฐ ์†์ƒ ๊ฐ€๋Šฅ์„ฑ
  • ๋ฐœ๊ฒฌ ์‹œ ์•Œ๋ฆผ์„ ๋ฐ›์„ CloudWatch Event rules ์„ค์ • ๊ฐ€๋Šฅ
  • CloudWatch Events rule์€ AWS Lambda or SNS๋ฅผ ๋Œ€์ƒ์œผ๋กœ ํ•  ์ˆ˜ ์žˆ๋‹ค
  • CryptoCurrency Attacks ๊ณต๊ฒฉ์œผ๋กœ๋ถ€ํ„ฐ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Œ /posts/images/aws/guard-duty.png

Amazon Inspector

  • ์ž๋™ํ™”๋œ ๋ณด์•ˆ ํ‰๊ฐ€
Tip

For EC2 instance

  • AWS System Manager(SSM) agent ํ™œ์šฉ
  • ์˜๋„ํ•˜์ง€ ์•Š์€ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ๊ฐ€๋Šฅ์„ฑ์— ๋Œ€ํ•œ ๋ถ„์„
  • ์‹คํ–‰์ค‘์ธ OS์˜ ์•Œ๋ ค์ง„ ์ทจ์•ฝ์„ฑ ๋ถ„์„

For Containers push to Amazon ECR

  • ECR ์ปจํ…Œ์ด๋„ˆ์— push์— ๋Œ€ํ•œ ๋ถ„์„
  • AWS Security Hub์™€ ๋ณด๊ณ  ๋ฐ ํ†ตํ•ฉ
  • Amazon Event Bridge ๊ฒฐ๊ณผ ์ „์†ก

AWS Inspector๊ฐ€ ํ‰๊ฐ€ํ•˜๋Š” ๊ฒƒ๋“ค

  • EC2 ์ธ์Šคํ„ด์Šค ๋ฐ ์ปจํ…Œ์ด๋„ˆ infrastructure ๋งŒ ํ•ด๋‹น
  • ํ•„์š”ํ•œ ๊ฒฝ์šฐ์—๋งŒ ์ธํ”„๋ผ์˜ ์ง€์†์ ์ธ ๊ฒ€์ƒ‰
  • ํŒจํ‚ค์ง€ ์ทจ์•ฝ์„ฑ (EC2 & ECR) - CVE ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค
  • Network reachability (EC2)
  • ์œ„ํ—˜ ์ ์ˆ˜๋Š” ์šฐ์„ ์ˆœ์œ„ ์ง€์ •์— ๋Œ€ํ•œ ๋ชจ๋“  ์ทจ์•ฝ์„ฑ๊ณผ ์—ฐ๊ฒฐ

Amazon Macie

  • ๋จธ์‹ ๋Ÿฌ๋‹๊ณผ ํŒจํ„ด ๋งค์นญ์„ ํ™œ์šฉํ•ด AWS์˜ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๊ฒ€์ƒ‰ ๋ฐ ๋ณดํ˜ธํ•˜๋Š” ์™„์ „ ๊ด€๋ฆฌํ˜• ๋ฐ์ดํ„ฐ ๋ฒ ์ด์Šค ๋ณด์•ˆ ๋ฐ ํ”„๋ผ์ด๋ฒ„์‹œ ์„œ๋น„์Šค
  • ๊ฐœ์ธ ์‹๋ณ„ ๊ฐ€๋Šฅ ์ •๋ณด (personally identifiable information-PII)์™€ ๊ฐ™์€ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์‹๋ณ„ํ•˜๊ณ  ๊ฒฝ๊ณ ํ•˜๋„๋ก ๋„์™€์คŒ

AWS ๊ณต์œ ์  ์ฑ…์ž„ ๋ชจ๋ธ

  • AWS์˜ ์ฑ…์ž„

    • ํด๋ผ์šฐ๋“œ์˜ ๋ณด์•ˆ
    • ๋ชจ๋“  AWS ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ธํ”„๋ผ(hardware, software, facilities, and networking) ๋ณดํ˜ธ
    • S3, DynamoDB, RDS ๋“ฑ๊ณผ ๊ฐ™์€ ๊ด€๋ฆฌํ˜• ์„œ๋น„์Šค
  • ๊ณ ๊ฐ์˜ ์ฑ…์ž„

