CIé¨ ä½ç«¹ã§ãã
ä»åã¯ãMacie ã使ã㨠CloudTrail ã®å©ç¨æãæå³ããå¢å ãã¦é©ãããã¨ãã話ã§ããçãããåããããæ¹ãããªãããã«ãããã°ã«æ®ãã¦ããã¾ãã
Amazon Macie
ä»å㯠Amazon Macie ã«ã¤ãã¦è¨è¼ãã¾ããAmazon Macie ã¯ãS3 ãã»ãã¥ã¢ã«ä½¿ãã«ããããéå¸¸ã«æå¹ãªãµã¼ãã¹ã§ããMacie 㯠S3 ã«ä¿åããã¦ãããã¡ã¤ã«ç¾¤ãããããåæãããæ©å¯æ å ±ãå«ã¾ãã¦ãããã©ããããæ¤ç¥ãã¦æãã¦ããã¾ããå®éã« Amazon Macie ãæ¤è¨¼ã®ãããå人æ¤è¨¼ã¢ã«ã¦ã³ãã§æå¹ã«ãã¦ã¿ã¾ããã
æå¹åããã ãã§ãç¾å¨ã® S3 ãã±ããã®ç¶æ³ãä¸è¦§ã§è¡¨ç¤ºããã¾ããããã ãã§ Public Access ããªããã¨ãä¸ç®ã§ãããã¾ããã
ãã ããæå¹åããã ãã§ã¯ S3 Object ã«å¯¾ããæ©å¯æ å ±ã®æ¤æ»ï¼æ¤åºï¼ã¯è¡ããã¾ããã
Macie ã®å©ç¨æ
以ä¸ã§ç°¡åã«å©ç¨æã«ã¤ãã¦èª¬æãã¾ãã
以ä¸ã®å©ç¨æã¯ Macie ãæå¹åããã¨ç¶ç¶çã«è«æ±ãããå©ç¨æã§ããã¤ã¾ããã±ããæ°ã«å¿ã㦠$0.1 æ¯æè«æ±ãããã®ã¿ã§ãã®ã§ãé常ã«ä½ã³ã¹ãã§ãã
ã»ãã¥ãªãã£ã¨ã¢ã¯ã»ã¹å¶å¾¡ã«ã¤ãã¦è©ä¾¡ãããã±ãã | æé |
---|---|
æåã® 30 æ¥éã«è©ä¾¡ãããã¹ã¦ã®ãã±ãã | ç¡æ (0.00 USD) |
æåã® 30 æ¥å¾ã«è©ä¾¡ãã S3 ãã±ããã®æ°/æ | S3 ãã±ããããã 0.10USD |
ããã«å ãã¦ãæ¤åºã¸ã§ãã«å¯¾ãã¦å©ç¨æãçºçãã¾ããããã¯ã¸ã§ããå®è¡ããªãéãã¯è«æ±ããã¾ããã
æ©å¯ãã¼ã¿æ¤åºã®ãã¼ã¿å¦çé | æé |
---|---|
æåã® 1 GB/æ | ç¡æ (0.00 USD) |
次㮠50,000 GB/æ | GB ããã 1.25USD |
次㮠450,000 GB/æ | GB ããã 0.63USD |
500,000 GB/æãè¶ ããå ´å | GB ããã 0.31USD |
詳細ã¯ä»¥ä¸ãã覧ãã ããã
sensitive data discovery jobs
S3 ã«ä¿åããã¦ããåãã¡ã¤ã«ã«æ©å¯æ
å ±ããããã©ãããæ¤æ»ãã ã«ã¯ sensitive data discovery jobs
ã®å®è¡ãå¿
è¦ã«ãªãã¾ããå
ã«ãç´¹ä»ããéããã¸ã§ããå®è¡ãããã¨ã§ãã¼ã¿ã®å¦ç容éã«å¯¾ãã¦å©ç¨æéãçºçãã¾ãã
ã¸ã§ãã使ããã«ã¯ãMacie ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãã®ãCreate jobããæ¼ä¸ãã¦é²ãã¾ãã
Jobã§æåã«é¸æããã®ããã©ã®ãã±ãããæ¤æ»ãããã§ããããã§å ¨ãã±ããã䏿°ã«æ¤æ»ãããã¨ãã§ãã¾ããå®éãç§ã¯å ¨ã¦ã®ãã±ããã鏿ãã¦å®è¡ãã¦ã¿ã¾ããã
CloudTrail ã®å©ç¨æãçªç¶å¢å
ãµã¼ãã¼ã¯ã¼ã¯ã¹ã®ç¤¾å
ã§ã¯ãCost Anomaly Detection ã®ä»ã«ç¬èªå®è£
ã®ãmarusaãã¨è¨ãããã³ã¹ã管çãã¼ã«ãåä½ãã¦ãã¾ãã
â»Cost Anomaly Detection ã«ã¤ãã¦ã¯ä»¥ä¸ãã覧ãã ãã
ãã® marusa ã«ãã£ã¦ãç§ã®å人æ¤è¨¼ã¢ã«ã¦ã³ãã§å©ç¨æãæ¥æ¿ã«å¢å ãã¦ãããã¨ã«æ°ä»ãã¾ããã
