Case Study for Repurposing Video Content With Generative AI / AWS Community Day Taiwan 2024
Sophosã¯8æ22æ¥(è±å½æé)ããQilin ransomware caught stealing credentials stored in Google Chrome â Sophos Newsãã«ããã¦ãã©ã³ãµã ã¦ã§ã¢ãQilinãã«ãã侵害ã調æ»ããä¸ã§ãGoogle Chromeã«ä¿åãããèªè¨¼æ å ±ã大éã«çªåããæ»æã確èªããã¨ä¼ããã2024å¹´7æã«ç¢ºèªããããã®äºæ¡ã§ã¯ãActive Directoryã®ãã¡ã¤ã³ã³ã³ããã¼ã©ããã°ã«ã¼ãããªã·ã¼ãªãã¸ã§ã¯ã(GPO: Group Policy Object)ã使ç¨ãã¦æªæã®ããã¹ã¯ãªããããã¡ã¤ã³åå 端æ«ãã¹ã¦ã«é å¸ãã¦å®è¡ããã¨ãããã Qilin ransomware caught stealing credentials stored in Google Chrome â Sophos News 侵害çµè·¯ åæã¢
è±èªã®ãAuthenticationããæ´çãã ããããã¯å ã»ã©ã®åé¡ã§è¨ãã¨ããã®ãã¦ã¼ã¶èªè¨¼ãã¨ãã¦ã®ãèªè¨¼ããã¤ã¾ãè±èªã®ãAuthenticationãã«è©²å½ãããèªè¨¼ãã«ã¤ãã¦ãããã«æ´çãé²ãã¦ããã¾ãã å ã»ã©ããã¦ã¼ã¶èªè¨¼ãããã·ã¹ãã ãå©ç¨ãããã¨ãã¦ããã¦ã¼ã¶ããã·ã¹ãã ã«ç»é²æ¸ã¿ã®ã¦ã¼ã¶ãã©ããèå¥ããã¦ã¼ã¶ã主張ãã身å ãæ¤è¨¼ããããã»ã¹ãã¨èª¬æãã¾ããããã¦ã¼ã¶ã®èå¥ãã¨ã身å ã®æ¤è¨¼ãã¯ã¦ã¼ã¶èªè¨¼ã«æ¬ ããã¾ããããå®éã¯ä»ã«ããã¦ã¼ã¶ã®æå¹ï¼ç¡å¹ç¶æ ã®ç¢ºèªãããæ¤è¨¼ã«æåããå ´åã®èº«å ã®ä¿è¨¼ï¼ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®çºè¡çï¼ããªã©ã®å¦çãä¸è¬çã«ã¦ã¼ã¶èªè¨¼ã®ããã»ã¹ã«ã¯å«ã¾ãã¾ãã ããã§åé ã®ãââèªè¨¼ããæ¯ãè¿ãã¾ãããããã¹ã¯ã¼ãèªè¨¼ãSMSèªè¨¼ãæç´èªè¨¼ãé¡èªè¨¼ã¯å®ã¯ããã§è¨ãã¦ã¼ã¶èªè¨¼ã«ã¯è©²å½ãããã¦ã¼ã¶èªè¨¼ä¸ã®ä¸å¦çã§ããã身å ã®æ¤è¨¼ããæ ã£ã¦ãããã¨ãã
2024å¹´4æ25æ¥ç´ççºå£² 2024å¹´4æ25æ¥é»åççºå£² å¸ååµï¼æ¿ååºæãè A5å¤ï¼456ãã¼ã¸ å®ä¾¡3,740åï¼æ¬ä½3,400åï¼ç¨10%ï¼ ISBN 978-4-297-14178-3 Gihyo Direct Amazon 楽天ããã¯ã¹ 丸åã¸ã¥ã³ã¯å æ¸åº ã¨ããã·.com é»åç Gihyo Digital Publishing Amazon Kindle ããã¯ã©ã¤ã 楽天kobo honto æ¬æ¸ã®ãµãã¼ããã¼ã¸ãµã³ãã«ãã¡ã¤ã«ã®ãã¦ã³ãã¼ããæ£èª¤è¡¨ãªã© ãã®æ¬ã®æ¦è¦ SSL/TLSã¯ï¼éä¿¡ã®ç§å¯ãå®ãããã«å©ç¨ããã¦ããéä¿¡ãããã³ã«ã§ããHTTPSãHTTP/3ã«ãå©ç¨ããã¦ããï¼ä»æ¥ã®Webã§ã¯å©ç¨ãä¸è¬çã«ãªã£ã¦ãã¾ããæ¬æ¸ã§ã¯ï¼ãã®ææ°ãã¼ã¸ã§ã³ã§ããTLS 1.3ã®ããã¿ã¨ï¼ãã®ä½¿ãæ¹ã解説ãã¾ããSSL/TLSã¯å ¬éããã¦ããå®è£ ä¾ãªã©ãçä¼¼ããã°åºæ¬ç
éµããã£ã±ãããããã®è¨äºã¯ Eureka Advent Calendar 2021 ã® 13æ¥ç®ã®è¨äºã§ãã ã¯ããã«ããã«ã¡ã¯ãã¨ã¦ã¬ã« SREãã¼ã ã®ãã©ãã§ãï¼ 2020å¹´é ããä»å¹´ã«ããã¦ã ã¨ã¦ã¬ã«ã®SREãã¼ã ã¨Securityãã¼ã ã§ã¯AWS IAMã®ã»ãã¥ã¢åã注åãã¤ã³ãã®ã²ã¨ã¤ã¨ãã¦ãç¶ç¶çã«åãçµãã§ãã¾ããã æ¬è¨äºã§ã¯ããã®å®è·µããå¦ãã§ããIAM管çã§å®ãã¹ã大ååããã³ãå ·ä½çã«ã©ããã£ã¦ã»ãã¥ã¢ãªçæ³åã«è¿ã¥ãã¦ããããä»å¾ã®æ¹åæ§ãªã©ã話ãããã¨æãã¾ãã Why âIAMâ so important ?ãããããªãã§IAMã注åãã¤ã³ããªã®ï¼ã¨çåã«æãããæ¹ãããã§ãããã ã¯ã©ã¦ãã®å¤§ããªå¼·ã¿ã§ããããã¹ã¦ãAPIçµç±ã§æä½ã§ãããã¨ããæ§è³ªããã«ãIAMã¯å¤§ããªAttack Surfaceã§ãããã¾ãã Gartner社ã®äºæ¸¬ã«ããã¨ã2023
ã¯ããã« å人ã§ãä»äºã§ãAWSã使ã£ã¦ããæã«æ°ã«ãªãã®ã¯ã»ãã¥ãªãã£ã§ãããã ä¸ãä¸ã¢ã¯ã»ã¹ãã¼ãªã©ãæ¼ãã¦ãã¾ãããããä½ã§ãåºæ¥ã¡ããã¦ã¼ã¶ã¼ã ã£ãã ãã大å¤ãªãã¨ã«ãªãã¾ãã ãã AWSã®IAMã¯AWSã®ä¸ã§ãä¸çªé£ãããµã¼ãã¹ãªã®ã§ã¯ï¼ã¨æããããè¤éã§ãã ãã®ä¸ã§ãç°¡åã§ããã«ãå®è·µåºæ¥ãTipsã4ã¤ç´¹ä»ãã¾ãã ç®æ¬¡ MFAèªè¨¼ãã¦ãªãæã®æ¨©éãæå°ã«ãã IAMã¦ã¼ã¶ã¼ã®MFAããã¤ã¹ãæå¹åãã ã¦ã¼ã¶ã¼ã«æ¨©éãå§ä»»ãããã¼ã«ãä½æãã CLIã使ãæããMFAèªè¨¼ãã¦ãã¼ã«ãåãæ¿ãã 1. MFAèªè¨¼ãã¦ãªãæã®æ¨©éãæå°ã«ãã ã¾ããä¸è¨ã®ããªã·ã¼ãä½æ¥ç¨ã®ã¦ã¼ã¶ã¼ã«ç´ä»ãã¾ãã { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "iam:ListVirtu
ç¾å¨ç§ã¯ barista ã¨ãã OpenID Connect 㨠OAuth2.0 ã«æºæ ããID製åã®å®è£ ãè¡ã£ã¦ãã¾ãã ã¾ããç§ã®æå±ããäºæ¥éçºé¨ã§ã¯ prismatix ã¨ããECãCRM ã® API 製åã®éçºãè¡ã£ã¦ãã¾ããããã® prismatix ã®èªå¯ãµã¼ãã¼ã¨ã㦠barista ãå©ç¨ãã¦ãã¾ãã barista ãã¼ã ã®å¢å¡ããprismatix