- ã¯ããã«
- æ§æå³
- ï¼åèï¼Amazon Bedrockã®æé試ç®ä¾(æ±äº¬ãªã¼ã¸ã§ã³/Anthropic Claude 3.5 Sonnetã¢ãã«)
- Amazon Bedrockã«ããè¦ç´
- New Relicã¸éããããã°ä¾
- ä½æããããã·ã¥ãã¼ã
- å人çã«æãããã¨
- ã¾ã¨ã
- 宣ä¼
ã¯ããã«
ããã«ã¡ã¯ãããã¼ã¸ããµã¼ãã¹é¨ã®ç¦ç°ã§ãã
ã¿ãªããã¯ã»ãã¥ãªãã£ã¤ãã³ããã©ã®ããã«å¯è¦åããã¦ãã¾ããï¼
以åã以ä¸ã®ããã°ã§ã»ãã¥ãªãã£ã¤ãã³ãã®å¯è¦åã«ã¤ãã¦åãçµãã ã®ã§ãã
ã¤ãã³ããçºçãããã¨ã¯åãã£ã¦ãããã®å¾ã®å
·ä½çãªã¢ã¯ã·ã§ã³ãåããã¥ããçµå±AWSã®ã³ã³ã½ã¼ã«ç»é¢ã«å
¥ã£ã¦ç¢ºèªãããªã©
ããã·ã¥ãã¼ãä¸ã§ãä½ãçºçããã®ãããä½ãããã°ããã®ããã®æµããä¸æãå®çµåºæ¥ãªã課é¡ããããè¨ç»ãé絶ãã¦ãã¾ããã
ãã æè¿ãAmazon Bedrockãæ´»ç¨ãã¦ã¤ãã³ãæ
å ±ãè¦ç´ãããããå¯è¦åãããã¨ã§ãã®èª²é¡ã解決ã§ããã®ã§ã¯ãªããã¨æããå®è·µãã¦ã¿ã¾ããã
æ¬ããã°ã§ã¯ãã®åãçµã¿ã«ã¤ãã¦ãç´¹ä»ãã¾ãã
æ§æå³
å®ç¾ããã«ããã£ã¦ä»¥ä¸æ§æãæ³å®ãã¾ããã
æ¬ããã°ã§ã¯Lambdaã使ç¨ãã¦å¯è¦åããå
容ã«ã¤ãã¦ãç´¹ä»ãã¾ãã
Step Functionã§ãNew Relicã¸ãã¼ã¿ãéããã¨ã¯åºæ¥ã¾ããããã¼ã¿ã®æ§é åãä¸æããããªãã£ãã®ã§
Step Functionã¯å¾æ¥æ¹è¯ãã¦Lambdaã¨åããããªå
容ãå®ç¾ã§ããããã«ããäºå®ã§ãã
ã¡ãªã¿ã«ä»¥ä¸æ§æã§New Relicã¸ãã¼ã¿ãéããã¨ã¯åºæ¥ã¾ããã
ï¼æ§é åããã¤ããã§ããã¾ããã¼ã¿æ§é åãã§ããªãã£ãã¯æããï¼
ï¼åèï¼Amazon Bedrockã®æé試ç®ä¾(æ±äº¬ãªã¼ã¸ã§ã³/Anthropic Claude 3.5 Sonnetã¢ãã«)
Amazon Bedrockã¯ã主ã«2ã¤ã®æéã¢ãã«ãããã¾ãã
ãªã³ããã³ãä¾¡æ ¼:
- å©ç¨ããåã ãæ¯æãæè»ãªæéä½ç³»ã
- å ¥åãã¼ã¯ã³ã¨åºåãã¼ã¯ã³ãã¨ã«èª²éããã¾ãã
ãããä¾¡æ ¼:
- 大éå¦çåãã«50%å²å¼ãããæéã
- ãããå¦çã¯ãå ¥åãã¼ã¯ã³ã¨åºåãã¼ã¯ã³ããããã§å²å¼ãé©ç¨ããã¾ã
æé詳細
å©ç¨å½¢å¼ | 1,000å ¥åãã¼ã¯ã³ãããã®æé | 1,000åºåãã¼ã¯ã³ãããã®æé | åè |
---|---|---|---|
ãªã³ããã³ã | $0.003 | $0.015 | æ¨æºæé |
ãããå¦ç | $0.0015 | $0.0075 | 50%å²å¼ |
ãã£ãã·ã¥æ¸ã込㿠| $0.00375 | N/A | æ¸ãè¾¼ã¿æã®ã¿èª²é |
ãã£ãã·ã¥èªã¿åã | $0.0003 | N/A | èªã¿åãæ90%å²å¼ |
試ç®ä¾
ãªã³ããã³ãå©ç¨ã®å ´å
å ¥åãã¼ã¯ã³æ° | åºåãã¼ã¯ã³æ° | å ¥åã³ã¹ã ($) | åºåã³ã¹ã ($) | åè¨ã³ã¹ã ($) |
