ããã«ã¡ã¯ãã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®äºåºã§ãã
re:Invent 1 æ¥ç®ã§åå ãã GameDay 㧠DDoS ã¨æ¦ã£ãã®ã§ãæ¯ãè¿ãã¨ã㦠AWS ã«ããã DDoS 対çã»å¯¾å¿ã«ã¤ãã¦ã¾ã¨ãã¦ã¿ã¾ããã
â» AWS GameDay ã¨ãã®è©³ç´°ã¯è¨è¼ãã¦ããã¾ããã
åå ãã GameDay ã®æ¦è¦ã¯ä¸è¨ã®éãã
SEC402-R | AWS GameDay: Winning the DDoS game [REPEAT]
In this workshop, compete in a team-based environment to practice protecting a web application in real time. Your team uses AWS WAF and AWS Shield to mitigate distributed HTTP floods, web exploits, and malicious bots that disrupt the experience of your customers. This workshop offers a risk-free environment where teamwork is paramount as you work together under pressure. Watch a real-time scoreboard as your team works through each level. The most effective team will earn a prize at the end! You must bring your laptop to participate.
DDoS æ»æã¨ã¯
DDoSã®åºæ¬æ¦å¿µ
DDoS (Distributed Denial of Service) æ»æã¨ã¯ãå¤æ°ã®ããã¤ã¹ããä¸æã«ã¿ã¼ã²ããã¸ã¢ã¯ã»ã¹ãéä¸ããããã¨ã§ããµã¼ãã¹ã®æä¾ã妨ããæ»æã®ãã¨ãæãã¾ãã ä¾ãã°ã大è¦æ¨¡ãªããããããã使ç¨ãã¦ç¹å®ã®ã¦ã§ããµã¤ãã«å¯¾ãã¦å¤§éã®ãªã¯ã¨ã¹ããéãç¶ãããã¨ã§ããµã¼ãã¹ã®å¿çé度ãä½ä¸ãããããå®å ¨ã«åæ¢ãããããããã¨ãããã¾ãã æ»æè ã¯ãã«ã¦ã§ã¢ã使ç¨ãã¦ããã¤ã¹ããè¸ã¿å°ãã¨ãã¦å©ç¨ãã大éã®ãªã¯ã¨ã¹ããéä¿¡ãããããæ»æå ãåºç¯å²ã«åæ£ãã¾ãã
æ»æã®ç¨®é¡
- ãããã¯ã¼ã¯å¸¯åæ»æ: 帯åå¹ ãå§è¿«ãããããã¯ã¼ã¯ã使ç¨ä¸å¯ã«ããã
- ãããã³ã«æ»æ: TCP/IP ãããã³ã«ã®èå¼±æ§ãå©ç¨ããã·ã¹ãã ãªã½ã¼ã¹ãæ¶èãããã
- ã¢ããªã±ã¼ã·ã§ã³å±¤æ»æ: HTTP ãªã¯ã¨ã¹ãã®ãããªæ£å½ãªéä¿¡ã«è¦ããå½¢ã§ã¢ããªã±ã¼ã·ã§ã³ãéè² è·ã«ããã
å½±é¿ã¨ãªã¹ã¯
DDoS æ»æã¯ããã®è¦æ¨¡ãææ³ã®å¤æ§æ§ããé²å¾¡ãé£ããã¨ããã¦ãã¾ãã é£ããçç±ã¨ãã¦ã¯ã
- æ»æã«ä½¿ç¨ããããããããããå°ççã«åºç¯å²ã«åæ£ãã¦ãããããä¸é¨ã®IPã¢ãã¬ã¹ããããã¯ããã ãã§ã¯å¹æãéå®ç
- æ»æè ãé »ç¹ã«ææ³ãå¤ãããã¨ã§ãæ¢åã®ã»ãã¥ãªãã£ã«ã¼ã«ãç°¡åã«åé¿ãã¦ãã¾ããã¨ããã