Cost Explorer ã§åæããã¦ã¿ãã¨ãMacie ã®å©ç¨æã ãã§ã¯ãªããCloudTrail ã®å©ç¨æã大ããå¢å ãã¦ãããã¨ããããã¾ããã
Macie ã®å©ç¨æãé«é¡ã«ãªãã®ã¯çè§£ãã¦ãã¾ãããã使 CloudTrail ã®å©ç¨æãå¢å ããã®ã§ããããï¼
CloudTrail å©ç¨æå¢å ã®çç±
çµè«ãããä¼ããã㨠sensitive data discovery jobs
㯠CloudTrail ã®å©ç¨æãå¢å ãããåå ã«ãªãã¾ãã
ãã®çç±ã§ãã sensitive data discovery jobs ã§ã¯ãæå®ãã S3 ãã±ããå ã«ä¿ç®¡ããã¦ããå ¨ã¦ã®ãªãã¸ã§ã¯ããæ¤æ»ãããããå ¨ã¦ã®ãªãã¸ã§ã¯ããä¸åº¦ Get object ãã¾ããé常 S3 Object åä½ã®ãã°ï¼GetObject, DeleteObject ã PutObject ã¨ãã API operationï¼ã¯ CloudTrail ã«ä¿åããã¾ãããããããä¿åããããã«è¨å®ã§æå¹åãããã¨ãã§ãã¾ãã
ä¸å³ã®è¨å®ç»é¢ã§ãData eventsãã«ãã§ãã¯ãå ¥ãããã¨ã§æå¹åããã¾ãã詳ããã¯ä»¥ä¸ã®ããã¥ã¡ã³ããåããã¦ã覧ãã ããã
ã¤ã¾ãç§ã®æ¤è¨¼ã¢ã«ã¦ã³ãã®ããã« CloudTrail ã§ S3 ã® Data event ãæå¹åãã¦ããå ´åãã㤠Macie ã® discovery job ã« CloudTrail ã®ãã±ãããæå®ããå ´åã«ã¯ãCloudTrail ã®éå»å ¨ã¦ã®ãã¡ã¤ã«ã Get ããã¨ããè¨é²ã CloudTrail ã«æ¸ãè¾¼ã¾ãã¦ãã¾ããããCloudTrail ã®å©ç¨æãå¢å ããã¦ãã¾ããã¨ã«ãªãã¾ãã
Athena ã§ã®å©ç¨æåæ
å®éã«ã©ãããã Macie ã® discovery job ã«ãã£ã¦ CloudTrail ã®å±¥æ´ãçºçããã®ã追ãããã¦ã¿ã¾ããã
ã¯ã¨ãªï¼SQLï¼ã®ä¾ã¯ä»¥ä¸ã®éãã§ãã
SELECT count(eventname) AS count, eventname FROM "default"."cloudtrail_logs_apnortheast1_202105" WHERE useridentity.arn='arn:aws:sts::XXXXXXXXXXXX:assumed-role/AWSServiceRoleForAmazonMacie/classifier-content-fetcher' GROUP BY eventname;
XXXXXXXXXXXX
㯠AWS ã¢ã«ã¦ã³ãã® ID ã®ããä¼ãã¦ãã¾ããAWSServiceRoleForAmazonMacie
ã«ãã£ã¦ã³ã³ãã³ãããã§ããããã¦ãããã°ãã«ã¦ã³ããã¾ããã
ã¯ã¨ãªã®çµæããä¸ç»åã®éã GetObjectãGetObjectAclãHeadObject ããããã154ä¸å以ä¸å®è¡ããããã¨ããããã¾ãããããã¯ã¤ã¾ã S3 Bucket ã«ãªãã¸ã§ã¯ãã154ä¸ãã¡ã¤ã«ä»¥ä¸è¨ç½®ããã¦ããã¨ãããã¨ã§ãã
CloudWatch ã§ S3 ãã±ããã«é ç½®ããã¦ãããªãã¸ã§ã¯ãã®æ°ã確èªãã
ç¹å®ã® S3 ãã±ããã«ä¿æããã¦ãããªãã¸ã§ã¯ãã®åæ°ã¯ãCloudWatch ãè¦ããã¨ã§ããããã®æ°ã確èªã§ãã¾ãã
NumberOfObjects ã®æ¨ç§»ã確èªããã¨ãCloudTrail ã«å©ç¨ãã¦ãã S3 ãã±ããã«ã¯ 154ä¸ç¨åº¦ã®ãã¡ã¤ã«ãä¿åããã¦ãããã¨ããããã¾ããã