ã®èªå¯ã«ã¤ãã¦ã®ç解ãä¿é²ãããã OAuth 2.0 ãããç¨åº¦ãã£ããã¨ç解ãã¦ããã¡ã³ãã¼ãå¢ããããã£ãã®ã§ãåå¼·ä¼ãéå¬ãã¾ããã åå¼·ä¼ã®å 容 æ¦è¦ é°å²æ°ã§OAuth2.0ã使ã£ã¦ããã¨ã³ã¸ãã¢ãOAuth2.0ãæ´çãã¦ãæãåãããªããå¦ã¹ãæ¬ãå ¨å¡ã§è¼ªèª OIDC ç·¨ã¯ãã®ãã¨ããäºå® æ»æç·¨ããããã RFC èªãã ããããã åå è å ¨å¡ã以ä¸ãæºãããã¨ãç®æ¨ OAuth 2.0 ã®æå³ãç解
Cognitoã£ã¦æ°è¦ã¦ã¼ã¶ã¼ç»é²ç»é¢ããµã¤ã³ã¤ã³ç»é¢ãããã°ã©ãã³ã°ããã¤ã¡ã¼ã¸ããã£ã¦ãéããã°ã©ãã¼ã«ã¯æ·å± ãé«ããã ããªãâ¦â¦ããããªããªãã®ããã«ããã®ããã°ãæ¸ãã¾ãããCognitoã®æ·å± ãã¡ãã£ã¨ä¸ãããããããã°ã©ãã³ã°ç¡ãã§Cognitoã試ãã¦ã¿ã¾ãã Amazon Cognitoã£ã¦ã¦ã¼ã¶ã¼èªè¨¼ãããã¼ã¸ãã«ç®¡çãã¦ããããµã¼ãã¹ã§ããã£ã¦ã¿ãããã©ã æ°è¦ã¦ã¼ã¶ã¼ç»é²ç»é¢ããµã¤ã³ã¤ã³ç»é¢ãããã°ã©ãã³ã°ããã¤ã¡ã¼ã¸ããã£ã¦ãéããã°ã©ãã¼ã«ã¯æ·å± ãé«ããã ããªãâ¦â¦ã ãããªããªãã®ããã«ããã®ããã°ãæ¸ãã¾ããã Cognitoã®æ·å± ãã¡ãã£ã¨ä¸ãããããããã°ã©ãã³ã°ç¡ãã§Cognitoã試ãã¦ã¿ã¾ãã è¦ããã«ãAWS CLIã§Cognitoã使ãæé ãç´¹ä»ãã¾ãã Cognitoã®æ©è½èªä½ã¯ãå¼ç¤¾ããã°ã§è©³ãã解説ãã¦ããã®ã§ãã²ãã¡ãã御覧ãã ããã A
All slide content and descriptions are owned by their creators.
Basicèªè¨¼ã¨OAuthã¨ãã®è¾ºã®æ å ±ã«ã¤ãã¦æ´çãã¦ãããOAuthãèªè¨¼ã»èªå¯ã«ã¤ãã¦èª¬æãããã¨ããã¨ã1æåè¨è¿°ãããã³ã«èª¤ããå«ã¾ãã¦ãã¾ãå¯è½æ§ãããã®ã§ãæ¬å½ã«ç·å¼µæãæã£ã¦è¨è¿°ããªããã°ãªããªããããã§ããªãããã®æç« ã«ã¯ããããã®èª¤ããå«ã¾ãã¦ããã Usernameã¨Passwordãåãåã£ã¦èªè¨¼ããå½¢å¼ã®èªè¨¼æ¹æ³ãUsernameã«ã¯Emailã使ããã¨ããã (è¦ã¯å ¨ã¦ã¼ã¶ã®ä¸ã§ä¸æãªãã¨ãä¿è¨¼ããã¦ãã¦ãã¤ä»ã®äººããã®å¤ãç¥ã£ã¦ãã¦ãç¹ã«åé¡ããªãã¨ããæ å ±ã§ããã°OK)ãPasswordã¯æ¬äººããç¥ãå¾ãªãæ å ±ã OAuthã¨ããä»æ§ã«åã£ã¦æä¾ãããèªå¯æ¹æ³ãå¤ãOAuth 1.0ã¨ãOAuth 1.0ã®è¤éãªã¨ãããªã©ãæ¹åããOAuth 2.0ããããä¸è¬çã«ã¯OAuth 2.0ã使ããã¨ãå¤ãããä¾ãã°å¹¾ã¤ãã®ãµã¼ãã¹ã®æä¾ãã¦ããèªå¯æ¹æ³ã¯OAut
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}