- æ»æãã©ãã£ãã¯ã¨æ£å½ãªãã©ãã£ãã¯ãåºå¥ãã«ããå ´åãå¤ããéå°ãªãããã¯ãæ£è¦ã®ã¦ã¼ã¶ã¼ã«ãå½±é¿ãä¸ãããªã¹ã¯ãä¼´ã
ãªã©ãæãããã¾ãã
DDoS æ»æã«ãã£ã¦ãµã¼ãã¹åæ¢ã顧客ã®ä¿¡é ¼æ失ãåçæ¸å°ãªã©ã®æ·±å»ãªå½±é¿ãçããå¯è½æ§ããããããäºåã®å¯¾çã¨æ»æãåããéã®è¿ éãªå¯¾å¿ãéè¦ã¨ãªãã¾ãã
AWS ã«ããã DDos 対ç
AWS 㧠DDoS ã«æå¹ãªãµã¼ãã¹
AWS Shield
AWS Shield ã¯ãAWS ç°å¢ã®ãªã½ã¼ã¹ã DDoS æ»æããå®ãããã®ãµã¼ãã¹ã§ãã
ãã©ã³ã¯ 2 ã¤
é ç® | Shield Standard | Shield Advanced |
---|---|---|
è²»ç¨ | ç¡æ | 3,000 USD/æï¼1å¹´å¥ç´ï¼ |
ä¿è·ç¯å² | ã¬ã¤ã¤ã¼3ããã³ã¬ã¤ã¤ã¼4ã®æ»æï¼SYNãã©ãããUDPãã©ããããªãã¬ã¯ã·ã§ã³æ»æãªã©ï¼ | ã¬ã¤ã¤ã¼3â7ã®æ»æï¼ã¢ããªã±ã¼ã·ã§ã³å±¤æ»æãå«ãï¼ |
ãµãã¼ã | ãªã | 24/7ã®DDoS対å¿ãã¼ã ï¼DDoS Response Teamï¼ |
éç¥æ©è½ | ç¡ã | CloudWatch ã¨é£æºãããã¨ã§ãªã¢ã«ã¿ã¤ã éç¥ãå¯è½ |
追å æ©è½ | ãªã | æ»ææã®ãã¼ã¿è»¢éã³ã¹ãè¿éãAWS WAF é£æº |
ã¢ãã¿ãªã³ã°ã¨ã¬ãã¼ã | åºæ¬çãªãã©ãã£ãã¯ã¢ãã¿ãªã³ã° | 詳細ãªã¬ãã¼ãã¨æ»æåæï¼æ»æè¦æ¨¡ãå½±é¿ç¯å²ãªã©ã®è©³ç´°æ å ±ï¼ |
Advanced ã§ä¿è·ã§ãããªã½ã¼ã¹:
- Amazon EC2 instances
- Elastic Load Balancing load balancers
- Amazon CloudFront distributions
- Amazon Route 53 hosted zones
- AWS Global Accelerator standard accelerators
AWS WAF
AWS WAF ã¯ãã¢ããªã±ã¼ã·ã§ã³å±¤ã®æ»æãé²ãããã® Web ã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ã§ããSQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã®ãããªã¦ã§ãæ»æããä¿è·ãã¾ãã
ä¿è·ã§ãããªã½ã¼ã¹:
- Amazon CloudFront distribution
- Amazon API Gateway REST API
- Application Load Balancer
- AWS AppSync GraphQL API
- Amazon Cognito user pool
- AWS App Runner service
- AWS Verified Access instance
æ¨å¥¨ãããè¨å®
é²å¾¡å±¤ã®å¤å±¤åï¼Defense in Depthï¼
- AWS ShieldãAWS WAFãAmazon CloudFront ãªã©ãããã¯ã¼ã¯å±¤ã¨ã¢ããªã±ã¼ã·ã§ã³å±¤ã®é²å¾¡æ段ãçµã¿åãããã
ã³ã³ãã³ãé ä¿¡ã®æ´»ç¨
- Amazon CloudFront ã§ãã©ãã£ãã¯ãã¨ãã¸ãã±ã¼ã·ã§ã³ã«åæ£ã
- AWS WAF ã«ã¼ã«ã CloudFront ã«çµ±åãã¦ä¸æ£ãã©ãã£ãã¯ããããã¯ã
