ããã«ã¡ã¯ãæè¡2課ã®è³è³ã§ãã
æè¿ãAmazon Linux2ã®EC2ã«å¯¾ãã¦DSaaSãå°å
¥ããæ©ä¼ããã£ãã®ã§ããã®éã«å®æ½ããå
å®¹ãæ®ãã¦ããããã¨æãã¾ãã
DSaaSã§ãããAWS Marketplaceã§DSaaSã®ã©ã¤ã»ã³ã¹å¥ç´ããããã¨ã§å人ã§ãæ°è»½ã«ä½¿ç¨ãããã¨ãã§ãã¾ãã
以åãå¼ç¤¾ã®å¯ºç°ãã¾ã¨ãã¦ãã¾ããã®ã§ããã¡ããåèã«æ¤è¨¼ç°å¢ãæ§ç¯ãã¾ããã
AWS Marketplace ã§ Trend Micro Deep Security as a Service ã®ã©ã¤ã»ã³ã¹ãå¥ç´ãã¦ãæ¤è¨¼ç°å¢ã§ä½¿ããããã«ãã¦ã¿ã
ä»åã®å
容ã¨ãã¦ã¯ä»¥ä¸ã«ãªãã¾ãã
- Deep Security Managerã« AWSã¢ã«ã¦ã³ãã追å
- Amazon Linux2ã«ã»ãã·ã§ã³ããã¼ã¸ã£ã§Deep Security Agentãã¤ã³ã¹ãã¼ã«
- Amazon Linux2ã«ã©ã³ã³ãã³ãã§Deep Security Agentãã¤ã³ã¹ãã¼ã«
â»OSã«ãã£ã¦ã¯ãµãã¼ãããã¦ããªããã¼ã¸ã§ã³ã®ã¨ã¼ã¸ã§ã³ããã¤ã³ã¹ãã¼ã«ãããå¯è½æ§ãããããã確å®ã«å¸æãããã¼ã¸ã§ã³ãã¤ã³ã¹ãã¼ã«ãããå ´åã¯ãä»åã®æ¹æ³ã§ã¯ãªããã¼ã¸ã§ã³æ¯ã®ã¤ã³ã¹ãã¼ã©ã使ç¨ãããã¨ããå§ããã¾ãããã¡ãã«OSæ¯ã«ãµãã¼ãããã¦ããDeep Security Agentãã¾ã¨ãããã¦ãã¾ãã
1.Deep Security Managerã«AWSã¢ã«ã¦ã³ãã追å
Deep Security Managerï¼ä»¥éDSMï¼ã«AWSã¢ã«ã¦ã³ãã追å ãããã¨ã§ããã®ã¢ã«ã¦ã³ãã«ç´ã¥ãEC2ã®ä¸è¦§ã表示ãããã¨ãã§ãã¾ãã
ã¾ãã該å½ã®AWSã¢ã«ã¦ã³ãã«ã¦ãAWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ãã°ã¤ã³ãã¦ããã¾ãã
â»å¾ã»ã©ãDSMã¨ã®é£æºã®ããCloudFormationã«ã¦IAMãã¼ã«ã使ãããã¨ã«ãªãã¾ãã
DSMã«ãã°ã¤ã³ãã¾ãã
ãã³ã³ãã¥ã¼ã¿ãâã+追å ãâãAWSã¢ã«ã¦ã³ãã®è¿½å ãã鏿ãã¾ãã
å¥ã¦ã¤ã³ãã¦ã§ã¦ã£ã¶ã¼ãã表示ããã¾ãã
ã»ããã¢ããã¿ã¤ãã¯ãã¯ã¤ãã¯ããé¸ã³ããæ¬¡ã¸ãã鏿ãã¾ãã
ã¢ã«ã¦ã³ãã®ã»ããã¢ããã§ã¯ãç¹ã«ä½ããããæ¬¡ã¸ãã鏿ãã¾ãã
ãã°ã¤ã³ãã¦ããAWSã¢ã«ã¦ã³ãã«ã¦CloudFormationãèµ·åãã¾ãã
ç¹ã«ä½ã夿´ãããæ¬¡ã¸ãã鏿ãã¾ãã
ç¹ã«ä½ã夿´ãããæ¬¡ã¸ãã鏿ãã¾ãã
ç¹ã«ä½ã夿´ãããæ¬¡ã¸ãã鏿ãã¾ãã
IAMãªã½ã¼ã¹ã使ããããã¨ãæ¿èªããã«ãã§ãã¯ãå
¥ãããã¹ã¿ãã¯ã®ä½æãã鏿ãã¾ãã
ã¹ã¿ãã¯ã®ã¹ãã¼ã¿ã¹ããCREATE_COMPLETEãã«ãªãã¾ã§æ«ãå¾
ã¡ã¾ãã