ããã«ãã Amazon Macie ã® sensitive data discovery jobs å®è¡æ CloudTrail ç¨ã®ãã±ããã鏿ãã¦ãããããåè¨463ä¸ä»¥ä¸ã® S3 Data event (GetObjectãGetObjectAclãHeadObject) ãçºçãããã®å©ç¨éãè«æ±ããããã¨ã®è£ä»ããåãã¾ããã
ä½è«ï¼CloudTrail ã®æ¤æ»çµæ
ããã¯ä½è«ã§ãããCloudTrail ç¨ã®ãã±ãããæ¤æ»ããçµæã56åã® SensitiveData:S3Object/Financial
ã High ã§çºè¦ããã¾ããã
ãã㯠Credit card number no keyword
ã«å¤ããã¨ã®ããã§ã以ä¸ã®æ¡ä»¶ã«å½ã¦ã¯ã¾ãæååãåå¨ãã¦ããã¨ãããã¨ã§ããã
Detection requires the data to be a 13â19 digit sequence that adheres to the Luhn check formula and uses a standard card number prefix for any of the following types of credit cards: American Express, Dankort, Dinerâs Club, Discover, Electron, Japanese Card Bureau (JCB), Mastercard, UnionPay, and Visa.
å¶ç¶ãçæããããã°ã®ä¸ã«13æ¡ãã19æ¡ã®æ°åãåå¨ããã®ãã154ä¸ãã¡ã¤ã«ä¸ã56åã ãããã£ãããã§ããã詳細ã¯ä»¥ä¸ãåããã¦ã覧ãã ããã
ã¾ã¨ã
ä»å㯠Amazon Macie ãå©ç¨ãããã¨ã§ãCloudTrail ã®å©ç¨æãæå³ããå¢ãã¦ãã¾ã£ãå®ä½é¨ã«ã¤ãã¦è¨è¼ãã¾ããããã®æ¡ä»¶ãå度ãããããã¦ããã¾ãã
- CloudTrail ã§ S3 ã®ãã¼ã¿ã¤ãã³ããè¨é²ããè¨å®ãæå¹ã«ãã¦ãã
- Amazon Macie ã® sensitive data discovery jobs ãå®è¡ããã«ããããCloudTrail ç¨ã® S3 ãã±ãããå«ãã
- CloudTrail ã«å¤§éã®ãã°ãã¡ã¤ã«ãåå¨ãã¦ããï¼ä½æããã°ããã® AWS ã¢ã«ã¦ã³ãã®å ´åã¯ãã¡ã¤ã«æ°ãå°ãªãããåé¡ã«ãªããªãï¼
ä¸è¨ã®æ¡ä»¶ã«å
¨ã¦å½ã¦ã¯ã¾ãã¨ãCloudTrail ã®å©ç¨æãæå³ããå¢å ããå ´åãããã¾ãããããé¿ããã«ã¯ sensitive data discovery jobs
ã®å®è¡å¯¾è±¡ã¨ã㦠CloudTrail ç¨ã® S3 ãã±ãããé¿ãã¦é ãã®ãè¯ãã§ããããä»ã«ããELB ã®ã¢ã¯ã»ã¹ãã°ã AWS Config ç¨ã®ãã±ãããªã©ãå°ãããªãã¸ã§ã¯ãã大éã«è¨ç½®ããããããªãã±ãã㯠discovery job ã®å¯¾è±¡å¤ã¨ãã¦ãè¯ãå ´åãããã¨èãã¾ãã
æ¬ããã°ã¯ä»¥ä¸ã«ãªãã¾ãã
ã§ã¯ã¾ããä¼ããã¾ãããã
ä½ç«¹ é½ä¸ (Yoichi Satake) ã¨ã³ã¸ãã¢ããã°ã®è¨äºä¸è¦§ã¯ã³ãã©
ããã¼ã¸ããµã¼ãã¹é¨æå±ãAWSè³æ ¼å ¨å ã2010å¹´1æããAWSãå©ç¨ãã¦ãã¦ãã¾ãã2021-2022 AWS Ambassadors/2023-2024 Japan AWS Top Engineers/2020-2024 All Certifications EngineersãAWSã®ã³ã¹ã忏ãæé©åã徿ã¨ãã¦ãã¾ãã