---|---|---|---|---|
10,000 | 5,000 | 0.03 | 0.075 | 0.105 |
100,000 | 50,000 | 0.30 | 0.75 | 1.05 |
ãããå¦çã®å ´å
å ¥åãã¼ã¯ã³æ° | åºåãã¼ã¯ã³æ° | å ¥åã³ã¹ã ($) | åºåã³ã¹ã ($) | åè¨ã³ã¹ã ($) |
---|---|---|---|---|
10,000 | 5,000 | 0.015 | 0.0375 | 0.0525 |
100,000 | 50,000 | 0.15 | 0.375 | 0.525 |
Amazon Bedrockã«ããè¦ç´
å©ç¨ããçæAIã¢ãã«
Anthropic Claude 3.5 Sonnetã¢ãã«ã使ç¨ãã¾ããã
Bedrockã«ããè¦ç´ã®æµã
- AWS Security Hubããã®æ
å ±åå¾
- ç¹å®æ¡ä»¶ï¼ä¾: ã³ã³ãã©ã¤ã¢ã³ã¹ã¹ãã¼ã¿ã¹ããFAILEDããéè¦åº¦ããCRITICALãã¾ãã¯ãHIGHããªã©ï¼ã«åºã¥ãæ¤åºçµæãåå¾ã
- Bedrockã§ã®è§£æ
- ã¤ãã³ãå 容ãè¦ç´ããæ¨å¥¨ããã対å¿æ¹éãJSONå½¢å¼ã§åºåã
- New Relicç¨ãã©ã¼ãããã¸ã®å¤æ
- è¦ç´çµæãNew Relicãã°å½¢å¼ã«æ´å½¢ã
- New Relicã¸ã®éä¿¡
- æ´å½¢æ¸ã¿ãã°ãNew Relicã«éä¿¡ããããã·ã¥ãã¼ãä¸ã§å¯è¦åã
Lambdaå®è¡æã®ãã°
New Relicã¸éããããã°ä¾
New Relicã¸éãããæ å ±ã¨ãã¦Bedrockå¦çãã¼ã¿ã¯ãbedrock.xxxãSecurity Hubããåå¾ããæ å ±ã¯ãaws.xxxãã¨æ確åãã¦ããã¾ãã
{ "aws.accountId": "xxxx", "aws.associatedStandards": "[]", "aws.complianceStatus": "N/A", "aws.description": "A process is querying a domain name associated with a known Command & Control server.", "aws.findingId": "arn:aws:guardduty:ap-northeast-1:xxxx:detector/8cbf263a94caaf7bea2e0496d87b6897/finding/2d07b45bf63d4e2b97ea3653e54979ae", "aws.lastUpdatedAt": "2025-01-02T12:26:01.458Z", "aws.message": "N/A", "aws.productName": "GuardDuty", "aws.region": "ap-northeast-1", "aws.resourceArn": "[\"N/A\"]", "aws.resourceId": "[\"arn:aws:ec2:ap-northeast-1:xxxx:instance/i-99999999\"]", "aws.resourceType": "[\"AwsEc2Instance\"]", "aws.service": "SecurityHub", "aws.severity": "HIGH", "aws.title": "A Command & Control server domain name was queried by EC2 instance i-99999999.", "bedrock.impact": "ãã®æ´»åã¯ãEC2ã¤ã³ã¹ã¿ã³ã¹ãæªæã®ããã¢ã¯ã¿ã¼ã«å¶å¾¡ããã¦ããå¯è½æ§ã示ãã¦ããããã¼ã¿æ¼æ´©ããããªãæ»æã®æ¡å¤§ã«ã¤ãªããæããããã¾ãã", "bedrock.productName": "GuardDuty", "bedrock.recommendation": "1. 