ãã©ãã£ãã¯ã®åæ£ã¨ã¹ã±ã¼ãªã³ã°
- Amazon CloudFront 㨠Elastic Load Balancing ã§ãã©ãã£ãã¯ãåæ£ã
- Auto Scaling ã§ãªã½ã¼ã¹ãåçã«æ¡å¼µããæ»æã®å½±é¿ã軽æ¸ã
ãã©ãã£ãã¯ã®ç£è¦ã¨ãã°è¨é²
- Amazon CloudWatch ã§ç°å¸¸ãç£è¦ã
- VPC Flow Logs ã AWS WAF ã®ãã°ã§æ»æã®è©³ç´°ãåæã
ã¬ã¼ãå¶éã¨éä¿¡å¶å¾¡
- AWS WAF ã®ã¬ã¼ãå¶éã«ã¼ã«ã IP ãããã¯ãªã¹ãã§ä¸å¯©ãªãã©ãã£ãã¯ãå¶å¾¡ã
- ã»ãã¥ãªãã£ã°ã«ã¼ãã¨ãããã¯ã¼ã¯ ACL ã§æå°æ¨©éã®éä¿¡è¨å®ãé©ç¨ã
AWS ã«ããã DDos 対å¿
調æ»æ¹æ³
AWS Shield Advanced ã®ããã·ã¥ãã¼ã
- Global threat dashboard ããæ»æã®ç¨®é¡ãè¦æ¨¡ã確èªã
AWS WAF ã®ãã°ã§æ»æã®è©³ç´°ã調æ»
- AWS WAF ã®ãã°ããä¸æ£ãã©ãã£ãã¯ã®ãã¿ã¼ã³ãåæã
- æ»æå ã®IPã¢ãã¬ã¹ãæ»æå 容ãç¹å®ã
åææ¹æ³ã¯ä¸è¨ããã¥ã¡ã³ãã«åææ¹æ³ãåãããããæ¸ãã¦ããã¾ãã
Amazon CloudWatch Logs ã«ãã AWS WAF ãã°ã®åæ | Amazon Web Services ããã°
対å¦æ¹æ³
AWS WAF ã§ã®ã«ã¼ã«é©ç¨
- ã¬ã¼ãå¶éã«ã¼ã«: æ»æç㪠IP ã¢ãã¬ã¹ãç¹å®ãã1ç§ãããã®ãªã¯ã¨ã¹ãæ°ãè¶ ããã¢ã¯ã»ã¹ãé®æã
- IP ã»ãã: æ»æå ã® IP ããããã¯ãªã¹ãã«è¿½å ãã¦ãåçºãé²æ¢ã
AWS Shield Advanced ã® DDoS ç·©åæ©è½ã®æ´»ç¨
- èªåçã«æ»æãç·©åãã Shield Advanced ã®ãããã¯ã·ã§ã³ãæå¹åã
- å¿ è¦ã«å¿ãã¦ãDDoS Response Teamï¼DRTï¼ã«é£çµ¡ããã«ã¹ã¿ã ã«ã¼ã«ã®ä½æã調æ´ãä¾é ¼ãã¾ãã
å¦ç¿ãªã½ã¼ã¹
- AWS DDoSã¬ã¸ãªã¨ã³ã·ã¼ã®ãã¹ããã©ã¯ãã£ã¹ - AWS DDoSã¬ã¸ãªã¨ã³ã·ã¼ã®ãã¹ããã©ã¯ãã£ã¹
- AWS ç°å¢ã§ã® DDoS æ»æã«å¯¾ããèé害æ§ãé«ããããã®ãã¹ããã©ã¯ãã£ã¹ã解説
- How AWS protects customers from DDoS events | AWS Security Blog
- AWS ãã©ã®ããã«ã㦠DDoS æ»æãã顧客ãä¿è·ãã¦ãããã解説
- AWS Solutions Architect ããã°: AWSåå¿è
åãWebinarãAWSä¸ã§ã®DDoS対çãè³æããã³QAå
Ž
- AWS ç°å¢ã§ã® DDoS 対çã«ã¤ãã¦ã®åå¿è åãã¦ã§ããã¼è³æ
ã¾ã¨ã
ä»åãGameDay ããã£ããã« DDoS æ»æã AWS ã§ã®é²å¾¡çã«ã¤ãã¦å¦ã¶ãã¨ãã§ãã¾ããã ä»å¾ã¯ãã°ã®åæã®æ¹æ³ãªã©ãæ·±ãåå¼·ãã¦ããããã¨æãã¾ãã æ¬è¨äºãã©ãªããã®åèã«ãªãã°å¹¸ãã§ãã
äºåº çæ å (è¨äºä¸è¦§)
2021å¹´4ææ°åå ¥ç¤¾
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨
2024 Japan AWS Jr. Champions