AWSã®LightSailãå°ãå®ããªã£ã¦ããã RAM 1Gã§ã$5ãªã®ã§ã¨ã¦ãããããã ååã®ããã¼ãããã¯RAM 500Mã§å¶éãã¨ã¦ãå¤ãã£ãã®ã§ãã£ãã®ãã¨æåããä½ãç´ããã ä½ãã®ã«4æ¥ãããããã£ãããã®ä»£ããSystemdãrsyslogã¨ãè¥å¹²ãããããã«ãªã£ããããããã 便å®ä¸ãsuricataã¨ufwããããã£ã¦ãã¨ã«ãã¦ããã©è¨±ãã¦ãã ãããªã æ§æ AWSã®VPSã«åããã¼ãããçãè¨ç½®ãã¦ãããããS3ã«ãã£ããã¢ãããã¼ãã èªå® ã®PCã«ã¤ã³ã¹ãã¼ã«ããELKã«ã¦ãã°ãåéãã¦åæããã ååã¨æ¯ã¹ã¦ufwã¨dionaeaã追å ãããã 使ç¨ãããã® Suricata IDSã¨ãã¦åä½ã ã¢ã¯ã»ã¹ãä¸è¬çãªã·ã°ããã£ã«ãããããããã¨ã§ã©ã®ãããªæ»æãæ¥ãããããã¨ã§å¤æã§ããã Dionaea æ§ã ãªãã¼ãã«å¯¾ããã¢ã¯ã»ã¹ããã£ããã£ã§ããããã¼ããã
éè¨ç³»ããã°ãã»ãã¥ãªãã£ã¨ãããã¤ã«ã¨ããæè³ã¨ãããã / Miscellaneous Blogs. Security, miles, investments, etc ãã®ãã³ãå¼ç¤¾ãµã¼ãã¹ãSchoo for Businessï¼ä»¥ä¸ãæ¬ãµã¼ãã¹ãï¼ã«ããã¾ãã¦ãå¼ç¤¾ã®ã客æ§ã®å人ãã¼ã¿ããç¹å®æ¡ä»¶ä¸ã«ãããã客æ§éã§é²è¦§å¯è½ãªç¶æ ã«ãããããã«ããå人ãã¼ã¿ï¼ä¸»ã«æå±ä¼ç¤¾åã»æ°åï¼ãæ¼ãããã¦ãããã¨ãå¤æãããã¾ãããã客æ§ã«ã¯å¤§å¤ãå¿é ããããããäºæ ã¨ãªãã¾ãããã¨ãæ·±ããè©«ã³ç³ãä¸ãã¾ãã æ¬äºæ¡ã«ä¿ãç¾æç¹ã®èª¿æ»çµæã«ã¤ãã¦ã以ä¸ã®ã¨ãããå ±åç³ãä¸ãã¾ãã ãªããç¾æç¹ã§ã¯ãæ¬ä»¶ã«ãããæ¥ç¸¾äºæ³ã®å¤æ´ã¯ãããã¾ãããä»å¾é示ãã¹ãäºé ãçºçããå ´åã«ã¯éããã«ãç¥ãããããã¾ãã 1. æ¬ä»¶ã®æ¦è¦æ¬ãµã¼ãã¹ã«ã¦éåå¦ç¿æ©è½*1ããå©ç¨ããã ãéã2020å¹´3æ30æ¥ï½2
TL;DR AWSã®ããã¼ã¸ããµã¼ãã¹ãæ´»ç¨ãã¦ä½ã¤ã³ã¿ã©ã¯ã·ã§ã³åã®ããã¼ãããç°å¢ãä½ã£ã ã³ã¹ããæã ç´$15ã§éç¨å¯è½ ã³ãã³ã3åãããã§èª°ã§ããããã¤ã§ããããã«ãªã£ã¦ããã®ã§èå³ãããã°ä½¿ã£ã¦ã¿ã¦ããã㪠èæ¯ AWSã«ç½®ãä½ã¤ã³ã¿ã©ã¯ã·ã§ã³åããã¼ãããï¼synã«å¯¾ãã¦synackã ãè¿ãã¦å¾ã¯éããã¦ããéä¿¡ãç£è¦ãããã¤ï¼ãä»ãªãã·ã£ããã¨ã¹ããã¨å®è£ ã§ãããã ãããªãããã¨éå»ã®ã¯ã½å®è£ ãæãåºãã¦æ¶çµ¶ãã¦ãâ Masayoshi MIZUTANI (@m_mizutani) 2019å¹´2æ1æ¥ ã¨ããæãã§æã¯ã©ã¦ãä¸ã§éç¨ãã¦ããããã¼ãããã®ãã¨ããµã¨æãåºããã®ã§ãããä»äºã§å¤å°AWSã®ãµã¼ãã¹ãç解ããä»ã ã£ããããã¡ãã£ã¨ã¾ã¨ãã«å®è£ ã§ãããã ããªããå®è£ ãããªãã¤ã³ã¹ã¿ã³ã¹ã§å®çµããããããªãã¦ã¯ã©ã¦ãã®ããã¼ã¸ããµã¼ãã¹ã¡ããã¨ä½¿ã£ã¦æ¶èããªãä½ãã«ã
æ¦è¦ åå¿é²ãå ¼ãã¦AWSä¸ã®EC2ã«ä½ã¤ã³ã¿ã©ã¯ã·ã§ã³åã®ããã¼ãããï¼å®éã«ä¾µå ¥ãªã©ã¯ãããã«æ»æãã¼ã¿ã®åéãããããã¼ãããï¼ã®æ§ç¯æ¹æ³ãã¾ã¨ãã¾ããæ§æã¨ãã¦ã¯ä»¥ä¸ã®ããã«ãªãã¾ãã æåãããã¼ããããéç¨ãã¦ããæã¯ãã¡ãã¡ã¹ã¯ãªãããæ¸ãã¦ãããã調ã¹ã¦ãã¾ããããããå æ¸é¢åããããªã£ã¦ããã®ã§ãããã®ã®ã¤ã³ã¿ã¼ãã§ã¼ã¹ã¨ãã¦Kibanaã使ããã¨ã«ãã¾ããã ã¤ã³ã¹ã¿ã³ã¹ã¯ããç¹æ®ãªæ§æã§ãããã¼ã¸ã¡ã³ãã¨ãã¦ä½¿ãããã©ã«ãNICã®eth0ã®ä»ã«ã観測ç¨ã®NICï¼eth1ï¼ã¨ã°ãã¼ãã«ã¢ãã¬ã¹ã追å ãã¦è¦³æ¸¬ãã¼ã¿ã«ä½è¨ãªãã¼ã¿ãæ··ããªãããã«ãã¾ããeth1ã«ã¯IPã¢ãã¬ã¹ã¯å²ãå½ã¦ããOSã¯ä¸åã®å¿çããã¾ããããããã¼ãããã½ããã¦ã§ã¢ãé©åã«ARPãTCPã®å¿çãªã©ãè¿ããã¨ã«ãã£ã¦è¿½å ã§å²ãå½ã¦ãã°ãã¼ãã«ã¢ãã¬ã¹ã«å¯¾ããæ»æããã£ããã£ãã¾ãã ãã°ãã¼ã¿ã¯f
ååã®ãããã 3å¹´ã»ã©åã«AWSä¸ã«ããã¼ãããç°å¢ãä½æãã¾ããã 大éæã«èª¬æããã¨ãï¼ä¸»ã«ï¼AWSã®EC2ã¤ã³ã¹ã¿ã³ã¹ãã¦ã«ã©ã®ãããªexploitãé£ãã§ããã®ãï¼ã¨ããã®ãç¥ãããã«ã EC2ã¤ã³ã¹ã¿ã³ã¹ã«ç®¡çç¨ãããã³è¦³æ¸¬ç¨ã®Elastic IP addressãè¨å®ããããã§ããã¼ããããåãã ããã¼ãããã§åå¾ããçãã¼ã¿ï¼pcapï¼ãS3ã«ä¿åããLambdaã§åæãã åæçµæ㯠CloudWatch Logs Insights ã§é²è¦§ã§ããããã«ãã ã¨ããæ§æã«ãã¦ãã¾ãããããã¯ããã§ããã¼ã¸ããµã¼ãã¹ã使ã£ãé¢ç½ãæ§æã ã£ãã¨å½æã¯æã£ã¦ããã®ã§ãããå®éã«åããã¦ã¿ãã¨ããã¤ãã®èª²é¡ããããæçµçã«ã¯éç¨ãæ¢ãã¦ãã¾ãã¾ããã ååã®èª²é¡ 1) Elastic IP addressã®å¶éã§ã¹ã±ã¼ã«ãã«ãã EC2ã¯èªåã§2ã¤ä»¥ä¸ã®ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}