該å½ã®EC2ã¤ã³ã¹ã¿ã³ã¹ãå³æã«éé¢ãããããã¯ã¼ã¯ããåãé¢ãã¦ãã ããã\n2. ãã©ã¬ã³ã¸ãã¯èª¿æ»ãå®æ½ãããã«ã¦ã§ã¢ã®æç¡ãä¾µå ¥çµè·¯ãç¹å®ãã¦ãã ããã\n3. ã¤ã³ã¹ã¿ã³ã¹ã®ã¤ã¡ã¼ã¸ãåå¾ãã詳細ãªåæãè¡ã£ã¦ãã ããã\n4. å¿ è¦ã«å¿ãã¦ãã¤ã³ã¹ã¿ã³ã¹ãçµäºããã¯ãªã¼ã³ãªç¶æ ããåæ§ç¯ãããã¨ãæ¤è¨ãã¦ãã ããã\n5. ã»ãã¥ãªãã£ã°ã«ã¼ãã¨NACLãè¦ç´ããä¸è¦ãªéä¿¡ãå¶éãã¦ãã ããã\n\nAWSå ¬å¼ããã¥ã¡ã³ã:\nhttps://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html", "bedrock.severity": "HIGH", "bedrock.summary": "EC2ã¤ã³ã¹ã¿ã³ã¹(i-99999999)ãæ¢ç¥ã®Command & Control (C&C)ãµã¼ãã¼ã®ãã¡ã¤ã³åã«å¯¾ãã¦DNSã¯ã¨ãªãå®è¡ãã¾ãããããã¯æ½å¨çãªãã«ã¦ã§ã¢ææãã»ãã¥ãªãã£ä¾µå®³ã示åãã¦ãã¾ãã", "logtype": "security-findings", "newrelic.source": "api.logs", "plugin.version": "1.0.0", "service": "AWS Security Hub", "timestamp": 1736235445163, }
ä½æããããã·ã¥ãã¼ã
以ä¸ã®ãããªæ å ±ãå¯è¦åããããã·ã¥ãã¼ããä½æãã¾ããã
ããã·ã¥ãã¼ãå 容
- ã¤ãã³ãçºçæ°ããã³ãªã½ã¼ã¹å²å
- ã¤ãã³ãçºçæ°ã®æ¨ç§»
- çºçããã¤ãã³ãã®è©³ç´°æ å ±
ããã·ã¥ãã¼ãå¤æ°ã®ä½¿ç¨
AWSã¢ã«ã¦ã³ããã¤ãã³ãã¬ãã«ãã¨ã«è¡¨ç¤ºå 容ãåãæ¿ããããããã«ãã¾ããã
ã¤ãã³ãçºçæ°ããã³ãªã½ã¼ã¹å²åã®ææ¡
çºçããã¤ãã³ãã®è©³ç´°æ å ±
以ä¸æ å ±ã確èªå¯è½ã§ãã
æ¦è¦ï¼Toråºå£ãã¼ãIPã¢ãã¬ã¹ããKubernetes APIãå¼ã³åºãããImpactï¼å½±é¿ï¼ã¿ã¯ãã£ã¯ã¹ã§ä¸è¬çã«ä½¿ç¨ãããAPIãå®è¡ããã¾ããã å¿ è¦ãªã¢ã¯ã·ã§ã³ä¾:1. 該å½ããKubernetesã¯ã©ã¹ã¿ã¼ã®ã»ãã¥ãªãã£è¨å®ã確èªããå¿ è¦ã«å¿ãã¦å¼·åãã¦ãã ããã 2. Toråºå£ãã¼ãããã®ã¢ã¯ã»ã¹ãå¶éããããã®ãããã¯ã¼ã¯ããªã·ã¼ãå®è£ ãã¦ãã ããã 3. Kubernetes APIãµã¼ãã¼ã®ãã°ã詳細ã«èª¿æ»ããä¸å¯©ãªã¢ã¯ãã£ããã£ããªãã確èªãã¦ãã ããã 4. IAMãã¼ã«ã¨Kubernetesã®RBACããªã·ã¼ãè¦ç´ããæå°æ¨©éã®ååã«å¾ã£ã¦è¨å®ãã¦ãã ããã AWS