    • ํด๋ผ์šฐ๋“œ ๋‚ด ๋ณด์•ˆ
    • EC2 ์ธ์Šคํ„ด์Šค์˜ ๊ฒฝ์šฐ ๊ณ ๊ฐ์€ ๊ฒŒ์ŠคํŠธ OS(๋ณด์•ˆ ํŒจ์น˜ ๋ฐ ์—…๋ฐ์ดํŠธ ํฌํ•จ), ๋ฐฉํ™”๋ฒฝ ๋ฐ ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ, IAM์„ ๊ด€๋ฆฌํ•ด์•ผ ํ•จ
    • ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”
  • ๊ณต์œ  : ํŒจ์น˜ ๊ด€๋ฆฌ, ๊ตฌ์„ฑ ๊ด€๋ฆฌ, ์ธ์‹ ๋ฐ ๊ต์œก

RDS์—์„œ ์ฑ…์ž„๋ชจ๋ธ

  • AWS์˜ ์ฑ…์ž„
    • ๊ทผ๋ณธ์ ์ธ EC2 ์ธ์Šคํ„ด์Šค ๊ด€๋ฆฌ SSH ์•ก์„ธ์Šค
    • ์ž๋™ํ™”๋œ DB ํŒจ์น˜
    • ์ž๋™ํ™”๋œ OS ํŒจ์น˜
    • ๊ทผ๋ณธ์ ์ธ ์ธ์Šคํ„ด์Šค ๋ฐ ๋””์Šคํฌ ๊ฐ์‚ฌ ๋ฐ ๊ธฐ๋Šฅ ๋ณด์žฅ
  • ๊ณ ๊ฐ์˜ ์ฑ…์ž„
    • DB Security Group์˜ ํฌํŠธ / IP / ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™ ํ™•์ธ
    • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋‚ด์˜ ์‚ฌ์šฉ์ž ์ƒ์„ฑ ๋ฐ ๊ถŒํ•œ
    • ๊ณต์šฉ ์ ‘๊ทผ ๊ถŒํ•œ ์œ ๋ฌด ๊ด€๊ณ„์—†์ด ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ž‘์„ฑ
    • ๋งค๊ฐœ ๋ณ€์ˆ˜ ๊ทธ๋ฃน ๋˜๋Š” DB๊ฐ€ SSL ์—ฐ๊ฒฐ๋งŒ ํ—ˆ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธ
    • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์•”ํ˜ธํ™” ์„ค์ •

S3์—์„œ ์ฑ…์ž„๋ชจ๋ธ

  • AWS์˜ ์ฑ…์ž„
    • ๋ฌด์ œํ•œ ์Šคํ† ๋ฆฌ์ง€์˜ ์ œ๊ณต์„ ๋ณด์žฅ
    • ์•”ํ˜ธํ™” ์ œ๊ณต์„ ๋ณด์žฅ
    • ์„œ๋กœ ๋‹ค๋ฅธ ๊ณ ๊ฐ๊ฐ„์˜ ๋ฐ์ดํ„ฐ ๋ถ„๋ฆฌ ๋ณด์žฅ
    • AWS ์ง์›์ด ๋ฐ์ดํ„ฐ์— ์•ก์„ธ์Šค ํ•  ์ˆ˜ ์—†๋„๋ก ๋ณด์žฅ
  • ๊ณ ๊ฐ์˜ ์ฑ…์ž„
    • Bucket์˜ ๊ตฌ์„ฑ
    • Bucket ์ •์ฑ… / ๊ณต์šฉ ์„ค์ •
    • IAM ์‚ฌ์šฉ์ž ๋ฐ ์—ญํ• 
    • ์•”ํ˜ธํ™” ์‚ฌ์šฉ

Shared Responsibility Model diagram

/posts/images/aws/Shared_Responsibility_Model_V2.59d1eccec334b366627e9295b304202faf7b899b.jpg
https://aws.amazon.com/ko/compliance/shared-responsibility-model/