DSMã®ãã³ã³ãã¥ã¼ã¿ãã確èªããã¨ã該å½ã®AWSã¢ã«ã¦ã³ãã«æ§ç¯ãããEC2ã®ä¸è¦§ã表示ããã¾ãã
2.Amazon Linux2ã«ã»ãã·ã§ã³ããã¼ã¸ã£ã§Deep Security Agentãã¤ã³ã¹ãã¼ã«
AmazonLinux2ã«å¯¾ãã¦ãAWS Systems Managerã®ã»ãã·ã§ã³ããã¼ã¸ã£ã§Deep Security Agentï¼ä»¥éDSAï¼ãã¤ã³ã¹ãã¼ã«ãã¦ã¿ã¾ãã
DSMã®ããµãã¼ãæ
å ±â¼ãããããã¤ã³ã¹ãã¼ã«ã¹ã¯ãªãããã鏿ãã¾ãã
å¥ã¦ã£ã³ãã¦ã表示ããã¾ãã
ããããDSAãã¤ã³ã¹ãã¼ã«ããããã®ã¹ã¯ãªããããã¦ã³ãã¼ããããã¨ãã§ãã¾ãã
ä»åã¯AmazonLinux2ã«ã¤ã³ã¹ãã¼ã«ããã®ã§ä»¥ä¸ã鏿ãã¦ããã¾ãã
ãã©ãããã©ã¼ã | LinuxçAgentã®ã¤ã³ã¹ãã¼ã« |
ã»ãã¥ãªãã£ããªã·ã¼ | Base Policy > Linux Server ï¼æå®ãããã«ã¹ã¿ã ããªã·ã¼ãããã°ããã§é¸æï¼ |
ã³ã³ãã¥ã¼ã¿ã°ã«ã¼ã | ã³ã³ãã¥ã¼ã¿ï¼ããã©ã«ãï¼ |
Relayã°ã«ã¼ã | ãã©ã¤ããªããã³ãã®Relayã°ã«ã¼ãï¼ããã©ã«ãï¼ |
Deep Security Managerã¸ã®æ¥ç¶ã«ä½¿ç¨ãããããã· | ãããã·ã鏿ï¼ããã©ã«ãããã®ã¾ã¾ã§è¯ãï¼ |
Relayã¸ã®æ¥ç¶ã«ä½¿ç¨ãããããã· | ãããã·ã鏿ï¼ããã©ã«ãããã®ã¾ã¾ã§è¯ãï¼ |
ä¸ã«ã¹ã¯ãã¼ã«ããã¨ãå®è¡ããã¹ã¯ãªããã確èªã§ãã¾ãã
ããã§ã¯ããã¡ã¤ã«ã«ä¿åãã鏿ããã¹ã¯ãªãããã¡ã¤ã«ããã¦ã³ãã¼ããã¾ãã
ãAgentDeploymentScript.shãã¨ãããã¡ã¤ã«ããã¦ã³ãã¼ãããã¾ãã
ãAgentDeploymentScript.shãããã¨ã«ãã»ãã·ã§ã³ããã¼ã¸ã£ã使ç¨ãã¦DSAãã¤ã³ã¹ãã¼ã«ãã¦ããã¾ãã
AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ãã°ã¤ã³ããAWS Systems Managerã®ãµã¼ãã¹ç»é¢ãèµ·åãã¾ãã
ãã¤ã³ã¹ã¿ã³ã¹ã¨ãã¼ãããããã»ãã·ã§ã³ããã¼ã¸ã£ã¼ãã鏿ãã¾ãã
â»ã»ãã·ã§ã³ããã¼ã¸ã£ã使ç¨ããããã«ã¯ãEC2ã«äºåã«ãAmazonSSMManagedInstanceCoreãã®ããªã·ã¼ãä»ä¸ãããã¼ã«ãã¢ã¿ãããã¦ããå¿
è¦ãããã¾ããå¾è¿°ããã©ã³ã³ãã³ãã§ãåæ§ã§ãã
ã¤ã³ã¹ãã¼ã«ãããEC2ã鏿ãããã»ãã·ã§ã³ã®éå§ãã鏿ãã¾ãã
ãã°ã¤ã³åºæ¥ããrootã¦ã¼ã¶ã«ãªãã¾ãã
sudo su -
ä»»æã®ãã©ã«ãã«ç§»åããã¹ã¯ãªãããã¡ã¤ã«ã使ãã¾ãã
ããã§ã¯ãã¦ã³ãã¼ããããã¡ã¤ã«åã¨åããAgentDeploymentScript.shãã¨ãã¾ããã
cd /tmp vi AgentDeploymentScript.sh
ãã¦ã³ãã¼ãããã¹ã¯ãªãããã¡ã¤ã«ã®å