EKSã®ã»ãã¥ãªãã£ãã¹ããã©ã¯ãã£ã¹ã«ã¤ãã¦ã¯ã以ä¸ã®AWSå ¬å¼ããã¥ã¡ã³ããåç §ãã¦ãã ããï¼ https://docs.aws.amazon.com/eks/latest/userguide/security.html åé¡:æ»æè ãTorãããã¯ã¼ã¯ã使ç¨ãã¦Kubernetesã¯ã©ã¹ã¿ã¼ã«ã¢ã¯ã»ã¹ããæ½å¨çã«æ害ãªæä½ãå®è¡ãã¦ããå¯è½æ§ãããã¾ããããã«ããããã¼ã¿æ¼æ´©ããªã½ã¼ã¹ã®ä¸æ£ä½¿ç¨ãã¾ãã¯ã¯ã©ã¹ã¿ã¼ã®ç ´å£ãªã©ã®å½±é¿ãçããå¯è½æ§ãããã¾ãã }
以ä¸æ å ±ã確èªå¯è½ã§ãã
æ¦è¦:AWS Configãæå¹åããã¦ããªãããæ£ããè¨å®ããã¦ãã¾ãããããã«ãããAWSãªã½ã¼ã¹ã®è¨å®å¤æ´ã®è¿½è·¡ãç£æ»ãè¡ããã¦ããªãå¯è½æ§ãããã¾ãã å¿ è¦ãªã¢ã¯ã·ã§ã³ä¾:AWS Configãæå¹åãããã¹ã¦ã®ãªã½ã¼ã¹ãè¨é²ããããã«è¨å®ãã¦ãã ãããã¾ããAWS Configã®ãµã¼ãã¹ãªã³ã¯ãã¼ã«ã使ç¨ããããã«è¨å®ãã¦ãã ããã詳細ãªæé ã«ã¤ãã¦ã¯ã以ä¸ã®AWSå ¬å¼ããã¥ã¡ã³ããåç §ãã¦ãã ããï¼https://docs.aws.amazon.com/console/securityhub/Config.1/remediation åé¡:ãªã½ã¼ã¹ã®è¨å®å¤æ´ã®è¿½è·¡ãã§ãããã»ãã¥ãªãã£ãªã¹ã¯ãè¦å¶è¦ä»¶ã¸ã®éåãè¦éãå¯è½æ§ãããã¾ããã¾ããã¤ã³ã·ãã³ã対å¿ãåé¡è§£æ±ºãå°é£ã«ãªãå¯è½æ§ãããã¾ãã
Bedrockã®å¦çã失æããå ´åï¼Lambdaå´ã§ä»¥ä¸ç¶æ ã«ãªã£ãå ´åï¼
Bedrockã§ã®å¦ç失æï¼New Relicé£æºå¤±æã¯é¿ãããã®ã§Bedrockã§ã®å¦ç失ææã¯
Bedrock以å¤ã®æ
å ±ãé£æºãããããã«ãã¾ããã
æ
å ±ã表示ãããããã«ãã¾ããã
以ä¸ã¯New Relicã¸éãããæ
å ±ã§ãã
â»New Relicã¸éãããæ
å ±ã¨ãã¦Bedrockå¦çãã¼ã¿ã¯ãbedrock.xxxãSecurity Hubããåå¾ããæ
å ±ã¯ãaws.xxxãã¨æ確åãã¦ããã¾ãã
{ "aws.accountId": "xxxx", "aws.associatedStandards": "[]", "aws.complianceStatus": "N/A", "aws.description": "A sequence of actions involving 14 signals indicating a possible credential compromise one or more S3 bucket(s) was observed for IAMUser/john_doe with principalId xxxxE in account 111122223333 between eventFirstSeen and eventLastSeen with the following behaviors: - 5 MITRE ATT&CK tactics observed: Exfiltration, Impact, Persistence, Defense Evasion, Discovery - 5 MITRE ATT&CK techniques observed: T1526 - Cloud Service Discovery, T1098 - Account Manipulation, T1078.004 - Valid Accounts: Cloud Accounts, T1485 - Data Destruction, T1530 - Data from Cloud Storage - Connected from a known Tor Exit Node: 10.0.0.1 - 7 sensitive APIs called: s3:DeleteObject, s3:GetObject, s3:PutBucketPublicAccessBlock, cloudtrail:DeleteTrail, iam:AttachUserPolicy, s3:ListObjects, s3:ListBuckets ", "aws.findingId": "arn:aws:guardduty:ap-northeast-1:xxxx:detector/xxxxding/xxx "aws.lastUpdatedAt": "2025-01-02T12:26:01.461Z", "aws.productName": "", "aws.region": "ap-northeast-1", "aws.resourceArn": "[\"N/A\",\"N/A\",\"N/A\"]", "aws.resourceId": "[\"arn:aws:s3:::EXAMPLE-BUCKET1\",\"arn:aws:s3:::EXAMPLE-BUCKET2\",\"arn:aws:s3:::EXAMPLE-BUCKET3\"]", "aws.resourceType": "[\"AwsS3Bucket\",\"AwsS3Bucket\",\"AwsS3Bucket\"]", "aws.service": "SecurityHub", "aws.severity": "CRITICAL", "aws.severityNormalized": 90, "aws.title": "Potential data compromise of one or more S3 buckets involving a sequence of actions associated with IAMUser/john_doe.", "bedrock.impact": "", "bedrock.recommendation": "", "bedrock.summary": "", "CustomMessage": "Security Hub Finding - Title: Potential data compromise of one or more S3 buckets involving a sequence of actions associated with IAMUser/john_doe., Compliance Status: N/A", "logtype": "security-findings", "newrelic.source": "api.logs", "plugin.version": "1.0.0", "service": "AWS Security Hub", "timestamp": 1736235024888 }
å人çã«æãããã¨
è¯ãã£ãç¹
- ã»ãã¥ãªãã£ã¤ãã³ãçºçæããä½ãèµ·ãããããä½ããã¹ãããããããããããªã£ãã
- AIã«ããè¦ç´ã¨ããã·ã¥ãã¼ã表示ã«ãã£ã¦ãå ¨ä½åã¨è©³ç´°æ å ±ãä¸ç®ã§ææ¡ã§ããä»çµã¿ãæ§ç¯ã§ããã
課é¡
AIè¦ç´ã®æ£ç¢ºæ§ã¸ã®æ¸å¿µ
- Bedrockã«ããè¦ç´çµæã誤ã£ã¦ããå ´åãããã«åºã¥ãã対å¿ãééã£ãæ¹åã«é²ãå¯è½æ§ããããªã¨æãã¾ããã