å®¹ãæ¸ãè¾¼ã¿ãã¹ã¯ãªãããã¡ã¤ã«ãå®è¡ãã¾ãã
bash AgentDeploymentScript.sh
æ«ãå¾
ã¡ãCommand session completed.ãã表示ãããã°ã¤ã³ã¹ãã¼ã«å®äºã§ãã
DSMã«ãã°ã¤ã³ãã¦ã³ã³ãã¥ã¼ã¿ã確èªããã¨ã対象ã¤ã³ã¹ã¿ã³ã¹ã®ã¹ãã¼ã¿ã¹ãã管ç対象ï¼ãªã³ã©ã¤ã³ï¼ãã«ãªãã¾ããã
対象ã¤ã³ã¹ã¿ã³ã¹ã®è©³ç´°ç»é¢ã確èªããã¨ãæå¹ã«ãã¦ããæ©è½æ¯ã«ã¹ãã¼ã¿ã¹ã確èªãããã¨ãã§ãã¾ãã
ã»ãã·ã§ã³ããã¼ã¸ã£ã§åé¡ãªãã¤ã³ã¹ãã¼ã«ã§ãã¾ããã
3.Amazon Linux2ã«ã³ãã³ãã©ã¤ã³ã§Deep Security Agentãã¤ã³ã¹ãã¼ã«
AmazonLinux2ã«å¯¾ãã¦ãAWS Systems Managerã®ã©ã³ã³ãã³ãã§DSAãã¤ã³ã¹ãã¼ã«ãã¦ã¿ã¾ãã
AWS Systems Managerã®ãµã¼ãã¹ç»é¢ãèµ·åãããã¤ã³ã¹ã¿ã³ã¹ã¨ãã¼ãããããã³ãã³ãã®å®è¡ãã鏿ãã¾ãã
ã©ã³ã³ãã³ãã®ããã¥ã¡ã³ããããAWS-RunShellScriptãã鏿ãã¾ãã
â»ä»¥éä»åã¯ãæç¤ºããæä½ä»¥å¤ããã©ã«ãã®ã¾ã¾é²ãã¾ã
ã³ãã³ãã®ãã©ã¡ã¼ã¿ã«ã¯ãDSMãããã¦ã³ãã¼ãããã¹ã¯ãªããã®å
容ãè²¼ãä»ãã¾ãã
ã¿ã¼ã²ããã¯ãChoose instances manuallyãã鏿ããDSAã®ã¤ã³ã¹ãã¼ã«ãã対象ã¨ãªãEC2ã¤ã³ã¹ã¿ã³ã¹ã鏿ãã¾ãã
ã³ãã³ãã失æããå ´åãªã©ã®å
容ã確èªãããå ´åã¯ãCloudWatchåºåããã§ãã¯ãå
¥ãã¾ãã
ããã§ã¯ããã©ã«ãã®ã¾ã¾ãå®è¡ãã鏿ãã¾ãã
ã³ãã³ããå®è¡ãããã¹ãã¼ã¿ã¹ããé²è¡ä¸ããããæåãã«ãªãã¾ã§æ«ãå¾
ã¡ã¾ãã
ã¹ãã¼ã¿ã¹ããæåãã«ãªãã¾ããã
DSMã«ãã°ã¤ã³ãã¦ã³ã³ãã¥ã¼ã¿ã確èªããã¨ã対象ã¤ã³ã¹ã¿ã³ã¹ã®ã¹ãã¼ã¿ã¹ãã管ç対象ï¼ãªã³ã©ã¤ã³ï¼ãã«ãªãã¾ããã
ã»ãã·ã§ã³ããã¼ã¸ã£ã®æã¨åæ§ã対象ã¤ã³ã¹ã¿ã³ã¹ã®è©³ç´°ç»é¢ãããã¹ãã¼ã¿ã¹ãæ£å¸¸ã§ãããã¨ã確èªã§ãã¾ãã
ã©ã³ã³ãã³ãã§åé¡ãªãã¤ã³ã¹ãã¼ã«ã§ãã¾ããã
æå¾ã«
DSaaSã®ãããªãµã¼ãã¹ããæ¤è¨¼ãããã¨ãã«ããã£ã¨ä½¿ããAWS Marketplaceã¯ã¨ã¦ãè¯ãã§ãããMarketplaceããã©ã¤ã»ã³ã¹ãå¥ç´ããDSaaSã®å ´åãèµ·åããåã®æé課éã«ãªãã®ã§ã¨ã¦ããªã¼ãºããã«ã§ãã
対象ã®ã¤ã³ã¹ã¿ã³ã¹ã«ç´æ¥ãã°ã¤ã³ããã«DSAãã¤ã³ã¹ãã¼ã«ãããã¨ãã§ãããã»ãã·ã§ã³ããã¼ã¸ã£ãã©ã³ã³ãã³ãã«ã¤ãã¦ããæ¹ãã¦ä½¿ã£ã¦ã¿ã¦ä¾¿å©ãªæ©è½ã ã¨æãã¾ãããæ´»ç¨ã§ããå ´ãããã°ã©ãã©ã使ã£ã¦ããããã¨æãã¾ãã