éç¨æã®æ³¨æç¹
ã1ãã®æ¸å¿µãããã®ã§AIçææ å ±ã§ãããã¨ãæ示ãã¤ã¤ï¼AIæ å ±ã¯è£è¶³æ å ±ã¨ãã¦æ±ãï¼ãåæï¼AWS Security Hubæ¤åºçµæï¼ãä¸ç·ã«è¡¨ç¤ºå¿ è¦ãããã¨æãã¾ããã
以ä¸ã¯ãã®ã¢ã©ã¼ãéç¥æã®ä¾ã§ãã以ä¸ã®ãããªAWSåæã表示ãã ã»ã¿ã¤ãã«ï¼AWS Config should be enabled and use the service-linked role for resource recording ã»æ¦è¦ï¼This control checks whether AWS Config is enabled in your account in the current AWS Region, records all resources that correspond to controls that are enabled in the current Region, and uses the service-linked AWS Config role. ã»ã¤ãã³ãã¬ãã«ï¼CRITICAL ã»ãªã½ã¼ã¹ã¿ã¤ãï¼["AwsAccount"]ããªã© ----- â AIã«ããè¦ç´ ã»æ¦è¦ï¼AWS Configãæå¹åããã¦ããããè¨å®ã¬ã³ã¼ãã¼ããªã³ã«ãªã£ã¦ãã¾ãããããã¯ãCIS AWS Foundations Benchmark v1.2.0/2.5ã®è¦ä»¶ã«éåãã¦ãã¾ãã ã»åé¡ï¼ãªã½ã¼ã¹ã®æ§æå¤æ´ã®è¿½è·¡ãã§ãããã»ãã¥ãªãã£ç£æ»ãã³ã³ãã©ã¤ã¢ã³ã¹ç¢ºèªãå°é£ã«ãªãã¾ããã¾ããæ½å¨çãªã»ãã¥ãªãã£ãªã¹ã¯ãè¦éãå¯è½æ§ãé«ããªãã¾ãã ã»å¿ è¦ãªã¢ã¯ã·ã§ã³ï¼AWS Configãæå¹åãããã¹ã¦ã®ãªã½ã¼ã¹ãè¨é²ããããã«è¨å®ãã¦ãã ãããã¾ããAWS Configã®ãµã¼ãã¹ãªã³ã¯ãã¼ã«ã使ç¨ããããã«è¨å®ãã¦ãã ããã詳細ãªæé ã«ã¤ãã¦ã¯ãæä¾ãããAWS Security Hubã®ããã¥ã¡ã³ãï¼https://docs.aws.amazon.com/console/securityhub/Config.1/remediationï¼ãåç §ãã¦ãã ããã ã»ããã·ã¥ãã¼ããªã³ã¯ãªã© -----
ã¾ã¨ã
Amazon Bedrockã使ç¨ãããã¨ã§Security Hubã®æ
å ±ãããæãã«è¦ç´ãããã¨ãå¯è½ã«ãªãã¾ããã
ä¸æ¹ã§Bedrockèªä½ã®æ£ç¢ºæ§ãå¦çæ¼ãçBedrockèªä½ã®ç£è¦ãå¿
è¦ã ãªã¨æãã¾ããã
ã¾ãéç¥é »åº¦ãé«ãã¨Bedrockã®ã³ã¹ãå¢å ã«ã¤ãªããã®ã§ãã®è¾ºãã®èæ
®ãå¿
è¦ããã§ãã
ã¨ã¯ãã便å©ã§ãããã¨ã¯å¤ãããªãã®ã§Bedrockãçµã¿åãããã·ã¹ãã éç¨æ¹æ³ã確ç«ãã¦ããããã§ããã
宣ä¼
å¼ç¤¾ã§ã¯ãã客æ§ç°å¢ã®ãªãã¶ã¼ãããªãã£ãå éããããã®ä¼´èµ°åã®New Relicå°å ¥æ¯æ´ãµã¼ãã¹ãªã©ããæä¾ãã¦ããã¾ãã ãããèå³ããæã¡ã®æ¹ã¯ããã¡ãã®ãµã¼ãã¹ãç´¹ä»ãã¼ã¸ã®ä¸çªä¸ã«ãããååããã©ã¼ã ãããååãé ãã¾ããã幸ãã§ãããã¾ãã